CISMP Sample Questions & Answers
Four domains tie for the top weight: managing risk, security governance frameworks, how security architecture operates, and technical security measures, with smaller shares for core principles, DevSecOps, disaster recovery, and emerging technologies.
Launch the full CISMP simulator →Showing 6 of 12 free samples.
- Question 1Intermediate
Information Risk · Key components of risk management
A financial organisation has implemented a mantrap (security vestibule) at the entrance of its data centre. The mantrap requires a valid smart card to enter the first door, and a biometric retina scan to open the second door, preventing tailgating. How is this control correctly categorised according to the CISMP v10.0 syllabus?
Show answer & explanation
Correct answer: B
A mantrap is a physical control (it is a tangible, architectural security measure). Its purpose is to stop unauthorized entry before it occurs, making it a preventive control.
- Question 2Intermediate
Information Risk · Risk management lifecycle
A security manager is performing a quantitative risk analysis on a legacy database server. If the server fails, the business estimates the Single Loss Expectancy (SLE) to be £12,000 in lost revenue and recovery costs. Historical data suggests this type of failure occurs once every three years. What is the Annual Loss Expectancy (ALE) for this risk?
Show answer & explanation
Correct answer: C
ALE is calculated by multiplying the Single Loss Expectancy (SLE) by the Annual Rate of Occurrence (ARO). The SLE is £12,000. An event occurring once every three years means the ARO is 0.333 (1/3). Therefore, ALE = £12,000 * (1/3) = £4,000.
- Question 3Beginner
Information Risk · Risk management lifecycle
An organisation decides that the cost of implementing encryption and access controls for a low-value, publicly available marketing dataset far exceeds the potential impact of its exposure. Management formally documents this decision and takes no further security action regarding this dataset. Which risk treatment option has been applied?
Show answer & explanation
Correct answer: D
Risk acceptance occurs when an organisation acknowledges a risk but decides not to take any action to mitigate, transfer, or avoid it, typically because the cost of the control outweighs the potential loss. This must be formally documented.
- Question 4AdvancedSelect 2
Information Risk · Key components of risk management
During a risk identification workshop, a security manager is categorising various threats to the organisation's new customer portal. According to the CISMP v10.0 syllabus, which TWO of the following are correctly categorised as deliberate cyber threats? (Select TWO)
Show answer & explanation
Correct answers: B, D
Credential stuffing is a deliberate, malicious cyber attack designed to breach systems using stolen username/password pairs.
Deploying ransomware is an intentional, malicious cyber attack (deliberate threat) aimed at extortion.
- Question 5Beginner
Information Security Frameworks · Organisational structure and policy for information security
Within an organisation's information security documentation hierarchy, which document type provides mandatory, high-level management intentions and directions regarding security, without detailing the specific technologies used to achieve them?
Show answer & explanation
Correct answer: D
A Policy is the highest-level document. It outlines mandatory management intentions, rules, and expectations but is technology-agnostic. Standards dictate specific mandatory technical requirements, procedures are step-by-step instructions, and guidelines are recommended best practices.
- Question 6Intermediate
Information Security Frameworks · Security standards, procedures and frameworks
A Chief Information Security Officer (CISO) is evaluating external frameworks to improve the organisation's foundational security posture. The CISO wants a framework that provides a prioritised, highly prescriptive set of specific technical practices grouped into Implementation Groups (IGs) based on the organisation's maturity. Which framework best meets this requirement?
Show answer & explanation
Correct answer: C
The Center for Internet Security (CIS) 18 Critical Security Controls is specifically known for its prioritised set of technical best practices, which are grouped into three Implementation Groups (IG1, IG2, IG3) to help organisations scale their security efforts based on their size and resources.
Ready for the real thing?
The full CISMP simulator has every exam-style question, timed mode, and instant scoring.