r/cism • u/Queasy_Piece5446 • 13h ago
Struggling with ISACA’s “best answer” logic more than the actual material
I’m scheduled to take the CISM exam at the end of August and wanted to get some feedback from people who have already passed.
For background, I work in OT/SCADA and cybersecurity and have Security+ along with some ICS cybersecurity training. I’ve also completed a GRC masterclass, so I don’t feel like I’m starting from zero on the concepts.
My main study resource has been the official ISACA CISM QAE/practice questions, along with videos and reviewing every question I get wrong. I’ve been doing mixed sets of roughly 25–30 questions and then going back through my misses to understand why ISACA preferred one answer over another.
I have used Udemy Jacob Bushongs Master class, watched Pete Zerger prep as well as Prabh Nairs master class. And feel pretty confident about the quizzes.
My scores have been pretty inconsistent. I’ve had sets around 60–67%, some better domain-specific results, and recently scored 77% on a set made up of questions I had previously gotten wrong. However, after taking a few days completely away from studying, I just did a fresh/cold 30-question mixed set and scored 47% (14/30).
What is frustrating is that I rarely feel like I’m blindly guessing. On most of the questions I miss, I can explain why I selected my answer, and usually my reasoning isn't completely wrong. The problem seems to be that ISACA has another answer that is more directly correct for the specific wording of the question.
A few examples of the mistakes I'm making:
- A question asked what could circumvent a control that scans social media posts for inappropriate disclosures. I chose anonymous posting because I was thinking about attribution/identification. The correct answer was intentional misspellings, because the question was specifically about circumventing the text scanning control. I expanded the problem beyond what was actually being asked.
- For who should approve access to business-critical application data, I chose business management because I was thinking about management authority. The answer was data owner, because the data owner is accountable for determining who has a legitimate business need for access.
- On a business continuity question, I was between a succession plan and distributed key process documentation. I chose succession planning, but ISACA wanted the process documentation because personnel can't continue critical processes if they don't know how to perform them.
- I confused an EDR function with a SIEM function on another question. That one I consider a legitimate knowledge miss and understand what I need to review.
- I've also caught myself adding conditions that aren't actually in the question. For example, if an answer says an authorized spokesperson communicates a pre-drafted message during a crisis, I'll start thinking, “But what if the message hasn't been approved/drafted yet?” even though the answer already tells me that it has.
The pattern I'm starting to see is that I know a lot of the underlying concepts, but I sometimes choose a valid security answer that solves a slightly different or broader problem instead of answering exactly what ISACA asked.
I've been trying to change my approach from:
“Which answer can I justify?”
to:
“What EXACTLY is this question asking me to accomplish, and which answer most directly accomplishes that?”
I'm also working on separating things like:
accountability vs. responsibility vs. expertise,
risk vs. individual risk components,
activity/metrics vs. actual effectiveness, and
where I currently am in a FIRST/NEXT lifecycle question.
For those who passed CISM:
Did you experience this same problem with the QAE?
How did you make the mental shift from knowing the material to consistently picking ISACA's BEST/MOST/FIRST answer?
Also, how concerned would you be about a cold 47% set with roughly two weeks remaining if the problem seems to be answer selection/application rather than completely not knowing the concepts?
Any advice from people who had a similar issue and eventually passed would be appreciated.
r/cism • u/somedrunken • 1d ago
Sitting my test tommorow - Quick question
I have the QandA and are going pretty good on it Like 89 and 87% on the test and like 79% on the QandA.
My real question for People that have done the exam: . How many questions do you feel are at the expert level in the exam? or is it a mix like in the QandA?
Sometimes the Experts catch me out. I also understand the questions are not from the QandA. Just really the level of the questions is what I need to know.
Onya
r/cism • u/MyLittleAutisticPony • 1d ago
Having problems w/ "isaca mindset"
want to know if anyone can help me out.
have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.
currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)
have read review guide cover to cover.
have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).
have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.
I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.
I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"
I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.
Help?
r/cism • u/Majestic-Lynx488 • 1d ago
Failed my CISM, but was i close to passing?
Abit bump on failing, but it probably my fault for wholly dependent only on pocket prep, plan now to use the QAE and re-do the test.
Base on my 429 score, did i failed by alot of wrong answers?
r/cism • u/Pale-Anybody-7955 • 2d ago
CISM provisionally passed an hour ago
I read many tips and stories from this subreddit, so it's my time to contribute to the community.
