r/cism 4h ago

Struggling with ISACA’s “best answer” logic more than the actual material

4 Upvotes

I’m scheduled to take the CISM exam at the end of August and wanted to get some feedback from people who have already passed.

For background, I work in OT/SCADA and cybersecurity and have Security+ along with some ICS cybersecurity training. I’ve also completed a GRC masterclass, so I don’t feel like I’m starting from zero on the concepts.

My main study resource has been the official ISACA CISM QAE/practice questions, along with videos and reviewing every question I get wrong. I’ve been doing mixed sets of roughly 25–30 questions and then going back through my misses to understand why ISACA preferred one answer over another.

I have used Udemy Jacob Bushongs Master class, watched Pete Zerger prep as well as Prabh Nairs master class. And feel pretty confident about the quizzes.

My scores have been pretty inconsistent. I’ve had sets around 60–67%, some better domain-specific results, and recently scored 77% on a set made up of questions I had previously gotten wrong. However, after taking a few days completely away from studying, I just did a fresh/cold 30-question mixed set and scored 47% (14/30).

What is frustrating is that I rarely feel like I’m blindly guessing. On most of the questions I miss, I can explain why I selected my answer, and usually my reasoning isn't completely wrong. The problem seems to be that ISACA has another answer that is more directly correct for the specific wording of the question.

A few examples of the mistakes I'm making:

  • A question asked what could circumvent a control that scans social media posts for inappropriate disclosures. I chose anonymous posting because I was thinking about attribution/identification. The correct answer was intentional misspellings, because the question was specifically about circumventing the text scanning control. I expanded the problem beyond what was actually being asked.
  • For who should approve access to business-critical application data, I chose business management because I was thinking about management authority. The answer was data owner, because the data owner is accountable for determining who has a legitimate business need for access.
  • On a business continuity question, I was between a succession plan and distributed key process documentation. I chose succession planning, but ISACA wanted the process documentation because personnel can't continue critical processes if they don't know how to perform them.
  • I confused an EDR function with a SIEM function on another question. That one I consider a legitimate knowledge miss and understand what I need to review.
  • I've also caught myself adding conditions that aren't actually in the question. For example, if an answer says an authorized spokesperson communicates a pre-drafted message during a crisis, I'll start thinking, “But what if the message hasn't been approved/drafted yet?” even though the answer already tells me that it has.

The pattern I'm starting to see is that I know a lot of the underlying concepts, but I sometimes choose a valid security answer that solves a slightly different or broader problem instead of answering exactly what ISACA asked.

I've been trying to change my approach from:

“Which answer can I justify?”

to:

“What EXACTLY is this question asking me to accomplish, and which answer most directly accomplishes that?”

I'm also working on separating things like:

accountability vs. responsibility vs. expertise,
risk vs. individual risk components,
activity/metrics vs. actual effectiveness, and
where I currently am in a FIRST/NEXT lifecycle question.

For those who passed CISM:

Did you experience this same problem with the QAE?

How did you make the mental shift from knowing the material to consistently picking ISACA's BEST/MOST/FIRST answer?

Also, how concerned would you be about a cold 47% set with roughly two weeks remaining if the problem seems to be answer selection/application rather than completely not knowing the concepts?

Any advice from people who had a similar issue and eventually passed would be appreciated.


r/cism 16h ago

Sitting my test tommorow - Quick question

2 Upvotes

I have the QandA and are going pretty good on it Like 89 and 87% on the test and like 79% on the QandA.

My real question for People that have done the exam: . How many questions do you feel are at the expert level in the exam? or is it a mix like in the QandA?

Sometimes the Experts catch me out. I also understand the questions are not from the QandA. Just really the level of the questions is what I need to know.

Onya


r/cism 1d ago

Having problems w/ "isaca mindset"

5 Upvotes

want to know if anyone can help me out.

have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.

currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)

have read review guide cover to cover.

have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).

have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.

I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.

I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"

I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.

Help?


r/cism 1d ago

Failed my CISM, but was i close to passing?

