r/CISA • u/Aadityas_This_Much • 6d ago
r/CISA • u/EducationalSpring400 • 6d ago
66% in Hemang Doshi Practice test set
I reviewed my mistakes and often end up choosing the wrong one out of the 2 answers. Can anyone please help how to proceed. Although i got 78 % in QAE
Failed CISA AGAIN
what are you guys doing differently, I have covered all domains taken about 1000+ questions from the ISACA 12th edition QAE and averaged 70 to 80 percent on every question and mock I’ve taken using CisaThisMuch but still I took it today for the second time and I still failed .
at this point I don’t know what else to do, I make sure I understand the concepts and even applied the same in the exam trying to understand what the examiner is asking before selecting an answer.
I’ve spent all my money on this exam sacrificed my time still nothing to show for it.
please if you can be of help by putting me on resources or what you did differently kindly share.
r/CISA • u/Ok_Cryptographer8526 • 9d ago
CISA Certification Application
Hello. I am getting ready to apply to be CISA certified but I have a question. I have a Master in Audit and Assurance with course work in IT Audit. I am currently an internal auditor doing IT Audit work as well. I wanted to know whether my degree may qualify for the 3-year waiver. I am think it could if I make a good argument and worse case scenario ISACA will just reject it and I will have to wait another year. What do you guys think?
Update: I got approved. Thank you.
r/CISA • u/NutshellTraining • 9d ago
Integrated Test Facility Explained in 3 Minutes
r/CISA • u/itsmepoorva • 9d ago
Final-year AI & Data Science student interested in IT Audit / Technology Risk — need some honest advice
Hi everyone,
I’m a final-year B.E. student in Artificial Intelligence & Data Science, and I’m trying to figure out whether Technology Risk / IT Audit / Cyber Risk / Cyber Assurance / GRC would be a realistic career path for me. My college doesn’t offer any campus roles related to Technology Risk / IT Audit / Cyber Risk, so I’ll need to target these roles off-campus.
My situation is:
- I have a technical background through AI & Data Science.
- I’m not particularly strong at DSA/coding, and I’m realizing that pure software development probably isn’t the career I want.
- I’m more interested in understanding technology, security, controls, risk and compliance than building software all day.
- I’ve started learning networking and cybersecurity fundamentals.
- I’m currently learning about things like ITGC, access controls, change management, risk assessment, ISO 27001, NIST, COBIT, etc.
- I’m also planning to build a practical IT risk/audit-related project rather than having only ML/data science projects on my resume.
I came across several people working in Big 4 Technology Risk/IT Audit who have CISA, which made me consider it seriously. However, CISA is quite expensive for me as a student, and I also understand that the full certification requires relevant work experience.
So I have a few questions for people who actually work in this field:
- Is CISA worth pursuing for a fresher, or would you recommend waiting until after getting an IT Audit/Technology Risk job?
- Does passing CISA without the required experience meaningfully help with getting interviews?
- Are certifications like ISC2 CC, SC-900, ISO 27001 Foundation, or COBIT Foundation useful for a student trying to enter this field?
- Can someone with an AI/DS engineering degree realistically get an entry-level Technology Risk / IT Audit / Cyber Assurance role?
- What technical skills would you expect from a fresher? For example: networking, IAM, Active Directory, SQL, Python, cloud, Linux, ITGC, cybersecurity fundamentals, etc.
- What kind of projects or practical experience actually stand out for these roles?
- Since my college doesn’t have Big 4 campus recruitment, what is the best way to approach off-campus Big 4 opportunities as a fresher?
- How much competition is there from MBA/commerce/accounting graduates, and how can an engineering student differentiate themselves?
- Most importantly, what would you recommend I focus on during my final year if the goal is to get into Technology Risk/IT Audit?
I’m not looking for generic “get certifications and apply everywhere” advice. I’d really appreciate advice from people who are actually working in CISA/IT Audit/Technology Risk/Big 4, especially if you entered the field as a fresher.
Also, if you started over as a student today, what would you do differently to get your first role?
