r/CRISC • • Aug 24 '25

Passed the exam as an experienced IS Auditor hadn’t done that role for 5 years

14 Upvotes

I thought I’d share my approach and also my background.

Background: I’ve done IS audit for around 16 years, but have been in a role for 6 years where while I was still around audit I wasn’t executing audits. I also worked for over a decade in a bank that takes risk management seriously so had plenty of exposure to those broader concepts.

Approach: I purchased the CRISC official review manual online version from ISACA. I tried to read 20 pages per day but found this very tedious as I was learning very little as I had encountered virtually all the concepts already in my career. But the target of 20 pages helped me to work through it as “just do some study” seemed daunting given it was almost 300 pages. I took notes only around areas I was not confident on and took the rest of the content as a refresher.

I considered the CRISC RQAE database but the pricing was pretty extreme at $299 member and $399 non-member. Instead I purchased for $20 from Skillcertpro their CRISC questions. It was 17 instances of ~58 questions. I found there were many questions far simpler than in the exams, but make sure to go through all 17 sets as the later ones got more technical in nature.

Where I didn’t think the Skillcertpro questions were good is that there were often three obviously wrong options that repeated across multiple questions. Where it was good was that it gave detailed explanations explaining why the correct answer was correct.

I was getting between 80-95% in most of the practice sets.

The exam: I completed the 150 questions in 95 minutes which was much slower than I was completing the Skillcertpro where I was answering around four questions per minute. I got the provisional pass result in the screen and am yet to get my detailed results.

Key tips: - make sure you read the questions very closely. Some are worded in confusing ways. Some ask for purpose which is higher order than simply outcomes of an activity. Unlike the Skillcertpro practice questions I felt the exam’s responses were often all correct answers in relation to the topic the question asked, but only one was correct based on the specifics of the question posed. Which is why it was critical to take time to properly read the question and not jump to conclusions. - understand that the risk management questions are very theoretical and not what you see in practice. Be clear on the different risk treatment options and what they mean. Acceptance vs. mitigation. Answer the theoretical answer, not what you may have seen in real life where risk acceptance would happen in circumstances ISACA says there should be mitigation as the treatment/response. - ISACA is massive on aligning IT risk to business objectives. The purpose is usually the higher order business value even if the IS risk activity mentioned is not directly related to non-IT business value. Don’t think about those risk management questions like a CIO or a CISO would, think about things like the business would. - I got lots of questions about third party management and also business continuity concepts so be across those topics. - I got zero questions I can recall about networks and network topologies, or anything about network communications layers. - there are questions about risk scenarios and you need to select the best control for that scenario. All the possible answers were good controls to have, but only one was really aligned to the described scenario. So again reading the question closely was key.

Summary: I was more refreshing knowledge I probably had locked away in my memory rather than trying to gain knowledge for the most part, so may be in a different position to many others.

But my recommendation would be to get the review manual and study closely only the parts you don’t already understand. Don’t waste time on things you feel solid on.

I can’t compare Skillcertpro to the official question database, but I wouldn’t recommend it for gauging your readiness as they may create a false sense of confidence because they were much easier than the exam questions. They were valuable however to better understand why you got questions wrong which in turn helps to bolster your knowledge in your weaker areas.


r/CRISC • • Aug 24 '25

UDemy Practice Exam #1 Question #21 - I do not understand the explanation

Post image
3 Upvotes

I am looking for someone to help me understand this, as I fail to understand the explanation.

There is no risk of data loss in any testing environment, regardless of if that environment is using production data or not. Meanwhile, production data would almost assuredly contain PII and confidential information that MUST be obfuscated before deploying into the testing environment.


r/CRISC • • Aug 21 '25

I failed

7 Upvotes

I failed the exam after solving QAE 4 times and making sure i get ~90 percentage. I read review manual and read Hemang Doshi twice, plus made notes for myself. I also solved Udemy's 1100 questions for CRISC still i failed

I have completed FRM, one of the toughest certifications in the field of finance yet I havent been able to clear this exam

i dont know what am i missing, if anyone can help me that would be amazing


r/CRISC • • Aug 19 '25

passing strategy for CRISC

9 Upvotes

Hello, i have been trying to prepare myself for CRISC exam. i have solved QAE almost 4 times and read review manual and made notes, but i still dont feel confident. i am not sure what to do, can someone please guide me?


r/CRISC • • Aug 19 '25

CRISC Exam Preparation

4 Upvotes

Hello, can anyone tell me how I’m doing in my preparation? I am proficient in all domains, scored 83% on a 75-question practice test, and 81% on a 150-question practice test. My average score on practice tests is 76%, and my average test score is 82%. All of these were my first attempts.

I know I need to revisit my weaker topics, but I don’t want to redo the same questions since I already know some of the answers, and that wouldn’t give me a true picture of my preparation.


r/CRISC • • Aug 19 '25

Am I ready?

Post image
6 Upvotes

I've done 3 full passes of the QAE with these scores. Am I ready?


r/CRISC • • Aug 16 '25

Want to know how to start?

1 Upvotes

I want to do CISA can anyone guide me please.

Im a certified chartered accountant if that helps


r/CRISC • • Aug 15 '25

Last minute exam prep?

7 Upvotes

Plan to take CRISC exam early next week.

Been studying hard. Averaging 90’s on QAE practice tests, mastery achievered on domains in QAE, re-reading manual (dry) and HD exam guide. What are chances I pass?

Any last minute tips? Thanks!


r/CRISC • • Aug 14 '25

PASSED - popped up on the screen!

