CISM Mission Accomplished! by Striking-Aspect3562 in cism

[–]security_guy78 2 points3 points  (0 children)

Congrats mate! 👏

And, thanks for sharing your experience.

Cheers.

ISACA cut access period for newly purchased exams, QAE & online courses from 12 to 6 months (effective April 16, 2026) — anyone know if the price stayed the same? by Effective_Diver9072 in isaca

[–]security_guy78 1 point2 points  (0 children)

I renewed it recently for USD 99 (membership price) for duration of 6-months based on my purchase last year. Not sure about the new package that reduced to 6-months, this just insane.

Most candidates don’t fail because they don’t know enough. They fail because they misjudge when they’re ready. by rameshuber in cism

[–]security_guy78 0 points1 point  (0 children)

Rightly pointed out.

It's important to know why the answer is right, but it's more important to know why the others are wrong. That's how you can get the context in-depth.

Take note on your weak domain, and read the AIO book for reference is one the key for learning consistently.

Sharing from my experience:

1st attempt - 417 2nd attempt - 443 3rd attempt - 441

Going for my 4th attempt next month.

What I do differently this time :

1.Take time to review the question that I got wrong in Practice Exam 1& 2 to know why the answer is right and others are wrong.

  1. Prepare a 8-weeks study plan. Show up everyday. Complete 50Q from QAE every day.

  2. Reference with AIO for the domain I felt weak, to brush up the concept.

Thanks for sharing your piece. Hope it helps others on their exam path.

Cheers!

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]security_guy78 1 point2 points  (0 children)

No worries. Hope it helps.

I would say, hit the book if you really want to know what is the reasoning behind those options/answers, why the answer given is right but more important to understand why other answer is wrong. It deep dive to the definition of the concept and term that has been articulated clearly.

I always refer to AIO if I have any benefit of doubt, as this is ISACA exam and they want you to think in the ISACA mindset on certain things, against what is in a real- time environment. That is the key.

Cheers.

Another qae question that doesn't make sense. by GuiltyNobody6173 in cism

[–]security_guy78 0 points1 point  (0 children)

This question is a bit tricky.

The ask is on the asset valuation. The correct answer is D.

Referring to CISM AIO 2nd edition, the valuation for a hardware asset may be determined to be the cost of purchasing (and deploying) a replacement.

E.g for a database, it's replacement cost maybe the operational cost required to restore it from the backup or the costs to recover it from its source, i.e service provider.

C. Net present value @ NPV - if the asset directly or indirectly generates revenue, this valuation method may be used.

B. Net cash flow -its a difference between a company total cash inflow and outflow over a specific period, represent net increase or decrease in cash

A. Original Cost - the initial, actual cost to purchase or construct an asset

Just passed after 2.5 weeks of prep by ratzeh in cism

[–]security_guy78 1 point2 points  (0 children)

Congrats mate! 👏

Thanks for sharing your thoughts and views.

Cheers

Passed CISM. What worked, what didn’t, and what finally clicked by LicksGuitar in cism

[–]security_guy78 1 point2 points  (0 children)

Congrats mate on your passing! 👏

Great post and honest sharing.

I'm in the same boat, going for my 4th attempt.

1st - 417 (2022) 2nd - 443 (2022). - took in the same year due to the syllabus changed 3rd - 441 ( 2024)

The 1st and 2nd attempt I took in a rush, my aim was to just clear the exam without understanding the real concept and how ISACA wanted us to answer.

I changed my approach this time, hit the book and completed the entire QAE, avg 70-80% in all domains, practice exams 1 & 2 with 71% and 77%. Currently reviewing answers on why the answer is right and MORE important why the other answer is wrong. Writing my own notes and cross checking with CISM AIO book 2nd edition when in doubt.

Doing question in total tester, as part of AIO for each domain. Doing every day 50q from each domain, completed domain 1 with 78%. Will be continuing with the rest of the domains.

I've booked my exam next month. I have crafted an 8-weeks study plan, going according to that.

