dc dotCreds
ISACA CISM Practice Test

CISM Practice Test

Start today’s free 10-question CISM set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 16, 2026, 2:12 AM CDT

Go Pro - One Time Unlock

Unlock the full CISM bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CISM questions

Use this CISM practice test to review ISACA Certified Information Security Manager. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Business Impact Analysis (BIA) 4. Incident Management (30%)

During a business impact analysis (BIA) for a critical system, the ISCP Coordinator discovers that the recovery effort requires significant resources, including specialized hardware and personnel. To ensure a realistic and effective contingency plan, what is the most critical step the Coordinator should undertake?

Concept tested:
Question 2 of 10
Objective Organizational Structures, Roles and Responsibilities 1. Information Security Governance (17%)

The organization's Supply Chain Risk Management (SCRM) policy aims to support organizational policies and align with the strategic plan. To ensure this alignment, what action should the SCRM manager prioritize?

Concept tested:
Question 3 of 10
Objective Incident Investigation and Evaluation 4. Incident Management (30%)

A security analyst has identified a potential phishing campaign targeting employees. The analyst’s investigation reveals that several employees have clicked on links in the emails, and preliminary data suggests that some have entered their credentials on a fraudulent website. Given the need to safeguard incident response records and the incident lead’s responsibility for record protection, what is the most appropriate initial action to take?

Concept tested:
Question 4 of 10
Objective Emerging Risk and Threat Landscape 2. Information Security Risk Management (20%)

A government agency is assessing the cybersecurity risks associated with a new software vendor. The agency’s C-SCRM strategy requires a layered approach to risk management. Given the agency’s discretion regarding baseline risk factors, what is the most prudent course of action when a credible finding indicates a substantial supply chain risk?

Concept tested:
Question 5 of 10
Objective Information Security Control Implementation and Integrations 3. Information Security Program (33%)

An audit confirms that security controls were implemented exactly as documented, but the organization has entered a higher-risk market and leadership has reduced its risk tolerance. Before declaring the controls effective, what should the security manager evaluate?

Concept tested:
Question 6 of 10
Objective Information Security Strategy Development 1. Information Security Governance (17%)

The CISM is tasked with reviewing the organization’s continuous monitoring strategy. The strategy currently relies on a limited set of metrics and lacks a formal process for updating it. What is the MOST effective action the CISM should recommend to improve the strategy’s effectiveness?

Concept tested:
Question 7 of 10
Objective Risk Treatment / Risk Response Options 2. Information Security Risk Management (20%)

A risk assessment of a core banking service concludes that exploitation of an unpatched weakness has a high likelihood and could cause severe business impact. The assessment is complete. What should the information security manager do NEXT?

Concept tested:
Question 8 of 10
Objective Information Security Program Metrics 3. Information Security Program (33%)

The board receives large volumes of compliance metrics, but the security program cannot explain whether control performance is changing risk or whether management should alter a risk response. What should the information security manager establish to make monitoring decision-useful?

Concept tested:
Question 9 of 10
Objective Information Governance Frameworks and Standards 1. Information Security Governance (17%)

A business unit deploys environmental sensors that can transmit collected data to several analytics services. The security policy states that sensor information may be reported only to authorized individuals or roles. What should the information security manager require the control owner to verify?

Concept tested:
Question 10 of 10
Objective Incident Management Tools and Techniques 4. Incident Management (30%)

The organization consistently discovers intrusions late in the attack life cycle, after attackers have expanded their foothold. What capability should the CISM prioritize to improve early detection?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CISM Pro $4.99 one-time

Unlock all 200 CISM questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question CISM PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, Certified Ethical Hacker, ISC2 CISSP, ISC2 CCSP, ISACA CISM, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CISM bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CISM practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CISM set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 During a business impact analysis (BIA) for a critical system, the ISCP Coordinator discovers that the recovery effort requires significant resources, including specialized hardware and personnel. To ensure a realistic and effective contingency plan, what is the most critical step the Coordinator should undertake?

Answer choices

  1. A. Immediately allocate the required resources to the system, regardless of cost.
  2. B. Request a formal change order to increase the system’s budget.
  3. C. Develop a detailed resource requirements table, documenting all necessary components and their associated costs.
  4. D. Prioritize recovery efforts based solely on business criticality, without considering resource availability.

Correct answer

Develop a detailed resource requirements table, documenting all necessary components and their associated costs.

