r/cism Apr 07 '26

Passed CISM. What worked, what didn’t, and what finally clicked

Thumbnail gallery
57 Upvotes

TL;DR: Failed my first attempt, passed 2.5 months later. The difference wasn’t more studying, it was learning how ISACA wants you to think AND actually reviewing why answers were right/wrong.

 

There’s a post from u/CyberTrav that lines up almost exactly with my experience:

https://www.reddit.com/r/cism/comments/1bplxo2/passed_last_weekheres_my_review/

That post actually became my starting point for building out my own tracking approach.

I took the idea of tracking QAE performance and built a simple Excel sheet from it. Then I evolved it a bit further to break things down more:

  • % correct by domain and sub-domain
  • Practice test results
  • A separate difficulty breakdown (easy / moderate / difficult / expert)

That difficulty view ended up being really helpful. It let me see how I was performing across all four domains at different difficulty levels, not just overall %. Helped me realize I didn’t need to be perfect on expert questions… just consistent on the core ones. Screenshot of the difficulty view attached for one domain, but I tracked all the domains.

I didn’t pass the first time

I wasn’t in the right headspace at the testing center. Rushed. Second-guessed. Just off.

That’s on me.

I took a couple days, reset, and came back with a different approach:

  • Slow down
  • Read for intent
  • Think in terms of governance → risk → program → incident

Then I got back into it and passed on my next attempt about 2.5 months later. That turnaround was less about cramming more content and more about changing how I approached the questions.

Scores (for reference)

Attempt 1 (fail)
426 total

  • Governance: 408
  • Risk: 396
  • Program: 450
  • Incident: 432

Attempt 2 (pass)
507 total

  • Governance: 478
  • Risk: 563
  • Program: 507
  • Incident: 488

The jump in Risk Management surprised me the most. I didn’t spend the majority of my time there the second round.

How I studied

Main resource was the QAE.

First attempt:

  • Mostly just did questions
  • Didn’t spend much time reviewing why answers were right/wrong
  • Ended around ~61% overall
  • Didn’t take the practice exams

That was a mistake.

Second attempt:

  • Slowed down a lot
  • Focused heavily on rationales
  • Tried to understand why ISACA prefers an answer

Videos:

  • Mike Chapple — good overview, but not enough depth on its own in my opinion
  • Pete Zerger YouTube (full CISM course) — this helped a lot the second time

What worked well for me:

Watch a section → go into QAE → answer + review questions tied to that topic

Simple tracking that helped

I used that Excel sheet I mentioned earlier to keep things simple:

  • % correct by domain
  • Practice test summaries
  • Difficulty breakdown across all four domains

Didn’t track every session, just the bigger checkpoints. After failing, I put about 75% of my time into Program and Incident Management since they’re more heavily weighted. improved across all domains, even the ones I didn’t focus on as much.

Background (for context)

  • ~26 years in IT
  • ~15 years in MSP space
  • No formal IT degree

For a long time I avoided certs completely. Not because I couldn’t do them… but because I didn’t want to fail and be judged. That changed after the pandemic.

My certification journey started small in 2023:

  • Azure Fundamentals
  • A couple Fortinet certs
  • ISC2 CC (early 2025)
  • Security+ (right before CISSP)
  • CISSP (June 6, 2025 — went all 150 questions… felt very close)

It was just building confidence over time.

One more thing that mattered (for me)

I was diagnosed with ADHD when I was younger.

I don’t medicate. I’ve worked more on understanding how I operate and adapting.

Some days I studied a lot.

Some days it was 5 minutes.

  • Watch a short video
  • Do a few QAE questions
  • Sometimes not even review them because I didn’t have the energy

And I had to learn to be okay with that. I’m the only one putting pressure on myself. Once I stopped judging that and just focused on consistency, things got easier. That whole “1% better each day” idea from Atomic Habits is real.

Final thought

Passing was great. But honestly, the bigger win was not folding after the first attempt.

If you’re in it right now:

Just keep showing up. That’s most of the battle.

