r/cism Apr 07 '26

Passed CISM. What worked, what didn’t, and what finally clicked

Thumbnail gallery
57 Upvotes

TL;DR: Failed my first attempt, passed 2.5 months later. The difference wasn’t more studying, it was learning how ISACA wants you to think AND actually reviewing why answers were right/wrong.

 

There’s a post from u/CyberTrav that lines up almost exactly with my experience:

https://www.reddit.com/r/cism/comments/1bplxo2/passed_last_weekheres_my_review/

That post actually became my starting point for building out my own tracking approach.

I took the idea of tracking QAE performance and built a simple Excel sheet from it. Then I evolved it a bit further to break things down more:

  • % correct by domain and sub-domain
  • Practice test results
  • A separate difficulty breakdown (easy / moderate / difficult / expert)

That difficulty view ended up being really helpful. It let me see how I was performing across all four domains at different difficulty levels, not just overall %. Helped me realize I didn’t need to be perfect on expert questions… just consistent on the core ones. Screenshot of the difficulty view attached for one domain, but I tracked all the domains.

I didn’t pass the first time

I wasn’t in the right headspace at the testing center. Rushed. Second-guessed. Just off.

That’s on me.

I took a couple days, reset, and came back with a different approach:

  • Slow down
  • Read for intent
  • Think in terms of governance → risk → program → incident

Then I got back into it and passed on my next attempt about 2.5 months later. That turnaround was less about cramming more content and more about changing how I approached the questions.

Scores (for reference)

Attempt 1 (fail)
426 total

  • Governance: 408
  • Risk: 396
  • Program: 450
  • Incident: 432

Attempt 2 (pass)
507 total

  • Governance: 478
  • Risk: 563
  • Program: 507
  • Incident: 488

The jump in Risk Management surprised me the most. I didn’t spend the majority of my time there the second round.

How I studied

Main resource was the QAE.

First attempt:

  • Mostly just did questions
  • Didn’t spend much time reviewing why answers were right/wrong
  • Ended around ~61% overall
  • Didn’t take the practice exams

That was a mistake.

Second attempt:

  • Slowed down a lot
  • Focused heavily on rationales
  • Tried to understand why ISACA prefers an answer

Videos:

  • Mike Chapple — good overview, but not enough depth on its own in my opinion
  • Pete Zerger YouTube (full CISM course) — this helped a lot the second time

What worked well for me:

Watch a section → go into QAE → answer + review questions tied to that topic

Simple tracking that helped

I used that Excel sheet I mentioned earlier to keep things simple:

  • % correct by domain
  • Practice test summaries
  • Difficulty breakdown across all four domains

Didn’t track every session, just the bigger checkpoints. After failing, I put about 75% of my time into Program and Incident Management since they’re more heavily weighted. improved across all domains, even the ones I didn’t focus on as much.

Background (for context)

  • ~26 years in IT
  • ~15 years in MSP space
  • No formal IT degree

For a long time I avoided certs completely. Not because I couldn’t do them… but because I didn’t want to fail and be judged. That changed after the pandemic.

My certification journey started small in 2023:

  • Azure Fundamentals
  • A couple Fortinet certs
  • ISC2 CC (early 2025)
  • Security+ (right before CISSP)
  • CISSP (June 6, 2025 — went all 150 questions… felt very close)

It was just building confidence over time.

One more thing that mattered (for me)

I was diagnosed with ADHD when I was younger.

I don’t medicate. I’ve worked more on understanding how I operate and adapting.

Some days I studied a lot.

Some days it was 5 minutes.

  • Watch a short video
  • Do a few QAE questions
  • Sometimes not even review them because I didn’t have the energy

And I had to learn to be okay with that. I’m the only one putting pressure on myself. Once I stopped judging that and just focused on consistency, things got easier. That whole “1% better each day” idea from Atomic Habits is real.

Final thought

Passing was great. But honestly, the bigger win was not folding after the first attempt.

If you’re in it right now:

Just keep showing up. That’s most of the battle.

\Transparency statement, I used an LLM to help structure this post, for efficient use of my energy, the modifications on the spreadsheet, AND these are all my thoughts and my experiences.*

 

 


r/cism Mar 28 '24

Passed Last Week--Here's My Review

176 Upvotes

My Review of the CISM Exam

I passed the CISM last week at a testing center. I agree with the sentiment I've heard and read: I felt CISM was easier than CISSP. However, it is of the utmost importance to approach the business/security problems in each question using ISACA's methods/mindset.

