CISMP Sample Questions

CISMP Sample Questions & Answers

Four domains tie for the top weight: managing risk, security governance frameworks, how security architecture operates, and technical security measures, with smaller shares for core principles, DevSecOps, disaster recovery, and emerging technologies.

Launch the full CISMP simulator →

Showing 6 of 12 free samples.

  1. Question 1Intermediate

    Information Risk · Key components of risk management

    A financial organisation has implemented a mantrap (security vestibule) at the entrance of its data centre. The mantrap requires a valid smart card to enter the first door, and a biometric retina scan to open the second door, preventing tailgating. How is this control correctly categorised according to the CISMP v10.0 syllabus?

    Show answer & explanation

    Correct answer: B

    A mantrap is a physical control (it is a tangible, architectural security measure). Its purpose is to stop unauthorized entry before it occurs, making it a preventive control.

  2. Question 2Intermediate

    Information Risk · Risk management lifecycle

    A security manager is performing a quantitative risk analysis on a legacy database server. If the server fails, the business estimates the Single Loss Expectancy (SLE) to be £12,000 in lost revenue and recovery costs. Historical data suggests this type of failure occurs once every three years. What is the Annual Loss Expectancy (ALE) for this risk?

    Show answer & explanation

    Correct answer: C

    ALE is calculated by multiplying the Single Loss Expectancy (SLE) by the Annual Rate of Occurrence (ARO). The SLE is £12,000. An event occurring once every three years means the ARO is 0.333 (1/3). Therefore, ALE = £12,000 * (1/3) = £4,000.

  3. Question 3Beginner

    Information Risk · Risk management lifecycle

    An organisation decides that the cost of implementing encryption and access controls for a low-value, publicly available marketing dataset far exceeds the potential impact of its exposure. Management formally documents this decision and takes no further security action regarding this dataset. Which risk treatment option has been applied?

    Show answer & explanation

    Correct answer: D

    Risk acceptance occurs when an organisation acknowledges a risk but decides not to take any action to mitigate, transfer, or avoid it, typically because the cost of the control outweighs the potential loss. This must be formally documented.

  4. Question 4AdvancedSelect 2

    Information Risk · Key components of risk management

    During a risk identification workshop, a security manager is categorising various threats to the organisation's new customer portal. According to the CISMP v10.0 syllabus, which TWO of the following are correctly categorised as deliberate cyber threats? (Select TWO)

    Show answer & explanation

    Correct answers: B, D

    Credential stuffing is a deliberate, malicious cyber attack designed to breach systems using stolen username/password pairs.

    Deploying ransomware is an intentional, malicious cyber attack (deliberate threat) aimed at extortion.

  5. Question 5Beginner

    Information Security Frameworks · Organisational structure and policy for information security

    Within an organisation's information security documentation hierarchy, which document type provides mandatory, high-level management intentions and directions regarding security, without detailing the specific technologies used to achieve them?

    Show answer & explanation

    Correct answer: D

    A Policy is the highest-level document. It outlines mandatory management intentions, rules, and expectations but is technology-agnostic. Standards dictate specific mandatory technical requirements, procedures are step-by-step instructions, and guidelines are recommended best practices.

  6. Question 6Intermediate

    Information Security Frameworks · Security standards, procedures and frameworks

    A Chief Information Security Officer (CISO) is evaluating external frameworks to improve the organisation's foundational security posture. The CISO wants a framework that provides a prioritised, highly prescriptive set of specific technical practices grouped into Implementation Groups (IGs) based on the organisation's maturity. Which framework best meets this requirement?

    Show answer & explanation

    Correct answer: C

    The Center for Internet Security (CIS) 18 Critical Security Controls is specifically known for its prioritised set of technical best practices, which are grouped into three Implementation Groups (IG1, IG2, IG3) to help organisations scale their security efforts based on their size and resources.

Ready for the real thing?

The full CISMP simulator has every exam-style question, timed mode, and instant scoring.

Go to the CISMP simulator →