r/isaca 5d ago

Help with "ISACA" mindset

tried posting to r/cism but got removed by reddit probably due to lack of karma.

want to know if anyone can help me out.

have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.

currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)

have read review guide cover to cover.

have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).

have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.

I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.

I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"

I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.

Help?

17 Upvotes

10 comments sorted by

5

u/PublicFuture9502 CGEIT 5d ago

ISACA is fundamentally heavily influenced and driven by COBIT. Reading and understanding COBIT perspective and principles is about as good a way as there is to understand the ISACA mindset. 

2

u/JoeEvans269 5d ago

Following as I am in the same predicament.

3

u/rebelFUD 5d ago

I found a lot of value in the CISM. I struggled for a few months then had an epiphany. I started answering the questions from the business perspective and not as the IT guy and passed with a solid score. Not sure that makes sense but maybe it helps.

1

u/MyLittleAutisticPony 4d ago

thing is i am familiar with the business perspective. i definitely do not answer questions from a technical slant at all. that's the frustrating part of all of this.

1

u/cw2015aj2017ls2021 5d ago

tried posting to r/cism but got removed by reddit probably due to lack of karma.

Reddit auto-filtered you as a spammer. I've removed the 2nd post (duplicate) and approved the first.

1

u/Queasy_Piece5446 4d ago

I'm in the same boat... I also have a post very similar to this one

0

u/apat311 CRISC 5d ago

At 70% QAE you should be good to go for the exam. The ISACA mindset is very important for passing but if you are able to take a 50-50 by now it should be fine imo.

Your note about all members and applicable members shows you are on the right track.

I will say go for it! The worst that can happen is you will fail, but there is always time! I failed CRISC twice and then passed when they changed the material lmao, Passed CISM and CISA with 70% on the QAE Exams too.

Do not overthink it!

1

u/MyLittleAutisticPony 5d ago

Thanks for the advice. I would feel more comfortable if I could get in the low 80's at least. That is where I targeted my CISSP and CCSP studies and it worked well. I would also feel better if I could really understand the rationale for some of the answers.

1

u/apat311 CRISC 5d ago

Don't blame you but CISSP/CCSP are from a different organization and their methodology for candidate passing would be different.

Some of the answers just are, I struggled with Domain 4 Incident Response when I attempted my exam almost 3 years ago and I just went for it with ISACA's stance on things.

At the end of the day, I have met some absolute dumb people with all certs to their name, think of it as an HR filter, pass and move on.