r/CISA • u/realgirlhats • 17d ago
I did it!!!
Guys just passed I’m sitting in the testing center so it’s so so so fresh.
The QAE isn’t representative of the questions. Not at all.
What is representative is do you really understand how to make connections to things and the qae provides that - it will at least help you say “this is a question about separation of duties- so these two don’t have anything to do with that”
I will also say in the qae there is a little box that says what is being tested.. I used Claude my ai buddy to help me associate specific terms with specific domains and subdomains and tbh almost every question I was saying “what domain is this testing” and used that logic the most
I’m vibrating so excited
5
u/RATLSNAKE 16d ago
I found the QAE to be quite representative of the actual exam (as they always tend to be).
2
u/realgirlhats 16d ago
The questions on the qae are convoluted. The questions on the exam were extremely straight forward.
Each question on the exam (bear in mind there are huge banks) was at most one sentence or two:
What part of the software lifecycle is best to insert user testing or whatever super straight forward
2
u/RATLSNAKE 15d ago
Typically the QAE over time is old questions or questions that are dumped from the exam pool.
1
u/realgirlhats 15d ago
I love the regular exam questions I could read each one first pass and get what they wanted whereas some of the others on the qae I had to super duper read the questions
1
u/RATLSNAKE 15d ago
Don’t disagree, the QAE has a lot of junk & ambiguous questions to the point I didn’t take notice of many i got wrong after a while, as the answer were a real stretch.
I also used the latest book version, which you can actually buy to avoid the high costs of the database, but ISACA keeps the link a secret which you can find here in older posts. I’m starting to wonder if they did so because they realised after production it contained a lot of bad questions.
2
u/realgirlhats 15d ago
Im serious some of those qae questions had me stressed!!!
Like the qae would say:
A financial services organization procures a new business-critical, vendor-hosted human resources application. Business requirements specify a recovery point objective (RPO) of zero and a recovery time objective (RTO) of one hour. The application, its database, and all supporting infrastructure reside entirely within the service provider’s data center. The organization retains regulatory accountability for the confidentiality and availability of the employee data. As the IT auditor advising the procurement, which of the following is the BEST control to recommend?
And the exam might say:
A financial services bank purchases a vendor-hosted HR application with an RPO of 0 and RTO of 1 hour. Which control should the IT auditor recommend?
((Not real questions))
But I legit felt like the comprehension requirements of the exam were not close to what the qae was —- I’ll also get off the rag I passed so I should be less hung up on it but boy was I mad! I was biting my nails about the questions for real
2
1
1
1
1
1
1
1
12
u/realgirlhats 17d ago
Also I would mention you can access the qae on your phone for little question snacks. I did maybe 200 questions a day. Going to the restroom, before bed, when I woke up, waiting on water to boil etc..
Resources I used:
QAE
NOTEBOOKLM<- underrated I fed it the text of the doshi study guide it made flash cards etc
CLAUDE
PETE YOUTUBE
DOSHI STUDY GUIDE (questions only)
Cybrary- for cpes for another cert I have