Isaca

CISM practice test

Practice with 15 free Testara sample questions, or choose paid access to the full 1242-question bank.

Provider
Isaca
Question bank
1242
Free sample
15 questions
Publisher
Testara

About this practice material

This page covers Testara's practice question bank for CISM, a certification listed under Isaca. Questions use original, exam-style scenarios and are not questions from the official certification exam.

Testara is an independent practice platform and is not affiliated with, endorsed by, or authorized by Isaca. The certification credential is issued by Isaca, not Testara. Certification and provider names belong to their respective owners.

Start practicing

The guest demo does not save an attempt. Sign in before buying access.

Try 15 questions free

Available without signing in

Free sample questions

These 15 questions and their explanations are server-rendered so you can inspect the material before opening the interactive demo.

  1. Question 1 · 1

    An information security risk analysis BEST assists an organization in ensuring that:

    Choose one answer.

    • the infrastructure has the appropriate level of access control.
    • cost-effective decisions are made with regard to which assets need protection
    • an appropriate level of funding is applied to security processes.
    • the organization implements appropriate security technologies
  2. Question 2 · 1

    Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?

    Choose one answer.

    • Review the third-party contract with the organization's legal department.
    • Communicate security policy with the third-party vendor.
    • Ensure security is involved in the procurement process.
    • Conduct an information security audit on the third-party vendor.
  3. Question 3 · 1

    Which of the following would BEST enable effective decision-making?

    Choose one answer.

    • Annualized loss estimates determined from past security events
    • A universally applied list of generic threats, impacts, and vulnerabilities
    • A consistent process to analyze new and historical information risk
    • Formalized acceptance of risk analysis by business management
  4. Question 4 · 1

    Which of the following is the BEST option to lower the cost to implement application security controls?

    Choose one answer.

    • Include standard application security requirements.
    • Perform security tests in the development environment.
    • Perform a risk analysis after project completion.
    • Integrate security activities within the development process.
  5. Question 5 · 1

    Which of the following is the GREATEST benefit of effective information security governance?

    Choose one answer.

    • Treatment priorities are based on risk exposure.
    • Information security standards are communicated to primary stakeholders.
    • The information security budget is aligned to the organization.
    • Executive management's strategy is aligned to the information security strategy.
  6. Question 6 · 1

    The ability to integrate information security governance into corporate governance is PRIMARILY driven by:

    Choose one answer.

    • the percentage of corporate budget allocated to the information security program.
    • how often information security metrics are presented to senior management.
    • how often the information security steering committee reviews and updates security policies.
    • how well the information security program supports business objectives.
  7. Question 7 · 1

    Which of the following presents the GREATEST challenge for protecting Internet of Things (IoT) devices?

    Choose one answer.

    • IoT vendor reputation
    • IoT architecture diversity
    • IoT-specific training
    • IoT device policies
  8. Question 8 · 1

    Which of the following parameters is MOST helpful when designing a disaster recovery strategy?

    Choose one answer.

    • Maximum tolerable downtime (MTD)
    • Mean time between failures (MTBF)
    • Allowable interruption window (AIW)
    • Recovery point objective (RPO)
  9. Question 9 · 1

    An IT service desk was not adequately prepared for a recent ransomware attack on user workstations. Which of the following should be given HIGHEST priority by the information security team when creating an action plan to improve service desk readiness?

    Choose one answer.

    • Investing in threat intelligence capability
    • Implementing key risk indicators (KRIs) for ransomware attacks
    • Updating the information security incident response manual
    • Strengthening the organization's data backup capability
  10. Question 10 · 1

    After a risk has been identified, analyzed, and evaluated, which of the following should be done NEXT?

    Choose one answer.

    • Monitor the risk.
    • Prioritize the risk for treatment
    • Identify the risk owner.
    • Identify controls for risk mitigation.
  11. Question 11 · 1

    Which of the following will BEST facilitate timely and effective incident response?

    Choose one answer.

    • Including penetration test results in incident response planning
    • Assessing the risk of compromised assets
    • Notifying stakeholders when invoking the incident response plan
    • Classifying the severity of an incident
  12. Question 12 · 1

    Which of the following MOST effectively communicates the current risk profile to senior management after controls are applied?

    Choose one answer.

    • Residual risk
    • Impact of loss events
    • Inherent risk
    • Number of risks avoided
  13. Question 13 · 1

    Which of the following processes should be done NEXT after completing a business impact analysis (BIA)?

    Choose one answer.

    • Evaluate the disaster recovery plan (DRP).
    • Develop the requirements for the incident response plan.
    • Develop a business continuity plan (BCP).
    • Identify resources for business recovery.
  14. Question 14 · 1

    Which of the following has the GREATEST impact on efforts to improve an organization's security posture?

    Choose one answer.

    • Well-documented security policies and procedures
    • Supportive tone at the top regarding security
    • Regular reporting to senior management
    • Automation of security controls
  15. Question 15 · 1

    Which of the following is MOST important to include in an information security policy?

    Choose one answer.

    • Maturity levels
    • Baselines
    • Best practices
    • Management objectives

Each purchase applies to this certification. Prices are one-time payments, not monthly subscriptions.

Starter

$29 USD one time

Full access to one certification's question bank in standard practice mode for 60 days.

  • Full question bank for one certification
  • 60 days of access
  • Standard practice mode
  • Question notes and community discussions
  • Attempt scores and answer review

Professional

$49 USD one time

Full access to one certification's question bank, custom test controls and advanced analytics for 60 days.

  • Custom test builder
  • Timers and question selection
  • Randomized question and answer order
  • Advanced performance and weak-question analytics
  • Priority customer support
Try 15 questions free