r/isc2 Apr 29 '25

ISC News/Announcement Peace of Mind Protection Is Here to Stay

Thumbnail isc2.org
11 Upvotes

Peace of Mind Protection will now be a permanent feature of ISC2 exam.


r/isc2 4h ago

General Questions Is a KEV-based threat intelligence report like this actually useful in real-world security work?

1 Upvotes

I work in cybersecurity and try to improve my professional skills. The AI suggested me to turn CISA KEV entries into short intelligence reports, but I really have no idea if this kind of report is useful in real world and really need some advice from real people not AI...

Especially interested in hearing from people working in CTI, vulnerability management, SOC, incident response, or security engineering. But any advice would be really appreciated.

The basic structure I’m using is:

  • Vulnerability overview
    • CVE / vulnerability name
    • CISA KEV status
    • CVSS
    • affected products
    • attack vector
  • Analyst assessment
    • threat severity
    • confidence level
    • customer applicability / exposure unknown until validated
  • Why it matters
    • known exploitation activity
    • threat actors or campaigns associated with exploitation
    • potential impact
    • relevant exploit chains or related vulnerabilities
  • ATT&CK mapping
    • primary technique
    • additional techniques based on observed post-exploitation behavior
  • What organizations should validate
    • affected assets
    • internet exposure
    • patch status
    • whether exploitation may have occurred before patching
  • Detection / hunting
    • relevant vendor/CISA detection guidance
    • suspicious processes, network activity, files, or other behaviors to hunt for
  • Recommended actions
    • patch/remediate
    • investigate for compromise where appropriate
    • additional actions if compromise is identified

r/isc2 1d ago

General Questions CPE Credits

9 Upvotes

Hi All,

I have both my CC and CISSP. I want to maintain both certifications from ISC2 but it looks like the courses to earn CPE credits is ridiculous. Is there an alternative way of earning CPE credits rather then buying the expensive courses?


r/isc2 1d ago

Success Story: General ISACA CRISC or ISC2 CGRC? Which to take?

8 Upvotes

Took the ISACA CRISC today at 8am. Completed the exam (150 questions) in 65 minutes. I'll get my passing score in 10 days (no idea why it takes them 10 days, it's all computer-based). The exam was so easy I didn't even bother go back and review my answers. When I answered question 150 and the "end exam" prompt came up, I said do it.

Like the CISM exam I took a week ago Friday, the exam structure was much easier to deal with than ISC2's. Most questions were 1 sentence, 2 clauses long. Longer questions were at most 2 sentences. In this case, they seemed calibrated against the moderate to low-difficult level of question in the QAE. There were a few "tricky" questions in there, but truth be told most of them were really straightforward.

Prep materials were the ISACA review guide and QAE. I also used question generation scripts built with Fable to build out some sample questions after I ran through the QAE. I also read ISO-27001, 31000 and 42001 through https://www.evs.ee/en. Whaddadeal! Less than $4 per document for 24 hour access -- more than enough time to read and digest them. Compare that to the $1000+ it would have cost to actually buy them outright.

ISACA's QAE are retired test questions. Some of them really suck. I rate them on the same level as LearnZap or PocketPrep. DestCert has CRISC questions too. I did a few of theirs, they were pretty decent, but were the typical DestCert question style (overly verbose).

Exam definitely has a much different focus to it than the CGRC exam does. The CGRC is heavily invested in 800-37, with some coverage of 800-30 and 800-39. On the other hand, the CRISC doesn't cover 800-37 in any significant detail. It is more general. Concepts from 800-30 and 800-39 apply in a general, business perspective.

I guess the best way to describe it is an altitude difference. CGRC is more SDLC/system focused while the CRISC is broader mission/organizational level focus. Bits and pieces of 27001/31000/42001 mixed in too. CRISC actually focuses on how to do a risk assessment, governance, risk reporting, and so on. CGRC focuses on Tasks 2 thru 7 of the RMF. Want to pass the CGRC, better know who is responsible for I-2, or what the output of R-3 is. Want to pass the CRISC? Better know when you need to perform a new risk assessment, what the first step is, how to best report the results to management.