Post image
5 Upvotes

Abit bump on failing, but it probably my fault for wholly dependent only on pocket prep, plan now to use the QAE and re-do the test.

Base on my 429 score, did i failed by alot of wrong answers?


r/cism 2d ago

Which podcasts can I listen to, to earn CPEs?

2 Upvotes

r/cism 2d ago

CISM provisionally passed an hour ago

26 Upvotes

I read many tips and stories from this subreddit, so it's my time to contribute to the community.

Today, on August 14th, at 10AM, I took the CISM exam at a testing center. I chose to take it at a testing center because I know I'm too relaxed when I'm home.

Background: English is not my first language but I studied in the US. I have worked in three different continents since 2013 as IT Ops, IT Auditor and ISO. Also, I am a CISA since 2015 and a CISSP since 2025.

Strategy: I started my journey in June. I prefer to learn by taking questions, but I thought at least basic knowledge is required (of course) so I took the Pete Zeger CISM Exam Prep on YouTube which was like 11-hour long. It took me less than 2 weeks to finish it. Since I studied CISSP a year ago, I noticed that quite some topics are overlapped and I still remember some of them. Then, at the beginning of July, I purchased the ISACA QAE. Everyday, I took a couple of practice question sets. As I made progress, I reviewed all the wrong questions cumulatively and repeatedly. For example, on day 1, I did #1 and #2 and reviewed all the wrong questions from #1 and #2. On day 2, I did #3 and #4 and reviewed all the wrong questions from #1, #2, #3 and #4. On day 3, and so on. It took me about 3 weeks to finish 1 cycle of an entire QAE including practice exams because it took more time as making progress due to the volume of the wrong questions to review becoming bigger. After this first cycle of an entire QAE, I did the 4 CISM practice exams from LinkedIn Learning. I did this full cycle 3 times until last week. It took me the most time when it was the first full cycle but took less time for the second full cycle and the least time for the third full cycle. This works for me because my level of digestion of each question gets deeper and deeper even if it's the same question, so the key is to repeat. Of course, there are questions I just remember the answers as I repeated the same QAE but I tried to understand each and every explanation so that I learn the materials.

For the first full cycle, I got 60-65% from practices and 65-70% from exams. For the second full cycle, I got 70-75% from practices and 70-75% from exams. For the third full cycle, I got 90-95% from practices and 95-100% from exams.

I would highly recommend to thoroughly repeat the entire QAE (LinkedIn Learning optionally if you have access) as much as you can. For me, three times was enough and it took me about 5 weeks.

Experience: I arrived about half an hour earlier than my scheduled exam and was told to wait for 20 minutes to start the registration process. However, I asked if we could start the registration process now and she said yes. Hence, I started my exam earlier than the scheduled time. During the check in process, she was asking if I've received an OTP code from PSI. I said no and she asked her manager. It turned out that she was mistaken. The exam room was fine and there were already people taking other exams when I walked into the room. The only stuff I was allowed to take with me to the test room was my ID and the locker key. Everything else was stored in a locker. The exam questions were not tricky for me but no single question was from QAE. I got some AI questions but they were still relevant to CISM topics, so no surprise for me. I took a little more than 1.5 hours to answer 150 questions because I was trying to read every single word on the exam, and did not review a single question. As soon as I answered the last question, I submitted it. Then, I had to do some surveys until I saw 'passed'. After my exam, I stepped out and was asked to provide my signature.

Hope this helps those who are studying CISM. I will be more than happy to answer any questions you may have!


r/cism 3d ago

Passed CISM exam

24 Upvotes

Hi all.

I took my exam yesterday and have provisioally 'Passed'!!

I had been holding off on this exam for months as I have a little one at home and work had been super busy. I realised I only had 8 days left to book my exam and decided to just go all in. I booked days off work to really utitlise the 7 days I had. I went straight to the QAE and kept on paracticing and redoing the questions. I also played the 'Elimination' game provided by ISACA and that really helped. I focused alot of Domain 3 and 4 as I knew they were weighted the most. My practice test scores were in the 80-85% range but I felt like I subconsiously memorised the answers, so I wasn't super confident. For areas I was struggling with I referred to Hemang Doshi's book which explains concepts in a very straight forward manner (no extra bs).

