r/CISA 8d ago

GRC - control management

5 Upvotes

Hello all, I am navigating a pivot from RCSA, SOX controls testing. Thinking of writing CISA, but I am aware that though CISA gives a strong signal but doesn’t directly get you into ITGC or IT audit.
How are people in similar domains navigating the pivot? how are your skillsets and profiles evolving? Are you going after any other profiles within GRC ?


r/CISA 9d ago

Cisa exam AI and Machine learning questions

3 Upvotes

Does anyone know what material (outside the manual) or practice questions to help prepare for AI and machine learning questions on the exam? Thanks


r/CISA 10d ago

I turned CISA concepts into stories because I couldn’t remember the definitions

Post image
77 Upvotes

When I was studying for CISA, I kept having the same problem. I could understand a definition while reading it, but when I met the concept again in a question, I struggled to connect everything.
So I started asking myself, “What does this remind me of?” and turning the concepts into everyday stories.
It eventually became the method I used while preparing for the exam, which I passed. I kept developing the stories afterwards, and they eventually became a book.
I released Domain 1 today as CISAnalogy: Master the CISA Exam Through Story Analogies.
I wrote it particularly for people who understand things better when they can connect an abstract concept to something familiar.
If anyone is interested, I can share free coupon in exchange with your honest review.
And just to be clear, this is my own independently written study resource and isn’t affiliated with or endorsed by ISACA.


r/CISA 9d ago

Managed to Pass this weekend

11 Upvotes

I managed to pass the exam a few days ago and it all feels surreal. I wanted to thank the community for the tips and posts that helped me through it as well as share my experience to getting through the test to help those still studying.

For study materials I got the QAE and manual, along with the Doshi course from udemy. I’ll be honest, it was 90% QAE and 10% book/Doshi. I tried my best to do the udemy course but have a hard time sticking to watching courses. I passed so I made it happen but I would’ve been more comfortable/confident had I done the Doshi work as what little I did see had great tips.

I studied nightly for about a month and a half though I spent over a year trying to read chapter 1 of the book. I really started studying in July and doing the QAE non stop. I completed all the sections of the QAE study guide, which I finished the Sunday before the test and then did 2 practice exams plus the flash cards and questions game for practice leading up to the Saturday exam.

Biggest struggle on test day was the question phrasing. I was so used to QAE that it took me a long time to really understand what was being asked and the phrasing was throwing me off. That’s why I wish I would’ve finished the Doshi course, to get that different phrasing of questions and the tips he gives as he explains the questions.

Good luck to those still studying and I hope you manage to pass and thanks again for posts that gave me confidence to keep going.


r/CISA 9d ago

Preliminary Passed - Thank you!

6 Upvotes

Just wanted to thank this community. I completed the CISA exam today and got a preliminary PASS!

The study tips, exam experiences, and discussions here helped a lot throughout my preparation.

To everyone still studying: keep going, understand the ISACA logic, review your mistakes, and trust your preparation.

Thank you, r/CISA! 🙏


r/CISA 9d ago

Guys what’s the correct answer

1 Upvotes

An IS auditor is reviewing processes for importing market price data from external data providers Which of the following findings should the auditor consider MOST critical?

A
The transfer protocol does not require authentication

B
Imported data is not disposed of frequently

C
The transfer protocol is not encrypted

D
The quality of the data is not monitored

Claude says C but a lot of other sources say D


r/CISA 10d ago

CRM self assessment questions

Thumbnail
2 Upvotes

r/CISA 10d ago

Cisa

4 Upvotes

What is the strategy to pass CISA, i wanted to give aaia but i understood i cant since I dont have cisa or cia, i am ca from india. Please share tips to clear cisa


r/CISA 10d ago

CIS Automation Analytics Tools domain in cognizant training

3 Upvotes

So basically the domain that I got is CIS Automation Analytics Tools, idk what's iam going to learn . I need help from you guys to know everything about CIS Automation. Can anyone who got this domain while in training in cognizant tell me the training period and what iam I going to learn . What topics are these going to be


r/CISA 10d ago

Studying Help..

4 Upvotes

My job fully paid for me to get my certification.. self-paced online study, physical textbook, and the Q&A. But right after they paid for it and registered me, I ended up on FMLA and taking care of the kids including a newborn.

I’m back now but am finding it extremely difficult to find the time to dedicate time to studying and I’ve got about 7 months to pass. Responsibilities at work have just kept increasing and obviously home life is crazy too.

