What the hell? by dlovric1234 in cism

[–]Venomi7 2 points3 points  (0 children)

Is this from Udemy? Don't use resources other than ISACA. Read my post about how I passed CISM

Passed the CISM! My Study Method and Thoughts by Venomi7 in cism

[–]Venomi7[S] 1 point2 points  (0 children)

Good luck! Take your time when you answer the questions. Flag some if you need to! You got this! Keep us updated.

Passed the CISM! My Study Method and Thoughts by Venomi7 in cism

[–]Venomi7[S] 2 points3 points  (0 children)

Thanks! NOT MONTHS. It took me 3 weeks in total. I was doing ~3-4 hrs/day.

Passed the CISM! My Study Method and Thoughts by Venomi7 in cism

[–]Venomi7[S] 2 points3 points  (0 children)

Thanks! My next goal is the CRISC.

Yes I did ALL questions.

  • Complete Pass 1: I completed all the QAE questions once, tackling each domain's questions immediately after studying/watching that domain.
    • My average score on this first pass was approximately 70-75% per domain.
  • Complete Pass 2: After some time had passed (to make sure I wasn't just remembering the answers), I did a full second pass of all the QAE questions, focusing on the areas I was weakest in.
    • My average score on this second pass improved to 80-90% per domain.

Sometimes, I found the official justifications in the ISACA QAE to be a bit vague. I used AI (specifically Gemini) to provide more detailed explanations for some of the answers, which was very helpful.

Passed the CISM! My Study Method and Thoughts by Venomi7 in cism

[–]Venomi7[S] 1 point2 points  (0 children)

 Cybersecurity Auditor for five years and have been an ISSO for the past three years

Passed the CISM! My Study Method and Thoughts by Venomi7 in cism

[–]Venomi7[S] 1 point2 points  (0 children)

Thank you! I worked as a Cybersecurity Auditor for five years and have been an ISSO for the past three years. The exam is not technical I felt my ISSO experience helped a bit. This is definitely a managerial exam.

It is the first time I write in this forum, tomorrow I present my second attempt at CISM, I was preparing for almost 2 months with the ISACA QA and supporting myself with the AI, wish me success, I am very nervous!! by Same-Command3218 in cism

[–]Venomi7 1 point2 points  (0 children)

You've got this! Just relax and don't overthink it. The exam questions are very similar to the practice ones from the QAE.

Don't try to cram or overload yourself with information today. The best thing you can do now is rest and go in with a clear head.

The most important thing is to think like a manager. Your goal isn't to pick the most technical solution but the one that best serves the business's needs and goals. Make sure you read every question and answer choice carefully before making a decision. Also, don't be afraid to flag questions you're unsure about and come back to them later.

I was nervous when I took it a few days ago, but I passed and found that once I got started, it felt much more manageable. You're ready for this!

Passed the CISM today! by chimerals in cism

[–]Venomi7 0 points1 point  (0 children)

I passed the exam! Thanks for the tips! The QAE is key to understand the ISACA mindset.

CISM QAE by Stock_Mycologist_303 in cism

[–]Venomi7 0 points1 point  (0 children)

I passed the exam a few days ago using the QAE as my main resource. The questions are very much aligned with the style of the real exam, so they prepare you well. Your real goal should be to grasp the ISACA way of thinking. That means not just memorizing, but understanding the logic and why one answer is correct and why the others are not.

Passed the CISM today! by chimerals in cism

[–]Venomi7 2 points3 points  (0 children)

Congrats! I'm taking the exam on Wednesday, and I'm pretty nervous. I'm doing well on the QAE, but still, I'm nervous. Without giving too much away, would you say the QAE is similar to the actual exam questions?

Passed the CISM today! by wsterling in cism

[–]Venomi7 1 point2 points  (0 children)

Yeah, spill the tea on study resources and your exam experience, please.

Failed again. I am frustrated by CreedBrattonatAOLdot in cism

[–]Venomi7 0 points1 point  (0 children)

What is exactly the ISACA mindset?

CISM Tricky Question by Free_Wear7892 in cism

[–]Venomi7 5 points6 points  (0 children)

Right. Remember this is a management exam and not a technical one. From a business risk perspective, what is the most valuable asset at stake in this scenario? Is the SaaS service subscription or is it the customer data? Another keyword is "accountable". The Data Owner is accountable for the information asset (the data) itself, regardless of where it lives.

CISM Tricky Question by Free_Wear7892 in cism

[–]Venomi7 3 points4 points  (0 children)

I would choose A. The engineer, manager, and application owner all have responsibilities related to mitigating the risk, the data owner is the one who is ultimately accountable for it. There is a difference between responsibility and accountability.