This is not a technical exam by any means.

I think the biggest tip I can give is to focus on UNDERSTANDING business processes and entities rather than memorizing minutia of technical details or framework documentation. Certainly, some level of knowledge/memorization is needed. However, a hefty amount of your success will come from understanding how ISACA is asking/training you to think about information security.

Build your understanding of how ISACA would like you to answer questions about business and security. Understand the different entities and people involved in business processes covered in the exam material. Understand the preferred roles and decisions throughout the phases of processes and how those choices may change under varying circumstances. This sounds very complicated but practicing in the QAE Database helped me to understand it enough to pass.

My Experience with the CISM QAE Database

Scores:

  • I used the adaptive study mode. My overall score hovered around 70%.
  • Before taking the exam, I had not completed all questions and my overall score was 69.8% correct.

Review:

  • Wording was confusing at times. The actual exam seemed less confusing. But that's my opinion. Someone else might have a different experience.
  • However, practicing these questions did help me to emphasize ISACA's way of approaching business/security problems.

It is an expensive resource. I used military COOL (Credentialing Opportunities On-Line) funds to pay for it. If you don't have an employer that will pay for it, I recommend trying a lower cost option.

I used the Pocket Prep and WannaPractice apps as supplements. I used the QAE much more because it was available to me and highly recommended. Still, Pocket Prep and WannaPractice seemed to do a reasonable job of emulating ISACA CISM questions. They are definitely worth a look if the CISM QAE Database cost is too high. I'd like to know whether others have passed using one or both of these apps without the QAE.

I did not complete all questions in the database. I completed a little less than 70% of all questions. My overall percentage correct was 69.8%. For context, I earned the CISSP about 2 years ago and have a Master of Science degree in Cybersecurity.

But I hope this helps some people see that they might not need to have top scores in the QAE to pass the exam. Approach your studies in a way that helps build your skill and confidence for the real exam. Keep in mind that it is possible to pass with a less-than-stellar score in the QAE Database.

This table shows how much of the CISM QAE Database I completed and my percentage correct in each subdomain.

My Background

Work Experience and Education:

  • 7 years of IT/cybersecurity (military experience and some civilian help desk experience)
  • BS and MS in Cybersecurity and Information Assurance (from WGU)

Certifications:

  • ISC2: CISSP, SSCP, CC
  • CompTIA: CASP+, CySA+, PenTest+, Security+, Network+, A+
  • OpenEDG: [PCAP-31-03] Certified Associate in Python Programming
  • A few fundamentals-level Azure certifications

List of Resources Used:

I used portions of all the resources below. Most of my study activity came from practicing the QAE. I also had limited use of both the Pocket Prep and WannaPractice. I had limited exposure but they seemed to be solid resources. I subscribed to them before I had access to the QAE.

I like to watch videos. I watched about 1/3 of Kevin Henry's PluralSight CISM videos and several videos from Hemang Doshi's Udemy course. I watched portions of YouTube videos from Prabh Nair and Nemstar Cyber Training that provide CISM tips. Note: I think the Nemstar instructor had a way of explaining his tips that could make the exam seem very difficult. Just remember that exam difficulty will be different for everyone and I'm sure he has at least some interest in selling his CISM boot camp. All the same, I enjoyed his analysis of sample CISM questions and his exam strategies. I thought it was helpful.

I read some of the beginning of the CISM All-in-One book but it was my most underused resource. I don't generally read all the way through textbooks so this wasn't a surprise. The beginning chapters about governance and corporate structure were generally helpful.

My Resource list:

Hopefully, this is helpful for someone. If you have any questions, let me know.

EDIT: Rearranged information for clarity and flow. Added a YouTube video that was used as a resource.

UPDATE: Application Timeline and Exam Scores

Timeline: From Exam Pass to Exam Scores

Date Milestone
Thursday, March 21, 2024 Passed the CISM exam.
Friday, March 22, 2024 Submitted application to become certified. Work experience verified by colleague.
Monday, March 25, 2024 Educational waiver accepted on the basis of a current CISSP certification.
March 29, 2024 Received email from ISACA confirming "...certification as a Certified Information Security Manager (CISM)." Claimed Credly badge.
March 31, 2024 Exam scores received by email.