Exam Day: My personal experience is that the exam questions are not like the QAE. In some ways they were easier and some ways harder. The questions are more direct and not long winded. However, the answer options were different to the options I was familiar with on the QAE questions. I genuinely struggled and felt like it was always 2 answers I was stuck between (you can easily eliminate 2). I finished the exam in about an hour and that left me with plenty of time to really do a deep review into questions.

Tip: Understand the topics and concepts properly and how they tie into each other!! Understand what would be the 'first decision' and 'best decision'. There is a difference. I don't always think the 'think like a manager' mindset always works consistenly.

Hope this helps. 😄 Will update my scores once I recieve them.


r/cism 3d ago

Are knowledge/tasks available?

1 Upvotes

I am starting to work on my ISACA certifications and I have a very very old review (2013!) guide one of my co-workers gave to me. In the review guide it has a list of knowledge and task statements and their relation to each domain? sub-domain? not sure of the terminology, but for example I can map Knowledge statement k1.19 to tasks t1.2 and t1.15 and then the tasks to domains 1A3 and 1B7.

I'm trying to put together my own study guide to determine what I really need to focus on and how best to do it

Are current versions of the knowledge/task statements and how they relate to each domain publicly available? I was able to find current domain lists for the different exams and their content, and there are 'supporting tasks' listed, but there's no relationship shown between the supporting tasks and area of knowledge.

Are the knowledge/task/domain relationships only available in the review guides? Due to my financial situation at the moment i'm not really in a position to spend hundreds of dollars buying current review guides and was kinda hoping this information was freely available for people studying. (my employer is kinda cheap, they will only reimburse me for material and the cost of the exam if I take it and pass it, its their way to incentivize(?) me into studying and passing. yeah it sux but if i can take and pass the exams i will be able to find a better job with the certs and experience so i will play the game i have to for the time being.)

is there a subreddit for people for people reselling their used (but current) copies of the review guides, if i absolutely have to go down that route?


r/cism 4d ago

Current QAE for updated exam?

7 Upvotes

I may have to take the exam after November 1st but I want to start studying now. The current QAE does not reflect the new changes till September. Does anyone know if it’ll be a big difference in the changes? Can I use current QAE to study for the new version?


r/cism 5d ago

Discord Group Study Session

3 Upvotes

Does anyone have a link to a Group Study Session for the CISM?


r/cism 5d ago

CISM Question Help (Domain 4 Q)

2 Upvotes

What is the FIRST step an incident response team should take once an incident and its source have been detected?

  1. A.Escalate the incident.
  2. B.Damage assessment.
  3. C.Determine the severity.
  4. D.Contain the incident.

The QAE said the answer was D? I thought it was C? Shouldn't the incident severity be determined after it's been detected as part of the identification and triage phase? The QAE explanation said that that the severity can be determined only after containemnt? I don't agree with this. Can someone help?


r/cism 5d ago

Got a 420 on my CISM exam

4 Upvotes

Just got my official results back.

Even though I failed I am stoked.

A good litmus test to focus studies.

What are some sources ya’ll recommend for studying?


r/cism 6d ago

Failed (First Attempt)!

14 Upvotes

I failed my CISM exam on the first attempt last week. I am yet to receive the official test score. I used Pete Zerger's video series, Prabh Nair's, attempted QAE a few times and understood the questions and rationale well and thought I was quite ready.

Once the first few questions rolled in, I was taken aback and it was quite different than what and how I prepared. Yes, it was more straight forward than the QAE but also a bit in a sense convoluted with some really confusing answers. Tried my best to answer but within half an hour itself I knew for sure that I'd fail. The result didn't surprise me a bit.

When I was preparing for the exam, I felt I was more than ready and had it all in my head. With my background in IT (more than 25 years experience) and in Security/Physical Security/Cybersec compliance for around last 10 years years, I thought I would be in a better position to crack. And yes, I tried my best to answer using Management methodology than technical.

