TechNuggets Academy
CISM

Free Certified Information Security Manager Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$5754 exam domainsLevel Advanced2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Information Security Governance
A CISM has been asked by the board of directors to report on the effectiveness of the information security program. Which metric would BEST demonstrate value delivery to the board?
Boards care about business outcomes, not technical activity counts. Showing a measurable reduction in residual risk tied to business objectives demonstrates that the security program is delivering value in terms the board can act on — this is the essence of governance reporting under CISM.
Question 2 of 12 · Domain 2: Information Security Risk Management
A financial institution's senior management wants to know the specific monetary impact before approving budget for a new fraud-detection control. Which risk assessment approach should the information security manager use?
Quantitative assessment using ALE produces monetary figures that directly support a cost-benefit budget justification to senior management.
Question 3 of 12 · Domain 3: Information Security Program
An organization is developing a new customer-facing web application. The security manager wants to ensure security requirements are addressed with the LEAST cost and rework to the project. At which point in the SDLC should security requirements be integrated?
Integrating security requirements during requirements/design (a 'shift-left' approach) allows controls to be architected into the system from the start, minimizing costly rework compared to adding controls later.
Question 4 of 12 · Domain 4: Incident Management
A ransomware attack encrypts files on several workstations in a manufacturing plant's engineering network segment. The incident manager confirms the malware is actively spreading via SMB shares. What is the BEST immediate containment action?
Segment isolation stops lateral spread while preserving evidence and business operations elsewhere, which is the core containment objective in incident management before eradication or recovery begins.
Question 5 of 12 · Domain 1: Information Security Governance
The information security manager and a business unit director disagree on whether a new cloud application meets the organization's security policy before go-live. The business director wants to proceed regardless. What should the information security manager do FIRST?
Governance structures exist precisely to resolve conflicts between business needs and security requirements. The information security manager's role is to formally escalate unresolved risk decisions to the appropriate governance body (e.g., steering committee or senior management) so an informed risk-based decision can be made and documented, not to unilaterally block or silently accept the risk.
Question 6 of 12 · Domain 2: Information Security Risk Management
The board has approved a risk appetite statement stating the organization will accept no more than $500,000 in annual expected loss from cyber risk. A business unit's risk assessment shows an annualized loss expectancy of $750,000 for a specific threat. What should the information security manager do NEXT?
When measured risk exceeds the board-approved appetite, the security manager's role is to present the risk owner and management with treatment options to reduce exposure to an acceptable level.
Question 7 of 12 · Domain 3: Information Security Program
A security manager must select a control framework to align IT and security objectives with overall enterprise goals, provide governance guidance to executive management, and demonstrate business value of the security program. Which framework BEST meets this requirement?
COBIT is an IT governance and management framework specifically designed to align IT and security objectives with enterprise goals and provide governance-level guidance and value demonstration to executives.
Question 8 of 12 · Domain 4: Incident Management
A financial institution's business impact analysis states that for the core payment processing system, no more than 15 minutes of transaction data can be lost in any outage. Which metric does this requirement define?
RPO defines the maximum acceptable amount of data loss measured in time, which directly determines backup and replication frequency requirements.
Question 9 of 12 · Domain 1: Information Security Governance
Which governance body is PRIMARILY responsible for ensuring that the information security strategy remains aligned with changing business objectives?
The information security steering committee, composed of senior business and IT stakeholders, is the governance body chartered to review and align the security strategy with evolving business objectives, approve major initiatives, and provide oversight — a core CISM governance concept.
Question 10 of 12 · Domain 2: Information Security Risk Management
A vulnerability scan identifies a critical unpatched vulnerability on a legacy application server supporting the finance department's month-end closing process. Who should be assigned as the risk owner responsible for accepting or treating this risk?
Risk ownership should reside with the business process owner, who understands the operational impact and has the authority to accept, treat, or fund remediation of the risk.
Question 11 of 12 · Domain 3: Information Security Program
An enterprise has outsourced its security operations center to a managed security service provider (MSSP). The security manager wants to ensure the MSSP consistently identifies and escalates critical alerts within the contracted time frame on an ongoing basis. Which mechanism is MOST effective for monitoring this performance?
Recurring SLA-based KPI reporting with defined escalation-time metrics gives continuous, measurable visibility into the MSSP's actual detection and escalation performance over time.
Question 12 of 12 · Domain 4: Incident Management
A post-incident review determines that a breach occurred through a server that had a known critical patch available for six months, despite an existing patch management policy requiring 30-day remediation. What is the MOST appropriate corrective action for the information security manager to recommend?
Effective post-incident review requires identifying and correcting the underlying process failure that allowed the exposure to persist, then verifying the fix prevents recurrence across all similar assets, which is the essence of lessons-learned management.
Ready for the real thing?

The full course: two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed explanations.

undefined $34.99 with code FREETEST33 — valid through Oct 6.

Get my $34.99 deal →

CISM exam — quick answers

How much does the CISM exam cost?

The exam fee is approximately $575 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 4 domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), Incident Management (30%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

How do I get the discount?

Use code FREETEST33 at checkout for $34.99 (list undefined) through Oct 6 — the enroll button applies it automatically.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Information Security Governance →Information Security Risk Management →Information Security Program →Incident Management →