CISM — ISACA Certified Information Security Manager
ISACA

ISACA Certified Information Security Manager (CISM) Practice Questions

★★★★★ 5.0 143 verified reviews
400 questions
2026-06-21 updated
✓ Online quiz simulator

Domain coverage

  • Information Security Governance (17%)
  • Information Security Risk Management (20%)
  • Information Security Program (33%)
  • Incident Management (30%)

Sample Questions (40 of 400 shown)

Q1
An organization's information security strategy should be the PRIMARY input to which of the following?
  1. Security governance framework design
  2. Enterprise risk scenario development
  3. Security program metrics
  4. Organizational risk appetite
✓ Correct Answer: A
The information security strategy defines the strategic direction and approach for security across the organization. It should be the primary input to the security governance framework design (A) because the framework is the structure that implements the strategy. The strategy informs what the governance framework needs to accomplish. Risk appetite (D) influences the strategy but isn't directly input from it. Enterprise risk scenarios (B) and security program metrics (C) are derived from the strategy and framework, not the other way around.
Q2
Which of the following should be done FIRST when developing an information security strategy that is aligned with organizational goals?
  1. Establish a security risk framework with key risk indicators (KRIs).
  2. Determine information security's impact on the achievement of organizational goals.
  3. Assess information security risk associated with the organizational goals
  4. Select information security projects related to the organizational goals.
✓ Correct Answer: C
When developing an information security strategy aligned with organizational goals, the FIRST step is to assess information security risk associated with the organizational goals (C). You must understand the risks to the business objectives before determining impact, establishing frameworks, or selecting projects. ISO 27001 and ISACA frameworks all emphasize risk assessment as the foundation. Option B (determining impact) comes after risk assessment. Option A (establishing KRI framework) and D (selecting projects) are subsequent steps.
Q3
Which of the following is the PRIMARY objective of developing an information security program that aligns with the information security strategy?
  1. To define the resources required to achieve information security goals
  2. To define a bottom-up approach for implementing information security policies
  3. To define standards to be implemented
  4. To define risk mitigation plans for security technologies
✓ Correct Answer: A
The primary objective of developing an information security program aligned with the information security strategy is to define the resources required (A) - people, budget, tools, and time needed to achieve the security goals. A program without defined resources cannot be executed. Option B describes a bottom-up approach which is less effective than top-down alignment. Options C and D are components of program development but not the primary objective.
Q4
Which of the following is MOST important to include in an information security framework?
  1. Guidance for designing information security controls
  2. Information security organizational structure
  3. Industry benchmarks of information security metrics
  4. Information security risk assessment
✓ Correct Answer: D
The MOST important element to include in an information security framework is information security risk assessment (D). Risk assessment is the foundation of all security frameworks (ISO 27001, NIST CSF, etc.) because you cannot protect what you haven't assessed. Without risk assessment, controls are arbitrary. Option A (control design guidance) is important but secondary. Option B (organizational structure) and C (industry benchmarks) are supporting elements.
Q5
Which of the following approaches to communication with senior management BEST enables an information security manager to maximize the effectiveness of the information security program?
  1. Reporting on industry security threats with potential impact to business objectives
  2. Conducting periodic one-on-one meetings to align security with business objectives
  3. Participating in operational review meetings to discuss daily operations and dependencies
  4. Providing regular status of updates to security policies and standards
✓ Correct Answer: B
The BEST approach for communicating with senior management to maximize effectiveness of the information security program is conducting periodic one-on-one meetings to align security with business objectives (B). Senior executives respond to business-aligned communication, not technical details. Regular face-to-face alignment ensures security supports business goals. Option A (reporting on threats) is fear-based and less effective. Option C (operational reviews) is too tactical. Option D (policy updates) is administrative.
Q6
Which of the following control types should be considered FIRST for aligning employee behavior with an organization's information security objectives?
  1. Administrative security controls
  2. Access security controls
  3. Technical security controls
  4. Physical security controls
✓ Correct Answer: A
To align employee behavior with security objectives, administrative security controls (A) should be considered FIRST. Administrative controls include policies, standards, procedures, awareness training, and culture-building - these shape behavior at the human level. Technical (C) and physical (D) controls enforce behavior but don't align it. Access controls (B) are a subset of technical controls. ISACA emphasizes that administrative/people controls are the foundation of security behavior.
