Certified Information Security Manager Practice Exams

CISM
⭐ Most popularAdvancedProfessionalInformation Security Manager

ISACA's management-level credential for information security leaders. Validates the ability to govern an information security programme, manage information security risk, develop and run the programme itself, and lead incident management — always tying security decisions back to business objectives.

240
minutes
70%
passing score
$760
exam fee

Start preparing today

5 flashcard sets · 5 learning tests · 2 timed exams · 150-question bank

Start Free Practice →

Overview

What this certification is and how the exam works.

The CISM (Certified Information Security Manager) is ISACA's credential for professionals who manage, design, and oversee an enterprise information security programme. It is deliberately a management rather than a technical certification: questions test what a security manager should do, in what order, and why, far more often than how a control works. The exam covers four domains: Information Security Governance (17%); Information Security Risk Management (20%); Information Security Program (33%); and Incident Management (30%). The exam is 150 items in 4 hours, scored on a 200–800 scale with 450 required to pass. Candidates need five years of information security work experience, at least three of it in security management across three or more domains, with waivers available for up to two years.

Why should I take the exam?

What this credential does for your career.

  • 1The recognized credential for security management roles — CISO, security director, and security programme manager
  • 2Consistently among the highest-paying IT certifications, and frequently a stated requirement in security leadership job postings
  • 3Proves you can express security in business terms: risk, cost, and objectives rather than tools and configurations
  • 4Complements the technical depth of CISSP with an explicitly governance-, programme-, and incident-management orientation

Skills measured

What you need to know to pass this exam.

  • Establish information security governance aligned to enterprise strategy, with defined roles and reporting lines
  • Develop security policies, standards, and procedures, and secure executive commitment and funding for them
  • Build a business case for security investment and justify it with risk reduction rather than fear
  • Identify, analyze, evaluate, and treat information security risk, and report residual risk against appetite
  • Assess and monitor third-party and supply-chain security risk throughout the vendor lifecycle
  • Develop an information security programme: roadmap, architecture, resources, controls, and awareness
  • Manage programme operations, integrate security into business processes and the SDLC, and measure with meaningful metrics
  • Prepare for incidents through classification, playbooks, communication plans, and tested response capability
  • Lead incident response, containment, eradication, recovery, and post-incident review to closure
  • Align business continuity and disaster recovery objectives with the incident management programme

Prerequisites

Credentials required before you can earn this certification.

🔑
Five years of information security work experience
At least three years must be in information security management across three or more of the four CISM domains. Waivers of up to two years are available for certain credentials and degrees. The exam may be passed first and experience submitted within five years

About our CISM practice exams

Our Certified Information Security Manager CISM question bank holds 150 exam-style questions with a written explanation on every answer, mapped to the four exam domains published for CISM, covering Information Security Governance, Information Security Risk Management, Information Security Program and Incident Management.

Alongside the bank there are two full-length timed exams at the real 240-minute limit and 70% pass mark, plus five topic-based learning tests for working a single domain at a time. Randomised mock exams are dealt on demand from the full 150-question pool, so you never run out of fresh papers.

Questions
150
Exam domains
4
Timed exams
2
Pass mark
70%

How our practice content is created

Practice questions are independently developed using the official ISACA CISM exam guide and ISACA documentation. Each question is checked for alignment with the current exam objectives and reviewed for technical accuracy before publication.

The CISM bank cites 1 distinct ISACA documentation page, and every question links the source it was written against — so you can check any answer at first hand.

Official CISM exam guide

ISACA is a trademark of its respective owner. This is an independent study resource and is not affiliated with, endorsed by, or authorised by ISACA.

Related certifications

Credentials that pair well with this exam or come next on the path.

Official resources

Provider documentation and study material for this exam.

Start Free Practice →

5 flashcard sets · 5 learning tests · 2 timed exams · 150-question bank