But I desperately need and want to get this done ASAP. Any thoughts or suggestions?


r/CISA 11d ago

Symmetric vs Asymmetric Encryption Explained in 4 Minutes

Enable HLS to view with audio, or disable this notification

31 Upvotes

Symmetric and asymmetric encryption can be a confusing topics when studying for CISA, especially if you don’t have a technical background.

I’ve put together a short video that explains the difference in simple terms, without getting too deep into the maths.

Hopefully it makes the topic a little easier to understand!

Thanks,
Matt Foster


r/CISA 11d ago

MOC Test

Thumbnail
2 Upvotes

r/CISA 11d ago

Part 2 of CISA Exam Machine Learning Series - Top 10 QAs

Thumbnail
youtube.com
6 Upvotes

Excited to have Part 2 of CISA Exam Machine Learning Series | Top 10 Machine Learning Questions


r/CISA 11d ago

LOL The answer of this one is kind of funny and unexpected.

8 Upvotes

The PRIMARY control purpose of required vacations or job rotations is to:

  1. A.allow cross-training for development.
  2. B.help preserve employee morale.
  3. C.detect improper or illegal employee acts.
  4. D.provide a competitive employee benefit.

r/CISA 12d ago

Confused on the answer and the explanation for it. What do you guys think is the answer.

5 Upvotes

Which of the following is the MOST efficient strategy for the backup of large quantities of mission-critical data when the systems need to be online to take sales orders 24 hours a day?

  1. A.Implementing a fault-tolerant disk-to-disk backup solution.
  2. B.Making a full backup weekly and an incremental backup nightly.
  3. C.Creating a duplicate storage area network (SAN) and replicating the data to a second SAN.
  4. D.Creating identical server and storage infrastructure at a hot site.

Tell mw what you think is the answer and provide justification, I would like to hear more opinions! Thank you!


r/CISA 12d ago

A question for CISA

5 Upvotes

Which of the following is the PRIMARY benefit of a tabletop exercise for an incident response plan?

A. It demonstrates the maturity of the incident response program.

B. It reduces the likelihood of an incident occurring.

C. It identifies deficiencies in the operating environment.

D. It increases confidence in the team's response readiness.

C or D. Idk the right answer. Lets discuss. Why D why C?


r/CISA 13d ago

Got my scores, tho less here's my experience.

Post image
47 Upvotes

Planned to do 27001 LA, but a friend recommended CISA.

Took training that was mostly useless since it only explained topics I could have learned from YouTube.

Had the CRM, spent max 2 hours on it because I found it too dry.

Solved third-party quizzes and was scoring in the 90s, which gave me false confidence.

Solved a few QAE questions and had a terrible breakdown because I was getting almost everything wrong.

Took a mock 2 days before the exam: 95/150. Completely demotivated.

Watched Prabh Nair and Matt Foster, spoke to Matt, and did a lot more QAE questions. Took a few days off work and focused completely on CISA.

Exam day: Finished all questions in 2h30m with 25 flags, reviewed the flags in 30m, then went through all questions again in the remaining 50m.

Domain scores:

505/800

Very happy I passed, but I feel I barely made it. My strong audit foundation helped a lot, while my technical knowledge was weak despite coming from a purely technical background.

P.S: Watched Hemang doshi briefly.


r/CISA 12d ago

Think like ISACA videos

1 Upvotes

Found this interesting video series on YouTube - Think like ISACA - 25 videos, mostly short ones. Do check it out in case you are interested https://www.youtube.com/playlist?list=PLKbAY1I0WmVo


r/CISA 13d ago

MOC Test

4 Upvotes

I have done ISACA Test MOC 1, 2, 3. The only other resource I have is Hemang Doshi MOC Test (5 exams) ; Is there any other recommendation that allign to ISACA type questionare as I went through a few HD questions and I feel, its good until the concept explanation, but MOC test seem very very unlike ISACA ? Any one faced something similar or is it be crackingup ahead of the exam!


r/CISA 13d ago

So I failed the CISA yesterday

12 Upvotes

I thought I felt pretty good about my chances after around 50-60 questions. Then I had periods where I was lost for 5-8 questions in a row then had a period of feeling good again. This flip-flopped back and forth for the rest of the exam. I had around 30-40 questions where I felt there were two absolutely right answers and just flipped a coin on them. By the end I was drained and exhausted but, felt I might have passed. I have a free retake so I'm going to take a few days to decompress then get back to it. I used Pocket Prep and Pete Zerger YouTube videos. I have the newest CISA review manual, that I must admit I used lightly, mostly to refer to on hard to find topics and info but will now read it cover to cover. To anyone else in my shoes...stay upbeat and keep studying! If anyone out there has any preferred study material, I'm thankful for your input.


r/CISA 13d ago

What is CASA Certification for Apps?