Q7
Which of the following BEST facilitates the development of information security procedures that effectively support the information security policy?
  1. Aligning procedures with industry best practices
  2. Classifying the information assets to be protected
  3. Considering the impact of systemic risk events
  4. Conducting an external benchmarking exercise
✓ Correct Answer: B
Classifying the information assets to be protected (B) BEST facilitates the development of security procedures that support the security policy. You cannot write effective procedures without knowing what assets you're protecting and their classification levels. Asset classification drives procedure requirements. Option A (aligning with best practices) is generic. Option C (systemic risk) is too narrow. Option D (benchmarking) is a validation step, not a foundation.
Q8
Which of the following is MOST helpful for determining priorities when creating a long-term information security roadmap?
  1. The organization's information security framework
  2. Information security steering committee input
  3. Enterprise architecture (EA)
  4. Industry best practices
✓ Correct Answer: B
The MOST helpful input for determining priorities in a long-term security roadmap is information security steering committee input (B). The steering committee represents business leadership and understands business priorities, which should drive security roadmap priorities. Option A (security framework) provides structure but not prioritization. Option C (Enterprise Architecture) is technical. Option D (industry best practices) is generic, not organization-specific.
Q9
How does data discovery assist with data classification?
  1. It provides assurance of data integrity.
  2. It shows where specific data is stored.
  3. It automatically classifies data by keywords.
  4. It helps to identify the data owner.
✓ Correct Answer: B
Data discovery assists with data classification by showing where specific data is stored (B). You cannot classify data effectively if you don't know where it resides across the organization. Data discovery tools scan repositories to locate unmanaged data. Option A (data integrity) is unrelated. Option C (automatic classification) is a potential capability but not the primary assistance. Option D (identifying data owner) may be a byproduct but isn't the main function.
Q10
Which of the following is the MOST important driver when developing an effective information security strategy?
  1. Benchmarking reports
  2. Information security standards
  3. Business requirements
  4. Security audit reports
✓ Correct Answer: C
The MOST important driver when developing an effective information security strategy is business requirements (C). Security exists to enable the business safely, not as an end in itself. ISACA's CISM domain emphasizes that security strategy must be business-driven. Options A (benchmarking), B (standards), and D (audit reports) are inputs to the strategy but not the primary driver. The business context determines what the strategy must achieve.
Q11
An employee clicked on a malicious link in an email that resulted in compromising company data. What is the BEST way to mitigate this risk in the future?
  1. Assess and update spam filtering rules.
  2. Establish an acceptable use policy.
  3. Implement disciplinary procedures.
  4. Conduct phishing awareness training.
✓ Correct Answer: D
The BEST way to mitigate the risk of employees clicking malicious links is conducting phishing awareness training (D). Technical controls (A - spam filtering) can be bypassed; the human element is the last line of defense. Training changes behavior. Option B (acceptable use policy) is administrative but doesn't train. Option C (disciplinary procedures) is punitive, not preventive. Awareness training is the industry standard recommended by ISACA and NIST.
Q12
An international organization with remote branches is implementing a corporate security policy for managing personally identifiable information (PII). Which of the following should be the information security manager's MAIN concern?
  1. Data backup strategy
  2. Organizational reporting structure
  3. Local regulations
  4. Consistency in awareness programs
✓ Correct Answer: C
For an international organization implementing PII security policy across remote branches, the MAIN concern is local regulations (C). Different jurisdictions have different data protection laws (GDPR in EU, CCPA in California, PIPL in China, etc.). A global policy must accommodate local legal requirements or face compliance violations. Option A (backup strategy) is operational. Option B (reporting structure) is organizational. Option D (awareness consistency) is desirable but secondary to legal compliance.
Q13
Which of the following is MOST important when developing an information security governance framework?
  1. Ensuring alignment with the organization's risk management framework
  2. Integrating security within the system development life cycle (SDLC) process
  3. Developing policies and procedures to support the framework
  4. Developing security incident response measures
✓ Correct Answer: A
The MOST important consideration when developing an information security governance framework is ensuring alignment with the organization's risk management framework (A). Security governance must be integrated with enterprise risk management (ERM) to be effective. ISO 31000 and ISO 27001 both emphasize this alignment. Option B (SDLC integration) is important but narrower in scope. Options C and D are components of the framework, not the primary alignment consideration.
Q14
What should be an information security manager's GREATEST concern when an HR department outsources data processing to a cloud service provider?
  1. Security posture of the provider
  2. Data loss protection insurance
  3. Required provider service levels
  4. The scope of the data
✓ Correct Answer: D
When HR outsources data processing to a cloud provider, the information security manager's GREATEST concern should be the scope of the data (D) - what specific PII and sensitive data is being processed by the provider. Understanding the data scope is prerequisite to assessing provider security posture (A), evaluating service levels (C), or reviewing insurance (B). You must know what data is at risk before you can evaluate anything else. This is a key due diligence step.
Q15
Which of the following is the PRIMARY objective of a cyber resilience strategy?
  1. Business continuity
  2. Employee awareness
  3. Executive support
  4. Regulatory compliance
✓ Correct Answer: A
The PRIMARY objective of a cyber resilience strategy is business continuity (A). Cyber resilience is about maintaining essential business functions during and after a cyber incident. Unlike traditional security which focuses on prevention, resilience accepts that incidents will happen and prepares for continuity. Options B, C, and D are enablers or compliance requirements, but the core objective is keeping the business running through adverse events.
Q16
Which of the following BEST facilitates the development of a comprehensive information security policy?
  1. Alignment with an established information security framework
  2. Security key performance indicators (KPIs)
  3. A review of recent information security incidents
  4. An established internal audit program
✓ Correct Answer: A
Alignment with an established information security framework (A) BEST facilitates the development of a comprehensive information security policy. Frameworks like ISO 27001, NIST CSF, or ISACA's provide proven structures and control objectives. Starting from a framework ensures completeness and alignment with industry standards. Options B (KPIs), C (incident review), and D (audit program) are important but are inputs to, not facilitators of, policy development.
Q17
In order to gain organization-wide support for an information security program, which of the following is MOST important to consider?
  1. Corporate risk framework
  2. Corporate culture
  3. Clarity of security roles and responsibilities
  4. Maturity of the security policy
✓ Correct Answer: B
To gain organization-wide support for an information security program, the MOST important factor is corporate culture (B). Security programs fail when they conflict with organizational culture. Understanding and working within the culture - or gradually shifting it - is essential for adoption. Option A (risk framework) is technical. Option C (roles clarity) is important but secondary. Option D (policy maturity) doesn't guarantee support if culture resists.
Q18
Which of the following should be the PRIMARY objective when establishing a new information security program?
  1. Facilitating operational security
  2. Optimizing resources
  3. Minimizing organizational risk
  4. Executing the security strategy
✓ Correct Answer: C
The PRIMARY objective when establishing a new information security program is minimizing organizational risk (C). The entire purpose of a security program is to reduce risk to acceptable levels. Option A (operational security) is a means to the end. Option B (resource optimization) is a management concern. Option D (executing strategy) is the process; risk minimization is the objective. ISACA defines the security program's purpose as risk reduction aligned with business goals.
Q19
An organization wants to integrate information security into its HR management processes. Which of the following should be the FIRST step?
  1. Calculate the return on investment (ROI).
  2. Provide security awareness training to HR.
  3. Assess the business objectives of the processes.
  4. Benchmark the processes with best practice to identify gaps.
✓ Correct Answer: C
When integrating information security into HR management processes, the FIRST step is to assess the business objectives of the processes (C). You must understand what HR is trying to achieve before determining how security supports those objectives. Options A (ROI), B (training HR), and D (benchmarking) are all subsequent steps. Business objective assessment ensures the security integration adds value to HR's mission rather than creating friction.
Q20
Which of the following is the BEST indication that an organization has integrated information security governance with corporate governance?
  1. Impact is measured according to business loss when assessing IT risk.
  2. Service levels for security vendors are defined according to business needs.
  3. Security policies are reviewed whenever business objectives are changed.
  4. Security performance metrics are measured against business objectives.
✓ Correct Answer: D
The BEST indication that information security governance is integrated with corporate governance is that security performance metrics are measured against business objectives (D). True integration means security is evaluated in business terms, not just technical metrics. Option A (measuring impact in business loss) is good but narrower. Option B (vendor SLA definition) is operational. Option C (policy review when business changes) shows awareness but not full integration. Metrics tied to business objectives demonstrate strategic alignment.
Q21
Which of the following is MOST important for guiding the development and management of a comprehensive information security program?
  1. Adopting information security program management best practices
  2. Aligning the organization's business objectives with IT objectives
  3. Establishing and maintaining an information security governance framework
  4. Implementing policies and procedures to address the information security strategy
✓ Correct Answer: C
The MOST important element for guiding the development and management of a comprehensive information security program is establishing and maintaining an information security governance framework (C). The governance framework provides the structure, authority, and direction for the entire program. Option A (best practices) is a reference. Option B (aligning business and IT objectives) is a goal. Option D (policies and procedures) is a component. The framework is the overarching structure that makes everything else coherent and accountable.
Q22
Which of the following is the BEST way to ensure data is not co-mingled or exposed when using a cloud service provider?
  1. Require the provider to follow stringent data classification procedures.
  2. Obtain an independent audit report.
  3. Review the provider's information security policies.
  4. Include high penalties for security breaches in the contract.
✓ Correct Answer: B
The BEST way to ensure data is not co-mingled or exposed when using a cloud service provider is to obtain an independent audit report (B) - such as SOC 2 Type II, ISO 27001 certification, or similar third-party attestation. Independent audits verify that the provider's controls are actually effective. Option A (requiring provider to follow procedures) relies on trust. Option C (reviewing policies) is paper-based. Option D (contract penalties) is remedial, not preventive. Independent verification is the industry standard approach.
Q23
Before approving the implementation of a new security solution, senior management requires a business case. Which of the following would BEST support the justification for investment?
  1. The solution contributes to business strategy.
  2. The solution improves business risk tolerance levels.
  3. The solution reduces the cost of noncompliance with regulations.
  4. The solution improves business resiliency.
✓ Correct Answer: A
When justifying investment in a new security solution to senior management, the BEST support is that the solution contributes to business strategy (A). Executives make decisions based on business value and strategic alignment, not technical merit alone. Options B (risk tolerance), C (compliance cost reduction), and D (business resiliency) are all valid but secondary to strategic contribution. ISACA emphasizes business case development focused on business strategy alignment.
Q24
When an organization implements an information security governance framework, it is MOST important for executive leadership to have a direct role in:
  1. reviewing the information security policy directing the organization.
  2. developing technical key risk indicators (KRIs) for information security.
  3. implementing information security metrics for the organization.
  4. approving information security standards and procedures for the organization.
✓ Correct Answer: A
When implementing an information security governance framework, it is MOST important for executive leadership to have a direct role in reviewing the information security policy directing the organization (A). Executive review and approval of the policy demonstrates commitment and ensures alignment with business objectives. Options B (developing KRIs), C (implementing metrics), and D (approving standards) are operational and should be delegated. Executive involvement should be at the policy level.
Q25
Biometrics are BEST used for:
  1. authorization.
  2. authentication.
  3. auditing.
  4. accounting.
✓ Correct Answer: B
Biometrics are BEST used for authentication (B) - verifying that a user is who they claim to be, based on unique physical characteristics (fingerprint, iris, face, etc.). Biometrics are something you are, one of the three authentication factors. Option A (authorization) is about what access rights a user has - biometrics don't determine authorization. Options C (auditing) and D (accounting) are separate security functions. Biometrics' primary strength is identity verification.
Q26
Which of the following is the PRIMARY reason to regularly update business continuity and disaster recovery documents?
  1. To ensure audit and compliance requirements are met
  2. To enforce security policy requirements
  3. To maintain business asset inventories
  4. To ensure the availability of business operations
✓ Correct Answer: D
The PRIMARY reason to regularly update business continuity and disaster recovery (BC/DR) documents is to ensure the availability of business operations (D). BC/DR plans must reflect current business processes, systems, and dependencies. Outdated plans may fail during an actual event. Options A (audit/compliance), B (policy enforcement), and C (asset inventories) are important but secondary. The core purpose of BC/DR is business availability during disruptions.
Q27
Of the following, who should own the risk associated with unauthorized access to application data?
  1. Data custodian
  2. Application developer
  3. Application owner
  4. Access administrator
✓ Correct Answer: C
The risk associated with unauthorized access to application data should be owned by the application owner (C). In RACI and risk management frameworks, risk owners are business process owners who understand the business impact of the risk. The data custodian (A) implements controls. The developer (B) builds the application. The access administrator (D) manages access rights. The owner has the authority and accountability for the business risk.
Q28
An organization learns that a third party has outsourced critical functions to another external provider. Which of the following is the information security manager's MOST important course of action?
  1. Engage an independent audit of the third party's external provider.
  2. Conduct an external audit of the contracted third party.
  3. Recommend canceling the contract with the third party.
  4. Evaluate the third party's agreements with its external provider.
✓ Correct Answer: D
When an organization learns that a third party has outsourced critical functions to another external provider (subcontractor chain), the MOST important course of action is to evaluate the third party's agreements with its external provider (D). This is part of supply chain risk management - you need to understand the subcontractor arrangements and ensure contractually that your security requirements flow down. Option A (independent audit) and B (external audit) may be subsequent steps. Option C (canceling contract) is extreme and premature.
Q29
An organization has acquired a new system with strict maintenance instructions and schedules. Where should this information be documented?
  1. Standards
  2. Procedures
  3. Guidelines
  4. Policies
✓ Correct Answer: B
Strict maintenance instructions and schedules for a new system should be documented in procedures (B). Procedures are step-by-step instructions for performing specific tasks. Standards (A) define mandatory requirements (e.g., "all systems must be patched within 30 days"). Guidelines (C) are recommendations. Policies (D) are high-level directives. Maintenance instructions are procedural documentation - detailed steps on how to perform maintenance.
Q30
The PRIMARY benefit of using http secure (https) is that it provides:
  1. confidentiality of data transmitted.
  2. integrity for data at rest.
  3. authentication.
  4. better session traceability.
✓ Correct Answer: A
The PRIMARY benefit of using HTTPS (HTTP Secure) is that it provides confidentiality of data transmitted (A) through TLS/SSL encryption. HTTPS also provides integrity and authentication, but confidentiality of data in transit is the primary benefit. Option B (integrity for data at rest) is incorrect - HTTPS protects data in transit, not at rest. Option C (authentication) is a secondary benefit (server certificate authentication). Option D (session traceability) is not a primary benefit of HTTPS.
Q31
An organization provides notebook PCs, cable wire locks, smartphone access, and virtual private network (VPN) access to its remote employees. Which of the following is MOST important for the information security manager to ensure?
  1. Employees are trained on the acceptable use policy.
  2. Employees use smartphone tethering when accessing from remote locations.
  3. Employees use the VPN when accessing the organization's online resources.
  4. Employees physically lock PCs when leaving the immediate area.
✓ Correct Answer: A
When providing remote employees with notebooks, cable locks, smartphone access, and VPN access, the MOST important thing for the information security manager to ensure is that employees are trained on the acceptable use policy (A). Technical controls (VPN, locks) can be misused or bypassed if users don't understand their responsibilities. Security awareness and policy training is the foundation. Options B, C, and D are specific technical measures but don't address the human factor which is often the weakest link.
Q32
Which of the following is the MOST effective way to determine the alignment of an information security program with the business strategy?
  1. Evaluate the results of business continuity testing.
  2. Evaluate the business impact of incidents.
  3. Review key performance indicators (KPIs).
  4. Engage business process owners.
✓ Correct Answer: C
The MOST effective way to determine alignment of an information security program with business strategy is to review key performance indicators (KPIs) (C). KPIs measure outcomes that matter to the business. If security KPIs are aligned with business objectives, the program is aligned. Option A (BC testing) is narrow. Option B (incident business impact) is reactive. Option D (engaging business process owners) is a method but KPI review is more effective for ongoing assessment. ISACA emphasizes measuring security performance against business goals.
Q33
Which of the following is the MOST important success factor when developing an information security strategy?
  1. The delivery of the strategy is adequately funded.
  2. The strategy is aligned with an industry-recognized security control framework.
  3. The strategy is based on proven technologies and industry trends.
  4. The strategy is approved by the board and executive management.
✓ Correct Answer: D
The MOST important success factor when developing an information security strategy is that the strategy is approved by the board and executive management (D). Without executive sponsorship and approval, the strategy cannot be funded or enforced. Option A (adequate funding) is important but follows approval. Option B (alignment with framework) is a best practice but not sufficient without buy-in. Option C (proven technologies) is tactical. Executive approval is the critical success factor for strategy adoption and implementation.
Q34
Which of the following BEST demonstrates a security-conscious organizational culture?
  1. Security incidents are reported directly to senior management.
  2. Security awareness metrics have been established and tracked.
  3. Phishing simulations are part of information security training.
  4. Employees identify potential incidents and report them.
✓ Correct Answer: D
A security-conscious organizational culture is BEST demonstrated when employees identify potential incidents and report them (D). This shows that security awareness is embedded in daily behavior, not just compliance training. Option A (incidents reported to senior management) suggests a reporting bottleneck. Option B (metrics established) is administrative. Option C (phishing simulations) is a training method. When employees proactively identify and report, it indicates true cultural adoption of security mindfulness.