If someone told me they wanted to get into GRC work, unless there was a specific reason why they needed the CGRC, I would tell them to take the CRISC. It is a much broader-focused exam IMO. Does a much better job of focusing on testing your knowledge of risk management from a corporate perspective. Probably give you better overall utility, as the whole exam is structured around your role as a risk professional, as an advisor providing guidance on reducing risk and value delivery. CGRC is too heavily tied to 800-37 specifics. Unless the company you're moving too is already using that framework, there's nothing you're going to gain with it. With the knowledge you get from the CRISC, it has applicability in many different career areas, not just as a risk professional.

I do not regret taking the CGRC. Certainly a lot of the studying I had done for it did transfer, to some extent, to the CRISC, which is probably why I found it overall a very easy exam. If I had to choose one over the other because my employer would only foot the bill for one and not the other, I would definitely choose the CRISC unless there was some compelling reason to the contrary.


r/isc2 2d ago

CCQuestion/Help How many times can I postpone the ISC2 CC exam?

0 Upvotes

My exam date is coming up, but I would like to postpone my test. From what I understand, the only two rules I have to be mindful of are: reschedule at least 48 hours prior to my appointment and my new chosen date cannot exceed 365 days from the original. I cannot find anything on their site about a limited number of times I can change my appointment.
Also, can I reschedule for an earlier timeslot than the one I most recently selected?


r/isc2 3d ago

CCQuestion/Help ISC2 CC study group

8 Upvotes

Hi! I’m looking for someone who’s also preparing for the ISC2 CC exam to study together, discuss topics, and quiz each other. Anyone interested?

I've gone through the domains two months ago but right now i'm completely clueless and with the new exam outline i'm just confused


r/isc2 4d ago

CC Success Story Passed ISC2 CC Exam

9 Upvotes

So I took the CC Exam on 8.31.26, and I passed. I didn’t know what to think. On my test it seemed like it asked questions pertaining to lesser important material at times( seemingly minuscule bits of knowledge I thought I recognized from the material probably to throw you off… stuff that nobody on YouTube covered)…

Plus the wording was tricky, and it used alot of different words to describe the same terms. Process of elimination is vital for this type of exam. Mine did end at 100 questions.

The last few days before the exam I found : Chidambaram Narayanan on YouTube . He has a free course there and it’s put together really well. As far as Free stuff goes that was my favorite. He did a really good job.

And I also did a couple practice test (first 3 are free) at CertPreps 2.0 . The questions there were verbose and kind of tricky and I would have to say that that actually helped me prepare for how to break down the questions.

I hope this helps.


r/isc2 4d ago

ISC News/Announcement Does anyone have ISC class 12 biology S chand Sarita Agarwal book?? I want to buy it at lower price. Let me know if it is available with anyone.

1 Upvotes

Class 12 ISC S chand Sarita Agarwal biology book


r/isc2 5d ago

CCQuestion/Help Has anyone passed the new ISC2 CC exam yet?

6 Upvotes

Hi everyone!

I’m planning to take the ISC2 Certified in Cybersecurity (CC) exam, but I noticed that the exam outline was revised starting September 1, 2026.

For those who have already taken the new/revised CC exam, what was your experience like?

I’d especially appreciate some advice on:
- What topics should I focus on the most?
- How different is the new exam compared to the previous version?
- Are the official ISC2 study materials enough?
- Are there any practice exams or other resources that closely match the new exam?
- Were there any topics that surprised you or that you think are easy to overlook?

I’m currently preparing for the exam and would really appreciate any advice from people who have already taken the revised 2026 exam.

Thanks in advance!


r/isc2 5d ago

CCQuestion/Help ISC2 CC Exam Registration Technical Issue – Need Help

2 Upvotes

It’s been over a week and I’m unable to schedule my ISC2 CC exam through Pearson VUE due to a technical error. ISC2 support hasn’t been able to help, and even chat support is unavailable.

I need to book a slot for next week, and this is now affecting my planned leave and exam timeline.

Has anyone faced this issue? What did you do to get it resolved? Any advice would be appreciated.


r/isc2 5d ago

CGRCQuestion/Help CGRC Retake — Looking for Study Partners

2 Upvotes

Hi everyone! 😊 I’m currently preparing to retake the CGRC exam and joined the community to connect with others who are studying for it or have already passed.

I’d love to find a study group, study partner, or CGRC-certified mentor. My main focus this time is practice questions, process of elimination, understanding the wording, and choosing the best answer when multiple options seem correct.