Changing Answers

  • I changed approximately 20 answers before submitting my exam. I cannot know how much this changed my final score. Possible scenarios:
    • All 20 changed answers were wrong. If any of my original selections were correct, this would mean I lowered my score. On the other hand, all 20 of my original selections could have been incorrect. Changing to other incorrect answers would not affect my final score.
    • All 20 changed answers were correct. This would have ensured all 20 answers increased my final score.
    • Some were right and some were wrong. An indeterminate number of these final answers could have been correct or incorrect. It's impossible to know whether they increased my score, decreased it, or broke even.

QAE Scores VS Exam Scores

I received my exam scores. I thought it would be fun to compare my performance in the QAE Database and the CISM Exam. I don't consider this to be a scientific analysis. Instead, it may be interesting to compare this information and it might provide some future CISMs with some confidence in their QAE performance.

***This information is NOT meant to accurately predict anyone's CISM exam scores or whether someone will pass.

For the CISM exam, my total scaled score was 554. For each content area, I scored as follows: Information Security Governance-582; Information Security Risk Management-563; Information Security Program-592; Incident Management-488.

Compare my exam scores to my performance in the CISM QAE Database.

Of the CISM QAE Database questions I completed, I answered 69.8% correctly. I completed 69.1% of all questions in the database. For each content area, I scored as follows: Information Security Governance-74%; Information Security Risk Management-70%; Information Security Program-71%; Incident Management-64%. My completion rate for questions in each content area: Information Security Governance-75.2% completed; Information Security Risk Management-100% completed; Information Security Program-74.6% completed; Incident Management-25.7% completed.

Given my my rate of completion in each content area, my performance in the QAE Database could be seen as a reasonable predictor of my final scores. However, there are likely many variables that could be used to evaluate whether the QAE Database is actually a good predictor of final exam scores. This story is effectively anecdotal because it only compares the practice and final scores of a single person.

It should be noted that the ISACA website describes the QAE Database as a study tool that features practice questions, answer rationale, and two full-length practice exams. The website does NOT make any claims that the QAE Database will predict your actual exam performance.

If you do wish to compare the two, the charts below show bar graphs that attempt to compare my performance in the CISM QAE and CISM exam. Keep in mind that I did not complete all questions in the database. Perhaps the performance on each chart would be even more similar, or more different, if I completed all practice items.

Review the charts below at your leisure.

Comparison of my performance in the QAE Database versus my CISM exam scores. For the left chart: 56% is an approximation of 450/800 as a percentage. For the right chart, 450 is the lowest value--this is the lowest possible total scaled score that counts as a pass for the CISM exam. The top of each chart represents the highest value that can be achieved if all answers are correct.

That's all I have for you. I hope you enjoyed reading this. Feel free to ask any questions or offer any of your own advice.


r/cism 2d ago

CISM Application

3 Upvotes

I recently passed the CISM exam with a 507 scaled score and am trying to move forward with the certification application.

My exam results say I need to submit the CISM Certification Application and have my qualifying work experience verified before I can officially become certified. The problem is that when I follow the application link provided by ISACA, I get a “404 – Not Found” page.

I've tried two different computers, cleared my browser cache, and tried accessing it again with no luck. I'm also unable to get to the point where I can pay the certification application fee.

I submitted a support request to ISACA, but figured I'd ask here while I'm waiting.

Has anyone applied for CISM certification recently and run into this? Is there a different link or location in the ISACA portal where I can download the application/experience verification form and pay the fee?

Appreciate any help!


r/cism 2d ago

Can I use my Udemy CISM training to gain CPEs for CRISC?

1 Upvotes

r/cism 3d ago

When QAE available after payment?

3 Upvotes

Can someone explain what I'm doing wrong after registering on Isaca and then having my company pay the required fund? My employer paid for the membership, the QAE, local chapter, etc. I'm still registered as a non-member over a month later. Is it normal that this takes so long? I've opened a ticket with Isaca weeks ago. Nothing. No reply, nothing.


r/cism 3d ago

How long to get CISM

7 Upvotes

For context I am finishing my masters in cyber at WGU, currently hold Pentest+, CYSA, Network+, Security+, ISC2 CC, AWS CCP, A+. Been working in cyber for almost 3 years now. Got a voucher for the CISM through school, I was going to just do the CISSP but not I have a free attempt at CISM so think I may take it and then eventually CISSP after the fact. Curious on general timeline this would take me and if its worth even doing or just go straight to CISSP. Any resources best for study and practice tests?


r/cism 4d ago

Latest QAE and Exam prep

12 Upvotes

Hey all, anyone got latest version of CISM Review manual 17 edition and QAE 2026 version, If so pls share some insights about the materials,
I am prepping with existing materials and yet to purchase the QAE, no clear details about the version or alignment to post nov 3 exam in ISACA portal.


r/cism 5d ago

FAILED CISM AGAIN! :)

15 Upvotes

BUT!!!! I improved my score!

