ISACA · CISM
Validates expertise in information security governance, risk management, program development, and incident management for experienced security professionals.
Practice Questions
1,196
≈ 7 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
Use this CISM practice exam to prepare for Certified Information Security Manager (CISM) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 1,196 questions for ISACA CISM, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified Information Security Manager (CISM) is a globally recognized credential awarded by ISACA that validates expertise in managing, designing, and overseeing enterprise information security programs. First introduced in 2002, the certification has been earned by more than 107,000 professionals worldwide and was recognized as the 2025 Best Professional Certification Program. CISM is distinguished from technical certifications by its emphasis on governance, strategic alignment, and business outcomes — validating a practitioner's ability to bridge the gap between information security and organizational objectives.
The credential covers four core practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Together, these domains assess a candidate's ability to establish security frameworks aligned with business goals, identify and manage information risk, develop and oversee a security program from inception through continuous improvement, and lead effective incident response and recovery operations. A forthcoming content outline update effective November 3, 2026 will reflect evolving job practice areas, with updated preparation materials available in September 2026.
CISM is designed for experienced information security professionals who have transitioned — or are seeking to transition — from purely technical roles into management and leadership positions. Ideal candidates include information security managers, IT directors, risk managers, security consultants, and compliance officers who are responsible for overseeing enterprise security strategy rather than executing day-to-day technical tasks.
Candidates typically have at least five years of professional information security work experience, with at least three years in security management roles across the CISM domains. The certification is particularly well-suited for professionals in financial services, healthcare, government, and technology sectors where security governance and risk oversight are critical organizational functions.
ISACA does not impose formal prerequisites for sitting the CISM exam — candidates may register and take the exam at any time. However, to apply for the full certification after passing, candidates must demonstrate a minimum of five years of professional information security management work experience within the CISM job practice domains. At least three of those five years must be in information security management. This experience must have been gained within the ten-year period preceding the certification application date, and candidates have five years from their exam passing date to submit their application.
While no specific prior certifications are required, a solid foundation in information security concepts, IT governance frameworks (such as COBIT or ISO/IEC 27001), risk management methodologies, and incident response principles is strongly recommended. Familiarity with regulatory and compliance environments relevant to one's industry will also be beneficial given the governance-heavy nature of the exam.
The CISM exam consists of 150 multiple-choice questions, all of which are scored. The exam is administered over a four-hour time limit. It is delivered as a computer-based test, available either at authorized PSI testing centers worldwide or via remote proctoring, giving candidates flexible delivery options. Registration is continuous — there are no fixed testing windows — and candidates can schedule an appointment as early as 48 hours after payment of the exam registration fee, up to 90 days in advance.
Scoring is reported on a scale of 200 to 800, with a passing score of 450. Questions are designed to assess practical, job-relevant judgment rather than rote memorization, drawing on real-world information security management scenarios. Exam fees are $575 USD for ISACA members and $760 USD for non-members, plus a $50 certification application fee upon passing.
CISM holders command some of the highest salaries in the information security field. U.S.-based professionals with the certification earn an average of approximately $140,000–$150,000 annually, with total compensation averaging above $165,000 when bonuses and benefits are included. Professionals who advance to CISO-level positions — a common trajectory for CISM holders — report average total compensation exceeding $300,000 at large enterprises. Most newly certified professionals report salary increases of $15,000 to $30,000 within their first year, and combining CISM with CISSP can command an additional 10–20% premium in many markets.
The certification opens doors to senior leadership roles including Information Security Manager, Security Director, Chief Information Security Officer, Risk Manager, and IT Compliance Manager across virtually every industry vertical. Government agencies and defense contractors frequently list CISM as a required or preferred credential for security management positions. With the U.S. Bureau of Labor Statistics projecting 33% job growth for information security analysts through 2033 and cybercrime costs projected at $10.5 trillion globally in 2025, demand for credentialed security managers remains strong. CISM's emphasis on business alignment and governance makes it particularly compelling to executive hiring managers who need security leaders who can communicate risk in terms of business impact.
5 sample questions with answers and explanations. The full bank has 1,196 questions, enough for 7 full-length practice exams.