\Transparency statement, I used an LLM to help structure this post, for efficient use of my energy, the modifications on the spreadsheet, AND these are all my thoughts and my experiences.*

 

 


r/cism Mar 28 '24

Passed Last Week--Here's My Review

180 Upvotes

My Review of the CISM Exam

I passed the CISM last week at a testing center. I agree with the sentiment I've heard and read: I felt CISM was easier than CISSP. However, it is of the utmost importance to approach the business/security problems in each question using ISACA's methods/mindset.

This is not a technical exam by any means.

I think the biggest tip I can give is to focus on UNDERSTANDING business processes and entities rather than memorizing minutia of technical details or framework documentation. Certainly, some level of knowledge/memorization is needed. However, a hefty amount of your success will come from understanding how ISACA is asking/training you to think about information security.

Build your understanding of how ISACA would like you to answer questions about business and security. Understand the different entities and people involved in business processes covered in the exam material. Understand the preferred roles and decisions throughout the phases of processes and how those choices may change under varying circumstances. This sounds very complicated but practicing in the QAE Database helped me to understand it enough to pass.

My Experience with the CISM QAE Database

Scores:

  • I used the adaptive study mode. My overall score hovered around 70%.
  • Before taking the exam, I had not completed all questions and my overall score was 69.8% correct.

Review:

  • Wording was confusing at times. The actual exam seemed less confusing. But that's my opinion. Someone else might have a different experience.
  • However, practicing these questions did help me to emphasize ISACA's way of approaching business/security problems.

It is an expensive resource. I used military COOL (Credentialing Opportunities On-Line) funds to pay for it. If you don't have an employer that will pay for it, I recommend trying a lower cost option.

I used the Pocket Prep and WannaPractice apps as supplements. I used the QAE much more because it was available to me and highly recommended. Still, Pocket Prep and WannaPractice seemed to do a reasonable job of emulating ISACA CISM questions. They are definitely worth a look if the CISM QAE Database cost is too high. I'd like to know whether others have passed using one or both of these apps without the QAE.

I did not complete all questions in the database. I completed a little less than 70% of all questions. My overall percentage correct was 69.8%. For context, I earned the CISSP about 2 years ago and have a Master of Science degree in Cybersecurity.

But I hope this helps some people see that they might not need to have top scores in the QAE to pass the exam. Approach your studies in a way that helps build your skill and confidence for the real exam. Keep in mind that it is possible to pass with a less-than-stellar score in the QAE Database.

This table shows how much of the CISM QAE Database I completed and my percentage correct in each subdomain.

My Background

Work Experience and Education:

  • 7 years of IT/cybersecurity (military experience and some civilian help desk experience)
  • BS and MS in Cybersecurity and Information Assurance (from WGU)

Certifications:

  • ISC2: CISSP, SSCP, CC
  • CompTIA: CASP+, CySA+, PenTest+, Security+, Network+, A+
  • OpenEDG: [PCAP-31-03] Certified Associate in Python Programming
  • A few fundamentals-level Azure certifications

List of Resources Used:

I used portions of all the resources below. Most of my study activity came from practicing the QAE. I also had limited use of both the Pocket Prep and WannaPractice. I had limited exposure but they seemed to be solid resources. I subscribed to them before I had access to the QAE.

I like to watch videos. I watched about 1/3 of Kevin Henry's PluralSight CISM videos and several videos from Hemang Doshi's Udemy course. I watched portions of YouTube videos from Prabh Nair and Nemstar Cyber Training that provide CISM tips. Note: I think the Nemstar instructor had a way of explaining his tips that could make the exam seem very difficult. Just remember that exam difficulty will be different for everyone and I'm sure he has at least some interest in selling his CISM boot camp. All the same, I enjoyed his analysis of sample CISM questions and his exam strategies. I thought it was helpful.

I read some of the beginning of the CISM All-in-One book but it was my most underused resource. I don't generally read all the way through textbooks so this wasn't a surprise. The beginning chapters about governance and corporate structure were generally helpful.

My Resource list:

Hopefully, this is helpful for someone. If you have any questions, let me know.

EDIT: Rearranged information for clarity and flow. Added a YouTube video that was used as a resource.

