CISM
Certified Information Security Manager
Management-focused credential covering security governance, risk management, program development, and incident management, built for security leaders.
252 original CISM practice questions, every one citing a public source you can open and check. Spaced-repetition flashcards, an AI tutor on any question, and mock exams paced to the real CISM clock. No ads, no data collection.
Sitting it soon? CISM exam format, cost and passing score, each figure sourced from ISACA and dated.
Or read 4 free CISM practice questions first. No account needed.
- Exam length
- 240 min
- Pass score
- 450/800 (scaled)
- Questions
- 150
- Domains
- 4
Suggested prep: 8–12 weeks · Difficulty: Expert
Where do you stand on CISM?
Ten CISM practice questions, drawn across every exam domain and weighted the way the real exam is. You get your score, the explanation for anything you miss, and the public source each answer is based on.
No account, no email, no card. Nothing is saved.
Free CISM practice questions
One question per exam domain, 4 in all, each with the answer, the reasoning behind it, and the public source it was written from. Read them here with no account. These are original questions written against the published exam outline, not real exam items.
Question 1 · Information Security Governance
A ride-hailing firm plans to launch in a country whose law requires rider records to stay in-country. Engineering needs nine months to re-architect; the commercial team announced a launch in three. What is the BEST recommendation?
- APropose a compensating control such as encrypting the affected records with keys held in-country, and treat that as satisfying the requirement
- BLaunch on the announced date and remediate afterwards, treating the interim gap as a risk documented and accepted by the manager
- CRecommend deferring the launch until the architecture change is complete, since a legal requirement cannot be accepted as a risk
- DAdvise that legal counsel pursue an exemption or informal forbearance while engineering proceeds with the launch as planned
- EPresent the legal obligation, the viable launch options and the exposure attached to each to the executives who own the market entry decision
Show answer and explanation
Correct answer
Present the legal obligation, the viable launch options and the exposure attached to each to the executives who own the market entry decision
Market entry is a business decision with legal consequences, so the manager's role is to make the obligation and the option space visible to the accountable executives rather than to select the outcome alone. Launching with a documented acceptance treats a statutory duty as if it were a discretionary risk the manager may accept. Pursuing forbearance while proceeding assumes an outcome not yet obtained. Declaring in-country key custody sufficient is a technical judgement about legal adequacy that only counsel can make. Unilaterally recommending deferral is closer to correct but still substitutes the manager's judgement for the decision owner's.
Source: NIST IR 8286C, Staging Cybersecurity Risks for Enterprise Risk Management and Governance Oversight
Question 2 · Information Security Risk Management
Two analysts rate the same ransomware scenario differently, one citing sector breach reporting, the other ten years without an incident. Both rationales are defensible. How can the manager make assessments repeatable?
- AAverage the two ratings and record the midpoint as the agreed likelihood for the ransomware entry in the register
- BInstruct analysts to rely only on internal incident history so that every rating is grounded in observed fact rather than opinion
- CEscalate each disagreement of this kind to the risk committee so that it adjudicates between the two ratings and sets one
- DDefine and publish shared likelihood criteria covering what evidence counts and how threat capability and targeting are weighed
Show answer and explanation
Correct answer
Define and publish shared likelihood criteria covering what evidence counts and how threat capability and targeting are weighed
A documented assessment approach with defined scales and stated evidence rules is what makes results repeatable, comparable and defensible when challenged. Averaging conceals a methodological disagreement behind a number and would produce a different answer with a different pair of analysts. Restricting evidence to internal history systematically underestimates threats the firm has not yet experienced, which is precisely the ransomware case being argued. Escalating individual disagreements does not scale to a full register and puts the risk committee in the analyst's seat instead of the decision maker's.
Source: NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments
Question 3 · Information Security Program
A manager proposed allowlisting on packaging line workstations. Engineering says recipe changes several times per shift would each need approval, halting production. Risk remains above appetite. What should the manager do NEXT?
- AWithdraw the proposal and record the risk as accepted by manufacturing engineering, which owns the production impact
- BImplement the allowlisting as proposed, since the assessed risk already exceeds the organization's stated risk appetite
- CIdentify compensating controls with engineering that meet the security objective, then present the residual risk to the risk owner
- DEscalate to the chief executive and request a directive requiring manufacturing engineering to comply with the control
Show answer and explanation
Correct answer
Identify compensating controls with engineering that meet the security objective, then present the residual risk to the risk owner
When a selected control conflicts with an operational requirement, the manager looks for an alternative that achieves the same security objective and then reports the remaining risk to the accountable owner for a decision. Forcing the original control ignores a legitimate business impact, walking away leaves an above-appetite risk untreated and misassigns acceptance, and escalating for a directive skips the analysis that would tell executives whether the conflict has a workable solution.