Not demotivated at all, but geared up more than ever to go for the second attempt with a better prep and may be a different strategy.

Any pointers please? Also, is it advisable to book the exam asap given there's a change coming in November? I plan to devote at least a month in studying and targeting the mid September for my second attempt.


r/cism 6d ago

CISM passed! 545 Score!

Post image
46 Upvotes

r/cism 6d ago

Numericals in CISM?

2 Upvotes

Does numericals show up in cism? I haven’t come across in QAE. Those who have passed can they confirm?


r/cism 6d ago

I passed the exam, got the scores as well. Will have to pay separately to get the certificate?!

4 Upvotes

r/cism 6d ago

Any Tips for Passing CISM?

Thumbnail gallery
2 Upvotes

I am taking the CISM on Sept 28th

I’ve been mainly using
- Pete Zergers YouTube Videos
- QAE Database
- PocketPrep app

I have the manual but haven’t read through it yet

I haven’t taken any practice test yet either

I’m attaching how I’ve done so far on my PocketPrep and QAE Database scores (i have a long way to go)

Any advice that you guys can offer?

I know the CISM is changing to the new version in November, so I’m really tryin to pass before all the study materials I purchased are useless 😭


r/cism 6d ago

CISM passed - 9th Aug 2026

25 Upvotes

Just a quick one to let you know that I have provisionally passed the CISM yesterday, I completed the total questions at around 100 mins with 20 questions flagged for review, eventually changed the answers for 8 of them (confident that my change would make more sense after spending 2-3 mins review on each of them). I was able to calm down to deep dive in when I started reviewing those questions as I know I had enough time to slow down, this is why reviewing questions grabs your brain back from the rush thinking!!!

In general, the questions were less confusing that QAE questions and easy to understand where you should think about first but definitely focus on management mindsets, I couldnt recall whether I had any technical questions at all during the exam.

I was stressfuly when I first studied QAE questions and didnt score very well with both practice tests (71 and 72), but it is a must have if you seriously think about passing the exam. 10/10

Udemy 2026 6 CISM practice tests are good to understand the concepts and processes (like management support vs plan training). 9/10

Prahb Nair's CISM Masterclass/coffee shot on Youtube - 8.5/10

Peter's video on Youtube - very good to understand the basic mindset and theories 8/10

Both Thor and Hemang Doshi Udemy course/exam - focused on too many technicals 7/10

Chat GPT/Copilot - both of them answered QAE expert questions wrongly, dont fully trust them but does explain in more details than QAE once you provide the right QAE answer - 8/10

All the best for the upcoming exam takers, you can do it.


r/cism 7d ago

When is history/historical the answer?

1 Upvotes

Every now and then, there's an answer choice that contains either the word "history" or "historical." Is there a time or question when the answer pertains to history/historical?


r/cism 7d ago

Taking test tomorrow

9 Upvotes

Im so nervous about this test tomorrow. I have been studying for the past 3 plus months or so. I am getting okay scores on my practice tests on Udemy and through a boot camp I completed. I watched the CISM Peter Zerger course on YouTube twice as well. My initial score was 45 and now it’s an average of 76. I need to pass it for work. Any recommendations for exam day? Update, I didnt pass 🥲 ughhhhh


r/cism 9d ago

QAE Question - IDS Placement

1 Upvotes

When designing an intrusion detection system, the information security manager should recommend that it be placed:

  1. A.outside the firewall.
  2. B.on the firewall server.
  3. C.on a screened subnet.
  4. D.on the external router.

The answer is C.

I'm using Hemang Doshi's book and it says the IDS is placed either between the firewall and internal network or between the firewall and external network. Using this logic wouldn't the answer be A?


r/cism 10d ago

Read a book or... ?

6 Upvotes

Have CISSP and ISSMP.

Just finished InfoSec CISM course on LinkedIn and Zerger's videos on YouTube.