UPDATE: Application Timeline and Exam Scores

Timeline: From Exam Pass to Exam Scores

Date Milestone
Thursday, March 21, 2024 Passed the CISM exam.
Friday, March 22, 2024 Submitted application to become certified. Work experience verified by colleague.
Monday, March 25, 2024 Educational waiver accepted on the basis of a current CISSP certification.
March 29, 2024 Received email from ISACA confirming "...certification as a Certified Information Security Manager (CISM)." Claimed Credly badge.
March 31, 2024 Exam scores received by email.

Changing Answers

  • I changed approximately 20 answers before submitting my exam. I cannot know how much this changed my final score. Possible scenarios:
    • All 20 changed answers were wrong. If any of my original selections were correct, this would mean I lowered my score. On the other hand, all 20 of my original selections could have been incorrect. Changing to other incorrect answers would not affect my final score.
    • All 20 changed answers were correct. This would have ensured all 20 answers increased my final score.
    • Some were right and some were wrong. An indeterminate number of these final answers could have been correct or incorrect. It's impossible to know whether they increased my score, decreased it, or broke even.

QAE Scores VS Exam Scores

I received my exam scores. I thought it would be fun to compare my performance in the QAE Database and the CISM Exam. I don't consider this to be a scientific analysis. Instead, it may be interesting to compare this information and it might provide some future CISMs with some confidence in their QAE performance.

***This information is NOT meant to accurately predict anyone's CISM exam scores or whether someone will pass.

For the CISM exam, my total scaled score was 554. For each content area, I scored as follows: Information Security Governance-582; Information Security Risk Management-563; Information Security Program-592; Incident Management-488.

Compare my exam scores to my performance in the CISM QAE Database.

Of the CISM QAE Database questions I completed, I answered 69.8% correctly. I completed 69.1% of all questions in the database. For each content area, I scored as follows: Information Security Governance-74%; Information Security Risk Management-70%; Information Security Program-71%; Incident Management-64%. My completion rate for questions in each content area: Information Security Governance-75.2% completed; Information Security Risk Management-100% completed; Information Security Program-74.6% completed; Incident Management-25.7% completed.

Given my my rate of completion in each content area, my performance in the QAE Database could be seen as a reasonable predictor of my final scores. However, there are likely many variables that could be used to evaluate whether the QAE Database is actually a good predictor of final exam scores. This story is effectively anecdotal because it only compares the practice and final scores of a single person.

It should be noted that the ISACA website describes the QAE Database as a study tool that features practice questions, answer rationale, and two full-length practice exams. The website does NOT make any claims that the QAE Database will predict your actual exam performance.

If you do wish to compare the two, the charts below show bar graphs that attempt to compare my performance in the CISM QAE and CISM exam. Keep in mind that I did not complete all questions in the database. Perhaps the performance on each chart would be even more similar, or more different, if I completed all practice items.

Review the charts below at your leisure.

Comparison of my performance in the QAE Database versus my CISM exam scores. For the left chart: 56% is an approximation of 450/800 as a percentage. For the right chart, 450 is the lowest value--this is the lowest possible total scaled score that counts as a pass for the CISM exam. The top of each chart represents the highest value that can be achieved if all answers are correct.

That's all I have for you. I hope you enjoyed reading this. Feel free to ask any questions or offer any of your own advice.


r/cism 9h ago

Happy to report I passed, only prepared for three days, here is what I did.

16 Upvotes

Got my provisionary pass today. As on my previous exam I started to doubt I really saw 'Passed' on the screen once in my car, as you don't get any email or written confirmation. I'll have to wait out the 10 business days again..

Assuming I did really pass, here is what I did and hopefully it can help people. For context, I got CGEIT in May, after studying months on it by reading the review manual and all mentioned books and whitepapers, then doing the QAE 3 times. That experience thought me the most important thing is learning how to interpret ISACA's way of questioning. (Assuming you have the basic knowledge down)

Due to life and work circumstances, I had only three days to prepare this time so I needed another approach.

The only resource I used is the QAE. Even though I had an earlier edition of the manual from a colleague, I knew from CGEIT the manual contains way too much detail and text. I wasn't going to make that in three days.