Source: NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations
Question 4 · Incident Management
Attackers are active on a port segment including crane control systems. The security lead wants immediate isolation; the operations director objects that three vessels are mid-discharge. What should the security manager do?
- AConvene the incident commander and the operations business owner to weigh operational consequence against security risk and record the decision
- BEscalate directly to the chief executive so that the most senior available authority makes the call on interrupting operations
- CInstruct the security team to isolate the segment immediately, because containing attacker access always takes precedence over commercial impact
- DDefer to the terminal operations director, since the accountable business owner is entitled to decide when their systems are interrupted
Show answer and explanation
Correct answer
Convene the incident commander and the operations business owner to weigh operational consequence against security risk and record the decision
Containment is a risk decision with business consequences, and the plan's role is to bring the technical assessment and the operational consequence together under someone empowered to choose and to be accountable for the choice. Isolating unilaterally treats security as superior to the business it exists to protect. Deferring wholly to operations lets commercial pressure decide a risk question without the security assessment in the balance. Jumping to the chief executive bypasses the governance structure that was built precisely to resolve this, and adds delay while the attacker remains active.
Domain breakdown
Official weights from the ISACA exam outline. We track your mastery on each domain individually so you know where to focus.
These are the weights in force today. ISACA's 2026 exam content outline takes effect 3 November 2026, and this breakdown switches to it on that date.
Exam transition
The 2026 CISM outline: what changes on 3 November 2026
Old and new domain weights side by side from ISACA, the two new content areas, and what it means if you test before or after the change.
Guides for CISM
- Exam transitionThe 2026 CISM outline: what changes on 3 November 2026Old and new domain weights side by side from ISACA, the two new content areas, and what it means if you test before or after the change.
- The CISM exam changes November 3, 2026: what's new and when to testThe November 2026 CISM update adds architecture content areas and shifts emphasis toward program and strategy. Here is what actually changes and how to time your test date.
- From Security+ to CISSP: the 3-cert career roadmapMost people who earn the CISSP started somewhere else. Here is the path that makes sense based on your experience level.
Study strategy for any certification
- Why spaced repetition beats cramming for technical examsThe cognitive science behind SM-2, and why most cert-prep tools still ignore it.
- Study by domain weight, not by comfortThe domain you enjoy reviewing and the domain worth the most exam points are usually not the same one. Here is how to let the blueprint, not your comfort level, set your study time.
- Interleaved Practice: Why Mixing Domains Beats Studying One at a TimeStudying one domain until it feels mastered, then moving to the next, is the intuitive approach. It's also weaker than mixing domains from day one.
CISM FAQ
How many questions are on the CISM exam?
The ISACA CISM exam has 150 questions and runs 240 minutes. A passing score is 450/800 (scaled).
What domains does CISM cover?
4 domains, per the official ISACA outline: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), Incident Management (30%).
How long should I study for CISM?
Typical prep time is 8–12 weeks, depending on your experience. TierOne's spaced-repetition queue is built for short daily sessions, so progress compounds even on a busy schedule.
Can I try CISM practice questions for free?
Yes. The free tier includes 25 CISM practice questions spread across every exam domain, each with a cited source, the Question of the Day, and the AI tutor (5 explanations per day). No credit card required.
Is there a pass guarantee?
Yes. If you fail your CISM exam after 30 or more days on Pro, send us your score report and choose 3 free months or a full refund.
Is the CISM exam changing in 2026?
Yes. ISACA's updated CISM exam content outline takes effect 3 November 2026, and exams taken on or after that date reflect it. The four domains keep their names; Information Security Governance moves from 17% to 18% and Incident Management from 30% to 29%, while Risk Management (20%) and Program (33%) are unchanged. ISACA also adds enterprise architecture and information security architecture as content areas and puts greater emphasis on strategy and program development.
Ready to start prepping for the CISM?
Sign up free in 30 seconds. Take a Quick Quiz to see where you stand. The platform handles the rest.
Not affiliated with or endorsed by ISACA. CISM is a trademark of its owner.