CISM 365 Simulation Exam Questions Practice Exam — CISM 365 Simulation Exam Questions

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Exam information

CISM (Certified Information Security Manager) Latest Complete Exam Information

Basic Exam Information

- Exam Languages: Multiple language options are available, including Simplified Chinese, Traditional Chinese, English, Japanese, etc., with globally unified language selections.

- Registration Eligibility: There are no restrictions for exam registration, and all candidates may sit for the exam. However, formal CISM credential application is required after passing the exam. Credential application prerequisites:

 • Minimum 5 years of professional experience in information security, with 3 years concentrated in four core information security management domains (strategy, program management & implementation, security governance, incident management)

 • Education‑based experience exemptions: A 4‑year bachelor’s degree deducts 1 year; a master’s degree deducts 1 year; an information‑security‑focused bachelor’s degree deducts 1 year

 • Relevant certifications (e.g., CISSP, CISA, CRISC) deduct 1 year

 • Compliance with the ISACA Code of Professional Ethics

- Exam Fees: USD 575 for ISACA members, USD 760 for non‑members; an additional USD 50 certification fee is required for credential application upon passing the exam.

- Exam Duration: 4 hours (240 minutes), covering time for answering all exam questions.

- Exam Format:

 • Global Standard: Two modes are available – remote‑proctored online exams (video proctoring via PSI) and in‑person computer‑based testing (CBT).

 • Special Rule for Mainland China: Only in‑person CBT at authorized test centers is available (arranged by ISACA‑authorized partners).

- Exam Content: Comprises 150 multiple‑choice questions, all scored with no unscored pre‑test items.

- Score Information:

 • A preliminary pass/fail score report is available immediately after the exam

 • Official exam results are sent via email within 10 working days post‑exam

 • Passing score: 450 out of a full score of 800 (200‑800 scoring scale)

- Exam Eligibility Validity: After successful registration, candidates must book and complete the exam within 12 months; exam eligibility expires if overdue.

- Reschedule & Cancellation Policy: Rescheduling or cancellation must be completed at least 48 hours prior to the exam appointment; no changes are allowed within 48 hours before the exam start time.


---


Detailed Exam Content (Current Exam Outline Valid until November 3, 2026)

The CISM exam covers four core knowledge domains with a total weightage of 100%, focusing on the management capabilities and practical application of information security managers.


1. Information Security Governance 17% :Corporate governance culture, regulations and frameworks, information security strategy formulation, governance standards, budget & resource planning, business case development

2. Information Security Risk Management 20% :Risk assessment and analysis, vulnerability & control deficiency analysis, risk response options, risk & control ownership, risk monitoring and reporting

3. Information Security Program Development and Management 33% :Program resource management, security policy & procedure formulation, security awareness training, vendor management, security metrics and performance evaluation

4. Information Security Incident Management 30% :Incident detection, investigation, response and recovery planning, business impact analysis (BIA), business continuity & disaster recovery, incident communication and reporting


Upcoming 2026 November 3 Exam Outline Update

- Weightage of Risk Management (Domain 2) will increase to 33%, becoming the largest domain

- New content on enterprise architecture and information security architecture will be added

- Greater emphasis will be placed on information security strategy and program development

- New study materials will be released on September 1, 2026



Registration Process

Global Standard Registration Process

1. Visit the [official global ISACA website](https://www.isaca.org/) to create and log into a MyISACA account

2. Register for the CISM exam, fill in personal information, work experience and other relevant details

3. Pay the exam fee (USD 575 for members / USD 760 for non‑members)

4. Receive an Authorization to Test (ATT) notification via email within 1‑3 working days upon successful payment, including candidate ID and 12‑month eligibility validity

5. Log into the ISACA account, click Certification & CPE Management, then click Schedule Your Exam

6. Redirect to the PSI dashboard to select exam time, location and format (only in‑person CBT available for Mainland China)

7. Save the PSI appointment confirmation email received

8. Present valid ID documents matching registration information on exam day


Special Registration Process for Mainland China Candidates

1. Register via the [ISACA China official website](https://www.isaca.org.cn/) or ISACA‑authorized partners such as ZhongShen Audit Online

2. Adopt the mode of institutional registration & payment followed by individual exam scheduling

3. Submit personal information, academic certificates and other documents for institutional‑assisted registration

4. Pay the exam fee (USD 575 for members / USD 760 for non‑members) and complete registration procedures via authorized institutions

5. Independently book in‑person test centers in Mainland China via the PSI platform after receiving the ATT notification

6. Present valid ID documents (ID card or passport) on exam day



Supplementary Notes

1. Credential Validity: The CISM credential is valid for 3 years. Holders must earn 120 Continuing Professional Education (CPE) credits and pay renewal fees to maintain credential validity.

2. Retake Policy: Candidates who fail the exam must wait 30 days for a retake; a 90‑day waiting period is required after two consecutive failures. Retake fees are the same as initial exam fees.

3. Exam Update: The new exam outline will take effect on November 3, 2026. A major update to the exam question bank is scheduled after this date.



Wish all candidates success in their exams!