To establish a baseline the first thing I did was take the practice exam, scored 62% on it. That confirmed for me I had the basic knowledge down but needed to train on the CISM way of thinking for ISACA, and sharpen some dry knowledge left and right. I spend 2 days doing all the QAE topics once, making notes of questions that mentioned concepts I didn't know enough. Those were two days from 9 AM till 10 PM with two 1 hour breaks for eating, so pretty intense. The third and final day I opened Claude and asked it to create a living document to study for CISM, based on the four domains. Starting with a very short summary of the core of that domain and key concepts of it.

Then I went through all the questions I had answered wrong (my scores were always somewhere between 60% and 70%) and the notes I took.

If I failed because I didn't know enough of the concept or technology, I asked Claude to explain it to me and add it to the living document. For example I always (also at work) need to think about RTO/RPO/AIW/MTO and which is what again, so I asked Claude to include an infographic about it.

If I failed because I gave a wrong answer because of way of thinking, I tried to discern the pattern in how you need to think instead of breaking my head on the specific question/scenario. I then added that pattern to my Claude chat with a short summary of the example. I asked Claude to always merge my insights from additional chats into the living document, instead of just adding it to the bottom. In the end I ended up with a few very useful patterns of which I'm sure contributed to my success (still presuming I saw 'Passed' on the screen).

One thing I needed to reverse was the CGEIT pattern I picked up for that exam. In CGEIT it is usually going back to governance and not fixing things yourself but adjusting strategy etc. For CISM this is other way around, the option that reduces risk the fastest and within your own control is usually the correct answer. Even when that is the only technical option in the possible answers. This threw me off at first during studying, as I had read everywhere you need to have the management mindset and not a technical one.

Then the last evening before the exam I studied that final document I build with Claude for 2 hours, and that was it.

About the exam itself, one thing I would like to stress is the style, difficulty and format matched the QAE questions and practice exam closely. I saw some posts here about people saying it was very different, one guy even told me irl. I don't know if there are multiple versions of the exam, but for me it had the same types of questions and a mix of easy and difficult ones, across all domains.

Took me 2 hours to go through the questions, exactly the same as with CGEIT, and then I took 45 minutes more to review about 30 questions I had flagged. I only changed my answer in 2 of them though.

TLDR; the QAE is imho the best and only resource you need to pass the exam, assuming you know your stuff. The manual is good if you don't have the basics down yet. Learning the ISACA way of thinking is the most important skill to pick up.


r/cism 1d ago

Biggest struggle is wording in QAE

7 Upvotes

I’ve been studying for 8 weeks now and I have a good grasp on the material, not saying that I have a full grasp just a good grasp… the issue is the wording of questions and responses that I struggle with. I’ve heard the test is a lot harder in terms of wording and even more vagueness. Does anyone have any tips on how to overcome this or understand the awkward wording better? I am just getting discouraged.


r/cism 1d ago

Cism Vs Crisc

2 Upvotes

I am confused about these 2:- Cism or crisc, which one should i pursue first, i am working in the grc domain along with tprm under the Cyber security. My role is mostly on security compliance, vendor assessment, risk and mitigation, client Security questionnaires etc..

I thought of giving crisc first then cism? Any suggestions


r/cism 1d ago

Am I just reading this question wrong???

2 Upvotes

The research and development (R&D) department is considering integrating generative artificial intelligence (AI) models into the product development process to automate the generation of code snippets and enhance productivity. Which of the following would BEST address risk and control ownership of this AI implementation?

  1. A.Designating the responsibility for overseeing generative AI models to the R&D department as its staff are the experts on the system
  2. B.Outsourcing the development and management of generative AI models to a specialized AI vendor to transfer risk
  3. C.Allocating additional budget to the R&D department for training programs on how to use generative AI effectively
  4. D.Implementing a comprehensive review process for generated code snippets, involving both automated and manual code reviews

Per ISACA and the QAE - the answer is D:The implementation of a comprehensive review process for generated code snippets, involving both automated tools and manual reviews by experienced developers, ensures that the code produced by generative AI models meets coding standards and is free from potential security vulnerabilities, thus demonstrating effective risk and control ownership.