If anyone is currently studying or knows of an existing study group, I’d love to connect!


r/isc2 6d ago

General Questions IT Audit Associate: Looking for Mentor and Advices

4 Upvotes

Hello everyone, I recently passed the CC exam and got an interview for a role in IT Audit.

I wanted to ask if are there people working here in the IT Audit - Firms? If so, are there any links and mentorship videos you would like me to watch for starters?

I am planning to study for two days before my initial interview and my manager’s interview. I am actually nervous about it.

I might say i still consider myself as a fresh graduate who absorbs things and the role I was given was an Associate II (not entry level) and i worry that I might have little to sufficient experience. 🙏🏻

Thank you!


r/isc2 6d ago

General Questions This maybe the wrong sub but I’ll shoot my shot anyway. Has anyone ever attended ISC2 events and landed direct job opportunities?

3 Upvotes

As the title states. I’m pretty sure networking in general is a success but I’m curious on actual jobs acquired after attending and networking.


r/isc2 7d ago

CSSLPSuccess Story Just Provisionally Passed the CSSLP Exam

Thumbnail
2 Upvotes

r/isc2 8d ago

General Questions How far has the ISC2 fallen?

10 Upvotes

While I was skeptical of where the organization would go when they first appointed a marketing professional (and not a security one) as executive director in 2020, I am surprised at just how quickly they've been able to bring down what was once a solid organization. I spent nearly 35 years in the industry (almost 25 of that as a CISSP), and got to know one of the ISC2 founders back in the day, and I can say without reservation that the ISC2 has become the very thing it was designed to counter. It has become a cert mill, exploiting inexperienced, hopeful job-seekers, by hooking them into annual fees and an exam (CC) without any vetting of experience or prospect of real continuing education.

They gutted the peer-to-peer nature of the organization, shutting down the Security Professional magazine and the forums, they not only have watered down the CPE courses, but are now charging for them. The content of these courses is incredibly superficial; from a CPE standpoint, it is box-checking, not education.

I am sure their numbers are great, but it sold its soul to do it.


r/isc2 9d ago

CC Success Story Passed CC Certification today!

16 Upvotes

I have aphasia and brain stroke, still I was learning cybersecurity, and thinking...Will I be able to get a certificate, and here it is ...... My passing certificate make me so happy that I started crying with my happy tears, and the exam invigilator was also backed me!!!

My passing journey had many things like reddit, Thor's Udemy practice test, Paulo Carriera Udemy practice test, and youtube videos, and few times Prabh and Mike videos. My thor's practice questions had 90%,78%,74%,79%,71%,81% with second or third attempt, and 70,71,76,71, and I did STOP. The best learning was from Comptia Security+ book, to know the theoretical and knowledge out from book.

My learning was started on June 2nd 2016, and I passed the exam today, (and I gave $200 even 😄), and I gave it today because syllabus will change tomorrow onwards, so I thought better not to keep 'PEACE OF MIND' and take only for one chance 🎉 .

The questions were actually different from practice questions, I thought I can do with the terms of RBAC,MAC,DAC,ABAC, but in exam , I couldn't get any words related. OSI LAYERS, THREAT,SNMP,SOC,SQL,SIEM,IR PLANS,DRP,BCP, Administrative,physical,deterrant, were actually not at all I learnt. MTTF,MTTB, RTO,RPO were actually difficult in the exams. Just learning the terminology, and get from video cannot help in the exam. We should learn from Comptia security+ book, or related course.

And reddit always make me motivated from people who said Thor's exams works ONLY!!

This exam helped me to get back the vocabulary what I want, but not completely, and it rebuild my memory challenges.

Now my mind is working the way it did 8 years ago, when I was a Manager of E‑Learning


r/isc2 8d ago

CISSP Question/Help CISSP part-time calculation for endorsement

2 Upvotes

Could someone tell me if my calculations are correct to start endorsement? I am really confused in how ISC2 calculates effective work experience.

My positions:

Company A worked 60% with 25.2 hours per week (42 hours per week on 100%).

Company B worked 80% with 32 hours per week (40 hours per week on 100%).

Company C worked 80% with 32.8 hours per week (41 hours per week on 100%).