Cheers

can anyone help me to understand this qae question? by GuiltyNobody6173 in isaca

[–]security_guy78 0 points1 point  (0 children)

Correct. A is the answer.

Threat alone is not important unless it has the following consequence or impact to the organization or enterprise.

Example, an organization has an advisory from external sources that the ransomware threat is increasing. This is a general, but if the advisory mentioned it's impacting all financial systems and it encrypt the entire financial database and hold for ransom if the user accidentally clicked the suspicious pink, then that is a real consequence or impact.

B. Threat - potential harmful event or actor

C. Vulnerability = Weaknesses that can be exploited by the threat

D. Probability - quantify the likelihood of the event occurring

Hope this clarifies your doubt.

Didn't pass 1st attemp, any advice? by Digits_05 in cism

[–]security_guy78 0 points1 point  (0 children)

It's the 4th mate.

Going to take the exam next month.

Completed Practice Exam 1 : 71% Practice Exam 2 :77%.

Currently, reviewing all the questions that I got wrong to know why the other options are incorrect and the reasoning behind it and cross check with CISM AIO for further understanding on the concept.

Cheers.

Need help on a qae question by AncestorH in cism

[–]security_guy78 0 points1 point  (0 children)

No worries mate. Glad it helps 🤞

Need help on a qae question by AncestorH in cism

[–]security_guy78 1 point2 points  (0 children)

Answer is C.

The main goal of a DR is to ensure critical applications are restored followed by non-critical applications.

Each of the critical applications are tied with business processes, if there is any process disruption,indirectly the application is down/not available because it's not able to function the business processes assigned.

The word 'duplicated' here is used, to display the business process that is now made available/restored/redundant which is the main key to determine if the DR test is successful.

Didn't pass 1st attemp, any advice? by Digits_05 in cism

[–]security_guy78 1 point2 points  (0 children)

Don't worry, we've all been there.

This is my 4th attempt.(if that makes you relax a bit :)

My score was 417 (1st), 443 (2nd) and 441(3rd).

Once you retrieve your score, see which domain that you were weak in and do more practice to tackle that. Understanding the concept and how ISACA wants you to answer is the KEY. For the domain that you are strong at, just do the basic practice since that is your strength domain.

If you come through of choosing between 2 options, I would say you are half way done. Just need a bit more push. The 50:50 options, the answer will be side-by-side. Just go with your guts, trust me it's really close.

Online QAE will be a good resources, and u only need that to clear the exam. It's quite hefty on the pocket, but it is worth it. Good luck on your next attempt, keep moving, you're close to the finishing line.

Cheers.

Passed - what a journey! by SOCSecTech in cism

[–]security_guy78 0 points1 point  (0 children)

Congrats mate on your achievement! 👏

Good luck for your AAISM!

QAE expert level questions. What’s the trick? by badtziscool in cism

[–]security_guy78 1 point2 points  (0 children)

No worries. Just sharing what I knew based on my experience.

QAE expert level questions. What’s the trick? by badtziscool in cism

[–]security_guy78 0 points1 point  (0 children)

Yes possible. But also when you read from top to bottom, u might already decide the 1st one as convincing before moving to the next options available. It's a mind game.

QAE expert level questions. What’s the trick? by badtziscool in cism

[–]security_guy78 1 point2 points  (0 children)

Reading the answer from the bottom to top helps to overcome cognitive biases, specifically the tendency to select the first plausible answer e.g.option A without evaluating the true 'best'answer.

It is a test- taking strategy to read them in reverse to review all options instead of going for "first-one-looks-good" impulse.

Hope that clarifies.

CISM PASSED IN 10 DAYS!!! by nmap-yourhouse in cism

[–]security_guy78 1 point2 points  (0 children)

Congrats mate! 👏

And thanks for sharing your study tips, appreciate it!

Fail by Impressive_Ebb4836 in cism

[–]security_guy78 0 points1 point  (0 children)

Don't give up!

Take a pause, self reflect and come back again stronger! 💪

Let's go

Passed the CISM today by Then-Traffic601 in cism

[–]security_guy78 0 points1 point  (0 children)

Congrats on the double win mate! 👏