Sample questions

CISM 365 Simulation Exam Questions · Q1
The IT service desk is not adequately prepared for recent ransomware attacks targeting user workstations. When formulating an action plan to improve the service desk's readiness, which of the following is the highest priority?
  • A.
    Update the information security incident response manual
  • B.
    Enhance the enterprise's data backup capabilities
  • C.
    Invest in threat intelligence capabilities
  • D.
    Implement key risk indicators (KRIs) for ransomware attacks

Answer: A

Key Focus: Priority of basic preparation for incident response. As the frontline response role, the service desk's core pain point of inadequate preparation is the lack of clear operational guidelines. Updating the information security incident response manual can directly provide standardized processes (such as escalation paths, disposal steps, and tool usage) after a ransomware attack, making it the most direct priority action to improve readiness. - Eliminate B: Enhancing data backup capabilities is a long-term defensive measure to prevent ransomware, not an immediate priority for improving the service desk's "response readiness"; - Eliminate C: Investing in threat intelligence capabilities is an early warning tool that cannot address the service desk's existing problem of "no processes for response"; - Eliminate D: Implementing KRIs is a risk monitoring indicator used to identify attack trends, which does not directly improve the service desk's response operational capabilities.
CISM 365 Simulation Exam Questions · Q2
Which of the following is most conducive for the information security manager to gain organizational support for implementing security controls?
  • A.
    Develop an enterprise risk management framework
  • B.
    Communicate the results of a business impact analysis (BIA)
  • C.
    Establish effective stakeholder relationships
  • D.
    Conduct regular vulnerability assessments

Answer: B

Key Focus: Core logic for gaining organizational support for security controls. BIA results directly link the specific business impacts of missing security controls (such as revenue loss, compliance penalties, reputational damage, and business downtime), enabling management and business departments to intuitively perceive the necessity of security controls, which is the most persuasive basis for support. - Eliminate A: Developing a risk management framework is foundational system construction that does not directly reflect the business value of individual security controls, making it difficult to drive immediate support; - Eliminate C: Establishing stakeholder relationships is a long-term communication foundation, but without specific business impact data, persuasion is insufficient; - Eliminate D: Conducting regular vulnerability assessments is a technical risk identification method that only indicates the existence of risks, not the business benefits of control measures.
CISM 365 Simulation Exam Questions · Q3
What is the main purpose of an unannounced disaster recovery exercise?
  • A.
    Evaluate service level agreements
  • B.
    Provide metrics to senior management
  • C.
    Estimate recovery time objectives
  • D.
    Assess how personnel respond to the situation

Answer: D

Key Focus: Core objective of an "unannounced" disaster recovery exercise. Such exercises simulate the suddenness of real disasters, with the core purpose of testing personnel's actual response capabilities without prior warning (such as operational proficiency, cross-departmental collaboration efficiency, emergency judgment, and process execution accuracy). - Eliminate A: Evaluating service level agreements is an indirect auxiliary value after the exercise, not the main purpose; - Eliminate B: Providing metrics to senior management is a subsequent output of the exercise, not the core objective; - Eliminate C: Estimating the recovery time objective (RTO) is one of the core objectives of a planned exercise. Unannounced exercises focus more on the authenticity of the response process rather than precise time estimation.
CISM 365 Simulation Exam Questions · Q4
Which of the following is the most important consideration for determining the type of disaster recovery site?
  • A.
    Recovery Time Objective (RTO)
  • B.
    Disaster recovery test results
  • C.
    Data retention requirements
  • D.
    Reciprocal agreements

Answer: A

Key Focus: Core basis for deciding the type of recovery site. RTO defines the maximum acceptable time for business recovery after a disaster, directly determining the deployment mode of the recovery site: - Hot standby site (RTO < 4 hours), warm standby site (RTO 4-24 hours), cold standby site (RTO > 24 hours) all require matching resource investment and deployment modes based on RTO. - Eliminate B: Disaster recovery test results are the basis for evaluating the effectiveness of existing sites, not a prerequisite for determining the site type; - Eliminate C: Data retention requirements are decision factors for backup strategies (such as backup cycles and storage media), unrelated to the type of recovery site; - Eliminate D: Reciprocal agreements are alternative recovery plans for specific scenarios (such as mutual backup with peer enterprises), only applicable to niche cases, not core decision criteria.
CISM 365 Simulation Exam Questions · Q5
Which of the following is most helpful for ensuring that information security aligns with enterprise objectives?
  • A.
    Develop and implement a security awareness program
  • B.
    Implement a control self-assessment process
  • C.
    Internal audit participation in security processes
  • D.
    Establish acceptable risk thresholds

Answer: D

Key Focus: Core of aligning information security with enterprise objectives. The essence of enterprise objectives is to achieve business value within acceptable risk limits. Establishing acceptable risk thresholds clarifies the boundaries of security work (such as which risks are tolerable and which require mandatory controls), ensuring that security measures do not deviate from the enterprise's risk appetite and business development direction. - Eliminate A: A security awareness program is a specific implementation measure that only improves employee compliance and cannot address the strategic alignment between security and enterprise objectives; - Eliminate B: Implementing a control self-assessment process is a tool to test the effectiveness of controls, not directly related to enterprise objectives; - Eliminate C: Internal audit participation in security processes is a supervision and correction method used to identify deviations between security and objectives, not the core for ensuring alignment.

FAQ

How many practice questions are available for CISM 365 Simulation Exam Questions?

This question bank includes 365 CISM 365 Simulation Exam Questions practice questions covering single and multiple choice, each with answers and explanations.

Are CISM 365 Simulation Exam Questions practice questions available in Chinese and English?

Yes, CISM 365 Simulation Exam Questions practice questions are provided in both Chinese and English.

Can I try CISM 365 Simulation Exam Questions practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.