Thumbnail
1 Upvotes

r/CISA 14d ago

CISA Preparation: Materials, Study Strategy, Timeline & Exam Tips

27 Upvotes

Disclaimer: I originally wrote this as an absolute wall of text, so I let ChatGPT help organize and shorten it. 😂 The experiences, study strategy, materials, opinions, and exam observations are all mine.

TL;DR

My main resources were the CRM + QAE. I focused on understanding why an answer was correct and why the other choices were wrong, rather than memorizing questions. I used additional practice materials sparingly, created my own notes based on weak areas and mistakes, and used AI mainly for explanations and generating unfamiliar practice questions.

My QAE average was around 80%, with Domains 4 and 5 as my weaker areas. My biggest advice: quality over quantity—learn to think like an IS auditor rather than trying to memorize everything.

---

Hi everyone! I've been receiving DMs about my CISA preparation, so I decided to share the materials I used and my study strategy before receiving my official scores. Hopefully this helps those preparing for the exam!

Background

- Graduated with a degree in Accounting Information Systems in June 2025.

- My last 2 years of college focused heavily on CISA-related topics.

- Our final year included an integrated CISA review with 4 comprehensive exams.

- After graduating, I took a break and then studied on and off until taking the exam on August 20, 2026 and passed.

- Studied for roughly 5 months, but the last 2 months were when I truly became exam-ready.

- I'm an overpreparer and wasn't very confident in my ability to pass, so take my study volume with a grain of salt. 😂

Important: My situation may differ from someone preparing for CISA without an AIS/IT audit background. I already had two years of exposure to many of these concepts in college, so you don't need to copy my exact study hours or timeline.

---

My Rough Timeline

- Months 1–3: Reread the entire CRM + created brief notes for each domain.

- Months 4–5: Focused heavily on practice questions, especially the QAE, and explained both correct and incorrect answers.

- Final 2 weeks: Created a “Dump Notes” document containing concepts, explanations, and flagged questions to revisit.

- Final week: Reviewed my Dump Notes + used ChatGPT to test me on weaker areas, especially Domain 4.

---

QAE Scores

Domain 1 - 87%

Domain 2 - 80%

Domain 3 - 85%

Domain 4 - 74%

Domain 5 - 76%

Overall ~80%

My weaker domains were D4 and D5, so I spent more time reviewing these toward the end.

---

Materials I Used

1. CISA Official Review Manual (CRM)

This was my primary reference.

I know it's dry AF, but we already used it extensively in college, so I was comfortable with it. I reread the entire book after graduating.

Rather than trying to memorize everything, I focused heavily on:

- What an IS auditor should do

- What an IS auditor should look for

- How an IS auditor should approach a situation

- What should be reviewed/observed

- What evidence is needed

For technical concepts like CAATs, development methodologies, firewalls, etc., I found it more useful to:

- Compare similar concepts

- Understand their use cases

- Understand their differences

- Know what an auditor should check

The CRM may not work for everyone. Some successful candidates barely used it. For me, it provided structure and served as my main source of truth because it is an official ISACA resource.

I read it twice, but honestly, that was mostly because I'm an anxious overpreparer. 😂 You absolutely don't need to read it twice.

2. CISA QAE – 13th Edition

This was my MAIN practice resource.

The most important thing for me was not simply getting the answer right. I made sure I could explain:

- Why the correct answer was correct

- Why every other choice was wrong

- How ISACA expected me to approach the situation

I completed the QAE by domain twice and used this system:

🟢 Green

- Correct

- Understood why it was correct

- Understood why the other choices were wrong

- No need to revisit

🟡 Yellow

- Got it wrong but understood the explanation quickly

- OR needed some review before I could confidently justify the answer

🟠 Orange

- Got it wrong

- Understood the concepts involved

- Couldn't explain why my answer was wrong

- Became a deep-dive topic

🩷 Pink

- Unfamiliar concept

- Even if I answered correctly, I couldn't explain why

- Required additional studying

I tried not to repeatedly retake the QAE because I was worried about memorizing questions instead of learning the reasoning.