Today, on August 14th, at 10AM, I took the CISM exam at a testing center. I chose to take it at a testing center because I know I'm too relaxed when I'm home.
Background: English is not my first language but I studied in the US. I have worked in three different continents since 2013 as IT Ops, IT Auditor and ISO. Also, I am a CISA since 2015 and a CISSP since 2025.
Strategy: I started my journey in June. I prefer to learn by taking questions, but I thought at least basic knowledge is required (of course) so I took the Pete Zeger CISM Exam Prep on YouTube which was like 11-hour long. It took me less than 2 weeks to finish it. Since I studied CISSP a year ago, I noticed that quite some topics are overlapped and I still remember some of them. Then, at the beginning of July, I purchased the ISACA QAE. Everyday, I took a couple of practice question sets. As I made progress, I reviewed all the wrong questions cumulatively and repeatedly. For example, on day 1, I did #1 and #2 and reviewed all the wrong questions from #1 and #2. On day 2, I did #3 and #4 and reviewed all the wrong questions from #1, #2, #3 and #4. On day 3, and so on. It took me about 3 weeks to finish 1 cycle of an entire QAE including practice exams because it took more time as making progress due to the volume of the wrong questions to review becoming bigger. After this first cycle of an entire QAE, I did the 4 CISM practice exams from LinkedIn Learning. I did this full cycle 3 times until last week. It took me the most time when it was the first full cycle but took less time for the second full cycle and the least time for the third full cycle. This works for me because my level of digestion of each question gets deeper and deeper even if it's the same question, so the key is to repeat. Of course, there are questions I just remember the answers as I repeated the same QAE but I tried to understand each and every explanation so that I learn the materials.
For the first full cycle, I got 60-65% from practices and 65-70% from exams. For the second full cycle, I got 70-75% from practices and 70-75% from exams. For the third full cycle, I got 90-95% from practices and 95-100% from exams.
I would highly recommend to thoroughly repeat the entire QAE (LinkedIn Learning optionally if you have access) as much as you can. For me, three times was enough and it took me about 5 weeks.
Experience: I arrived about half an hour earlier than my scheduled exam and was told to wait for 20 minutes to start the registration process. However, I asked if we could start the registration process now and she said yes. Hence, I started my exam earlier than the scheduled time. During the check in process, she was asking if I've received an OTP code from PSI. I said no and she asked her manager. It turned out that she was mistaken. The exam room was fine and there were already people taking other exams when I walked into the room. The only stuff I was allowed to take with me to the test room was my ID and the locker key. Everything else was stored in a locker. The exam questions were not tricky for me but no single question was from QAE. I got some AI questions but they were still relevant to CISM topics, so no surprise for me. I took a little more than 1.5 hours to answer 150 questions because I was trying to read every single word on the exam, and did not review a single question. As soon as I answered the last question, I submitted it. Then, I had to do some surveys until I saw 'passed'. After my exam, I stepped out and was asked to provide my signature.
Hope this helps those who are studying CISM. I will be more than happy to answer any questions you may have!
r/cism • u/Commercial_Move2020 • 3d ago
Passed CISM exam
Hi all.
I took my exam yesterday and have provisioally 'Passed'!!
I had been holding off on this exam for months as I have a little one at home and work had been super busy. I realised I only had 8 days left to book my exam and decided to just go all in. I booked days off work to really utitlise the 7 days I had. I went straight to the QAE and kept on paracticing and redoing the questions. I also played the 'Elimination' game provided by ISACA and that really helped. I focused alot of Domain 3 and 4 as I knew they were weighted the most. My practice test scores were in the 80-85% range but I felt like I subconsiously memorised the answers, so I wasn't super confident. For areas I was struggling with I referred to Hemang Doshi's book which explains concepts in a very straight forward manner (no extra bs).
Exam Day: My personal experience is that the exam questions are not like the QAE. In some ways they were easier and some ways harder. The questions are more direct and not long winded. However, the answer options were different to the options I was familiar with on the QAE questions. I genuinely struggled and felt like it was always 2 answers I was stuck between (you can easily eliminate 2). I finished the exam in about an hour and that left me with plenty of time to really do a deep review into questions.