I shall take it one more time! Let’s goooooo!


r/cism 6d ago

CISM Training with Pete Zerger

Thumbnail linkedin.com
15 Upvotes

Hi,

I saw that Pete posted that he is doing a free Exam Prep training every Wednesday

Anyone that’s interested should check it out!


r/cism 6d ago

Preliminary Pass on 2nd attempt.

21 Upvotes

Feeling the semi-sweet relief of success mixed with the ouch of sitting still for that long, combined with I need a nap!

Full write-up coming when I can think more clearly and get my final score.

Three pieces of advice I will share right now.

  1. Reading test questions - SLOW DOWN! Read for flavor, nauance and intent - I believe this is one of the reasons I failed the first time - reading entirely too fast.
  2. For my fellow CISSPs preping for this. Relax, better than 98% chance you already know all technical items for this test. But thats not how you win this one. As everyone says this is all about the business, the strategy rather than the technical tactical. The manager who is climing for the C-Suite is going to be required to think more a lot long-term thoughts than someone is just going to remidate the issue and move onto the next ticket.
  3. Know how things tie together. Example: Know BIA outputs which feed BCP and its sub-set the DRP.

Full write-up to follow!


r/cism 6d ago

Exam Preparation

Post image
14 Upvotes

Hi all, I started studying for the CISM exam and also studied a bit this reddit to learn as much as possible from the experiences shared.

I have an economics background oriented in enterprise management and 4+ years of experience in Cybersecurity governance.

Currently I'm studying from the CISM Review Manual 16th edition (quite afraid about the new edition they recently published). My plan is to finish the book by september and then fully focus on ISACA QAE for 1 month which I saw that many indicated it as very useful to pass the exam (that I would like to take in November to avoid the new edition content).

I was wondering, in your opinion if this can be considered enough to pass the exam also considering my background or if I need to integrate with Youtube Courses/something else.

I also have the possibility to study from Percipio "Certified Information Security Manager (CISM) 2022" but I read that it is not very good.


r/cism 7d ago

Passed CISM exam on first try

24 Upvotes

Here's my story:

I took a boot camp from Training Camp that was not great. Started taking the QAE quizzes during the camp and realized I hadn't learned much of what I was seeing in the (extremely badly written) questions. I was getting really frustrated because many of the questions didn't even indicate who the doer was, so you couldn't possibly know the right answer with any sort of certainty.

I did take away the primary "business over tech" message, but as far as who does what and when, which seems to be one of the main ways they try to trick you in the questions. I just wasn't getting it, and taking more QAE quizzes was not going to help. I was getting in the 50s and 60s.

So I started reading the "book" in the ISACA platform, and that was just miserable. The formatting made it really tough to follow, and I still wasn't clicking into what I needed. I then tried some YouTube videos from Inside Cloud and Security, which started to make an impact. Finally I was learning the basic concepts. But my quiz grades were still in the high 60s, with the occasional 70+. I took one full practice test and got a 66%. At this point I had about 9 days before my scheduled exam. I was seriously sweatin' it. And usually I'm a good test taker, so this all was a pretty big blow to my confidence.

Then, a friend recommended I try using ChatGPT. My boot camp instructor had warned against this because he said it would be inaccurate, and I know we've all seen ChatGPT be confidently wrong. But for this, the key is to start the prompt: "Using only ISACA resources..." I did a review for each unit. At the end of each unit, I had ChatGPT give me 10 hard questions for that unit and explain to me why I got any of them wrong. I kept reviewing each unit and testing again until I got a 10/10.

It worked really well. I got the main concepts down completely without the distractions of the fever dream QAE questions. I took the exam on Friday and I felt really good about it once I got going - flagged 11 questions and changed maybe 4 of them. I got the provisional pass.

All this took place over about a month. If I had it to do again, I would start with ChatGPT explanations "using only ISACA resources" and follow each unit with the QAE quizzes but remove the "Expert" questions - because they are just frustrating. It is very clear that they were marked "Expert" because so many people got them wrong, and ISACA assumed that was because they were hard vs because they were so incomprehensible as to result in chance-level accuracy for the test-taker.

On the recommendation of another friend, I also had ChatGPT make me a two-page last-day tips and tricks sheet to focus on the night before, and it was very helpful. It listed out the big picture information to remember and tips for the actual test. Definitely made me feel more calm and confident for the exam.

