u/GuiltyNobody6173

▲ 3 r/cism

Next cert after CISM? What builds off of this?

Is there another certification that can build off of CISM? Not so sure I want to tackle the CISSP yet, but I thought I would ask other professionals for advice. My previous employers have verified my experience so I should be receiving official notice of certification next week.

reddit.com
u/GuiltyNobody6173 — 12 days ago
▲ 8 r/cism

I passed today

I received some key help on certain topics that I really struggled with, and I am extremely grateful for the assistance. I don't know my scores yet. I may have missed that information on the screen because I was laser focused on the word Passed.

My study materials were very much what others have suggested with the most weight given to the QAE testing online.

Pete Zerger

Hermang Doshing material

Prabh Nair - didn't really like his material. Hard to understand at times, and the explanations left me still questioning the reasoning for the answer selection.

Sprinkling of Thor Petersen

QAE online testing

Official Study guide

I read the study guide, but it is so high level that I never thought it really did much to teach me anything. I couldn't go back to reference material for clarity. Whenever I did that, it left thinking what a waste of my time.

Perplexity AI was probably the biggest help. It's a necessary skill to be able to prompt your questions so the responses are relevant. It was most helpful because there were topics in IR and DR for example that just didn't make sense for the longest time....rto, rpo, etc, and I could ask my questions a gazillion different ways and there was no frustration. I would copy and paste the questions and answers and spend quite a bit of time coming at the concepts from different perspectives to understand the reasons why and why not. A lot of the answers you have to just accept as you're learning material to pass the exam, and then the real world will be a lot different.

I come from the typical operations/technical background of sysadmin so it was a huge lift and shift of my thinking. Glad I did it, but it was hard.

I would study for 2 hrs every day before work, 20-30 questions per session, and then go at the incorrect answers.

I went through qae 21/2 times. I think half of my struggle was learning how to read and understand the questions. If any of us were asked the questions in a clear manner, I'll bet most could give the correct response.

reddit.com
u/GuiltyNobody6173 — 1 month ago
▲ 5 r/cism

Please explain exposure to me in a way that makes sense

This is an explanation from qae. I can't get my head around it. AI makes it worse. what is being explained in this statement?

Sorry i didn't get this posted. Your explanations make sense in plain english. Then I read A, and it all falls apart.

>When considering the extent of protection requirements, which of the following choices would be the MOST important consideration affecting all the others?

  1. A.Exposure
  2. B.Threat
  3. C.Vulnerability
  4. D.Magnitude

A is the correct answer.

Justification

  1. Exposure is the quantified potential for loss that may occur due to an adverse event, calculated as the product of probability and magnitude (impact). Because probability is itself a function of threat and vulnerability, exposure takes into account all three of the other factors and, if known, is the most important consideration.
  2. A threat is anything (e.g., object, substance, human) that is capable of acting against an asset in a manner that can result in harm. Threats may cause harm only if they correspond to vulnerability, so the probability of an event can be calculated only when both are known.
  3. Vulnerability is a weakness in the design, implementation, operation or internal control that could expose the system to adverse threats from threat events. Vulnerability may lead to harm only when acted on by a corresponding threat, so the probability of an event can be calculated if both are known.
  4. Magnitude (or impact) measures the potential severity of loss from a realized event/scenario. Whether such an event will be realized depends on its probability (likelihood), which requires assessment of both threat and vulnerability.
reddit.com
u/GuiltyNobody6173 — 2 months ago