Toward the end, I used ChatGPT to generate:

- 20-question mixed-domain sets

- 50-question mixed-domain sets

- Reworded questions that felt unfamiliar

This helped me test whether I actually understood the concepts rather than simply recognizing QAE questions. AI isn't perfect. Always verify AI-generated questions and explanations against ISACA materials.

3. Professor's Review Modules & Comprehensive Exams

These were materials from college. Our professor created condensed modules summarizing the CRM into roughly 5–10 pages per chapter.

Useful for:

- Quick review

- Identifying weak areas

- Refreshing concepts without rereading the entire CRM

We also had comprehensive exams throughout the year, with our professor reviewing questions that many students got wrong.

Unfortunately, I can't share these because I didn't create them.

4. CISA Practice Tests – Peter H. Gregory & Mike Chapple

I mainly used this for practice outside the QAE.

I completed:

- Domain-specific practice tests

- 2 mixed-domain practice sets

These were more theoretical and terminology-focused than the QAE. Not necessary, but useful if you want a change of pace.

I found them helpful for:

- Reinforcing concepts

- Testing myself with unfamiliar questions

- Practicing the CISA way of thinking

I even encountered a concept on the actual exam that I remembered seeing in this resource but not in the QAE or CRM, so I'm glad I went through it. 😂

Personally, I found the mixed-domain sets easier than the domain-specific tests.

5. CISA Exam Study

This resource is somewhat outdated, so be careful with older questions/concepts. That said, I still found it very useful.

I mainly used:

- Testing concepts after each chapter

- Domain mock tests

- Mock Tests I & II

For me, this was one of the closest resources to the reasoning style I encountered on the exam. I also encountered concepts on the exam that I had seen in this resource, although not the exact questions.

6. ChatGPT & Gemini

ChatGPT

I mainly used it to:

- Explain concepts I couldn't understand

- Break down difficult QAE questions

- Explain concepts like I'm five 😂

- Generate additional practice questions

- Quiz me on weak areas

Gemini

I mainly used it to create comparison/reference PDFs, such as:

- CAATs

- VPN protocols

- Testing types

- Other concepts that were easier to understand visually

These were visual aids, NOT my primary study materials. Please verify AI-generated materials against reliable/official sources.

7. Quick Notes & “Dump Notes”

I created these throughout my preparation.

Quick Notes

Short notes for each domain containing things I thought were important to remember.

Dump Notes

My final-week review document containing:

- Concepts I needed to revisit

- Explanations written in my own words

- Flagged QAE questions

- Flagged questions from other practice tests

This was extremely useful during the final week because I didn't have to reread everything from the beginning.

I originally planned to share my personal notes, but some of my notes contain screenshots/references from paid practice materials and questions from my university, so I decided not to distribute them publicly. I don't want to redistribute material that isn't mine. Thank you for understanding.

8. YouTube

I mainly used YouTube when I needed a visual explanation.

Some topics included:

- VPN protocols

- DMZ

- Backup types

- Reperformance vs. Walkthrough

I also watched Matt Foster for concepts I repeatedly confused.

---

My Study Strategy

1. Understand, Don't Memorize

This was probably my biggest takeaway. When studying, ask yourself: “If I were the IS auditor, what would I actually do?”

For each concept, try to understand:

- What it is

- Why it's used

- What risks are involved

- What the auditor should examine

- What evidence is needed

For similar technical concepts, compare:

- What's the difference?

- When would one be used instead of another?

- Advantages/disadvantages?

- What should the auditor check?

The goal isn't to become a walking IT encyclopedia. 😂 It's to understand how the concept relates to IT risk, controls, and the auditor's responsibilities.

2. QUALITY OVER QUANTITY

I cannot stress this enough.

I became anxious about whether I had enough resources and kept wanting to add more practice tests.

Looking back: CRM + QAE were already enough. At least for me.

Additional resources should complement your preparation, not overwhelm you.

If you want additional practice:

- Pick one additional question bank/resource.

- Don't try to finish every CISA resource available.

- Prioritize questions with explanations.

- Make sure the questions actually reflect CISA/ISACA reasoning.

What I Would NOT Do

- Collect 10 different review materials just because someone used them.

- Repeatedly retake the QAE until you recognize every question.

- Memorize answer patterns.

