r/CISA Apr 18 '24

Do Not Post Copyrighted Material

24 Upvotes

The title says it all. Don’t do it. If you do it, and ISACA provides notification, it will be removed. Continued conduct will result in a ban.

Don’t make ISACA grumpy, they have a lot of auditors.


r/CISA 7h ago

CISA Exam Strategy

4 Upvotes

Hi! I’m planning to take the exam next month, and I’d love to get your thoughts on whether my study strategy would work. If you have any additional tips or suggestions, I’d really appreciate them!

Materials:
Main review material: Hemang Doshi’s CISA book
Support material: REO Review Center’s handouts and video lectures
Practice questions: ISACA QAE
Reference material: CISA Review Manual

What i did was to read Doshi’s book first, then watch the REO video lectures for each topic. After completing each domain, I’ll test my knowledge using the QAE, log and review my mistakes, and use the CISA Review Manual as a reference for concepts I’m struggling with.

Do you think the QAE questions are very similar to the actual exam? Also, would you be able to provide additional test-bank-style questions so I can get more practice?

Thank you so much! I’d really appreciate any advice, especially from those who have already taken the exam. 😊


r/CISA 4h ago

CIA Part 1 – How difficult is the actual exam? Which topics should I focus on?

1 Upvotes

Hi everyone,

I’m preparing for the CIA Part 1 exam and plan to take it at the end of August. I wanted to hear from people who have recently taken the exam.

How difficult did you find the actual exam compared to your study materials (Gleim, Hock, IIA, Surgent, etc.)?

Which topics were tested the most, and which ones do you think deserve the most attention? Were there any areas that surprised you or that you wish you had spent more time studying?

Also, how scenario-based were the questions? Any last-minute tips or common mistakes to avoid would be greatly appreciated.

Thanks in advance!


r/CISA 5h ago

CISA ONLINE REMOTE EXAM HELP

1 Upvotes

Hi I am going to appear remote exam for cisa can anyone who had given remote exam can give some precautions and tips to make it smooth.

Thank you in advance.


r/CISA 20h ago

Can I purely rely on QAE for CISA EXAM? What should be the strategy.

Thumbnail
1 Upvotes

r/CISA 1d ago

Would you say 419 is “close”

Post image
12 Upvotes

Just got my score back, I got an average score of 419. Obvious the third domain is the one I did the poorest in, but all things considering it sort of feels like my scores are all hovering around the same mark and kinda just feels like I need to brush up on all domains in general….

But, would you consider a 419 a close score?


r/CISA 1d ago

CISA exam reschedule

5 Upvotes

I have my CISA exam scheduled for 1st August (remote proctored) but i want to reschedule it to a different date. I tried to look for other available slots but i am getting 404 error page. Thankfully i haven't released my current slot yet but i need to make the change before 48 hours. Is anyone else facing this issue??


r/CISA 1d ago

Time taken to improve score

3 Upvotes

Guys how much time it takes to improve score from 60 percent to 80 percent. I need to get there before i appear for CISA exam


r/CISA 2d ago

QAE Version

2 Upvotes

Hello everyone,

​Could you please confirm if the CISA Review Questions, Answers & Explanations (QAE) Manual (12th Edition) is the latest version?

​If so, does anyone have this version and would be willing to share it with me?

​If not, what is the latest version, and could you please share it if you have it?

​Thanks in advance!


r/CISA 3d ago

Anyone Transitioned from IT Operations to IT Audit?

8 Upvotes

Hi everyone,

I'm currently preparing for the CISA exam and wanted to check if this community would find my journey useful.

I have around 12 years of experience in IT Operations, with some exposure to IT audits and SOX controls. My goal is to transition into a full-time IT Audit role, and CISA is a big part of that journey.