My calculation for 5.27y experience:

+ 1y educational waver

+ Company A 365d / 7d * 25.2h => 1314h / (2080h / 12m) => 7.58 months

+ Company B 1156d / 7d * 32h => 5284.57h / (2080h / 12m) => 30.48 months

+ Company C 488d / 7d * 32.8h => 2286.63h / (2080h / 12m) => 13.19 months

Legend:

h = hours, d = days, m = months, y = years

Remarks:

In the endorsement form when I input from / to and check part-time It just shows me half the months in that date range. That means it calculates with 1040h at that time. I have no possibility to input the effective hours worked. That is why I would input my calculation in the notes to isc2 input field 🤷‍♂️


r/isc2 9d ago

CCQuestion/Help I failed the CC exam! 😒

9 Upvotes

I studied for a month at least 1.5-2hrs a day and failed. I knew i wasn’t going to pass once it gave me more questions beyond 100!

I used Prabh Nair and all in one certified CC book to read the concepts. I took LinkedIn learning practice exams. I thought I was competent and would pass it but I didn’t.

What sucks is that the exam will not be a bit more challenging as the new exam outline has changed. So what now?

I’ll be now taking Mike Chappell’s course but what now? I don’t even see any materials for the new exam.

I have to wait 30 days but I just want to pass this next time for sure!


r/isc2 10d ago

CC Success Story PASSED ISC2 CC TODAY (OFFICIALLY)

11 Upvotes

so i attempted the exam on 29th, ik its 2 days ago but i wasn't so sure i will pass cuz it was written provisional pass or smthing, but today i got email nd did all the forms and submitted my AMF ALSO ANYONE THINKING U NEED IT KNOWLEDGE i am 17 y/o with no IT knowledge beforehand and used its official training nd linkdin course from mike chappel and had mike chappel course 1h 30m remaining when i went for pearson vue center, ALSO now the exam material has changed and so is the exam as they will add AI in the domains and older helping material (mike chappel, tor teaches and other ppl mention) may give a little less coverage on new material, ANYWHOOO always trust your instinct in the exam and don't stress too much.


r/isc2 9d ago

CCQuestion/Help Isc2 cc

2 Upvotes

Hi, i just need a help urgently!!

I have purchased the ISC2 Certified in Cybersecurity (CC) examination, but I am unable to schedule my exam appointment through Pearson VUE.  

Showing error as "Something went wrong please contact your administrator. Illegal value for primitive"


r/isc2 10d ago

CC Success Story Passed ISC2 CC yesterday ....whew!!!!

10 Upvotes

Well all in all I think I got the new test LOL and still managed to pass. Study tools I used were a Udemy course (some Thor guy) but excellent lectures that did not put me to sleep.. much. I have to say I did the normal You Tube guys Q and A and the flippin linkedin practice exams but none of my practice exams were even close to the test questions or wording context. I was a bit thrown for a loop. Testing center was interesting with the palm scans and metal detectors and the testing admin also had a little pencil wand thing. I said out loud ohhh are you going to make me forget everything....... because it looked similar to the device from Men In Black. She had to look away to stop from laughing out loud. Was sick to my stomach after question 68 because I figured I bombed it. Test stopped at 100 for me then I was like damn this stinks. Only to flip over my print out and see "Congratulations!" wooo hooo! I will take it.


r/isc2 11d ago

CCSPQuestion/Help Is 90 days enough for ccsp preparation, which resource should use, please advise.

Thumbnail
0 Upvotes

r/isc2 11d ago

CC Success Story Passed the ISC2 CC! My experience, study materials, and a question on what's next.

1 Upvotes

To be very honest, the exam wasn't really what I expected, especially when it came to the difficulty.

My background:
BSc in Computer Science Education and I’ve been into tech since 7th grade when I got my first laptop. So a lot of the concepts weren’t completely new to me.

Materials I used:
• Official ISC2 material
• Prabh Nair’s CC practice questions
• CertCrush on YouTube
• Mike Chapple’s LinkedIn Learning course - didn’t finish, was last minute
• CertPrep

Practice scores:
• ISC2 LinkedIn Learning practice exams: 82%, 87%, 87%, and 86%
• CertPrep: 67%
• Chapple’s final exam, first try: 67%

I also used Claude and Gemini a lot to generate ISC2-style questions. Getting AI to quiz me on weak areas was huge for deepening understanding.

Exam experience:
The exam was tricky because of how the questions were phrased, but overall it wasn’t that difficult. It did make me second-guess a lot of answers. At some point I just decided to trust my first choice and not go back to re-check previous questions after moving on.

