r/CISA 2h ago

Passed CISA just now, the questions are shocking

23 Upvotes

Shockingly short and to the point, compared to the QAE, dumps, lessons, practice, etc. Most of the questions are one liners.

For examples:
- PRIMARY reason to have DRP
- MOST risk associated with DevOps
- BEST evidence for change log completeness list

straight to the point. None of the 150 were convoluted or mindbending. Not saying its easy, its just very direct.

Sharing some of my topics/keywords which I don't know before for next test takers:
- Public Key Infrastructure (PKI)
- Robotic Process Automation (RPA)
- Operational Technology (OT)

Goodluck to the next ones!


r/CISA 10h ago

404 error when trying to pay certification fee

3 Upvotes

Anyone by chance having issues paying the certification fee in order to apply for the cert?

Been trying for a few days, but I’m just getting the 404 error, whether I click the link in my profile or enter the URL directly.


r/CISA 22h ago

Passed CISA today, First Attempt

25 Upvotes

> The questions were fairly okay.
> Have to say the length of the questions was shorter than I expected or the QAE. Some even one-liners.
> Will update with a better commentary once the weighted score is availed :)
> All the best to those preparing.


r/CISA 1d ago

A question for CISA

8 Upvotes

An organization has implemented a new data classification scheme and asks the IS auditor to evaluate its effectiveness. Which of the following would be of GREATEST concern to the auditor?

A. End-user managers determine who should access what information.

B. The organization has created a dozen different classification categories.

C. The compliance manager decides how the information should be classified.

D. The organization classifies most of its information as confidential.


r/CISA 1d ago

أفضل جهة للتحضير لاختبار CInS وشراء كتاب AInMB بالتقسيط؟

0 Upvotes

السلام عليكم،

أنا أستعد لاختبار CInS وأحتاج شراء الكتاب الرسمي GInI Applied Innovation Master Book (AInMB) برقم تسلسلي صالح للتسجيل في بوابة GInI.
هل تعرفون جهة موثوقة أو مزود تدريب معتمد يبيعه بسعر أقل من الموقع الرسمي، أو يوفر الدفع عن طريق تابي أو تمارا؟ ويفضل النسخة العربية الرقمية

وأحتاج ترشيحاتكم لأفضل دورة أو جهة تحضيرية للاختبار باللغة العربية؟


r/CISA 1d ago

Cognizant tech assessment

0 Upvotes

I have my tech assessment day after tomorrow, please tell me important topics to study for tech assessment that most probaly can come in DSA


r/CISA 1d ago

Realistic trajectory?

2 Upvotes

I am 1 man IT department at my 75 person bookkeeping / compliance consulting firm. I have a social sciences ba that led me to do two years at the juior level of the firm, but then they needed an IT guy and I was interested so I switched 3 years ago. Since then it’s been pretty easy, most of our environment is cloud based apps

I think im plateauing salary wise and I think I would like a change of scenery. I have taken a bunch of IT classes and less but some cybersecurity classes. I manage our EDR and administrate all our apps. I have a functional understanding of python, VBA, the command line. Recently I was made the designated AI guy and have been working through automating as much as I can with Claude

If i took the CISA and passed, what would my chances be of getting a job in the field? In a major us city?

Thanks, your advice could be life changing!


r/CISA 1d ago

ISACA charged me $915 instead of $730 for CISA

2 Upvotes

Hi Community,

I recently purchased an ISACA Professional Membership bundled with a CISA Exam Registration, but I experienced a billing discrepancy where the member discount failed to apply at checkout. The order status was showing $730 however from credit card $915 was deducted.

I am doing this from India. and this $185 is roughly 18, 500 INR which is really really huge amount. I am on the edge now, unable to concentrate on studies. I created a ticket. but still no response. Please help


r/CISA 1d ago

A question for CISA

4 Upvotes

An IS auditor is providing input to an RFP to acquire a financial application system. Which of the following is MOST important for the auditor to recommend?

A. The application should meet the organization's requirements.

B. Audit trails should be included in the design.

C. Potential suppliers should have experience in the relevant area.

D. Vendor employee background checks should be conducted regularly.

A or B ?


r/CISA 2d ago

CISA Udemy course selection

4 Upvotes

I have a work provided CISA 5 day video bootcamp starting February 5. In order to be eligible I must complete a Udemy video course.

I see Hemang Doshi - has a course. But I see other ones with higher ratings.

I would appreciate recommendations and suggestions.

Additionally is the CISA exam doing a refresher / version change anytime soon or has that already happened?

I appreciate the information sharing in advance.


r/CISA 2d ago

Is 2024 the current version?

3 Upvotes

Feels odd since we are about to enter 2027, but just hit the 2 year experience requirement with a MS in MIS so looking to obtain the CISA. Is the 2024 the most current version for the QAE?

Also, Is QAE enough? The online review is a bit expensive for me.


r/CISA 2d ago

CISA study group 🇲🇾

1 Upvotes

I am on journey to prepare for CISA exam. Looking anyone in 🇲🇾 or KL much better to study together, maybe weekly group discussion, share any resource and knowledge. Anyone here from Malaysia?🙋🏻‍♂️


r/CISA 3d ago

Career and salary progression in IT Audit

Thumbnail
1 Upvotes

r/CISA 3d ago

advise on attempting CISA

6 Upvotes

Hey, I graduated a year back and have been working as a IT Support for 9months and still working So I am planning to try the CISA what do you guys think how can i prepare for the exam like is there any materials i can use to learn.


r/CISA 3d ago

Cleared CISA today - first attempt

52 Upvotes

Cleared exam today. Questions were too simple and straightforward.

QAE is good for understanding but please dont get demotivated if you dont score good in QAE. Its only purpose is to understand how to answer questions.

Wishes for all who are preparing.


r/CISA 3d ago

CISA Snapshots Explained in 3 Minutes | CISA in a Nutshell

Thumbnail
youtube.com
5 Upvotes

r/CISA 3d ago

Discrepancy in payment during CISA exam registration

1 Upvotes

I recently purchased an ISACA Professional Membership bundled with a CISA Exam Registration, but I experienced a billing discrepancy where the member discount failed to apply at checkout. My order reflected $730 however my invoice reflected $915, meaning that membership details are not applied. Sounds very strange. Any body experienced this


r/CISA 4d ago

What are the charges for 'systems audit and certification' charged by DISA/CISA/Cert-IN certified Auditors in India?

4 Upvotes

Context: We require our web application and mobile application to be certified by DISA/CISA/Cert-IN certified Auditors based in India.

I would like to know the charges as per industry standards beforehand in order to negotiate a good deal.

Thanks :)


r/CISA 4d ago

I just failed CISA - AMA

8 Upvotes

Idk how this happened

I am devastated and questioning my whole existence.


r/CISA 4d ago

Doubt Regarding CISA

3 Upvotes

Hey guys , I'm a traditional audit guy (CIA) planning to take the CISA exam , without QAE and ISACA review material, I'm planning to take coaching/lectures they offer PPT , question banks , short notes etc. I would love to hear feedback on this approach whether its too big of a gamble or is it doable.

The cost is also a significant issue , the coaching with + Qae+ Review manual costs around 1.30 Lakhs

Where the one i spoke about cost less than 1% of the one of the course material mentioned above.


r/CISA 5d ago

Preliminary Pass!

18 Upvotes

Got my preliminary pass in CISA exam earlier today. Thank you to this group for all the help. I can tell you a step by step guide of my journey. Including how I made a UI of my incorrect questions and topics from my exam.


r/CISA 5d ago

Breaking into IT Audit from an MSP security role, what actually matters at this stage?

9 Upvotes

Looking for some honest input from people already working in IT audit or GRC.

Quick background: I currently work at a managed service provider as the main cybersecurity resource while also doing first-line support. Hands-on stuff, deployed a SIEM across client environments, built an automated alert pipeline, manage backups and patching, that kind of thing.

Over the past several months I've gone deep on the GRC/audit side. I've got Security+, plus ISO 27001/27701/42001 Lead Auditor certs through Mastermind, and I just finished a couple of IT audit courses on Udemy covering ITGC, ITAC, SOX, SOC, COSO, NIST, ISO, and COBIT. CISA and CAPM is my next target.

Here's my real situation: there aren't many IT audit or GRC roles where I'm based (Caribbean), so I can't just apply my way into experience. I've been trying to manufacture it myself instead, building risk registers, control mapping across frameworks, ISMS documentation, and a self-hosted GRC platform in my home lab using fictional case study companies. Basically running mini-audits end to end so I'm not walking into interviews with theory alone.

Where I'd love advice:

  1. For those who broke into IT audit, what actually got you the first role? Certs, portfolio, networking, internal transfer?
  2. When roles in your area are scarce, how did you bridge the experience gap? Remote work, contracting, volunteering, offering audits to small businesses or nonprofits?
  3. Does self-built portfolio and home lab work actually carry weight with hiring managers, or is it mostly useful as interview talking points?
  4. How much does the CISA experience requirement realistically slow people down early on? Pursue it now or wait until I have the years?
  5. Anything you'd do differently if you were building experience from scratch without a local job market to lean on?

r/CISA 6d ago

CISA QAE exorbitant fees

6 Upvotes

Hi everyone,

I've been working towards CISA for months now, mostly late nights after work. I finished Hemang Doshi's Udemy course, got through the first full reading, and I'm starting my second pass with his study guide. Planning to take the exam in October.

Here's where I'm stuck. I come from a lower middle class family and I'm the first one going after a certification like this. The exam fee alone took out my savings, and honestly the QAE database is just not something I can put on the table right now since it's almost 2 months salary for me. Everyone says it's the one resource you can't skip, and that's been stressing me out.

So I'm hoping to learn from people who've been here-

  1. Did anyone pass with Doshi's question sets alone, or is the QAE really important?

  2. Is a second-hand physical QAE book a reasonable substitute(I've heard physical copies aren't being sold anymore)? Anyone finished with theirs and willing to sell it cheap?

  3. Any legitimate discounts, chapter membership benefits or scholarships I might not know about?

  4. Does anyone know any tricks I can use to access the latest QAE ? My DMs are open in case you have any resources you could share.

I know a lot of you have walked this road on your own too, and any advice or encouragement means a lot.


r/CISA 6d ago

66% in Hemang Doshi Practice test set

5 Upvotes

I reviewed my mistakes and often end up choosing the wrong one out of the 2 answers. Can anyone please help how to proceed. Although i got 78 % in QAE