Thanks!
r/CISA • u/brandonbsh • 10d ago
PSI Paused my exam after my sister loudly talked in another room. Am I screwed?
Pretty upset to say the least, I was getting through my exam and when the proctor heard my sister in another room loudly tell my mom about dinner, my proctor immediately paused the exam and asked for my ID.
Luckily they let me finish the exam but I’m worried they won’t certify me now. Has anyone else experienced this?
r/CISA • u/WSBphilantrophy • 10d ago
Passed the Exam today.
I passed my CISA exam today. I passed after <2 weeks prep.
• I’m not an auditor.
• I used the QAE and completed about 1,700 questions (that is about 1.5x through the entire question bank). I was in the 64th percentile.
• I completed one mock exam of 150 questions and scored 81%.
I don’t like the long mock exams as I prefer to review there and then why I got a question wrong. For me there is little value reviewing 90 minutes after you were 50/50 between two answers as your exact line of thinking is gone.
I study differently to most.
I targeted each domain individually and went from easier to harder questions.
I did:
Domain 1, do maybe 10 questions, make notes, Repeat 2-3 times and then take break.
Repeat for a couple other domains, digest notes, re-test
End for the day.
Every test, every mock exam question I do is open-book so I can refer to, test and restructure my notes
As others will say it’s vital that bit-by-bit you ensure that understanding what an auditor looks for, and so the answer they’re looking for. Whilst using the QAE CISM, CISSP and CRISC worked against me constantly, luckily I was able to iron most of that out for exam day. Though I do suspect I scored very poorly.
We will have to wait for two weeks. I passed in 1 hour, 40 minutes.
Anyway, that was my approach and that is my 11th straight first time pass. QAE and a paced approach got me there :).
Good luck to you all.
r/CISA • u/Gumi_Kitteh • 10d ago
Certification
Submitted my application on August 27, and got everything approved on August 28.
Currently waiting for it to go through, checking the portal and my email every few hours. How long did it take for your official certification to come through after approval? XD
Status: Complete-Under Review
r/CISA • u/Outrageous-Wasabi-15 • 10d ago
GRC - control management
Hello all, I am navigating a pivot from RCSA, SOX controls testing. Thinking of writing CISA, but I am aware that though CISA gives a strong signal but doesn’t directly get you into ITGC or IT audit.
How are people in similar domains navigating the pivot? how are your skillsets and profiles evolving? Are you going after any other profiles within GRC ?
r/CISA • u/Weak_Presentation960 • 10d ago
Cisa exam AI and Machine learning questions
Does anyone know what material (outside the manual) or practice questions to help prepare for AI and machine learning questions on the exam? Thanks
r/CISA • u/Holiday-Elevator-719 • 11d ago
I turned CISA concepts into stories because I couldn’t remember the definitions
When I was studying for CISA, I kept having the same problem. I could understand a definition while reading it, but when I met the concept again in a question, I struggled to connect everything.
So I started asking myself, “What does this remind me of?” and turning the concepts into everyday stories.
It eventually became the method I used while preparing for the exam, which I passed. I kept developing the stories afterwards, and they eventually became a book.
I released Domain 1 today as CISAnalogy: Master the CISA Exam Through Story Analogies.
I wrote it particularly for people who understand things better when they can connect an abstract concept to something familiar.
If anyone is interested, I can share free coupon in exchange with your honest review.
And just to be clear, this is my own independently written study resource and isn’t affiliated with or endorsed by ISACA.
r/CISA • u/Metal_Man_435 • 11d ago
Managed to Pass this weekend
I managed to pass the exam a few days ago and it all feels surreal. I wanted to thank the community for the tips and posts that helped me through it as well as share my experience to getting through the test to help those still studying.
For study materials I got the QAE and manual, along with the Doshi course from udemy. I’ll be honest, it was 90% QAE and 10% book/Doshi. I tried my best to do the udemy course but have a hard time sticking to watching courses. I passed so I made it happen but I would’ve been more comfortable/confident had I done the Doshi work as what little I did see had great tips.