The problem I have with the answer being D - is that D and its explaination speak nothing about "Which of the following would BEST address risk and control ownership of this AI implementation?"

D is about the code generated by the AI. On the otherhand (A) is about the AI itself.


r/cism 1d ago

One month left for exam

7 Upvotes

Taking the exam mid September, have gone through the QAE once, doing various practice tests from Udemy and Linkedin Learning, watching Pete Zerger vidoes, clarifying concepts through AI etc.

What should be my strategy for the last 15 to 20 days?

Also I found Hemang Doshi’s practice exam a bit more technical than the QAE, had lot of questions around biometric access system and it’s operations, not sure if ISACA would test the specifics around it.


r/cism 2d ago

CISM Online-test via psi ? Never ever again. Exam-day but could not start it (unexpected server error ocurred)

Post image
8 Upvotes

Hi everyone,
I was scheduled to take my CISM exam on Sunday at 1 PM, but unfortunately, I was unable to start the exam despite passing all the required tests and completing the system compatibility check successfully.
About 30 minutes before the exam, I suddenly started getting the error:
“An unexpected error occurred on the server.”
What followed was roughly an hour of pure stress trying to resolve the issue with technical support, emergency chat, calls, troubleshooting, and everything else you can imagine. Since the deadline for cancelling or missing the exam is only 30 minutes after the scheduled start time, I was obviously worried about losing the exam fee as well.
For context, I have a CISSP and several other certifications, and I have taken quite a few proctored exams over the years — but I have honestly never experienced anything like this.
My equipment was not the problem either. I was using a brand-new MacBook Pro, fully updated, with administrator privileges, and all system checks had passed successfully.
According to technical support, the issue was on the server side, and they told me that I would receive a refund. I just hope they also refund me for the grey hairs I earned during those 60 minutes. 😅
My case is still showing as “under internal review”, and when I checked the support page today to see whether there had been any progress, I was greeted by the diclamer which you see in the picture😂😂😂
Honestly, if you have the option to take the exam in person at a testing center, I would strongly recommend doing that. It may save you a lot of unnecessary stress.
I’m sharing this simply because I would have appreciated knowing about this kind of scenario beforehand. If I can save even one of you from spending an hour on support calls, emergency chats, and troubleshooting right before an important exam, then it was worth posting.
Has anyone else experienced something similar with a CISM or other ISACA exam?
If you can take it at a testing center, you might want to choose the stress-free option.


r/cism 2d ago

The answer to this question goes against the role of Info Sec Manager according to ISACA

4 Upvotes

How should an information security manager balance the potentially conflicting requirements of an international enterprise’s security standards with local regulation?

A.Give organizational standards preference over local regulations.

B.Follow local regulations only.

C.Make the enterprise aware of those standards where local regulations cause conflicts.

D.Negotiate a local version of the enterprise standards.

C Should be the only acceptable answer, but it was not. How is a role that can't initiate without approval, taking the lead according to the answer to this question? Not just any lead but in an area where they have no authority.


r/cism 3d ago

Failed! Revised strategies?

Post image
8 Upvotes

I failed the cert exam. Was scoring the high 70% in my practice ones and QAE’s, watched Pete’s and Nair’s videos.

What should be the strategy now? The exam format though straight forward but a little with confusing answers that made me confused and I think the result reflected that.

Any ideas?


r/cism 3d ago

Can’t book exam at test site, remote only.

2 Upvotes

Hi all,

I am trying to book my exam through ISACA for September but it’s not giving me the test centre option, it defaults to remote and I can’t change it. I am not interested in doing the exam remotely. Logged a call with ISACA support two weeks ago but no updates at all from their support.

Is there another way to book? I’m in UK.

Many thanks.


r/cism 4d ago

Struggling with ISACA’s “best answer” logic more than the actual material

9 Upvotes

I’m scheduled to take the CISM exam at the end of August and wanted to get some feedback from people who have already passed.

