Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

CISM Exam Questions & Answers

Certified Information Security Manager  •  Isaca

1191 Questions 240 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample CISM Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following service offerings in a typical Infrastructure as a Service (laaS) model will BEST enable a cloud service provider to assist customers when recovering from a security incident?

Correct Answer: D
Explanation:

A snapshot is a point-in-time copy of the state of a virtual machine (VM) that can be used to restore the VM to a previous state in case of a security incident or a disaster. A snapshot can capture the VM's disk, memory, and device configuration, allowing for a quick and easy recovery of the VM's data and functionality. Snapshots can also be used to create backups, clones, or replicas of VMs for testing, analysis, or migration purposes. Snapshots are a common service offering in Infrastructure as a Service (IaaS) models, where customers can provision and manage VMs on demand from a cloud service provider (CSP).A CSP that offers the capability to take snapshots of VMs can assist customers when recovering from a security incident by providing them with the following benefits12:

Faster recovery time: Snapshots can reduce the downtime and data loss caused by a security incident by allowing customers to quickly revert their VMs to a known good state. Snapshots can also help customers avoid the need to reinstall or reconfigure their VMs after an incident, saving time and resources.

Easier incident analysis: Snapshots can enable customers to perform online or offline analysis of their VMs after an incident, without affecting the production environment. Customers can use snapshots to examine the VM's disk, memory, and logs for evidence of compromise, root cause analysis, or forensic investigation. Customers can also use snapshots to test and validate their incident response plans or remediation actions before applying them to the production VMs.

Enhanced security posture: Snapshots can improve the security posture of customers by enabling them to implement best practices such as backup and restore, disaster recovery, and business continuity. Snapshots can help customers protect their VMs from accidental or malicious deletion, corruption, or modification, as well as from environmental or technical disruptions. Snapshots can also help customers comply with regulatory or contractual requirements for data retention, availability, or integrity.References=What is Disaster Recovery as a Service? | CSA - Cloud Security Alliance,What Is Cloud Incident Response (IR)? CrowdStrike

Q2 MultipleChoice

An organization is in the process of acquiring a new company. Which of the following is the FIRST step to determine how to protect newly acquired data assets prior to integration?

Correct Answer: A
Explanation:

The correct answer is A because the organization must first identify and inventory the newly acquired information assets before determining how to protect them. Without knowing what data assets exist, where they are located, who owns them, how they are used, and what sensitivity or criticality they have, the organization cannot select appropriate controls. Including security requirements in the contract is important during acquisition planning, but the question asks how to protect newly acquired data assets prior to integration. Assessing controls is necessary, but it should be based on a clear understanding of the assets being protected. Reviewing data architecture is useful, but it is also dependent on first identifying the assets and their locations. CISM risk management emphasizes asset identification, ownership, classification, and risk assessment as foundational steps in protecting information. An asset inventory enables classification, impact analysis, access review, control selection, and integration planning. Therefore, inventorying information assets is the correct first step.

Q3 MultipleChoice

An employee who is a remote user has copied financial data from the corporate server to a laptop using virtual private network (VPN) connectivity. Which of the following is the MOST important factor to determine if it should be classified as a data leakage incident?

Correct Answer: D
Q4 MultipleChoice

Due to changes in an organization's environment, security controls may no longer be adequate. What is the information security manager's BEST course of action?

Correct Answer: B
Explanation:

According to the CISM Review Manual, the information security manager's best course of action when security controls may no longer be adequate due to changes in the organization's environment is to perform a new risk assessment. A risk assessment is a process of identifying, analyzing, and evaluating the risks that affect the organization's information assets and business processes. A risk assessment should be performed periodically or whenever there are significant changes in the organization's environment, such as new threats, vulnerabilities, technologies, regulations, or business objectives. A risk assessment helps to determine the current level of risk exposure and the adequacy of existing security controls. A risk assessment also provides the basis for developing or updating the risk treatment plan, which defines the appropriate risk responses, such as implementing new or enhanced security controls, transferring the risk to a third party, accepting the risk, or avoiding the risk.

The other options are not the best course of action in this scenario. Reviewing the previous risk assessment and countermeasures may not reflect the current state of the organization's environment and may not identify new or emerging risks. Evaluating countermeasures to mitigate new risks may be premature without performing a new risk assessment to identify and prioritize the risks. Transferring the new risk to a third party may not be feasible or cost-effective without performing a new risk assessment to evaluate the risk level and the available risk transfer options.

References= CISM Review Manual, 16th Edition, Chapter 2, Section 1, pages 43-45.

Q5 MultipleChoice

Which of the following BEST encourages staff to report issues related to information security?

Correct Answer: C
Explanation:

The correct answer is C because staff are more likely to report information security issues when leadership establishes a positive security culture. A positive culture encourages openness, trust, accountability, and timely reporting without fear of unfair blame. In CISM governance, information security is not only a technical function; it depends heavily on behavior, communication, leadership support, and organizational values. Tabletop exercises are useful for testing incident response readiness, but they do not necessarily encourage everyday reporting by all staff. Incentives for security skills training may improve participation in learning activities, but they do not directly create a reporting culture. Formal incident response processes are important because they define how incidents are handled, but processes alone may not motivate employees to report concerns if the culture is negative or punitive. Leadership behavior is critical because employees follow the tone set by management. Therefore, leaders setting a positive security culture is the best way to encourage staff to report information security issues.

Get access to all 1191 verified questions with detailed answers.

Unlock All CISM Questions

Frequently Asked Questions

To be eligible for CISM certification, you must have a minimum of 5 years of professional information security management experience, with at least 3 years in information security management roles. ISACA may waive up to 2 years of the experience requirement if you hold certain qualifying certifications like CISSP or CISA.

The CISM exam is 4 hours long and consists of 150 multiple-choice questions. You must achieve a minimum scaled score of 450 out of 800 to pass the exam.

The CISM exam covers four main domains: Information Security Governance (23%), Information Risk Management (25%), Information Security Program Development and Management (28%), and Information Security Incident Management (24%). Each domain tests your knowledge and competency in critical information security management areas.

If you fail the CISM exam, you can retake it after 30 days have passed from your previous attempt. There is no limit to the number of times you can retake the exam, though you must pay the exam fee each time.

The CISM exam typically costs between $500-$700 USD depending on your location and member status with ISACA. Additionally, there is an annual maintenance fee of around $85 to maintain your active certification after passing the exam and meeting experience requirements.
Exam Details
  • Exam CodeCISM
  • VendorIsaca
  • Total Questions1191
  • Duration240 min
  • LanguageEnglish
  • Last UpdatedSep 6, 2026
4.9/5

Pass CISM First Time

Get all 1191 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals