Certified Information Security Manager
(CISM) Examination: 100 Practice Questions
with Answers and Detailed Rationales
Question 1. Which organization administers the Certified Information Security Manager (CISM)
certification?
A) ISACA
B) (ISC)²
C) CompTIA
D) SANS Institute
Answer: A
Rationale: ISACA has administered the CISM certification since its inception. The certification validates
expertise in information security governance, program development and management, incident
management, and risk management. More than 107,000 people have obtained ISACA's CISM
certification since 2002 .
Question 2. How many questions are on the CISM examination?
A) 100 questions
B) 125 questions
C) 150 questions
D) 200 questions
,Answer: C
Rationale: The CISM exam consists of 150 multiple-choice questions . Candidates must complete the
exam within four hours .
Question 3. How much time is allotted for the CISM examination?
A) 2 hours
B) 3 hours
C) 4 hours
D) 5 hours
Answer: C
Rationale: Candidates are given 4 hours to complete the 150-question exam . This requires effective
time management to complete all questions.
Question 4. What is the passing score for the CISM examination?
A) 400/800
B) 450/800
C) 500/800
D) 600/800
Answer: B
,Rationale: The CISM exam uses a scaled scoring system. The passing score is 450 out of a possible 800
points .
Question 5. Under the current exam structure, which domain carries the highest weight?
A) Information Security Governance
B) Information Security Risk Management
C) Information Security Program
D) Incident Management
Answer: C
Rationale: Information Security Program is the highest-weighted domain at 33% of the exam. This
domain focuses on configuring and implementing information security strategies .
Question 6. What is the domain weight for Information Security Governance under the current exam?
A) 15%
B) 17%
C) 20%
D) 25%
Answer: B
, Rationale: Information Security Governance accounts for 17% of the exam, testing ability to develop,
maintain, and manage information security governance frameworks .
Question 7. What is the domain weight for Information Security Risk Management?
A) 15%
B) 17%
C) 20%
D) 25%
Answer: C
Rationale: Information Security Risk Management accounts for 20% of the exam, focusing on identifying
risks applicable to an organization .
Question 8. What is the domain weight for Incident Management?
A) 25%
B) 27%
C) 30%
D) 33%
Answer: C
Rationale: Incident Management accounts for 30% of the exam, addressing readiness for information
security incidents and response operations .
(CISM) Examination: 100 Practice Questions
with Answers and Detailed Rationales
Question 1. Which organization administers the Certified Information Security Manager (CISM)
certification?
A) ISACA
B) (ISC)²
C) CompTIA
D) SANS Institute
Answer: A
Rationale: ISACA has administered the CISM certification since its inception. The certification validates
expertise in information security governance, program development and management, incident
management, and risk management. More than 107,000 people have obtained ISACA's CISM
certification since 2002 .
Question 2. How many questions are on the CISM examination?
A) 100 questions
B) 125 questions
C) 150 questions
D) 200 questions
,Answer: C
Rationale: The CISM exam consists of 150 multiple-choice questions . Candidates must complete the
exam within four hours .
Question 3. How much time is allotted for the CISM examination?
A) 2 hours
B) 3 hours
C) 4 hours
D) 5 hours
Answer: C
Rationale: Candidates are given 4 hours to complete the 150-question exam . This requires effective
time management to complete all questions.
Question 4. What is the passing score for the CISM examination?
A) 400/800
B) 450/800
C) 500/800
D) 600/800
Answer: B
,Rationale: The CISM exam uses a scaled scoring system. The passing score is 450 out of a possible 800
points .
Question 5. Under the current exam structure, which domain carries the highest weight?
A) Information Security Governance
B) Information Security Risk Management
C) Information Security Program
D) Incident Management
Answer: C
Rationale: Information Security Program is the highest-weighted domain at 33% of the exam. This
domain focuses on configuring and implementing information security strategies .
Question 6. What is the domain weight for Information Security Governance under the current exam?
A) 15%
B) 17%
C) 20%
D) 25%
Answer: B
, Rationale: Information Security Governance accounts for 17% of the exam, testing ability to develop,
maintain, and manage information security governance frameworks .
Question 7. What is the domain weight for Information Security Risk Management?
A) 15%
B) 17%
C) 20%
D) 25%
Answer: C
Rationale: Information Security Risk Management accounts for 20% of the exam, focusing on identifying
risks applicable to an organization .
Question 8. What is the domain weight for Incident Management?
A) 25%
B) 27%
C) 30%
D) 33%
Answer: C
Rationale: Incident Management accounts for 30% of the exam, addressing readiness for information
security incidents and response operations .