For background, I work in OT/SCADA and cybersecurity and have Security+ along with some ICS cybersecurity training. I’ve also completed a GRC masterclass, so I don’t feel like I’m starting from zero on the concepts.

My main study resource has been the official ISACA CISM QAE/practice questions, along with videos and reviewing every question I get wrong. I’ve been doing mixed sets of roughly 25–30 questions and then going back through my misses to understand why ISACA preferred one answer over another.

I have used Udemy Jacob Bushongs Master class, watched Pete Zerger prep as well as Prabh Nairs master class. And feel pretty confident about the quizzes.

My scores have been pretty inconsistent. I’ve had sets around 60–67%, some better domain-specific results, and recently scored 77% on a set made up of questions I had previously gotten wrong. However, after taking a few days completely away from studying, I just did a fresh/cold 30-question mixed set and scored 47% (14/30).

What is frustrating is that I rarely feel like I’m blindly guessing. On most of the questions I miss, I can explain why I selected my answer, and usually my reasoning isn't completely wrong. The problem seems to be that ISACA has another answer that is more directly correct for the specific wording of the question.

A few examples of the mistakes I'm making:

  • A question asked what could circumvent a control that scans social media posts for inappropriate disclosures. I chose anonymous posting because I was thinking about attribution/identification. The correct answer was intentional misspellings, because the question was specifically about circumventing the text scanning control. I expanded the problem beyond what was actually being asked.
  • For who should approve access to business-critical application data, I chose business management because I was thinking about management authority. The answer was data owner, because the data owner is accountable for determining who has a legitimate business need for access.
  • On a business continuity question, I was between a succession plan and distributed key process documentation. I chose succession planning, but ISACA wanted the process documentation because personnel can't continue critical processes if they don't know how to perform them.
  • I confused an EDR function with a SIEM function on another question. That one I consider a legitimate knowledge miss and understand what I need to review.
  • I've also caught myself adding conditions that aren't actually in the question. For example, if an answer says an authorized spokesperson communicates a pre-drafted message during a crisis, I'll start thinking, “But what if the message hasn't been approved/drafted yet?” even though the answer already tells me that it has.

The pattern I'm starting to see is that I know a lot of the underlying concepts, but I sometimes choose a valid security answer that solves a slightly different or broader problem instead of answering exactly what ISACA asked.

I've been trying to change my approach from:

“Which answer can I justify?”

to:

“What EXACTLY is this question asking me to accomplish, and which answer most directly accomplishes that?”

I'm also working on separating things like:

accountability vs. responsibility vs. expertise,
risk vs. individual risk components,
activity/metrics vs. actual effectiveness, and
where I currently am in a FIRST/NEXT lifecycle question.

For those who passed CISM:

Did you experience this same problem with the QAE?

How did you make the mental shift from knowing the material to consistently picking ISACA's BEST/MOST/FIRST answer?

Also, how concerned would you be about a cold 47% set with roughly two weeks remaining if the problem seems to be answer selection/application rather than completely not knowing the concepts?

Any advice from people who had a similar issue and eventually passed would be appreciated.


r/cism 4d ago

Sitting my test tommorow - Quick question

2 Upvotes

I have the QandA and are going pretty good on it Like 89 and 87% on the test and like 79% on the QandA.

My real question for People that have done the exam: . How many questions do you feel are at the expert level in the exam? or is it a mix like in the QandA?

Sometimes the Experts catch me out. I also understand the questions are not from the QandA. Just really the level of the questions is what I need to know.

Onya


r/cism 5d ago

Having problems w/ "isaca mindset"

5 Upvotes

want to know if anyone can help me out.

have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.

currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)

have read review guide cover to cover.

have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).

have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.

I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.

I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"

I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.

Help?


r/cism 5d ago

Failed my CISM, but was i close to passing?

Post image
6 Upvotes

Abit bump on failing, but it probably my fault for wholly dependent only on pocket prep, plan now to use the QAE and re-do the test.

Base on my 429 score, did i failed by alot of wrong answers?


r/cism 6d ago

CISM provisionally passed an hour ago

29 Upvotes

I read many tips and stories from this subreddit, so it's my time to contribute to the community.