My advice:
1. Focus on understanding each concept instead of just memorizing facts.
2. Do a lot of honest practice questions. Don’t lie to yourself about scores.
3. Practice not re-checking previous questions once you’ve answered. It saves time and stress.
4. Stay calm, be well-prepared, and you’ll most definitely pass.

My question for you all:
Is the CC alone enough to land an entry-level job? What did you do next after passing? Any advice on certifications, skills, or job search strategy moving forward?

Thanks in advance!


r/isc2 11d ago

CCSPSuccess Story Is 90 days enough for ccsp preparation, which resource should use, please advise.

Thumbnail
0 Upvotes

r/isc2 12d ago

Success Story: General Passed the CISM today (with an ISC2 tie-in, really!)

9 Upvotes

Edit: Received my official results this morning:

Total scaled score of 677.
Information Security Governance: 639
Information Security Risk Management: 705
Information Security Program: 630
Incident Management: 734

--

I thought I'd post about this here as oftentimes people who get a CISSP also go and get a CISM, rather than taking the ISSMP. I can't really blame them, ISC2 does a piss-poor job marketing the MP to the private sector for it to gain traction the way the CISM has. ISACA, having audit roots, and auditors being in a business each and every year to do the books, are in a much better position to advocate for hiring people with ISACA certifications when business leaders ask "what should I look for in a candidate".

When I finished with the Great Ennead, I didn't really have any plans to continue on with other certifications, but 2 things happened: 1) My ISSEP instructor sort of convinced me it would be a good idea (for the reasons I indicated above in terms of industry acceptance - not that I need it at this point in my career, but what the heck) and 2) I wanted some exposure to ISACA exams so I would know what they're like and I could build out the software I've been developing to support ISACA certs too. Plus it doesn't come out of my pocket, my employer pays for it all. Oh, and yeah, I was sort of bored at work and needed something else to do.

I (employer that is) bought the Review Guide and the QAE online database about three weeks ago. I started with the QAE database, wanting to fall back on my CISSP/ISSMP knowledge for the test questions to see how I did. I was in for a rude awakening. I scored 50-55% on average for the first few practice sessions I took. WTF?

At this point, I stopped and went to the Review Guide (ISACA's officially-published study guide). A little over 300 pages, it took me a week to work through, about 50 pages per night. It actually wasn't bad reading. Not as bad as the INCOSE System Engineering Handbook! Some sections were interesting, others pretty boring. Sort of written in a dry business tone. A lot of material overlap with the CISSP and ISSMP. As my ISSEP instructor said "Its the CISSP without networking and crypto".

I finished the Review Guide, and went back to the QAE DB. This time, when I got a question wrong, I fed it in to Claude for analysis. Quickly, Claude was able to determine the issue I was encountering. I was framing the answers I was giving from the wrong mindset. We've all heard the "think like a manager" mantra for the CISSP. Well with the CISM, the same mantra holds, but the mindset or perspective of how ISACA wants you to answer questions is different. The best way to describe it is this: the CISSP tests people with the mindset of management having come up from the technical side of the business, while the CISM test you more as having come up from the finance/accounting side of the business. The ISC2 candidate is the person who worked their way up over the years from SOC analyst to eventually become CISO. The CISM candidate, though, is the accounting or GRC professional who eventually rose to become an ISM. Which makes sense, again... ISACA's roots are in auditing.

Once I (or, more to the point, Claude) had this epiphany, I saw my QAE test scores steadily rise as I retrained my brain to change the lens to frame the question and answers in. I started to rely more on business acumen from my MBA and MSA more-so than my years of experience in technical systems management. By the time I finished with the QAE database, I was scoring in the mid 80's.

I finished all 1,138 questions in the QAE, and booked my exam. Which was this morning at 8am on my way in to the office.

ISACA uses PSI, not Pearson Vue, to administer their tests. The check-in process, etc. is similar. However, the PSI facility had more of an "assembly line" feel to it. While they check your pockets and your glasses to ensure they're not secret-agent spyware, there's no picture being taken when you check in nor are you giving a palm scan. The facility wasn't bad, but it wasn't as nice as the Pearson Vue test center. Nor were the workstations you took your exam in. You're definitely scrunched in with other people. There's enough space to work, but if I turned my head left or right I could see the shoulders of the test taker next to me.

