10 free ISACA CISM practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 1,250 questions. Work through them, then open each answer to check your reasoning.
Get all 1,250 questions (US$39) · Download these 10 as a PDF
Question 1
An information security risk analysis BEST assists an organization in ensuring that:
Show answer and explanation
Correct answer: B. cost-effective decisions are made with regard to which assets need protection
which assets need protection Risk analysis fundamentally helps organizations prioritize their security investments by identifying which assets face the greatest threats and require protection. This directly enables cost-effective decision-making about where limited security resources should be allocated. While risk analysis informs other decisions like access control and technology selection, the BEST overall purpose is ensuring resources are spent efficiently on protecting critical assets.
Why the other options are wrong
- A. Risk analysis informs access control decisions but doesn't ensure their implementation.
- C. While risk analysis guides funding decisions, it doesn't directly apply funding itself.
- D. Risk analysis informs technology choices but doesn't mandate specific technologies.
Question 2
In a multinational organization, local security regulations should be implemented over global security policy because:
Show answer and explanation
Correct answer: D. requirements of local regulations take precedence.
Legal and regulatory requirements are mandatory obligations that take precedence over internal policies. If local regulations exist, they represent binding legal requirements that the organization must meet regardless of global policy preferences. Non-compliance with local regulations can result in legal penalties, fines, and loss of operating licenses, making regulatory requirements the ultimate authority in any jurisdiction.
Why the other options are wrong
- A. Business objectives don't override regulatory requirements; compliance is mandatory.
- B. Practicality of awareness doesn't determine which requirements apply.
- C. Global policies may contain necessary controls; the real issue is that local regulations are mandatory.
Question 3
To gain a clear understanding of the impact that a new regulatory requirement will have on an organization's information security controls, an information security manager should FIRST:
Show answer and explanation
Correct answer: D. perform a gap analysis.
A gap analysis is the FIRST appropriate step because it directly compares the organization's existing security controls against the new regulatory requirements, clearly identifying what is missing or inadequate. This establishes baseline understanding before committing resources. While risk assessment and cost-benefit analysis follow logically afterward, the gap analysis provides the foundational understanding of what controls need to be added or modified to meet the new requirement.
Why the other options are wrong
- A. Cost-benefit analysis requires knowing the gap first.
- B. Risk assessment comes after understanding the specific gaps.
- C. Management interviews provide business context but not technical understanding of control gaps.
Question 4
When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?
Show answer and explanation
Correct answer: D. Risk management
Risk management is the comprehensive process that evaluates how business strategy changes affect the organizational threat landscape, identifies new risks, and determines both whether existing controls remain adequate and what new controls are needed. Risk management encompasses the systematic evaluation and selection of controls in response to strategic shifts. While change management is also important operationally, risk management is the process specifically designed to evaluate and select controls based on new business contexts.
Why the other options are wrong
- A. Access control management addresses a specific control type, not the overall evaluation needed.
- B. Change management handles implementation but not the control evaluation and selection process.
- C. Configuration management tracks settings but doesn't evaluate control adequacy or select new controls.
Question 5
Which of the following is the BEST way to build a risk-aware culture?
Show answer and explanation
Correct answer: D. Establish incentives and a channel for staff to report risks.
risks. Establishing incentives and channels for staff to report risks creates a proactive, participatory risk-aware culture where employees feel empowered and rewarded for contributing to organizational security. This bottom-up engagement is more effective for building sustained cultural change than top-down messaging or testing. When employees are encouraged and motivated to identify and report risks, they become active participants in risk management rather than passive recipients of information.
Why the other options are wrong
- A. Changing messages periodically doesn't build sustained awareness or behavioral change.
- B. Communicating threats is reactive and doesn't necessarily build a culture of proactive risk management.
- C. Testing compliance and posting results is accountability-focused but doesn't encourage proactive risk reporting.
Question 6
What would be an information security manager's BEST recommendation upon learning that an existing contract with a third party does not clearly identify requirements for safeguarding the organization's critical data?