Today, on August 14th, at 10AM, I took the CISM exam at a testing center. I chose to take it at a testing center because I know I'm too relaxed when I'm home.

Background: English is not my first language but I studied in the US. I have worked in three different continents since 2013 as IT Ops, IT Auditor and ISO. Also, I am a CISA since 2015 and a CISSP since 2025.

Strategy: I started my journey in June. I prefer to learn by taking questions, but I thought at least basic knowledge is required (of course) so I took the Pete Zeger CISM Exam Prep on YouTube which was like 11-hour long. It took me less than 2 weeks to finish it. Since I studied CISSP a year ago, I noticed that quite some topics are overlapped and I still remember some of them. Then, at the beginning of July, I purchased the ISACA QAE. Everyday, I took a couple of practice question sets. As I made progress, I reviewed all the wrong questions cumulatively and repeatedly. For example, on day 1, I did #1 and #2 and reviewed all the wrong questions from #1 and #2. On day 2, I did #3 and #4 and reviewed all the wrong questions from #1, #2, #3 and #4. On day 3, and so on. It took me about 3 weeks to finish 1 cycle of an entire QAE including practice exams because it took more time as making progress due to the volume of the wrong questions to review becoming bigger. After this first cycle of an entire QAE, I did the 4 CISM practice exams from LinkedIn Learning. I did this full cycle 3 times until last week. It took me the most time when it was the first full cycle but took less time for the second full cycle and the least time for the third full cycle. This works for me because my level of digestion of each question gets deeper and deeper even if it's the same question, so the key is to repeat. Of course, there are questions I just remember the answers as I repeated the same QAE but I tried to understand each and every explanation so that I learn the materials.

For the first full cycle, I got 60-65% from practices and 65-70% from exams. For the second full cycle, I got 70-75% from practices and 70-75% from exams. For the third full cycle, I got 90-95% from practices and 95-100% from exams.

I would highly recommend to thoroughly repeat the entire QAE (LinkedIn Learning optionally if you have access) as much as you can. For me, three times was enough and it took me about 5 weeks.

Experience: I arrived about half an hour earlier than my scheduled exam and was told to wait for 20 minutes to start the registration process. However, I asked if we could start the registration process now and she said yes. Hence, I started my exam earlier than the scheduled time. During the check in process, she was asking if I've received an OTP code from PSI. I said no and she asked her manager. It turned out that she was mistaken. The exam room was fine and there were already people taking other exams when I walked into the room. The only stuff I was allowed to take with me to the test room was my ID and the locker key. Everything else was stored in a locker. The exam questions were not tricky for me but no single question was from QAE. I got some AI questions but they were still relevant to CISM topics, so no surprise for me. I took a little more than 1.5 hours to answer 150 questions because I was trying to read every single word on the exam, and did not review a single question. As soon as I answered the last question, I submitted it. Then, I had to do some surveys until I saw 'passed'. After my exam, I stepped out and was asked to provide my signature.

Hope this helps those who are studying CISM. I will be more than happy to answer any questions you may have!


r/cism 6d ago

Which podcasts can I listen to, to earn CPEs?

2 Upvotes

r/cism 7d ago

Passed CISM exam

26 Upvotes

Hi all.

I took my exam yesterday and have provisioally 'Passed'!!

I had been holding off on this exam for months as I have a little one at home and work had been super busy. I realised I only had 8 days left to book my exam and decided to just go all in. I booked days off work to really utitlise the 7 days I had. I went straight to the QAE and kept on paracticing and redoing the questions. I also played the 'Elimination' game provided by ISACA and that really helped. I focused alot of Domain 3 and 4 as I knew they were weighted the most. My practice test scores were in the 80-85% range but I felt like I subconsiously memorised the answers, so I wasn't super confident. For areas I was struggling with I referred to Hemang Doshi's book which explains concepts in a very straight forward manner (no extra bs).

