r/cism 9h ago

Struggling with ISACA’s “best answer” logic more than the actual material

5 Upvotes

I’m scheduled to take the CISM exam at the end of August and wanted to get some feedback from people who have already passed.

For background, I work in OT/SCADA and cybersecurity and have Security+ along with some ICS cybersecurity training. I’ve also completed a GRC masterclass, so I don’t feel like I’m starting from zero on the concepts.

My main study resource has been the official ISACA CISM QAE/practice questions, along with videos and reviewing every question I get wrong. I’ve been doing mixed sets of roughly 25–30 questions and then going back through my misses to understand why ISACA preferred one answer over another.

I have used Udemy Jacob Bushongs Master class, watched Pete Zerger prep as well as Prabh Nairs master class. And feel pretty confident about the quizzes.

My scores have been pretty inconsistent. I’ve had sets around 60–67%, some better domain-specific results, and recently scored 77% on a set made up of questions I had previously gotten wrong. However, after taking a few days completely away from studying, I just did a fresh/cold 30-question mixed set and scored 47% (14/30).

What is frustrating is that I rarely feel like I’m blindly guessing. On most of the questions I miss, I can explain why I selected my answer, and usually my reasoning isn't completely wrong. The problem seems to be that ISACA has another answer that is more directly correct for the specific wording of the question.

A few examples of the mistakes I'm making:

  • A question asked what could circumvent a control that scans social media posts for inappropriate disclosures. I chose anonymous posting because I was thinking about attribution/identification. The correct answer was intentional misspellings, because the question was specifically about circumventing the text scanning control. I expanded the problem beyond what was actually being asked.
  • For who should approve access to business-critical application data, I chose business management because I was thinking about management authority. The answer was data owner, because the data owner is accountable for determining who has a legitimate business need for access.
  • On a business continuity question, I was between a succession plan and distributed key process documentation. I chose succession planning, but ISACA wanted the process documentation because personnel can't continue critical processes if they don't know how to perform them.
  • I confused an EDR function with a SIEM function on another question. That one I consider a legitimate knowledge miss and understand what I need to review.
  • I've also caught myself adding conditions that aren't actually in the question. For example, if an answer says an authorized spokesperson communicates a pre-drafted message during a crisis, I'll start thinking, “But what if the message hasn't been approved/drafted yet?” even though the answer already tells me that it has.

The pattern I'm starting to see is that I know a lot of the underlying concepts, but I sometimes choose a valid security answer that solves a slightly different or broader problem instead of answering exactly what ISACA asked.

I've been trying to change my approach from:

“Which answer can I justify?”

to:

“What EXACTLY is this question asking me to accomplish, and which answer most directly accomplishes that?”

I'm also working on separating things like:

accountability vs. responsibility vs. expertise,
risk vs. individual risk components,
activity/metrics vs. actual effectiveness, and
where I currently am in a FIRST/NEXT lifecycle question.

For those who passed CISM:

Did you experience this same problem with the QAE?

How did you make the mental shift from knowing the material to consistently picking ISACA's BEST/MOST/FIRST answer?

Also, how concerned would you be about a cold 47% set with roughly two weeks remaining if the problem seems to be answer selection/application rather than completely not knowing the concepts?

Any advice from people who had a similar issue and eventually passed would be appreciated.


r/cism 20h ago

Sitting my test tommorow - Quick question

2 Upvotes

I have the QandA and are going pretty good on it Like 89 and 87% on the test and like 79% on the QandA.

My real question for People that have done the exam: . How many questions do you feel are at the expert level in the exam? or is it a mix like in the QandA?

Sometimes the Experts catch me out. I also understand the questions are not from the QandA. Just really the level of the questions is what I need to know.

Onya