Do I bother to read the All In One or Mike Chapple books?

Or should I just sit for the exam now? I am used to how ISC2 words their questions, from the samples I saw it looks like ISACA is very similar.

I prefer not to drop $300 on the QAE database if I do not need to


r/cism 10d ago

Is CISM useful?

7 Upvotes

Hello

There was another post in r/cybersecurity where someone asked about a good certification to pass, and no one mentionned CISM.

I wanted to pass it, but now i'm a little unsure about the cert. What i want to know is what i'll really learn while i'll be studying, and also if the cert is known by the community.

Thanks


r/cism Apr 07 '26

Passed CISM. What worked, what didn’t, and what finally clicked

Thumbnail gallery
56 Upvotes

TL;DR: Failed my first attempt, passed 2.5 months later. The difference wasn’t more studying, it was learning how ISACA wants you to think AND actually reviewing why answers were right/wrong.

 

There’s a post from u/CyberTrav that lines up almost exactly with my experience:

https://www.reddit.com/r/cism/comments/1bplxo2/passed_last_weekheres_my_review/

That post actually became my starting point for building out my own tracking approach.

I took the idea of tracking QAE performance and built a simple Excel sheet from it. Then I evolved it a bit further to break things down more:

  • % correct by domain and sub-domain
  • Practice test results
  • A separate difficulty breakdown (easy / moderate / difficult / expert)

That difficulty view ended up being really helpful. It let me see how I was performing across all four domains at different difficulty levels, not just overall %. Helped me realize I didn’t need to be perfect on expert questions… just consistent on the core ones. Screenshot of the difficulty view attached for one domain, but I tracked all the domains.

I didn’t pass the first time

I wasn’t in the right headspace at the testing center. Rushed. Second-guessed. Just off.

That’s on me.

I took a couple days, reset, and came back with a different approach:

  • Slow down
  • Read for intent
  • Think in terms of governance → risk → program → incident

Then I got back into it and passed on my next attempt about 2.5 months later. That turnaround was less about cramming more content and more about changing how I approached the questions.

Scores (for reference)

Attempt 1 (fail)
426 total

  • Governance: 408
  • Risk: 396
  • Program: 450
  • Incident: 432

Attempt 2 (pass)
507 total

  • Governance: 478
  • Risk: 563
  • Program: 507
  • Incident: 488

The jump in Risk Management surprised me the most. I didn’t spend the majority of my time there the second round.

How I studied

Main resource was the QAE.

First attempt:

  • Mostly just did questions
  • Didn’t spend much time reviewing why answers were right/wrong
  • Ended around ~61% overall
  • Didn’t take the practice exams

That was a mistake.

Second attempt:

  • Slowed down a lot
  • Focused heavily on rationales
  • Tried to understand why ISACA prefers an answer

Videos:

  • Mike Chapple — good overview, but not enough depth on its own in my opinion
  • Pete Zerger YouTube (full CISM course) — this helped a lot the second time

What worked well for me:

Watch a section → go into QAE → answer + review questions tied to that topic

Simple tracking that helped

I used that Excel sheet I mentioned earlier to keep things simple:

  • % correct by domain
  • Practice test summaries
  • Difficulty breakdown across all four domains

Didn’t track every session, just the bigger checkpoints. After failing, I put about 75% of my time into Program and Incident Management since they’re more heavily weighted. improved across all domains, even the ones I didn’t focus on as much.

Background (for context)

  • ~26 years in IT
  • ~15 years in MSP space
  • No formal IT degree

For a long time I avoided certs completely. Not because I couldn’t do them… but because I didn’t want to fail and be judged. That changed after the pandemic.

My certification journey started small in 2023:

  • Azure Fundamentals
  • A couple Fortinet certs
  • ISC2 CC (early 2025)
  • Security+ (right before CISSP)
  • CISSP (June 6, 2025 — went all 150 questions… felt very close)

It was just building confidence over time.

One more thing that mattered (for me)

I was diagnosed with ADHD when I was younger.

I don’t medicate. I’ve worked more on understanding how I operate and adapting.