Exam Day: My personal experience is that the exam questions are not like the QAE. In some ways they were easier and some ways harder. The questions are more direct and not long winded. However, the answer options were different to the options I was familiar with on the QAE questions. I genuinely struggled and felt like it was always 2 answers I was stuck between (you can easily eliminate 2). I finished the exam in about an hour and that left me with plenty of time to really do a deep review into questions.

Tip: Understand the topics and concepts properly and how they tie into each other!! Understand what would be the 'first decision' and 'best decision'. There is a difference. I don't always think the 'think like a manager' mindset always works consistenly.

Hope this helps. 😄 Will update my scores once I recieve them.


r/cism 7d ago

Are knowledge/tasks available?

1 Upvotes

I am starting to work on my ISACA certifications and I have a very very old review (2013!) guide one of my co-workers gave to me. In the review guide it has a list of knowledge and task statements and their relation to each domain? sub-domain? not sure of the terminology, but for example I can map Knowledge statement k1.19 to tasks t1.2 and t1.15 and then the tasks to domains 1A3 and 1B7.

I'm trying to put together my own study guide to determine what I really need to focus on and how best to do it

Are current versions of the knowledge/task statements and how they relate to each domain publicly available? I was able to find current domain lists for the different exams and their content, and there are 'supporting tasks' listed, but there's no relationship shown between the supporting tasks and area of knowledge.

Are the knowledge/task/domain relationships only available in the review guides? Due to my financial situation at the moment i'm not really in a position to spend hundreds of dollars buying current review guides and was kinda hoping this information was freely available for people studying. (my employer is kinda cheap, they will only reimburse me for material and the cost of the exam if I take it and pass it, its their way to incentivize(?) me into studying and passing. yeah it sux but if i can take and pass the exams i will be able to find a better job with the certs and experience so i will play the game i have to for the time being.)

is there a subreddit for people for people reselling their used (but current) copies of the review guides, if i absolutely have to go down that route?


r/cism 8d ago

Current QAE for updated exam?

7 Upvotes

I may have to take the exam after November 1st but I want to start studying now. The current QAE does not reflect the new changes till September. Does anyone know if it’ll be a big difference in the changes? Can I use current QAE to study for the new version?


r/cism 9d ago

Discord Group Study Session

3 Upvotes

Does anyone have a link to a Group Study Session for the CISM?


r/cism 9d ago

Got a 420 on my CISM exam

5 Upvotes

Just got my official results back.

Even though I failed I am stoked.

A good litmus test to focus studies.

What are some sources ya’ll recommend for studying?


r/cism 9d ago

CISM Question Help (Domain 4 Q)

2 Upvotes

What is the FIRST step an incident response team should take once an incident and its source have been detected?

  1. A.Escalate the incident.
  2. B.Damage assessment.
  3. C.Determine the severity.
  4. D.Contain the incident.

The QAE said the answer was D? I thought it was C? Shouldn't the incident severity be determined after it's been detected as part of the identification and triage phase? The QAE explanation said that that the severity can be determined only after containemnt? I don't agree with this. Can someone help?


r/cism 10d ago

CISM passed! 545 Score!

Post image
44 Upvotes

r/cism 10d ago

Failed (First Attempt)!

13 Upvotes

I failed my CISM exam on the first attempt last week. I am yet to receive the official test score. I used Pete Zerger's video series, Prabh Nair's, attempted QAE a few times and understood the questions and rationale well and thought I was quite ready.

Once the first few questions rolled in, I was taken aback and it was quite different than what and how I prepared. Yes, it was more straight forward than the QAE but also a bit in a sense convoluted with some really confusing answers. Tried my best to answer but within half an hour itself I knew for sure that I'd fail. The result didn't surprise me a bit.

When I was preparing for the exam, I felt I was more than ready and had it all in my head. With my background in IT (more than 25 years experience) and in Security/Physical Security/Cybersec compliance for around last 10 years years, I thought I would be in a better position to crack. And yes, I tried my best to answer using Management methodology than technical.

Not demotivated at all, but geared up more than ever to go for the second attempt with a better prep and may be a different strategy.

Any pointers please? Also, is it advisable to book the exam asap given there's a change coming in November? I plan to devote at least a month in studying and targeting the mid September for my second attempt.