Show answer and explanation
Correct answer: C. Create an addendum to the existing contract.
An addendum to the existing contract is the practical, standard approach to address contractual gaps. It allows the organization to add specific data safeguarding requirements without disrupting the existing business relationship or requiring full contract renegotiation. This remedial measure is more practical than cancellation and more effective than risk transfer alone, as it establishes clear contractual obligations for the provider to implement protective measures.
Why the other options are wrong
- A. Cancellation is an extreme response that disrupts business; amendment is more appropriate.
- B. Risk transfer without contractual obligations doesn't ensure the provider will actually implement safeguards.
- D. An audit verifies provider capabilities but doesn't address the contractual gap that must be filled.
Question 7
An organization has purchased a security information and event management (SIEM) tool.
Which of the following is MOST important to consider before implementation?
Show answer and explanation
Correct answer: A. Controls to be monitored
Identifying which controls and security events need to be monitored is the MOST critical consideration before SIEM implementation because it determines the entire scope and success of the deployment. Without knowing what to monitor, the SIEM implementation lacks purpose and focus. Once monitoring requirements are defined, reporting capabilities, vendor contracts, and support can be evaluated to meet those specific needs. Monitoring requirements drive all other implementation decisions.
Why the other options are wrong
- B. Reporting is important but depends first on knowing what will be monitored.
- C. The vendor contract is a supporting concern but not more important than defining monitoring requirements.
- D. Technical support is valuable but secondary to defining what the tool should actually monitor.
Question 8
Which of the following is MOST likely to be included in an enterprise security policy?
Show answer and explanation
Correct answer: A. Definitions of responsibilities
Definitions of responsibilities are the cornerstone of any enterprise security policy, clearly establishing who is accountable for various security functions and compliance. This is a high-level policy matter that applies organization-wide. Retention schedules and system access specifications are typically detailed in lower-level procedures or implementation standards rather than enterprise-level policies, and organizational risk is an input to policy rather than a component of it.
Why the other options are wrong
- B. Retention schedules are typically found in records management procedures, not enterprise security policy.
- C. System access specifications are implementation-level details found in standards or procedures.
- D. Organizational risk is analyzed to inform policy but isn't typically included as policy content itself.
Question 9
Which of the following should an information security manager do FIRST when a legacy application is not compliant with a regulatory requirement, but the business unit does not have the budget for remediation?
Show answer and explanation
Correct answer: D. Assess the consequences of noncompliance against the cost of remediation.
the cost of remediation. When a legacy application is noncompliant but lacks remediation budget, the information security manager must FIRST assess the consequences of noncompliance against remediation costs. This risk-benefit analysis is foundational to all subsequent decisions, it determines whether to pursue funding (A), accept risk (B), notify stakeholders (C), or take other action. Without understanding the actual risk exposure relative to cost, any decision lacks proper justification.
Why the other options are wrong
- A. Developing a business case is premature without first understanding the severity of noncompliance risk.
- B. Risk acceptance requires prior assessment and is a decision made after analysis, not before.
- C. Notification to legal and audit is appropriate after assessment, but not the first action.
Question 10
Which of the following is the MOST effective way to address an organization's security concerns during contract negotiations with a third party?
Show answer and explanation
Correct answer: C. Ensure security is involved in the procurement process.
process. Ensuring security is involved in the procurement process is the MOST effective approach because it embeds security requirements from the beginning of vendor selection and contract negotiation, rather than addressing concerns reactively. Early involvement allows security to shape contract terms, vendor selection criteria, and requirements. While other options (legal review, policy communication, audits) are supportive activities, early procurement involvement is the most proactive and comprehensive method.
Why the other options are wrong
- A. Legal department review is important but doesn't ensure security concerns are identified and addressed during negotiations.
- B. Communicating policy after vendor selection is reactionary rather than preventive.
- D. Auditing after contract signature may be too late to negotiate favorable security terms.
That was 10 of 1,250.
The full ISACA CISM pack has all 1,250 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