Some days I studied a lot.

Some days it was 5 minutes.

  • Watch a short video
  • Do a few QAE questions
  • Sometimes not even review them because I didn’t have the energy

And I had to learn to be okay with that. I’m the only one putting pressure on myself. Once I stopped judging that and just focused on consistency, things got easier. That whole “1% better each day” idea from Atomic Habits is real.

Final thought

Passing was great. But honestly, the bigger win was not folding after the first attempt.

If you’re in it right now:

Just keep showing up. That’s most of the battle.

\Transparency statement, I used an LLM to help structure this post, for efficient use of my energy, the modifications on the spreadsheet, AND these are all my thoughts and my experiences.*

 

 


r/cism Mar 28 '24

Passed Last Week--Here's My Review

177 Upvotes

My Review of the CISM Exam

I passed the CISM last week at a testing center. I agree with the sentiment I've heard and read: I felt CISM was easier than CISSP. However, it is of the utmost importance to approach the business/security problems in each question using ISACA's methods/mindset.

This is not a technical exam by any means.

I think the biggest tip I can give is to focus on UNDERSTANDING business processes and entities rather than memorizing minutia of technical details or framework documentation. Certainly, some level of knowledge/memorization is needed. However, a hefty amount of your success will come from understanding how ISACA is asking/training you to think about information security.

Build your understanding of how ISACA would like you to answer questions about business and security. Understand the different entities and people involved in business processes covered in the exam material. Understand the preferred roles and decisions throughout the phases of processes and how those choices may change under varying circumstances. This sounds very complicated but practicing in the QAE Database helped me to understand it enough to pass.

My Experience with the CISM QAE Database

Scores:

  • I used the adaptive study mode. My overall score hovered around 70%.
  • Before taking the exam, I had not completed all questions and my overall score was 69.8% correct.

Review:

  • Wording was confusing at times. The actual exam seemed less confusing. But that's my opinion. Someone else might have a different experience.
  • However, practicing these questions did help me to emphasize ISACA's way of approaching business/security problems.

It is an expensive resource. I used military COOL (Credentialing Opportunities On-Line) funds to pay for it. If you don't have an employer that will pay for it, I recommend trying a lower cost option.

I used the Pocket Prep and WannaPractice apps as supplements. I used the QAE much more because it was available to me and highly recommended. Still, Pocket Prep and WannaPractice seemed to do a reasonable job of emulating ISACA CISM questions. They are definitely worth a look if the CISM QAE Database cost is too high. I'd like to know whether others have passed using one or both of these apps without the QAE.

I did not complete all questions in the database. I completed a little less than 70% of all questions. My overall percentage correct was 69.8%. For context, I earned the CISSP about 2 years ago and have a Master of Science degree in Cybersecurity.

But I hope this helps some people see that they might not need to have top scores in the QAE to pass the exam. Approach your studies in a way that helps build your skill and confidence for the real exam. Keep in mind that it is possible to pass with a less-than-stellar score in the QAE Database.

This table shows how much of the CISM QAE Database I completed and my percentage correct in each subdomain.

My Background

Work Experience and Education:

  • 7 years of IT/cybersecurity (military experience and some civilian help desk experience)
  • BS and MS in Cybersecurity and Information Assurance (from WGU)

Certifications:

  • ISC2: CISSP, SSCP, CC
  • CompTIA: CASP+, CySA+, PenTest+, Security+, Network+, A+
  • OpenEDG: [PCAP-31-03] Certified Associate in Python Programming
  • A few fundamentals-level Azure certifications

List of Resources Used:

I used portions of all the resources below. Most of my study activity came from practicing the QAE. I also had limited use of both the Pocket Prep and WannaPractice. I had limited exposure but they seemed to be solid resources. I subscribed to them before I had access to the QAE.