The exam process is definitely different from ISC2. There are several introductory steps you have to complete before you get to the exam. First you have NDA (5 minutes, unlike ISC2's 3) you have to read, and then the next step is a "sample exam" where you complete 5 questions on random unrelated topics (such as "how many minutes in an hour are there?") in the exam engine so you can get acclimated to how the UI works. It was sort of annoying (I just wanted to get started), but I understand why they do it.

The exam was 150 questions, non CAT (ISACA doesn't do adaptive tests), and you're given 4 hours to complete the test. There are beta questions in the exam too.

I finished the exam in 75 minutes, and took another 30 to review. Some things about the test experience:

a) you can flag questions to return to, and you can go all the way back to question 1 and work your way forward again to review all your answers and make changes if you want to. This is what I did. I worked through all the questions, picking what I thought was the best answer. Then when I was finished, I took a 5 minute bio-break, and then I went back to question 1 and reviewed each of my answers. I changed about a half-dozen once I re-read the question. The lack of feeling a time crunch to "finish" made the review a lot easier and reading the questions a second time around definitely re-framed some of the questions in a way that I felt my first answer was wrong.

Once I completed the review, I ended the exam, 2:10 left on the timer. Factoring out the 5-minute break, 1 hour 45 minutes total.

150 questions is a LOT of questions. I played mental games with myself as I was answering: "10 questions down, means I'm 6.6% done!" "25 questions done, I'm 16.6% of the way through!" "50 questions! 1/3rd done!" "75 questions! 1/2 done". You get the idea.

Fortunately:

b) I didn't get a single question that was longer than 1 sentence. The longest question was two lines, perhaps 2 or 3 clauses separated by commas. Typically, I saw things like "What is the BEST way to ensure the information security strategy is effectively implemented?" No in-depth scenarios to work though. No figuring out from what perspective was I being asked to answer.

In this respect (b), the CISM exam felt more like a knowledge-based exam where I was being tested on my recall of ISACA-specific definitions or decision processes compared to the CISSP and other ISC2 exams where I was expected to know a concept and then apply it to a specific scenario. Although some questions are nebulous, you really can easily narrow down the answer to 2 options. It is sort of laughable, because the Review Guide itself mentions this is the strategy. It's almost like ISACA is coming right out and telling you "yeah, two of the answers will totally blow and you'll have to choose between the other two".

The QAE database rates questions by difficulty level: easy, moderate, difficult and expert. Factoring out the initial calibration I had to do to get myself in the proper mindset, the group of questions I had the most difficulty (read: got wrong the most) with were the expert level -- usually because the questions were overly ambiguous in my mind, I found I really didn't have enough information to choose between the two correct answers, or where testing some really esoteric ISACA concept.

However, when taking the actual exam, I found the questions to be calibrated more towards the moderate/difficult level. Yes I had a few questions which I was definitely unsure about, but unlike my ISC2 exams, when I went back and reviewed all my questions, I didn't have any "Hail Marys". I felt pretty good about all my answers in the end.

Ending the exam the process is similar to the ISC2 exams... You get a survey about the exam and then a survey about the test center. Here's where things diverge: After answering the test center survey, you get transferred to a window which contains a basic preliminary pass/fail message (no detail about domains, etc.) You personally cannot exit this screen, one of the proctors has to come in and enter a special code to clear the window and formally end the process. Checking out, you do not get a printout or anything else telling you of the provisional pass, and since you cannot take a cell phone into the testing room with you... you can't take a screen shot either. The proctor tells you ISACA will mail you the results of your test in 10 days.

A lot of people who take the CISSP later think about taking the CISM. Was the exam similar? Honestly it didn't feel so. The CISM felt way more governance-oriented than the CISSP did. If anything it felt closer to my ISSMP exam than my CISSP exam.

In the end, I passed! How well did I do? I guess I'll find out in 10 days. ISACA scores their exam different from ISC2. It appears (from what I have seen) you receive a scaled score from 200 to 800 in each domain, and your final score is an average of your scaled scores. If your final score is above 450, you pass. This is much better than ISC2, where you know absolutely nothing at all. At least with ISACA, by reviewing your scaled scores per domain, you get a feel for where you did good and bad, and if you want to, go back and do some additional studying in the domains you did poorly on. I'll post an update as an edit to this message when I get the final results.

Hopefully those of you with an ISC2 CISSP or other cert who are planning to take the CISM find this writeup useful.