Start Your Free Practice Test
Enter your details, then choose a 25-question Quick Test or the full 50-question, 80-minute practice test.
Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.
Check your readiness for the ISACA Certified Information Security Manager (CISM) exam with 50 management-focused questions across all four domains of the 2022 job practice, each with an instant explanation. Free to take, timed to the pace of the real exam, and retake it as often as you want.
New to CISM? Learn more about the certification →
Enter your details, then choose a 25-question Quick Test or the full 50-question, 80-minute practice test.
This free ISACA CISM practice test checks your readiness with 50 management-focused questions across all four domains of the 2022 job practice, each with an explanation for every answer choice, under an 80-minute timer that matches the pace of the real exam. Built by Training Camp, an ISACA Accredited Training Partner. New to the certification? Learn what CISM is and who it is for, or see the CISM Boot Camp.
The CISM exam is organized into four weighted domains under the 2022 job practice: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). This practice test draws its 50 questions from every domain in the same proportions: 9, 10, 16, and 15. For the full breakdown, see our exam objectives hub or ISACA's official CISM exam content outline.
The real exam has 150 multiple-choice questions and a 240-minute (four-hour) time limit, and it is scored on a scale of 200 to 800 with 450 required to pass. Questions are written from the information security manager's point of view: what should the manager do first, what is most important, who is accountable. The distractors are often reasonable technical actions that are simply not the manager's best move, which is why practicing management judgment matters more than memorizing controls.
ISACA has announced an updated CISM exam content outline that takes effect November 3, 2026. Exams taken before that date use the 2022 job practice that this test follows. ISACA has not yet published the final domain names and weights for the new outline, and we will update this test when it does.
Take it once under the 80-minute timer without notes. That works out to 1.6 minutes per question, the same pace as 150 questions in 240 minutes on the real exam. Then read every explanation, including the ones for choices you did not pick. The wrong-answer explanations show the reasoning patterns ISACA expects, such as presenting options to the accountable risk owner rather than deciding for them, or preserving evidence before a containment action. Use the per-domain breakdown to decide where to study, then retake the test after a week to see whether your judgment has shifted.
Domains Covered · 2022 Job Practice
Strategy, governance structures, roles, and aligning security with business objectives.
Risk assessment, treatment, appetite, and reporting residual risk to accountable owners.
Building and running the program: architecture, metrics, awareness, and vendor risk.
Response planning, classification, containment, recovery, and post-incident review.
Four questions from the bank, one per domain, with the reasoning behind every answer. The full test has 50.
A newly hired information security manager finds that security initiatives are funded ad hoc, and the board frequently questions their value. To establish effective security governance, what should the manager do FIRST?
Correct. Governance begins with a security strategy that supports business objectives and has executive sponsorship; this is what gives security direction, authority, and demonstrable value to the board.
An information security manager is about to begin a risk assessment for a new customer-facing application. To ensure the results are meaningful to the business, what should the manager determine FIRST?
Correct. Understanding the value and criticality of the assets establishes the basis for impact, which drives the entire risk analysis and ensures results are relevant to the business.
An information security manager is initiating a business impact analysis (BIA). Which outcome of the BIA is MOST important for driving subsequent security and continuity decisions?
Correct. A BIA identifies critical processes and quantifies how impact grows over time when they are disrupted, which is the basis for setting recovery objectives and continuity priorities.
An information security manager is developing a new security program for an organization whose information security strategy has been approved but that has no program in place. To ensure the program delivers value and support, what should the manager establish FIRST?
Correct. The program is the vehicle for executing the approved security strategy; a roadmap tied to business objectives gives controls, staffing, and awareness their direction and a basis for prioritization.
Every one of the 50 questions works this way: an explanation for the right answer and for the one you picked, so a wrong answer teaches you something. Questions last reviewed against the current ISACA Certified Information Security Manager (CISM) objectives.
Quick answers about the test, the ISACA Certified Information Security Manager (CISM) exam, and how to prepare.
Yes. It is free to take, with a written explanation for every answer choice across all four ISACA CISM domains, and you can retake it as often as you want.
50 management-focused questions drawn from all four CISM domains, with an instant explanation after each answer and an 80-minute timer that matches the pace of the real exam (1.6 minutes per question). Your results break down by domain. It is a readiness check, not a substitute for full preparation.
The ISACA CISM exam has 150 multiple-choice questions and a 240-minute (four-hour) time limit.
CISM is scored on a scale of 200 to 800, and you need a scaled score of 450 or higher to pass. The scaled score is not a percentage of questions answered correctly.
The 2022 job practice has four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%).
Yes. ISACA has announced an updated CISM exam content outline that takes effect November 3, 2026. Exams taken before November 3, 2026 use the 2022 job practice that this test follows. ISACA has not published the final domain names and weights for the new outline, and we will update this test when it does.
CISM tests management judgment rather than hands-on technical skills, and most questions ask what the information security manager should do first, what is most important, or who is accountable. To certify, ISACA requires five years of information security work experience, with at least three of those years in information security management; waivers are available for certain other certifications and degrees.
Study ISACA's official CISM Review Manual and question database, use a structured CISM study guide, and consider an accelerated CISM Boot Camp that includes the exam voucher and a free retake if you need it. Practice questions help you get used to the manager's decision-making perspective.