Try 12 free ISACA CISM practice questions
Real exam-style questions taken word for word from the ISACA CISM study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Certified Information Security Manager (CISM) exam expects.
Question 1. A remote employee copied financial data from a corporate server to a personal laptop using an approved VPN connection. Which of the following is the MOST important factor in determining whether this event constitutes a data leakage incident?
- A. Whether the audit logs capture the full details of the data transfer
- B. Who holds ownership of the financial data that was copied
- C. The specific job role and title held by the employee
- D. Whether a legitimate business purpose exists for the data transfer
Show the answer
Answer: D. The existence of a valid, authorized use case is the deciding factor because if the employee had a legitimate business need to access and copy the data, the transfer is an authorized activity and not an incident. Ownership, job role, and audit logs are all relevant supporting details, but none of them determines whether the act itself was authorized. A transfer that lacks a valid business justification meets the threshold for a data leakage incident regardless of the other factors.
- A: Audit logs document what occurred and support investigation, but the presence or absence of log entries does not define whether the activity was authorized or constitutes a leakage event.
- B: Data ownership determines who is responsible for classification and access decisions, but an owner's employee can still have or lack a valid use case independent of ownership status.
- C: Job role is a factor in determining what access is appropriate, but the role alone does not confirm or rule out a valid use case for this specific transfer.
Question 2. An information security manager identifies several gaps in the incident response plan while actively managing a high-profile security incident. At what point would it be BEST to update the plan?
- A. Immediately, while the incident is still being managed
- B. During a scheduled tabletop exercise after the incident is closed
- C. During the post-incident review that follows the conclusion of the incident
- D. After completing a formal risk reassessment triggered by the incident
Show the answer
Answer: C. The post-incident review is the purpose-built forum for capturing lessons learned, documenting deficiencies observed during the response, and translating them into actionable plan improvements. At this stage the incident is resolved, the team can reflect without time pressure, and all stakeholders are engaged in a structured improvement process. Updating the plan during an active incident diverts attention from containment and recovery, while waiting for a future tabletop or risk reassessment introduces unnecessary delay.
- A: Modifying the plan mid-incident risks introducing errors under pressure, distracts responders from the immediate priority of containing and recovering from the event, and may invalidate current response actions.
- B: A tabletop exercise is a useful training mechanism but occurs on a separate schedule; delaying plan improvements until the next exercise means operating with known deficiencies in the interim.
- D: A risk reassessment evaluates the risk landscape and may eventually feed into plan revisions, but it is a slower, broader process that is not designed to capture and act on specific operational gaps observed during an incident.
Question 3. When developing an incident response strategy in collaboration with a cloud service provider, which of the following is the MOST important security consideration?
- A. Defining clear escalation processes between the organization and the provider
- B. Confirming the technical capabilities the provider can deploy during an incident
- C. Establishing recovery time objectives that the provider is contractually obligated to meet
- D. Reviewing the provider's most recent security audit reports and certifications
Show the answer
Answer: A. In a cloud-hosted environment the organization and the provider share incident response responsibilities across a split operational boundary. A clearly defined escalation process ensures that when an incident occurs, both parties know exactly when and how to engage each other, which authority level on each side owns which decisions, and how the handoff of information and control occurs. Without defined escalation paths, critical coordination delays occur precisely when speed matters most.
- B: Technical capabilities define what the provider can do but are only useful if there is a coordinated process for activating and directing those capabilities during an actual incident.
- C: Recovery time objectives set performance expectations but address the aftermath of an incident; they do not govern the real-time coordination needed to manage the incident itself.
- D: Audit reports and certifications provide assurance about baseline security posture during vendor selection and oversight reviews but are not a real-time incident response coordination mechanism.
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full ISACA CISM study guide
The complete guide covers the Certified Information Security Manager (CISM) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $20.99
Simply Certified is an independent publisher. CISM is a trademark of ISACA, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.