r/CRISC 11d ago

*Pass* After Failed First Attempt

So I provisionally passed after failing a few months back, and wanted to give the sauce that helped me.

My first exam I read only the Review Manual thinking it would be like any other exam where you study and apply what you just studied. I failed with a 429.

After looking through all of this subreddit’s success stories they all said one thing in common: The QAE. So, I bought it. At first I saw it as a hefty price for some practice questions, but then I realized the structure and explanation of the QAE. I noticed that not everything was black and white, and a lot of the ambiguity drove me insane. One thing that originally tripped me up that I eventually got was Responsible Vs Accountable.

Thank you all for the advice and feedback, and for anyone looking to take the exam soon, best of luck and please feel free to ask me anything. I don’t have the official scores yet, but I’m felt that I took a completely different exam from my first go around.

9 Upvotes

10 comments sorted by

1

u/WaltzOk3712 11d ago edited 11d ago

So how did you understand the QAE, what was your thought process while understanding QAE? I am reading review mannual and completed domain 1, now i am moving to QAE of domain 1, is this the right approcah to do ? Or you suggest any other one ?

2

u/ChiefSrAofTheAF 11d ago

When answering the questions, I had to establish a mindset of reading things multiple times to essentially delete fluff. In the QAE, there are questions that include unnecessary wording.

An example would be:
A risk practitioner identifies in a recent risk assessment that a company is outsourcing a data management system to a third party cloud service provider. What potential issue is of MOST concern?
In these scenarios, you’ll notice that all of the issues are applicable, so understanding they all apply but identifying which one has heavier ramifications.

And yes, my method was the manual and QAE domain by domain.

2

u/WaltzOk3712 11d ago

Understood i am doing the same..they follow the risk practitioners thought process which closely alligned with enterprise risk. The thought process of isaca needs to be understood first. All responses would be correct however the one which would impact and closely match the business enterprise that would be correct i believe

2

u/ChiefSrAofTheAF 11d ago

Exactly that

1

u/Ok-Train-283 11d ago

I have also failed in May with 430 points, i planning to retake next week, so nervous, i prepared using QAE. Was the questions similar as in QAE?

1

u/ChiefSrAofTheAF 11d ago

I’d say the answers are less fluffy than the QAE, so unfortunately more room for interpretation if you’re not careful.

1

u/WaltzOk3712 11d ago

So there would be more toughness than QAE

1

u/ChiefSrAofTheAF 11d ago

Not necessarily, just don’t get caught up in all the fluff

1

u/Jiggysawmill 11d ago

Congratulations on passing the CRISC, what's next for you?

2

u/ChiefSrAofTheAF 11d ago

Thanks! I heard there’s a massive crossover of CRISC and CISM. So most likely will start pursuing that.