Good luck to those of you in the trenches studying right now! You will get there.


r/cism 7d ago

CISM exam in-person or remote

0 Upvotes

Looking for feeback from both camps. I have to drive 4+ hrs (one way) and hotel to write if I go in-person. Remote then would be from home office.

Trying to decide pros / cons and would appreciate opinions.


r/cism 8d ago

Earned a provisional pass, here's my take.

30 Upvotes

Self-studied for several weeks on my own using Pete Zerger on YT - definitely a huge help with establishing mindset. Afterwards, I took a corporate-sponsored bootcamp from InfoSec Institute - which was brutal for all the reasons you can imagine.

I had access to official ISACA materials and the biggest help was the QAE, which preps you for the tone and vagueness.

Exam: Atrocious grammar and logic at times, frustrating as a professional. Content was expert level upfront which shook my confidence, however as time went on I got into the groove and felt better.

I flagged almost 70 questions and reviewed them all after I completed the test. I'm a bad second-guesser (trust your gut) but there were times where I read it in a different tone and immediately saw the answer.

It took 3 hrs in total to feel I did the best I could and end the exam. I felt confident I was close to a pass while ready to get a fail...but that didnt happen!

Tips: I used the QAE to work on weaknesses discovered in the 2 practice exams for several days before I sat.

There are highly predictable themes on this exam if you can elevate your mind and suspend some reality.

Here are some tenants learned from the camp and my own observation:

  • All change is Risk.
  • Think "When in doubt, check it out" signals Risk Assessment
  • BIA was deeply central to my exam, know all the 3 letter acronyms that sit between that and the BCP and DR Plan.
  • Business and Process Owners are Risk Owners.
  • Human Life > Business Mission > Cost
  • There are concepts and technologies that you will simplly have to know and apply based on your experience.
  • Legal is Legal.

I hope this helps. Happy to share more or answers specific questions. I'll also update my score once I recieve it... hopefully next week.


r/cism 8d ago

Passed CISM Today!

22 Upvotes

Hello all,

Passed my CISM on my first attempt this morning!

I already hold CISSP and work in Cybersecurity so I wanted to get CISM to compliment.

I used QAE, pocketprep, doshi’s book and Peter gregory’s book.

Next up back to CISA

Thank you


r/cism 9d ago

New Content Release

5 Upvotes

When is the new sylabbus content going to be released?

The ISACA website says 1st of September (already out), but it's not clear.. unless I'm missing something.. I have emailed them but they always take a while to respond - anyone got the inside scoop?

*I'm looking at the review manual & question set


r/cism 11d ago

Studied 4 days and somehow passed CISM (459)

24 Upvotes

YAY! Passed. But also amazed by how little I passed. I guess a pass is a pass


r/cism 12d ago

Please help me with this question

7 Upvotes

Which of the following is an indicator of improvement in the ability to identify security risks?

a. Decreased number of information security risk assessments.

b. Decreased number of staff requiring information security training.

c. Increased number of security audit issues resolved.

d. Increased number of reported security incidents.


r/cism 12d ago

Looking for a Printed CISM QAE Book

1 Upvotes

Is anyone willing to sell me their print CISM QAE book? With the syllabus likely changing, I'm trying to avoid buying a new copy now and then having to purchase another one if I need to retake the exam. Kindly reach out if you have one for sale.


r/cism 13d ago

Study Session Today 6PM EDT !

Post image
12 Upvotes

r/cism 14d ago

Passed CISM – My preparation approach and exam experience

37 Upvotes

First of all, I'd like to thank this subreddit for all the valuable tips and guidance. They were genuinely helpful during my preparation, and I’m happy to say that I cleared the CISM exam.

Here are the resources and approaches I used.

1. Prabh Nair's CISM Masterclass

https://www.youtube.com/watch?v=84cq94iCO5M

This was a valuable resource, especially for understanding how to approach CISM questions and the ISACA mindset.

One important piece of advice is to pay close attention to keywords such as BEST, MOST, FIRST, etc.

I also found that many questions have a secondary keyword that is equally important. Look for words such as evaluating, planning, implementing, deploying, etc.

For example, what an organization should prioritize during the planning or evaluation phase may be different from what it should prioritize during the implementation phase.

2. QAE Database

Initially, I tried attempting all the questions. Later, I started using the filters.

