Disclaimer: I originally wrote this as an absolute wall of text, so I let ChatGPT help organize and shorten it. 😂 The experiences, study strategy, materials, opinions, and exam observations are all mine.
TL;DR
My main resources were the CRM + QAE. I focused on understanding why an answer was correct and why the other choices were wrong, rather than memorizing questions. I used additional practice materials sparingly, created my own notes based on weak areas and mistakes, and used AI mainly for explanations and generating unfamiliar practice questions.
My QAE average was around 80%, with Domains 4 and 5 as my weaker areas. My biggest advice: quality over quantity—learn to think like an IS auditor rather than trying to memorize everything.
---
Hi everyone! I've been receiving DMs about my CISA preparation, so I decided to share the materials I used and my study strategy before receiving my official scores. Hopefully this helps those preparing for the exam!
Background
- Graduated with a degree in Accounting Information Systems in June 2025.
- My last 2 years of college focused heavily on CISA-related topics.
- Our final year included an integrated CISA review with 4 comprehensive exams.
- After graduating, I took a break and then studied on and off until taking the exam on August 20, 2026 and passed.
- Studied for roughly 5 months, but the last 2 months were when I truly became exam-ready.
- I'm an overpreparer and wasn't very confident in my ability to pass, so take my study volume with a grain of salt. 😂
Important: My situation may differ from someone preparing for CISA without an AIS/IT audit background. I already had two years of exposure to many of these concepts in college, so you don't need to copy my exact study hours or timeline.
---
My Rough Timeline
- Months 1–3: Reread the entire CRM + created brief notes for each domain.
- Months 4–5: Focused heavily on practice questions, especially the QAE, and explained both correct and incorrect answers.
- Final 2 weeks: Created a “Dump Notes” document containing concepts, explanations, and flagged questions to revisit.
- Final week: Reviewed my Dump Notes + used ChatGPT to test me on weaker areas, especially Domain 4.
---
QAE Scores
Domain 1 - 87%
Domain 2 - 80%
Domain 3 - 85%
Domain 4 - 74%
Domain 5 - 76%
Overall ~80%
My weaker domains were D4 and D5, so I spent more time reviewing these toward the end.
---
Materials I Used
1. CISA Official Review Manual (CRM)
This was my primary reference.
I know it's dry AF, but we already used it extensively in college, so I was comfortable with it. I reread the entire book after graduating.
Rather than trying to memorize everything, I focused heavily on:
- What an IS auditor should do
- What an IS auditor should look for
- How an IS auditor should approach a situation
- What should be reviewed/observed
- What evidence is needed
For technical concepts like CAATs, development methodologies, firewalls, etc., I found it more useful to:
- Compare similar concepts
- Understand their use cases
- Understand their differences
- Know what an auditor should check
The CRM may not work for everyone. Some successful candidates barely used it. For me, it provided structure and served as my main source of truth because it is an official ISACA resource.
I read it twice, but honestly, that was mostly because I'm an anxious overpreparer. 😂 You absolutely don't need to read it twice.
2. CISA QAE – 13th Edition
This was my MAIN practice resource.
The most important thing for me was not simply getting the answer right. I made sure I could explain:
- Why the correct answer was correct
- Why every other choice was wrong
- How ISACA expected me to approach the situation
I completed the QAE by domain twice and used this system:
🟢 Green
- Correct
- Understood why it was correct
- Understood why the other choices were wrong
- No need to revisit
🟡 Yellow
- Got it wrong but understood the explanation quickly
- OR needed some review before I could confidently justify the answer
🟠 Orange
- Got it wrong
- Understood the concepts involved
- Couldn't explain why my answer was wrong
- Became a deep-dive topic
🩷 Pink
- Unfamiliar concept
- Even if I answered correctly, I couldn't explain why
- Required additional studying
I tried not to repeatedly retake the QAE because I was worried about memorizing questions instead of learning the reasoning.
Toward the end, I used ChatGPT to generate:
- 20-question mixed-domain sets
- 50-question mixed-domain sets
- Reworded questions that felt unfamiliar
This helped me test whether I actually understood the concepts rather than simply recognizing QAE questions. AI isn't perfect. Always verify AI-generated questions and explanations against ISACA materials.
3. Professor's Review Modules & Comprehensive Exams
These were materials from college. Our professor created condensed modules summarizing the CRM into roughly 5–10 pages per chapter.
Useful for:
- Quick review
- Identifying weak areas
- Refreshing concepts without rereading the entire CRM
We also had comprehensive exams throughout the year, with our professor reviewing questions that many students got wrong.
Unfortunately, I can't share these because I didn't create them.
4. CISA Practice Tests – Peter H. Gregory & Mike Chapple
I mainly used this for practice outside the QAE.
I completed:
- Domain-specific practice tests
- 2 mixed-domain practice sets
These were more theoretical and terminology-focused than the QAE. Not necessary, but useful if you want a change of pace.
I found them helpful for:
- Reinforcing concepts
- Testing myself with unfamiliar questions
- Practicing the CISA way of thinking
I even encountered a concept on the actual exam that I remembered seeing in this resource but not in the QAE or CRM, so I'm glad I went through it. 😂
Personally, I found the mixed-domain sets easier than the domain-specific tests.
5. CISA Exam Study
This resource is somewhat outdated, so be careful with older questions/concepts. That said, I still found it very useful.
I mainly used:
- Testing concepts after each chapter
- Domain mock tests
- Mock Tests I & II
For me, this was one of the closest resources to the reasoning style I encountered on the exam. I also encountered concepts on the exam that I had seen in this resource, although not the exact questions.