Q35
Which of the following BEST helps to enable the desired information security culture within an organization?
  1. Information security awareness training and campaigns
  2. Incentives for appropriate information security-related behavior
  3. Effective information security policies and procedures
  4. Delegation of information security roles and responsibilities
✓ Correct Answer: A
Information security awareness training and campaigns (A) BEST help enable the desired information security culture. Training changes knowledge and behavior. Option B (incentives) can reinforce but don't establish culture alone. Option C (policies and procedures) are necessary but insufficient without training. Option D (delegation of roles) is organizational. ISACA emphasizes that awareness training is the primary tool for building security culture because it reaches all employees consistently.
Q36
The PRIMARY reason for senior management to monitor information security metrics is to ensure:
  1. alignment of the information security budget to corporate funding.
  2. alignment of information security with corporate governance.
  3. alignment of security and IT objectives.
  4. alignment with risk mitigation efforts.
✓ Correct Answer: B
The PRIMARY reason for senior management to monitor information security metrics is to ensure alignment of information security with corporate governance (B). Metrics provide visibility into whether security activities support governance objectives. Option A (budget alignment) is a subset. Option C (security and IT alignment) is operational. Option D (risk mitigation alignment) is a component. Corporate governance alignment is the strategic purpose of executive metric review per ISACA's governance framework.
Q37
Which of the following is MOST helpful to an information security manager when determining service level requirements for an outsourced application?
  1. Supplier business continuity plan (BCP)
  2. Information security policy
  3. Application capabilities
  4. Data classification
✓ Correct Answer: A
When determining service level requirements for an outsourced application, the MOST helpful input is the supplier's business continuity plan (BCP) (A). BCP ensures the supplier can maintain service during disruptions, which directly affects service levels. Option B (security policy) is important but doesn't define SLAs. Option C (application capabilities) defines functionality, not service levels. Option D (data classification) drives security requirements, not availability/reliability SLAs. BCP review ensures SLA feasibility during crises.
Q38
An enterprise has decided to procure security services from a third-party vendor to support its information security program. Which of the following is MOST important to include in the vendor selection criteria?
  1. The maturity of the vendor's internal control environment
  2. Feedback from the vendor's previous clients
  3. Alignment of the vendor's business objectives with enterprise security goals
  4. Penetration testing against the vendor's network
✓ Correct Answer: C
The MOST important criterion when selecting a third-party vendor for security services is alignment of the vendor's business objectives with enterprise security goals (C). The vendor must share your security vision and objectives for a successful partnership. Option A (vendor's internal control maturity) is important but secondary. Option B (previous client feedback) is a reference check. Option D (penetration testing) is a technical assessment. Strategic alignment ensures the vendor relationship supports your long-term security program success.
Q39
Which of the following is the MOST important consideration when evaluating the performance of existing security controls?
  1. Interviewing control owners to accurately collect metrics data
  2. Establishing testing scenarios based on international standards
  3. Selecting testing methods that match the purpose of the testing
  4. Obtaining senior management support to facilitate testing
✓ Correct Answer: C
The MOST important consideration when evaluating the performance of existing security controls is selecting testing methods that match the purpose of the testing (C). Different controls require different evaluation approaches (e.g., technical controls need vulnerability scanning; administrative controls need documentation review and interviews). Option A (interviewing control owners) is one method but not the most important consideration. Option B (international standards) provide frameworks but don't replace purpose-matched testing. Option D (management support) enables testing but isn't the technical consideration.
Q40
Which of the following metrics BEST demonstrates the effectiveness of an organization's security awareness program?
  1. Percentage of employee computers and devices infected with malware
  2. Percentage of employees who regularly attend security training
  3. Number of security incidents reported to the help desk
  4. Number of phishing emails viewed by end users
✓ Correct Answer: C
The BEST metric demonstrating the effectiveness of an organization's security awareness program is the number of security incidents reported to the help desk (C). High reporting numbers indicate that employees are recognizing and reporting potential incidents - the desired behavior from awareness training. Option A (malware infection percentage) measures endpoint protection effectiveness, not awareness. Option B (training attendance) measures participation, not effectiveness. Option D (phishing emails viewed) doesn't measure awareness program success. Reporting behavior is the best outcome metric.