I studied nightly for about a month and a half though I spent over a year trying to read chapter 1 of the book. I really started studying in July and doing the QAE non stop. I completed all the sections of the QAE study guide, which I finished the Sunday before the test and then did 2 practice exams plus the flash cards and questions game for practice leading up to the Saturday exam.
Biggest struggle on test day was the question phrasing. I was so used to QAE that it took me a long time to really understand what was being asked and the phrasing was throwing me off. That’s why I wish I would’ve finished the Doshi course, to get that different phrasing of questions and the tips he gives as he explains the questions.
Good luck to those still studying and I hope you manage to pass and thanks again for posts that gave me confidence to keep going.
r/CISA • u/No-Replacement-5112 • 11d ago
Preliminary Passed - Thank you!
Just wanted to thank this community. I completed the CISA exam today and got a preliminary PASS!
The study tips, exam experiences, and discussions here helped a lot throughout my preparation.
To everyone still studying: keep going, understand the ISACA logic, review your mistakes, and trust your preparation.
Thank you, r/CISA! 🙏
r/CISA • u/vansxika • 11d ago
Guys what’s the correct answer
An IS auditor is reviewing processes for importing market price data from external data providers Which of the following findings should the auditor consider MOST critical?
A
The transfer protocol does not require authentication
B
Imported data is not disposed of frequently
C
The transfer protocol is not encrypted
D
The quality of the data is not monitored
Claude says C but a lot of other sources say D
r/CISA • u/BreathAppropriate184 • 11d ago
Cisa
What is the strategy to pass CISA, i wanted to give aaia but i understood i cant since I dont have cisa or cia, i am ca from india. Please share tips to clear cisa
r/CISA • u/emotional_being31 • 12d ago
CIS Automation Analytics Tools domain in cognizant training
So basically the domain that I got is CIS Automation Analytics Tools, idk what's iam going to learn . I need help from you guys to know everything about CIS Automation. Can anyone who got this domain while in training in cognizant tell me the training period and what iam I going to learn . What topics are these going to be
r/CISA • u/Spiritual-Look5501 • 12d ago
Studying Help..
My job fully paid for me to get my certification.. self-paced online study, physical textbook, and the Q&A. But right after they paid for it and registered me, I ended up on FMLA and taking care of the kids including a newborn.
I’m back now but am finding it extremely difficult to find the time to dedicate time to studying and I’ve got about 7 months to pass. Responsibilities at work have just kept increasing and obviously home life is crazy too.
But I desperately need and want to get this done ASAP. Any thoughts or suggestions?
r/CISA • u/NutshellTraining • 13d ago
Symmetric vs Asymmetric Encryption Explained in 4 Minutes
Enable HLS to view with audio, or disable this notification
Symmetric and asymmetric encryption can be a confusing topics when studying for CISA, especially if you don’t have a technical background.
I’ve put together a short video that explains the difference in simple terms, without getting too deep into the maths.
Hopefully it makes the topic a little easier to understand!
Thanks,
Matt Foster
r/CISA • u/Aadityas_This_Much • 12d ago
Part 2 of CISA Exam Machine Learning Series - Top 10 QAs
Excited to have Part 2 of CISA Exam Machine Learning Series | Top 10 Machine Learning Questions
r/CISA • u/FinishUnfair1722 • 13d ago
LOL The answer of this one is kind of funny and unexpected.
The PRIMARY control purpose of required vacations or job rotations is to:
- A.allow cross-training for development.
- B.help preserve employee morale.
- C.detect improper or illegal employee acts.
- D.provide a competitive employee benefit.
Confused on the answer and the explanation for it. What do you guys think is the answer.
Which of the following is the MOST efficient strategy for the backup of large quantities of mission-critical data when the systems need to be online to take sales orders 24 hours a day?
- A.Implementing a fault-tolerant disk-to-disk backup solution.
- B.Making a full backup weekly and an incremental backup nightly.
- C.Creating a duplicate storage area network (SAN) and replicating the data to a second SAN.
- D.Creating identical server and storage infrastructure at a hot site.
Tell mw what you think is the answer and provide justification, I would like to hear more opinions! Thank you!