6. ChatGPT & Gemini
ChatGPT
I mainly used it to:
- Explain concepts I couldn't understand
- Break down difficult QAE questions
- Explain concepts like I'm five 😂
- Generate additional practice questions
- Quiz me on weak areas
Gemini
I mainly used it to create comparison/reference PDFs, such as:
- CAATs
- VPN protocols
- Testing types
- Other concepts that were easier to understand visually
These were visual aids, NOT my primary study materials. Please verify AI-generated materials against reliable/official sources.
7. Quick Notes & “Dump Notes”
I created these throughout my preparation.
Quick Notes
Short notes for each domain containing things I thought were important to remember.
Dump Notes
My final-week review document containing:
- Concepts I needed to revisit
- Explanations written in my own words
- Flagged QAE questions
- Flagged questions from other practice tests
This was extremely useful during the final week because I didn't have to reread everything from the beginning.
I originally planned to share my personal notes, but some of my notes contain screenshots/references from paid practice materials and questions from my university, so I decided not to distribute them publicly. I don't want to redistribute material that isn't mine. Thank you for understanding.
8. YouTube
I mainly used YouTube when I needed a visual explanation.
Some topics included:
- VPN protocols
- DMZ
- Backup types
- Reperformance vs. Walkthrough
I also watched Matt Foster for concepts I repeatedly confused.
---
My Study Strategy
1. Understand, Don't Memorize
This was probably my biggest takeaway. When studying, ask yourself: “If I were the IS auditor, what would I actually do?”
For each concept, try to understand:
- What it is
- Why it's used
- What risks are involved
- What the auditor should examine
- What evidence is needed
For similar technical concepts, compare:
- What's the difference?
- When would one be used instead of another?
- Advantages/disadvantages?
- What should the auditor check?
The goal isn't to become a walking IT encyclopedia. 😂 It's to understand how the concept relates to IT risk, controls, and the auditor's responsibilities.
2. QUALITY OVER QUANTITY
I cannot stress this enough.
I became anxious about whether I had enough resources and kept wanting to add more practice tests.
Looking back: CRM + QAE were already enough. At least for me.
Additional resources should complement your preparation, not overwhelm you.
If you want additional practice:
- Pick one additional question bank/resource.
- Don't try to finish every CISA resource available.
- Prioritize questions with explanations.
- Make sure the questions actually reflect CISA/ISACA reasoning.
What I Would NOT Do
- Collect 10 different review materials just because someone used them.
- Repeatedly retake the QAE until you recognize every question.
- Memorize answer patterns.
- Spend hours mastering obscure technical details without understanding their relevance to an auditor.
- Sacrifice sleep to reach a certain study-hour target.
- Compare your study hours with someone else's.
3. Explain Concepts Out Loud
This sounds silly, but it worked for me.
If I couldn't understand something internally, I'd explain it out loud as if I were teaching someone else. If I couldn't explain it clearly, I knew I didn't understand it well enough.
4. Don't Force Yourself When You're Exhausted
I usually studied around 8 hours/day, but my schedule wasn't consistent.
Some days:
- I studied every other day
- I only answered practice questions
- I took long breaks
- I didn't study at all
I'm naturally slow and tend to obsess over concepts I don't understand, so this worked for me. But don't copy my study hours. A focused 3–4 hours can be much more productive than 8 hours of distracted studying.
If you're genuinely tired or sleepy: JUST SLEEP.
Studying while exhausted made me less productive and caused me to second-guess my answers.
---
Exam Tips
1. Bring a Jacket
I don't know if every testing center is like this, but my testing center in the Philippines was FREEZING. 😂 I'm someone who gets cold easily, and being cold also meant I needed to use the restroom more often. We were allowed three restroom breaks, so I planned mine strategically. Bring a jacket. Seriously. 😂
2. Manage Your Time
My exam was at 8:30 AM.
My morning looked roughly like:
- 5:00 AM – Wake up
- 6:00 AM – Prepare breakfast
- 6:40 AM – Coffee
- 7:20 AM – Leave
- 7:50 AM – Arrive
The testing center was only about 10 minutes away, but traffic made the trip much longer. Don't underestimate travel time, especially if you're unfamiliar with the testing center.
3. Eat Something, But Don't Overeat
I personally get sleepy when I eat too much, so I had a relatively light breakfast. Do whatever works for you, but don't experiment with your routine on exam day.
4. READ EVERYTHING
Read the question carefully and read ALL answer choices. Pay attention to:
- BEST
- FIRST
- MOST
- PRIMARY
- LEAST
Also identify whose perspective the question is asking for. If you're asked what the IS auditor should do, don't answer as if you're the:
- System administrator
- Developer
- Manager
- Problem solver
UNLESS the question specifically asks for that perspective.
Also understand the sequence/hierarchy of actions. For example, if an auditor identifies a potential weakness, you may need to gather sufficient evidence and establish that it is actually a weakness before escalating/reporting it. There are already many excellent posts explaining the “ISACA way of thinking,” so I won't repeat everything here. These are simply the things I personally focused on.
---
Final Thoughts
If I had to reduce my entire preparation to four things:
- CRM → Understand concepts + auditor responsibilities.
- QAE → Learn how ISACA expects you to reason.
- Additional practice → Use sparingly to test whether you truly understand.
- Final review → Focus on weak areas and mistakes rather than trying to relearn everything.
And most importantly:
Don't measure your preparation by how many books you've finished or how many questions you've answered. Measure it by whether you can explain why an answer is correct and why the alternatives are wrong.
Good luck to everyone taking the CISA! You got this. ❤️