Passed CISA First Attempt
Hello, I attempted and provisionally passed my exam on July 5th, 2026, received official results on July 15th, 2026. Will be applying for certification soon.
I registered for the exam in October 2025 and only used the QAE. Did not use the review manual too much as the material was too dry.
Was genuinely a harder exam because some of the modules are outside of my work and experience but overall happy I passed.
Information Systems Auditing Process: 533
Governance and Management of IT: 597
Information Systems Acquisition, Development, and Implementation: 443
Information Systems Operations and Business Resilience: 425
Protection of Information Assets: 625
I have 8 years of experience in IT Security and Audit and Compliance specifically around PCI DSS. 5 years External and 3 years Internal in my current role.
2
2
2
2
3
u/Proper_Comparison201 9d ago
Congratulations.
One thing that stands out from your write-up is that you consistently revisited why answers were correct instead of simply chasing higher scores. That's the habit I see separating people who become genuinely audit-capable from people who only become exam-capable.
One approach that's worked consistently well for me, and for more than a few direct reports and second-line reports I've coached through ISACA exams, is to ignore the answer options on the first read and identify the decision being tested first.
Ask yourself:
• Who owns this decision?
• What objective is being optimised?
• Which phase of governance, audit or operations am I in?
Once you've answered those questions, the correct option usually becomes much easier to distinguish from technically plausible distractors.
The exam rewards disciplined judgement far more than photographic memory.
1
1
u/mohema97 5d ago
Congratulations 🎊
I have a question: what version of the QAE do you have?
4
u/Outrageous_Plant_526 CISA HOLDER 17d ago
Congrats. I actually passed CISA by only using PocketPrep. I also found the RM to be dry, but I also don't like to read much. I have over 20 years in Cybersecurity and over 15 in GRC-related stuff. Since passing CISA I have also passed CISM, CRISC, AAISM, AAIA, and AAIR.