A realistic contingency plan hinges on accurately identifying and documenting all necessary resources. This table provides a clear understanding of the requirements for effective recovery.

Wrong-answer review

  • A. Immediately allocate the required resources to the system, regardless of cost.: Allocating resources without proper assessment can lead to unnecessary expenses and may not guarantee effective recovery if the wrong resources are assigned.
  • B. Request a formal change order to increase the system’s budget.: Requesting a budget change is a reactive measure and doesn't address the core need for understanding and planning for resource requirements.
  • D. Prioritize recovery efforts based solely on business criticality, without considering resource availability.: Ignoring resource availability can lead to unrealistic recovery timelines and potentially compromise the system's restoration, undermining the entire contingency plan.

Extra learning features

Why candidates miss this

The ‘immediately allocate’ choice is tempting because it appears proactive. However, it lacks the crucial step of assessment, potentially leading to wasteful spending and an ineffective recovery. The decisive clue is the emphasis on ‘realistic’ and ‘effective’ contingency plans, highlighting the need for a thorough evaluation before action. Likely wrong answer: Immediately allocate the required resources to the system, regardless of cost. Review focus: Contingency Planning Guide (NIST SP 800-34 Rev. 1)

Why this matters

Understanding the criticality of resource requirements during a BIA directly impacts the ability to allocate sufficient resources for a successful recovery effort. Without this understanding, the recovery plan will be unrealistic, leading to prolonged downtime and potentially significant financial losses. This understanding is crucial for effective business continuity and minimizing operational disruption. The consequence is a prolonged outage and lost revenue.

Objective/domain: 4. Incident Management (30%)

Source: Contingency Planning Guide (NIST SP 800-34 Rev. 1)

Question 2 The organization's Supply Chain Risk Management (SCRM) policy aims to support organizational policies and align with the strategic plan. To ensure this alignment, what action should the SCRM manager prioritize?

Answer choices

  1. A. Compare the SCRM policy with the strategic plan for gaps.
  2. B. Establishing a cross-functional team to oversee policy development and integration.
  3. C. Prioritizing policy updates based on the most recent executive orders.
  4. D. Solely focusing on legal and regulatory compliance requirements.

Correct answer

Compare the SCRM policy with the strategic plan for gaps.

Objective/domain: 1. Information Security Governance (17%)

Source: Risk Management Framework (NIST SP 800-37 Rev. 2)

Question 3 A security analyst has identified a potential phishing campaign targeting employees. The analyst’s investigation reveals that several employees have clicked on links in the emails, and preliminary data suggests that some have entered their credentials on a fraudulent website. Given the need to safeguard incident response records and the incident lead’s responsibility for record protection, what is the most appropriate initial action to take?

Answer choices

  1. A. Immediately notify all employees of the phishing campaign and provide updated security awareness training
  2. B. Conduct a full forensic audit of all affected employee workstations
  3. C. Initiate a legal action against the sender of the phishing emails, seeking damages and potential criminal charges
  4. D. Securely preserve all relevant logs and data from the compromised systems and email servers, restricting access to authorized personnel only

Correct answer

Securely preserve all relevant logs and data from the compromised systems and email servers, restricting access to authorized personnel only

Objective/domain: 4. Incident Management (30%)

Source: Incident Response Recommendations (NIST SP 800-61 Rev. 3)

Question 4 A government agency is assessing the cybersecurity risks associated with a new software vendor. The agency’s C-SCRM strategy requires a layered approach to risk management. Given the agency’s discretion regarding baseline risk factors, what is the most prudent course of action when a credible finding indicates a substantial supply chain risk?

Answer choices

  1. A. Accept the identified risks and continue with the project, monitoring the vendor’s performance.
  2. B. Conduct a comprehensive risk assessment, inclusive of all baseline risk factors, and perform robust research.
  3. C. Immediately terminate the contract with the vendor.
  4. D. Request a detailed explanation from the vendor regarding the identified vulnerabilities.

Correct answer

Conduct a comprehensive risk assessment, inclusive of all baseline risk factors, and perform robust research.

Objective/domain: 2. Information Security Risk Management (20%)

Source: Cybersecurity Supply Chain Risk Management Practices (NIST SP 800-161 Rev. 1)

Question 5 An audit confirms that security controls were implemented exactly as documented, but the organization has entered a higher-risk market and leadership has reduced its risk tolerance. Before declaring the controls effective, what should the security manager evaluate?