You've viewed 3 of 400 questions. Start the free practice exam to answer all questions with instant feedback.

What Our Customers Say 143 verified reviews

5.0 ★★★★★ Based on 143 reviews
★★★★★★
First time using online prep for a certification. The CISM questions were clear, accurate, and well worth the price.
— Abigail M.
★★★★★★
I liked that the CISM questions update regularly. Felt current and aligned with what I actually saw on the test.
— Dylan P.
★★★★★★
Very realistic CISM exam simulation. The timer feature helped me practice pacing before the actual test.
— Ellie B.
★★★★★
Couldn’t have passed the CISM exam without this. The questions are challenging, the explanations are thorough, and the value is unbeatable.
— Hannah L.
★★★★★★
The CISM practice test is spot-on. The multi-select questions and explanations are exactly what you need for the real exam.
— Emily R.
★★★★★★
I used this alongside video courses for CISM prep. The questions helped solidify what I learned from the lectures.
— Aria N.

Log in to rate this exam and leave a review.

Submitted for moderation before publishing. Keep it helpful and respectful.

Frequently Asked Questions

CISM focuses on security management—governance, strategy, and program leadership. CISSP (from ISC2) covers a broader range of technical security topics. CISM is ideal for CISOs, security directors, and managers; CISSP suits security engineers and architects. Many professionals hold both to demonstrate breadth (CISSP) and depth in management (CISM).

Two new content areas are being added: Enterprise Architecture and Information Security Architecture. Domain weights will shift. Candidates testing before November 3, 2026 should use current materials; those testing after should use updated preparation resources available from September 2026.

ISACA requires 5 years of information security work experience, with at least 3 years in information security management across three or more CISM domains. Waivers of up to 2 years are available for certain certifications (CISA, CISSP) and post-graduate degrees.

ISACA uses a scaled scoring system (200-800), with 450 required to pass. The scaling adjusts for question difficulty variations. You receive a preliminary pass/fail immediately after completing the exam. Official results post within 10 business days.

Free Study Resources

Community-verified analysis of 217 topics from real test-taker discussions — 23 deep analyses and 20 FAQs.