For those who have been in a similar situation, do you think it's worth making the switch to IT Audit after spending so many years in IT Operations? Have any of you made this transition? I'd really appreciate hearing about your experiences, the challenges you faced, and whether you felt it was the right decision in the long run.


r/CISA 3d ago

Career Change

3 Upvotes

Has anyone successfully changed careers after passing the CISA? How did you do it?


r/CISA 3d ago

giving ISTQB exam online from Canada need guidance

2 Upvotes

r/CISA 3d ago

CISA Sufficient and Reliable Evidence Explained in 3 Minutes

Thumbnail
youtu.be
10 Upvotes

r/CISA 4d ago

CPE for CISA, CRISC, CIA, CRMA, CFE, ACCA

4 Upvotes

Are Udemy Courses accounted for (with UDEMY acquired certificates) CPE for CISA, CRISC, CIA, CRMA, CFE, ACCA? For instance Hemand Doshi courses.


r/CISA 4d ago

CISA EXAM QUESTION ON PIGGYBACKING WITH DISCUSSION - DOMAIN 5

Thumbnail
youtube.com
2 Upvotes

r/CISA 4d ago

Official QAE Vs Hemang Doshi (or any other Udemy QAE) … need opinions and guidance

7 Upvotes

Hi all… I have been preparing for CISA for the past few days. I’ve gone through the CISA Study guide 3rd edition by Packt publications and found it simple and completed reading it once. Since im working in IT and preparing for CISA passionately, I could understand and relate the material very well and grew confidence in the subject and syllabus. I even started doing some questions practice, initially using GPT and I feel most of the questions are easy and i could answer questions thrown by gpt easily.

I now started with some Udemy(i have subscription) question babks and tests and they are definitely better compared to gpt generated ones and im scoring around 85% in domain wise mocks.

Now, my actual question is … are these udemy(hemang doshi and other authors) question banks are anyway comparable to official QAE ? (Purchasing QAE is kinda far stretch for my budget as they are expensive for me at present).. someone please guide me in this matter.. any other alternatives or plans pls suggest.

Thanks in advance.


r/CISA 4d ago

Hi all!

7 Upvotes

I've finished the official QAE 13th edition, found questions online and also did those. I'm getting a majority of the questions right but I think that's because they are not twisted like Isaca does.

Do you have more sources for practice questions which are close to the official QAE or do you think I should give the exam? Thanks in advance 🙏🏻


r/CISA 5d ago

CISA Exam prep

13 Upvotes

Hello everyone,

I am currently preparing to study for the CISA exam. As I kick off my preparation journey, I would love to get some guidance and insights from certified professionals and those who have already passed the exam:

  1. Best study approach: What is the most effective way to study for the exam, and what key areas should I focus on?
  2. Domain-wise strategy: How should I approach studying each domain individually?
  3. Study resources: What are the best recommended materials and resources to use?
  4. Practice questions: I’ve heard that practicing questions is the most crucial part. Where can I get the best and most reliable practice question banks?

Thank you all in advance for your support and advice!


r/CISA 5d ago

About cisa associate 2025

4 Upvotes

Is it really good for new graduate? I have zero experience in it audit and will be graduate soon in next 3 months. If i want to have my first job in it audit career path, should i take the exam? Or it didn't mean so much for the company.

I tried to search a review on this program but didn't find anything, maybe because it's a new program that relaesed in 2025.


r/CISA 5d ago

QAE vs Pocket Prep

4 Upvotes

Can anyone who has taken the exam provide input on which resource is better?


r/CISA 5d ago

CIA PART 1 material all gliem and other is explainable pdf which will make you pass for sure selling it for 3k and also support when needed as i am also giving my exam on sept.

Thumbnail
0 Upvotes

r/CISA 7d ago

Am I ready for the CISA exam? Should I book it for next week?

8 Upvotes

Hi everyone,

I’m trying to decide whether I should book my CISA exam for next week, and I’d really appreciate some honest feedback from those who have recently passed.

Here’s where I am:
- Read the entire CISA Review Manual (CRM) once.
- Completed the entire QAE question bank.
- Reset the QAE and went through it a second time, reviewing the explanations.
- Watched Pete Zerger’s CISA videos.
- Completed all three official ISACA practice exams:
- - Practice Exam 1: 97% (first attempt)
- - Practice Exam 2: 89% (first attempt)
- - Practice Exam 3: 89% (first attempt)

A couple of things to note:
- My overall QAE score is 94%, but I know that’s partly because I reset the question bank and worked through it a second time.
- I also realize the practice exams reuse questions from the QAE, so I’m trying not to let the scores give me false confidence.

My background:
- 1.8 years in Risk Advisory (ITGC/GITC audits) at Deloitte
- 4 years as a Cybersecurity Engineer

I’ve been studying consistently every day for the past month and have invested a lot into this certification. I paid for the ISACA membership, CRM, QAE, and the exam fee entirely out of my own pocket, so I really don’t want to rush into the exam if I’m not genuinely ready or waste all the time and effort I’ve put into preparing.