Preview — answers shown1. A security manager conducts quantitative risk analysis for a database breach scenario using the FAIR methodology. The analysis determines Loss Event Frequency of 0.4 events per year with a loss magnitude distribution ranging from $200,000 to $2,000,000. Monte Carlo simulation with 10,000 iterations produces a mean Annualized Loss Expectancy of $680,000. Management questions why a single number is insufficient. What is the PRIMARY advantage of using Monte Carlo simulation over simple ALE calculations? (Select one!)
Explanation
Monte Carlo simulation generates a probability distribution showing the full range of possible outcomes and their relative likelihoods, enabling risk-informed decision making beyond simple averages. This communicates uncertainty and helps management understand confidence intervals. Monte Carlo does not provide a single-point estimate but rather a distribution. Subject matter expert judgment is still required for input parameters. Monte Carlo may increase assessment complexity and time but provides more defensible results for strategic decisions.
2. A global enterprise implements cloud services across IaaS, PaaS, and SaaS models. The security manager must ensure the organization understands security responsibilities under the shared responsibility model. The CISO asks which security controls remain the customer's responsibility regardless of cloud service model. Which two controls are always the customer's responsibility across all cloud service models? (Select two!)
Multiple correct answersExplanation
Data classification and protection, along with identity and access management for user accounts, remain the customer's responsibility regardless of whether the organization uses IaaS, PaaS, or SaaS. The cloud provider never assumes responsibility for classifying customer data or determining who should have access to it. Physical datacenter security is always the provider's responsibility across all service models. Hypervisor security is the provider's responsibility in all cloud models. Operating system patching is the customer's responsibility in IaaS but becomes the provider's responsibility in PaaS and SaaS environments.
3. During a risk assessment workshop, the security manager calculates that a database server worth 200000 USD has a 40 percent exposure factor for data corruption events that occur twice per year. A proposed backup solution costing 25000 USD annually would reduce the annualized rate of occurrence to 0.5 times per year. Should the organization implement this safeguard? (Select one!)
Explanation
To calculate safeguard value, first determine ALE before and after the control. ALE before equals SLE times ARO. SLE equals 200000 times 0.40 equals 80000. ALE before equals 80000 times 2 equals 160000. ALE after equals 80000 times 0.5 equals 40000. Safeguard value equals ALE before minus ALE after minus annual control cost, which equals 160000 minus 40000 minus 25000 equals 95000. Since the value is positive, the control is cost-justified. The other options misapply the formula or make incorrect assumptions about cost-benefit relationships.
4. An organization implements COBIT 2019 governance framework. The board establishes strategic direction and risk appetite while executive management implements security controls and monitors operational metrics. Which COBIT 2019 principle does this organizational structure demonstrate? (Select one!)
Explanation
COBIT 2019 explicitly distinguishes governance from management as a core principle. Governance involves board-level evaluation, direction, and monitoring of strategic objectives, while management executes operational activities through planning, building, running, and monitoring. The scenario demonstrates this separation where the board sets direction and risk appetite while management implements and monitors. Tailoring addresses customization to enterprise context. Holistic approach concerns enterprise-wide integration. Dynamic governance addresses adaptation over time.
5. A retail organization evaluates disaster recovery options for its e-commerce platform that generates 2 million dollars in daily revenue. Business requirements specify maximum tolerable downtime of 8 hours and maximum acceptable data loss of 30 minutes. The security manager must recommend a recovery site strategy. Which recovery site type meets these requirements at the lowest cost? (Select one!)
Explanation
Hot site is required to meet the 8-hour MTD and 30-minute RPO requirements. Hot sites maintain fully operational duplicate infrastructure with real-time or near-real-time data replication, enabling recovery within minutes to hours. The 30-minute RPO requirement demands continuous or very frequent replication that only hot sites provide. Warm sites rely on periodic backups, typically daily or hourly, which cannot meet 30-minute data loss requirements. Even if warm sites could meet RTO through fast hardware activation, the RPO requirement eliminates this option. Cold sites require days or weeks for equipment procurement and setup, far exceeding MTD. Mobile sites have variable activation times and typically cannot support real-time replication. While hot sites represent the highest ongoing cost, the business impact of 2 million dollars daily revenue and 8-hour MTD justifies the investment. The cost calculation must consider revenue loss during downtime: 8 hours represents approximately 666000 dollars in lost revenue, making hot site investment financially prudent. Security managers must align technical solutions with business impact and recovery requirements.
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
$17.99
One-time access to this exam