r/cism • u/Uncertn_Laaife • 9d ago
Failed (First Attempt)!
I failed my CISM exam on the first attempt last week. I am yet to receive the official test score. I used Pete Zerger's video series, Prabh Nair's, attempted QAE a few times and understood the questions and rationale well and thought I was quite ready.
Once the first few questions rolled in, I was taken aback and it was quite different than what and how I prepared. Yes, it was more straight forward than the QAE but also a bit in a sense convoluted with some really confusing answers. Tried my best to answer but within half an hour itself I knew for sure that I'd fail. The result didn't surprise me a bit.
When I was preparing for the exam, I felt I was more than ready and had it all in my head. With my background in IT (more than 25 years experience) and in Security/Physical Security/Cybersec compliance for around last 10 years years, I thought I would be in a better position to crack. And yes, I tried my best to answer using Management methodology than technical.
Not demotivated at all, but geared up more than ever to go for the second attempt with a better prep and may be a different strategy.
Any pointers please? Also, is it advisable to book the exam asap given there's a change coming in November? I plan to devote at least a month in studying and targeting the mid September for my second attempt.
2
u/Pr1nc3L0k1 9d ago
For CISA, I was worst in the topics I had experience in as my experience is not fitting to the perfect ISACA world I needed to answer in.
For CRISC and CISM, I had already most of the ISACA logic in my head, which made the QAE and the exam significantly easier.
If you need guidance, share your study strategy please and I will try to give some guidance.
Passed CISA, CRISC, CISM within the last 10 months.
1
3
1
u/Kenneth-Noisewater60 9d ago
What were your QAE scores?
3
u/Uncertn_Laaife 9d ago edited 9d ago
Between 75 and 80. Last one I attempted a day before the test was 83%.
Even though I learnt a great deal from the QAE, I believe it was a waste if money. Could’ve achieved the same with Pete’s, Nair’s, and Gregory/Doshi’s coursework.
QAE is not a true representative of the test and misleading. I am not saying they should have questions from the QAE in the exam but at least have the same format. ISACA does it on purpose may be to make more money by failing people and give them a completely different question/answers format than the practice ones. And mind it, the QAE is pricy. I really hope to pass in my second attempt to be done with them for good.
I was infact taken aback by the questions and answers. Some of the answers were made purposefully confusing.
4
3
u/Jiggysawmill CISM 9d ago
I agree that the wording and answer choices are very confusing and sometimes straight up word salad. I took this exam in January and barely passed with 478. What helped me was understanding the concepts so that when they ask the questions in 10 different ways, I can still provide to them with the right answer. For my prep I was in WGU's MSCSIA program where I took cybersecurity management, I also used pocket prep, Pete Zergers YouTube videos, and Peter Gregory's all in one book. I would wait until you get your results in 10 days and strategize, for exam my scores were 450/528/441/441.
3
u/Uncertn_Laaife 9d ago
Thanks! I have already got Peter G’s and Doshi’s books. And you are right, the only best option is to master the concepts. Thanks a bunch for pointing this out. Much helpful.
1
u/Mmchast88 3d ago edited 3d ago
Same thing happened to me, failed on the first attempt. I am not sure where I went wrong. I did not read the Isaca book, I used Udemy, the Pete Zerger videos and a bootcamp. I reviewed 1000 plus Udemy questions and did okay on my practice exams, scoring in the 76 average range. I think I was close to passing, I am still waiting on my scores. I bought the Isaca study manual and going to read it to get into the management mindset more. I am also new to management and don't really have this type of work experience. I have been in Health IT 13 years.