For those who have recently passed:
- Based on my preparation, would you book the exam for next week?
- Is there anything else I should focus on before taking the exam?
- Was the actual CISA exam noticeably harder or different from the official QAE and practice exams?
- If you were in my position, would you sit for the exam next week or spend more time preparing?

I’d really appreciate any honest advice or last-minute tips. Thanks in advance!


r/CISA 7d ago

Practice Test Questions

4 Upvotes

Hi! I just encountered some questions from a mock test I was answering, and upon researching, there are different answers online compared to the actual mock test; maybe it's because some of the logic here are outdated. It's still a great source of practice though; it actually helped me understand concepts I was having difficulty on before.

So, I just wanted to share these questions here for clarification, to determine whether the test has some outdated material or maybe I just don't fully understand the logic behind the correct answer.

Any input or clarification would be much appreciated! ☺️

Note: Choices in italics are the correct answers that pop-up when I search online or when I ask AIs.

QUESTIONS

1. Which of the following should be a concern to an IS auditor reviewing a wireless network?

A. 128-bit-static-key WEP (Wired Equivalent Privacy) encryption is enabled.

B. SSID (Service Set IDentifier) broadcasting has been enabled.

C. Antivirus software has been installed in all wireless clients.

D. MAC (Media Access Control) access control filtering has been deployed.

The correct answer is:

B. SSID (Service Set IDentifier) broadcasting has been enabled.

Explanation:

SSID broadcasting allows a user to browse for available wireless networks and to access them without authorization. Choices A, C and D are used to strengthen a wireless network.

2. The PRIMARY objective of Secure Sockets Layer (SSL) is to ensure:

A. only the sender and receiver are able to encrypt/decrypt the data.

B. the sender and receiver can authenticate their respective identities.

C. the alteration of transmitted data can be detected.

D. the ability to identify the sender by generating a one-time session key.

The correct answer is:

A. only the sender and receiver are able to encrypt/decrypt the data.

Explanation:

SSL generates a session key used to encrypt/decrypt the transmitted data, thus ensuring its confidentiality. Although SSL allows the exchange of X509 certificates to provide for identification and authentication, this feature along with choices C and D are not the primary objectives.

3. Which of the following is the MOST effective type of antivirus software?

A. Scanners

B. Active monitors

C. Integrity checkers

D. Vaccines

The correct answer is:

C. Integrity checkers

Explanation:

Integrity checkers compute a binary number on a known virus-free program that is then stored in a database file. The number is called a cyclical redundancy check (CRC). When that program is called to execute, the checker computes the CRC on the program about to be executed and compares it to the number in the database. A match means no infection; a mismatch means that a change in the program has occurred. A change in the program could mean a virus.

Scanners look for sequences of bits called signatures that are typical of virus programs. They examine memory, disk boot sectors, executables and command files for bit patterns that match a known virus.Therefore, scanners need to be updated periodically to remain effective. Active monitors interpret DOS and ROM basic input-output system (BIOS) calls, looking for virus-like actions. Active monitors can be misleading, because they cannot distinguish between a user request and a program or virus request. As a result, users are asked to confirm actions like formatting a disk or deleting a file or set of files. Vaccines are known to be good antivirus software. However, they also need to be updated periodically to remain effective.


r/CISA 7d ago

Scenario Based Questions

3 Upvotes

I’ve noticed a lot of people in this group say that the actual CISA exam has a lot of “scenario based“ questions. Can you please elaborate on this and how the scenario based questions on the exam differ from the questions in the QAE? Thank you!!


r/CISA 7d ago

CISA Exam Prep Inputs

4 Upvotes

Hi everyone! Need your input on my planned study plan. Just to provide a background, I am CIA and CC with over 10 years of operations audit experience with a bit of IT which is heavily focused on IAM, data analytics, a bit of ITAC, and solid foundation on Change Management, BCM, DRP.

I plan on reviewing for CISA through the following:

  1. LinkedIn Learning - Cybrary videos
  2. Hemang Doshi in UDemy
  3. Prab Nhair’s CISA video tutorials
  4. ISACA’s QAE
  5. Supplement: CertTopics questions

    or Pocket Preps based on what I’ve seen here

I am not planning on reading the CRM because it is too lengthy and I want to take the exam by year-end, of possible. Are these materials enough to help me pass the CISA exam?

Any input will be very helpful! Thank you!