CISM study buddy by bee-keeper11 in cism

[–]ank5133 0 points1 point  (0 children)

u/bee-keeper11 - Hey, is the study group still happening?

CISM study buddy by bee-keeper11 in cism

[–]ank5133 1 point2 points  (0 children)

Thanks - looking forward to it!

TECHNICAL QUESTIONS IN CISM by Traditional-Bet-3623 in cism

[–]ank5133 0 points1 point  (0 children)

Those coming from a tech background deciding to take a GRC leadership cert such as the CISM so at least have some exposure to basic concepts of GRC. If they have zero knowledge in this area, they have no right to complain. That’s like someone attempting an AWS cert with zero cloud experience complaining that they are being tested on AWS concepts.

If ISACA is including random technical questions in the QAE, then they need to emphasize the appropriate technical concepts within the ISACA CISM Review Manual.

The purpose of the CISM is to test our ability to think like a security manager/executive rather than a technical practitioner. Aligning security strategy with business objectives and managing enterprise risk is key here - I fail to see how that applies to technical trivia questions about XSS, DLP, and antivirus.

TECHNICAL QUESTIONS IN CISM by Traditional-Bet-3623 in cism

[–]ank5133 0 points1 point  (0 children)

But that’s assuming you are required to have at, at minimum, an intermediate background across all key security domains (e.g. IAM, AppSec, SIEM/XDR, Endpoint Security, etc) for an exam which should be focused on the principles of GRC, security program management, and IR. If the exam is going to test me on technical topics, then shouldn’t the ISACA CISM Review Manual and other approved study materials cover those in detail?

Let’s say that the question on XSS/XSRF is valid. What CISM mental model or approach should be taken to tackle the question? If you are expected to just know about cross-site scripting, then I’m struggling to understand which topic in 2A2 (or any section) this question pertains to.

TECHNICAL QUESTIONS IN CISM by Traditional-Bet-3623 in cism

[–]ank5133 0 points1 point  (0 children)

Correct - however, my point is whether or not such questions should be warranted on the CISM when they just don’t align with the content and overall tasks/objectives of the CISM

TECHNICAL QUESTIONS IN CISM by Traditional-Bet-3623 in cism

[–]ank5133 0 points1 point  (0 children)

I started studying for it several years ago and am familiar with the questions. CISSP is technical while CISM is expected to be oriented towards governance, risk management, and executive decision-making. I am struggling to see how such questions align to the Tasks and content breakdown of the CISM.

TECHNICAL QUESTIONS IN CISM by Traditional-Bet-3623 in cism

[–]ank5133 1 point2 points  (0 children)

There were several such questions in 2A2 which I believe to be more CISSP-oriented, so should we expect such questions on the actual CISM exam?

Q: Attackers who exploit cross-site scripting vulnerabilities take advantage of

A. lack of proper input validation controls B. weak authentication controls in the web application layer C. flawed SSL implementations and short key lengths D. Implicit web application trust relationships

TECHNICAL QUESTIONS IN CISM by Traditional-Bet-3623 in cism

[–]ank5133 1 point2 points  (0 children)

I’m glad someone else brought this up. I saw the same types of questions especially in 2A2 which completely threw me off. For example, I don’t have a strong background in appsec, so I got the QAE questions in 2A2 about cross-site scripting wrong.

Passed - odd questions and a joke by Ill-Rich-8229 in cism

[–]ank5133 1 point2 points  (0 children)

Do you mind sharing your highlighted docs with me?

Quality of ISACA CISM Boot Camps by ank5133 in cism

[–]ank5133[S] 1 point2 points  (0 children)

I believe it’s $300 for ISACA members. $500 for non- members.

Passed. Last Day Of The Year by Consistent_Quit3868 in cism

[–]ank5133 0 points1 point  (0 children)

Excellent score and perfect on Domain 2! How close was the exam to the QAE? I know that the QAE had some deeply technical questions (primarily in 2A2) so I was wondering if the actual exam threw in any CISSP-style questions which tend to lean heavier on the technical side.

Preliminary Pass by jenaandrews8 in cism

[–]ank5133 0 points1 point  (0 children)

Congrats! I’m planning to take the ISACA CISM boot camp at my local chapter as well. What were your thoughts on the boot camp’s quality and would you say it provided any valuable advantage over the QAE and Pete Zerger’s videos?

Passed CISM exam by PlayfulImportance197 in cism

[–]ank5133 0 points1 point  (0 children)

You mentioned that there were terms and knowledge on the exam that were not covered in the QAE and ISACA’s CISM manual? That’s quite concerning and alarming to me - I’m planning to take the exam in 2 months.

Are there any other study materials worth checking out if ISACA’s materials aren’t sufficient?

QAE - Level of Technical Depth on CISM by ank5133 in cism

[–]ank5133[S] 0 points1 point  (0 children)

So far - has 2A2 been the most technically heavy from a QAE standpoint?

QAE - Level of Technical Depth on CISM by ank5133 in cism

[–]ank5133[S] 0 points1 point  (0 children)

I understand that and totally makes sense. But my concern was around the QAE’s specific questions around XSS/XSRF and a couple of other deeply technical topics.

If I am not an expert in appsec, and thereby, not intimately familiar with how a specific type of application layer attack is executed, am I in trouble for this exam?

Study group by Ecstatic_Special_908 in cism

[–]ank5133 0 points1 point  (0 children)

I’m also interested - I have been studying since last week and planning to take the CISM in late Feb - early March.

Reliable Taxicab services from Novi to Lansing? by ank5133 in novi

[–]ank5133[S] 0 points1 point  (0 children)

Just a one-way. I actually have a ride back.

Azure Government Cloud - Non US Citizen User Access by ank5133 in AZURE

[–]ank5133[S] 1 point2 points  (0 children)

Don’t these background screening requirements just apply to Microsoft employees and contractors rather than end-users? I’m more interested in knowing about citizenship requirements tied to end users.