Answer choices

  1. A. Whether the organization has increased the total number of controls since entering the new market.
  2. B. Whether additional automation can reduce the effort required to monitor the existing controls.
  3. C. Whether the controls satisfy every regulatory framework that could potentially apply to the new market.
  4. D. Whether the controls remain correctly implemented and the security plan still meets current organizational needs and risk tolerance.

Correct answer

Whether the controls remain correctly implemented and the security plan still meets current organizational needs and risk tolerance.

Objective/domain: 3. Information Security Program (33%)

Source: Information Security Continuous Monitoring (NIST SP 800-137)

Question 6 The CISM is tasked with reviewing the organization’s continuous monitoring strategy. The strategy currently relies on a limited set of metrics and lacks a formal process for updating it. What is the MOST effective action the CISM should recommend to improve the strategy’s effectiveness?

Answer choices

  1. A. Mandate the use of a specific set of industry-standard security metrics
  2. B. Conduct a comprehensive security audit to identify all potential vulnerabilities
  3. C. Implement automated monitoring tools across all systems to reduce the burden on staff
  4. D. Establish regular strategy reviews for relevance and business alignment.

Correct answer

Establish regular strategy reviews for relevance and business alignment.

Objective/domain: 1. Information Security Governance (17%)

Source: Information Security Continuous Monitoring (NIST SP 800-137)

Question 7 A risk assessment of a core banking service concludes that exploitation of an unpatched weakness has a high likelihood and could cause severe business impact. The assessment is complete. What should the information security manager do NEXT?

Answer choices

  1. A. Present the risk determination to the appropriate risk decision maker.
  2. B. Repeat the assessment using a different methodology until the rating changes
  3. C. Archive the assessment because risk response is outside the risk-management process
  4. D. Automatically patch every affected system without considering operational impact or response authority

Correct answer

Present the risk determination to the appropriate risk decision maker.

Objective/domain: 2. Information Security Risk Management (20%)

Source: Guide for Conducting Risk Assessments (NIST SP 800-30 Rev. 1)

Question 8 The board receives large volumes of compliance metrics, but the security program cannot explain whether control performance is changing risk or whether management should alter a risk response. What should the information security manager establish to make monitoring decision-useful?

Answer choices

  1. A. A one-time enterprise risk assessment that replaces routine control monitoring until the next annual review.
  2. B. A continuous-monitoring strategy and program that converts control-effectiveness data into information used for risk-response decisions.
  3. C. A requirement to deploy the same security controls to every system so compliance metrics become easier to compare.
  4. D. A reporting model focused only on regulatory evidence because compliance measures are the most objective security indicators.

Correct answer

A continuous-monitoring strategy and program that converts control-effectiveness data into information used for risk-response decisions.

Objective/domain: 3. Information Security Program (33%)

Source: Information Security Continuous Monitoring (NIST SP 800-137)

Question 9 A business unit deploys environmental sensors that can transmit collected data to several analytics services. The security policy states that sensor information may be reported only to authorized individuals or roles. What should the information security manager require the control owner to verify?

Answer choices

  1. A. Every sensor user authenticates with a hardware token regardless of the data being collected
  2. B. Sensor data is retained indefinitely so that every transmission can be reconstructed
  3. C. All sensors are disabled whenever the business unit is not actively reviewing the data
  4. D. The sensor reporting paths and configurations restrict collected information to authorized recipients

Correct answer

The sensor reporting paths and configurations restrict collected information to authorized recipients

Objective/domain: 1. Information Security Governance (17%)

Source: Security and Privacy Controls (NIST SP 800-53 Rev. 5)

Question 10 The organization consistently discovers intrusions late in the attack life cycle, after attackers have expanded their foothold. What capability should the CISM prioritize to improve early detection?

Answer choices

  1. A. Integrate cyber threat intelligence into monitoring and detection processes.
  2. B. Delay alert investigation until multiple detection tools independently confirm the activity.
  3. C. Increase the frequency of post-incident management reports.
  4. D. Require annual security awareness training before employees receive network access.

Correct answer

Integrate cyber threat intelligence into monitoring and detection processes.

Objective/domain: 4. Incident Management (30%)

Source: Incident Response Recommendations (NIST SP 800-61 Rev. 3)

Where to go after the daily web set

How are CISM questions generated?

dotCreds builds CISM practice questions from public exam objectives and ISACA exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CISM practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.