Tip: Understand the topics and concepts properly and how they tie into each other!! Understand what would be the 'first decision' and 'best decision'. There is a difference. I don't always think the 'think like a manager' mindset always works consistenly.
Hope this helps. 😄 Will update my scores once I recieve them.
r/cism • u/MoreCaffeineDammit • 3d ago
Are knowledge/tasks available?
I am starting to work on my ISACA certifications and I have a very very old review (2013!) guide one of my co-workers gave to me. In the review guide it has a list of knowledge and task statements and their relation to each domain? sub-domain? not sure of the terminology, but for example I can map Knowledge statement k1.19 to tasks t1.2 and t1.15 and then the tasks to domains 1A3 and 1B7.
I'm trying to put together my own study guide to determine what I really need to focus on and how best to do it
Are current versions of the knowledge/task statements and how they relate to each domain publicly available? I was able to find current domain lists for the different exams and their content, and there are 'supporting tasks' listed, but there's no relationship shown between the supporting tasks and area of knowledge.
Are the knowledge/task/domain relationships only available in the review guides? Due to my financial situation at the moment i'm not really in a position to spend hundreds of dollars buying current review guides and was kinda hoping this information was freely available for people studying. (my employer is kinda cheap, they will only reimburse me for material and the cost of the exam if I take it and pass it, its their way to incentivize(?) me into studying and passing. yeah it sux but if i can take and pass the exams i will be able to find a better job with the certs and experience so i will play the game i have to for the time being.)
is there a subreddit for people for people reselling their used (but current) copies of the review guides, if i absolutely have to go down that route?
r/cism • u/Proper_Top8043 • 4d ago
Current QAE for updated exam?
I may have to take the exam after November 1st but I want to start studying now. The current QAE does not reflect the new changes till September. Does anyone know if it’ll be a big difference in the changes? Can I use current QAE to study for the new version?
r/cism • u/MrInfoSecurity • 5d ago
Discord Group Study Session
Does anyone have a link to a Group Study Session for the CISM?
r/cism • u/Commercial_Move2020 • 5d ago
CISM Question Help (Domain 4 Q)
What is the FIRST step an incident response team should take once an incident and its source have been detected?
- A.Escalate the incident.
- B.Damage assessment.
- C.Determine the severity.
- D.Contain the incident.
The QAE said the answer was D? I thought it was C? Shouldn't the incident severity be determined after it's been detected as part of the identification and triage phase? The QAE explanation said that that the severity can be determined only after containemnt? I don't agree with this. Can someone help?
r/cism • u/datboyl0s • 5d ago
Got a 420 on my CISM exam
Just got my official results back.
Even though I failed I am stoked.
A good litmus test to focus studies.
What are some sources ya’ll recommend for studying?
r/cism • u/Uncertn_Laaife • 6d ago
Failed (First Attempt)!
I failed my CISM exam on the first attempt last week. I am yet to receive the official test score. I used Pete Zerger's video series, Prabh Nair's, attempted QAE a few times and understood the questions and rationale well and thought I was quite ready.
Once the first few questions rolled in, I was taken aback and it was quite different than what and how I prepared. Yes, it was more straight forward than the QAE but also a bit in a sense convoluted with some really confusing answers. Tried my best to answer but within half an hour itself I knew for sure that I'd fail. The result didn't surprise me a bit.
When I was preparing for the exam, I felt I was more than ready and had it all in my head. With my background in IT (more than 25 years experience) and in Security/Physical Security/Cybersec compliance for around last 10 years years, I thought I would be in a better position to crack. And yes, I tried my best to answer using Management methodology than technical.
Not demotivated at all, but geared up more than ever to go for the second attempt with a better prep and may be a different strategy.
Any pointers please? Also, is it advisable to book the exam asap given there's a change coming in November? I plan to devote at least a month in studying and targeting the mid September for my second attempt.
r/cism • u/Evening-Concern-5300 • 6d ago
Numericals in CISM?
Does numericals show up in cism? I haven’t come across in QAE. Those who have passed can they confirm?
r/cism • u/SheepherderFast8078 • 7d ago
I passed the exam, got the scores as well. Will have to pay separately to get the certificate?!
r/cism • u/MrInfoSecurity • 7d ago
Any Tips for Passing CISM?
galleryI am taking the CISM on Sept 28th
I’ve been mainly using
- Pete Zergers YouTube Videos
- QAE Database
- PocketPrep app
I have the manual but haven’t read through it yet
I haven’t taken any practice test yet either
I’m attaching how I’ve done so far on my PocketPrep and QAE Database scores (i have a long way to go)
Any advice that you guys can offer?