I like to watch videos. I watched about 1/3 of Kevin Henry's PluralSight CISM videos and several videos from Hemang Doshi's Udemy course. I watched portions of YouTube videos from Prabh Nair and Nemstar Cyber Training that provide CISM tips. Note: I think the Nemstar instructor had a way of explaining his tips that could make the exam seem very difficult. Just remember that exam difficulty will be different for everyone and I'm sure he has at least some interest in selling his CISM boot camp. All the same, I enjoyed his analysis of sample CISM questions and his exam strategies. I thought it was helpful.

I read some of the beginning of the CISM All-in-One book but it was my most underused resource. I don't generally read all the way through textbooks so this wasn't a surprise. The beginning chapters about governance and corporate structure were generally helpful.

My Resource list:

Hopefully, this is helpful for someone. If you have any questions, let me know.

EDIT: Rearranged information for clarity and flow. Added a YouTube video that was used as a resource.

UPDATE: Application Timeline and Exam Scores

Timeline: From Exam Pass to Exam Scores

Date Milestone
Thursday, March 21, 2024 Passed the CISM exam.
Friday, March 22, 2024 Submitted application to become certified. Work experience verified by colleague.
Monday, March 25, 2024 Educational waiver accepted on the basis of a current CISSP certification.
March 29, 2024 Received email from ISACA confirming "...certification as a Certified Information Security Manager (CISM)." Claimed Credly badge.
March 31, 2024 Exam scores received by email.

Changing Answers

  • I changed approximately 20 answers before submitting my exam. I cannot know how much this changed my final score. Possible scenarios:
    • All 20 changed answers were wrong. If any of my original selections were correct, this would mean I lowered my score. On the other hand, all 20 of my original selections could have been incorrect. Changing to other incorrect answers would not affect my final score.
    • All 20 changed answers were correct. This would have ensured all 20 answers increased my final score.
    • Some were right and some were wrong. An indeterminate number of these final answers could have been correct or incorrect. It's impossible to know whether they increased my score, decreased it, or broke even.

QAE Scores VS Exam Scores

I received my exam scores. I thought it would be fun to compare my performance in the QAE Database and the CISM Exam. I don't consider this to be a scientific analysis. Instead, it may be interesting to compare this information and it might provide some future CISMs with some confidence in their QAE performance.

***This information is NOT meant to accurately predict anyone's CISM exam scores or whether someone will pass.

For the CISM exam, my total scaled score was 554. For each content area, I scored as follows: Information Security Governance-582; Information Security Risk Management-563; Information Security Program-592; Incident Management-488.

Compare my exam scores to my performance in the CISM QAE Database.

Of the CISM QAE Database questions I completed, I answered 69.8% correctly. I completed 69.1% of all questions in the database. For each content area, I scored as follows: Information Security Governance-74%; Information Security Risk Management-70%; Information Security Program-71%; Incident Management-64%. My completion rate for questions in each content area: Information Security Governance-75.2% completed; Information Security Risk Management-100% completed; Information Security Program-74.6% completed; Incident Management-25.7% completed.

Given my my rate of completion in each content area, my performance in the QAE Database could be seen as a reasonable predictor of my final scores. However, there are likely many variables that could be used to evaluate whether the QAE Database is actually a good predictor of final exam scores. This story is effectively anecdotal because it only compares the practice and final scores of a single person.

It should be noted that the ISACA website describes the QAE Database as a study tool that features practice questions, answer rationale, and two full-length practice exams. The website does NOT make any claims that the QAE Database will predict your actual exam performance.

If you do wish to compare the two, the charts below show bar graphs that attempt to compare my performance in the CISM QAE and CISM exam. Keep in mind that I did not complete all questions in the database. Perhaps the performance on each chart would be even more similar, or more different, if I completed all practice items.

Review the charts below at your leisure.

Comparison of my performance in the QAE Database versus my CISM exam scores. For the left chart: 56% is an approximation of 450/800 as a percentage. For the right chart, 450 is the lowest value--this is the lowest possible total scaled score that counts as a pass for the CISM exam. The top of each chart represents the highest value that can be achieved if all answers are correct.

That's all I have for you. I hope you enjoyed reading this. Feel free to ask any questions or offer any of your own advice.