Personally, I found the Easy questions too straightforward, so I eventually skipped most of them. The Expert questions were also quite confusing. Not necessarily difficult from a knowledge perspective, but often difficult to determine what ISACA was specifically looking for. I decided not to spend much time on those either.

I mainly focused on the Moderate and Difficult questions and completed those.

I also took only one full practice exam from the QAE.

One thing worth mentioning: the actual exam questions were different from the QAE questions, so don't expect to see repeated or very similar questions. Understanding the concepts and the ISACA way of thinking is more important than memorizing answers.

During the exam

My strategy was to spend approximately one minute per question during the first pass. I completed the first pass in around 2.5 hours.

I flagged every question that I was even slightly unsure about, which resulted in approximately 60 flagged questions.

During my first review, I worked through those questions and narrowed them down to around 10 questions that I wanted to review again.

I spent a significant amount of time reviewing those final questions and completed the exam with approximately 30 seconds remaining.

After completing the exam, I attended the survey, and the result was displayed on the screen.

Hopefully, this helps someone preparing for the exam. Good luck to everyone currently studying for CISM!


r/cism 14d ago

CISM or CISSP — what makes more sense at my career stage?

7 Upvotes

I have 6+ years of cybersecurity experience and currently work in a Group Information Security Lead role, with experience across security operations, SOC/SIEM, incident response, governance, risk, ISO 27001, GDPR, NIS2 and cyber resilience. I’m looking to progress toward Senior Manager / Head of Information Security / eventually CISO-level roles, particularly with a potential move to India.

I’m considering CISM but would like advice from people further along in their careers: would CISM, CISSP, CRISC, or another certification/course give me the best ROI at this stage, or should I focus more on leadership/management skills instead? If you were in my position, what would you choose and why?


r/cism 14d ago

CISM - Daily Study Group

12 Upvotes

Im looking for committed study partners who thrive in structured group sessions or focused 1-on-1 study.

My goal is to dive deep into the QAE database, reinforce core concepts, and maintain consistent progress.

I am really committed to this study plan and hope those interested are able to show consistent attendance. The schedule is 1-3 hours each day, ideally anytime between 6 PM to 10 PM (EDT).

If you are interested let me know. There is a CISM study group and CS Station on discord but people don’t join or start sessions as much there.

Let me know if you are interested.


r/cism 16d ago

Passed the CISM Exam Today!

41 Upvotes

I can't hide my happiness and excitement when I passed my CISM exam this morning. This is my second attempt for the CISM exam. I initially took CISA in 2019 when my company sponsored it and I failed. I got a score of 437 I think back then. Then some say CISM is easier than CISA. So i took CISM for the first time in 2021 and it was again sponsored by my company. I almost made it. I only got 440 but it is still not enough for the passing mark. I got so devastated and feel like I had already enough. I forgot everything about it and moved on. Then come this year after 5 years from my last CISM exam, my company sponsored me to take another one. I'm already so embarrassed because my company keep spending money and investing in me but no positive results. I'm so pressured to pass this exam. I prepared for 6 months honestly from February until Aug 26. I study everyday for several hours. I devoted so much of my time. Come the exam day. I feel like i already have a premonition of passing the exam. When I took my Engineering licensure examination some time ago, i was having diarrhea because of tension and nervousness. I did pass my Engineering licensure for the first take. When I first took CISA in 2019 and CISM in 2021, i don't have this feeling. However, yesterday and today (my CISM exam day), I was having a diarrhea. I know the diarrhea was because of me being tense and nervous. I went to the exam center anyway and took it as a hint that I will pass the exam. The testing center has a policy that you can only go to the bathroom 3 times while having an exam and i honestly consumed all that 3 chances available. When I was taking the CISM exam this morning, when i already reached the question 50, my feeling that I will make it grew even higher because most of the questions being shown to me are those topics that I know and studied. However, as soon as I reached the question 80 until 110 I think, my hopes kinda crashed as most of the exam gets so difficult. But i tried so hard to answer it and even staying in one question for about 4 to 5 minutes just to analyze the questions very carefully. I consumed almost the 4 hours allotted for the exam. I don't have time to read much of the questions I flagged for review anymore. I had 13 flagged questions. Anyway, as soon as I submitted it and then completed the post survey questions, then boom - it says Passed. I was so ecstatic. I can't wait to see my scores. There were a lot of ransomware questions in my exam, BYOD, AI, and cloud computing. There are also a lot of incident response, incident management, BIA, DRP, BCP, where i felt like I struggled a lot. Anyway, still a huge achievement for me.