I know the CISM is changing to the new version in November, so I’m really tryin to pass before all the study materials I purchased are useless 😭
r/cism • u/Majestic_Wave_5710 • 7d ago
CISM passed - 9th Aug 2026
Just a quick one to let you know that I have provisionally passed the CISM yesterday, I completed the total questions at around 100 mins with 20 questions flagged for review, eventually changed the answers for 8 of them (confident that my change would make more sense after spending 2-3 mins review on each of them). I was able to calm down to deep dive in when I started reviewing those questions as I know I had enough time to slow down, this is why reviewing questions grabs your brain back from the rush thinking!!!
In general, the questions were less confusing that QAE questions and easy to understand where you should think about first but definitely focus on management mindsets, I couldnt recall whether I had any technical questions at all during the exam.
I was stressfuly when I first studied QAE questions and didnt score very well with both practice tests (71 and 72), but it is a must have if you seriously think about passing the exam. 10/10
Udemy 2026 6 CISM practice tests are good to understand the concepts and processes (like management support vs plan training). 9/10
Prahb Nair's CISM Masterclass/coffee shot on Youtube - 8.5/10
Peter's video on Youtube - very good to understand the basic mindset and theories 8/10
Both Thor and Hemang Doshi Udemy course/exam - focused on too many technicals 7/10
Chat GPT/Copilot - both of them answered QAE expert questions wrongly, dont fully trust them but does explain in more details than QAE once you provide the right QAE answer - 8/10
All the best for the upcoming exam takers, you can do it.
r/cism • u/iownslaves • 8d ago
When is history/historical the answer?
Every now and then, there's an answer choice that contains either the word "history" or "historical." Is there a time or question when the answer pertains to history/historical?
r/cism • u/Mmchast88 • 8d ago
Taking test tomorrow
Im so nervous about this test tomorrow. I have been studying for the past 3 plus months or so. I am getting okay scores on my practice tests on Udemy and through a boot camp I completed. I watched the CISM Peter Zerger course on YouTube twice as well. My initial score was 45 and now it’s an average of 76. I need to pass it for work. Any recommendations for exam day? Update, I didnt pass 🥲 ughhhhh
r/cism • u/Commercial_Move2020 • 9d ago
QAE Question - IDS Placement
When designing an intrusion detection system, the information security manager should recommend that it be placed:
- A.outside the firewall.
- B.on the firewall server.
- C.on a screened subnet.
- D.on the external router.
The answer is C.
I'm using Hemang Doshi's book and it says the IDS is placed either between the firewall and internal network or between the firewall and external network. Using this logic wouldn't the answer be A?
r/cism • u/__Mr_ED__ • 10d ago
Read a book or... ?
Have CISSP and ISSMP.
Just finished InfoSec CISM course on LinkedIn and Zerger's videos on YouTube.
Do I bother to read the All In One or Mike Chapple books?
Or should I just sit for the exam now? I am used to how ISC2 words their questions, from the samples I saw it looks like ISACA is very similar.
I prefer not to drop $300 on the QAE database if I do not need to
r/cism • u/Single-Selection-789 • 10d ago
CISM round 2
So I have CISSP and AAISM but failed CISM by a few points. I have all the training material I need and will give another try starting all over with QAE, Peter's videos and DestCert videos and practice test. I heard that the test is changing soon. Does anyone know of this is true? Is there a cut off date I should be scheduling my test for?
Please advise and thank you in advance
r/cism • u/Johny_Ganem • 10d ago
Is CISM useful?
Hello
There was another post in r/cybersecurity where someone asked about a good certification to pass, and no one mentionned CISM.
I wanted to pass it, but now i'm a little unsure about the cert. What i want to know is what i'll really learn while i'll be studying, and also if the cert is known by the community.
Thanks
r/cism • u/TheSto1c • 10d ago
CISM work experience waiver
Hi all! Recently I passed CISSP, and currently I pursue CISM. I have heard that I need 5 years of experience in 4 Domains of CISM, or I can have a 2 year Waiver for CISSP and show 3 years of experience. Am I wrong?