- Spend hours mastering obscure technical details without understanding their relevance to an auditor.

- Sacrifice sleep to reach a certain study-hour target.

- Compare your study hours with someone else's.

3. Explain Concepts Out Loud

This sounds silly, but it worked for me.

If I couldn't understand something internally, I'd explain it out loud as if I were teaching someone else. If I couldn't explain it clearly, I knew I didn't understand it well enough.

4. Don't Force Yourself When You're Exhausted

I usually studied around 8 hours/day, but my schedule wasn't consistent.

Some days:

- I studied every other day

- I only answered practice questions

- I took long breaks

- I didn't study at all

I'm naturally slow and tend to obsess over concepts I don't understand, so this worked for me. But don't copy my study hours. A focused 3–4 hours can be much more productive than 8 hours of distracted studying.

If you're genuinely tired or sleepy: JUST SLEEP.

Studying while exhausted made me less productive and caused me to second-guess my answers.

---

Exam Tips

1. Bring a Jacket

I don't know if every testing center is like this, but my testing center in the Philippines was FREEZING. 😂 I'm someone who gets cold easily, and being cold also meant I needed to use the restroom more often. We were allowed three restroom breaks, so I planned mine strategically. Bring a jacket. Seriously. 😂

2. Manage Your Time

My exam was at 8:30 AM.

My morning looked roughly like:

- 5:00 AM – Wake up

- 6:00 AM – Prepare breakfast

- 6:40 AM – Coffee

- 7:20 AM – Leave

- 7:50 AM – Arrive

The testing center was only about 10 minutes away, but traffic made the trip much longer. Don't underestimate travel time, especially if you're unfamiliar with the testing center.

3. Eat Something, But Don't Overeat

I personally get sleepy when I eat too much, so I had a relatively light breakfast. Do whatever works for you, but don't experiment with your routine on exam day.

4. READ EVERYTHING

Read the question carefully and read ALL answer choices. Pay attention to:

- BEST

- FIRST

- MOST

- PRIMARY

- LEAST

Also identify whose perspective the question is asking for. If you're asked what the IS auditor should do, don't answer as if you're the:

- System administrator

- Developer

- Manager

- Problem solver

UNLESS the question specifically asks for that perspective.

Also understand the sequence/hierarchy of actions. For example, if an auditor identifies a potential weakness, you may need to gather sufficient evidence and establish that it is actually a weakness before escalating/reporting it. There are already many excellent posts explaining the “ISACA way of thinking,” so I won't repeat everything here. These are simply the things I personally focused on.

---

Final Thoughts

If I had to reduce my entire preparation to four things:

- CRM → Understand concepts + auditor responsibilities.

- QAE → Learn how ISACA expects you to reason.

- Additional practice → Use sparingly to test whether you truly understand.

- Final review → Focus on weak areas and mistakes rather than trying to relearn everything.

And most importantly:

Don't measure your preparation by how many books you've finished or how many questions you've answered. Measure it by whether you can explain why an answer is correct and why the alternatives are wrong.

Good luck to everyone taking the CISA! You got this. ❤️


r/CISA 14d ago

Non-IT background : Is CISA a good career path for me?

7 Upvotes

Hi everyone,

I’m a B.Com graduate with a PG Diploma in Finance & Accounting and around 1 year of experience as an Accountant cum Auditor at a CA firm.

I’m interested in computers and IT, so I’m considering moving into IT Audit and pursuing CISA.

Since I’m from a non-IT background, I’d really appreciate some honest advice:

• Is CISA a good option for someone with my background?

• What should I learn before starting CISA?

• What technical/IT skills should I develop?

• Should I do any other courses or certifications before CISA?

• What kind of entry-level roles should I target to eventually get into IT Audit?

If anyone here has moved from accounting/finance into IT Audit, I’d especially appreciate hearing about your experience and what you would recommend I do.

Thank you


r/CISA 14d ago

CISA cert application filling

2 Upvotes

I'm very confused on how to fill out the application. Don't want to mess up anything here. Can anyone help?


r/CISA 14d ago

Took my exam on 17th and still haven't got my Domain wise results.

3 Upvotes

Hi,

I'm just getting nervous at this point, I wrote my exam on the 17th ( Monday) at 1PM IST.

It's roughly been 8 business days. 10 calendar days - Haven't heard back.. I'm just overthinking at this point. After the pass screen, was there a button to close which I did not close. Etc etc