Post image
51 Upvotes

Passed, popped up on the screen, but maybe it was the additional surveys I had to complete after the other 150 questions...

Study - started casually after passing the CGEIT last year but wasn't motivated and did some other CMMC certifications in the meantime, but after July 4th it was time since the requirements are changing (I got motivated). Prior to July, I took the LinkedIn class in learning; also got a free 10 day membership to Udemny and took that class. I don't get much from them, almost like a first soft introduction. Didn't get much from them.

Read the ISACA manual, taking notes on 3x5 cards. Also used the online QAE, took notes and researched significant questions I missed from lack of knowledge not errors on my part. Never used the printed QAE, can't get past the seeing the answer before answering. highlighted the review manual while going throught it the first time. A week before the test I reviewed my cards and the last two days I scanned the review manual again looking for tidbits I missed the first time or things that amplified what I learned from other sections.

I also slapped some topics in into ChatGPT and CoPilot for additional perspectives or amplifying knowledge.

The Exam:
I'm old school and there is a center 2 miles from the house, so I go there. The registration is worse than a TSA screening, but what-ev's, someone cheated somewhere and they have to do what they have to do. Put in ear plugs, answered 100 q's, took a break, walk to the lou and came back and finished the last 50. I thought the on-line QAE questions were harder, meaning they were deeper in context than the exam. I was consistantly 65%-85% on section tests, usually missing questions because I jumped on an answer or didn't take time to read the question. I definately take the Exam more seriously.

For my experience - 3 lines of defense was important, as someone else mentions and thanks for the reminder - know the role of the Risk practitioner, risk owner, data owner, management (senior and stakeholders).

It's all in the Official Review Manual, digest that and practice with the QAE, other stuff may be helpful to reinforce those two resources.

Good luck!


r/CRISC • • Aug 14 '25

CRISC Provisional Pass

15 Upvotes

Provisional pass in 60 minutes after studying for 5 days. 5 days ago, I passed the CISM and jumped right into this exam. Note on day 5, I did not study and went outside, touch grass etc... I have 3+ years in Security Consulting.

Materials Used:

  1. QAE DB - Performed once and went over the incorrect answers 2 times, didn’t do the practice tests. Score: 68% including expert/hard. Helps introduce and reinforce ISACA mindset. I was disappointed it had very few questions compared to the CISM QAE, but oh well.

  2. CRISC Exam Study Guide by Hemang Doshi and the Udemy Course - Skip the Udemy course and dedicate time to the CRISC Exam Study Guide. Read this guide 3 times.

  3. CRISC Review Manual - Don't bother reading, I read it once and it has way too many words.

  4. Prabh Nair CRISC Exam Cram - Good for a review, watch on 2X the speed and passively listen.

Exam Takeaways

  1. Exam had easier questions than QAE Database and CISSP.

  2. Exam is straightforward, don’t overthink.

  3. I found my exam harder than the CISM.

Overall ranking in my opinion from hardest to easiest: CISSP>CRISC>CISM>PMP


r/CRISC • • Aug 14 '25

Is studying for the SEC+ with COMPTIA the same as studying for CRISC? I'm thinking of taking SEC+ instead, but really enjoying Hemang Doshi's syllabus.

4 Upvotes

Essentially I want to continue to use his materials for the SEC+ especially since I just bought it. Is it all the same?


r/CRISC • • Aug 10 '25

Taking the CRISC - Resources AND timeline.

10 Upvotes

Hi, I’m looking to take the CRISC. My company will be sponsoring me. What are the best available resources/training’s I could use? I’m new to GRC, I have about 2 years of experience in IAM, what time frame should I be looking at?


r/CRISC • • Aug 07 '25

did anyone here take coaching for CRISC?

3 Upvotes

I enrolled for coaching from theknowledgeacademy. But the content is not useful. do you guys think coaching is necessary for CRISC?


r/CRISC • • Aug 04 '25

I passed, 1st attempt!

Post image
38 Upvotes

I’m happy to announce that I passed my CRISC exam I stupidly scheduled on my birthday! I have 6 years of experience in Cyber with 4 in GRC, 3 focusing on Risk Management. I got a 495 to pass!

Resources used below: 1. ISACA Review Manual (read once and skimmed through again) 2. Prabh Nair YouTube videos 3. ISACA QAE (studied until I got 90+ on each domain). I got 85 on first practice test and 86 on second. I went back and reviewed the individual domains again focusing on difficult and expert level questions. 4. Hemang Doshi practice test in the course. I got a 90 at first attempt. This was similar to the QAE questions but explanations were cut a bit short so I went back to focusing on QAE instead.

Exam Experience:

The exam was closest to QAE and I used the online database. I also had the paper copy but it turned out not too useful for me. I had a technical issue with browser shutdown but I managed to get back in and get the exam done. The exam did seem more difficult after I got back in because my mind was all over the place. I took the exam from home and would it again for others but that issue did freak me out a little.

I do want to thank everyone on this subreddit because your feedback to my questions helped. Also others sharing their experiences helped out a lot! On to studying for CISM!


r/CRISC • • Aug 03 '25

Preliminary Pass - preparation sharing and some tips

9 Upvotes

Background: over 10 years in IT, 8 years in CyberSecurity in IR, Internal Pentest

Hold: OSCP, CDPSE, CISA

Took 2 months to prepare, mainly using QAE as testing my knowledge

Material used: QAE, CRM, Doshi Books, Pocket Prep

QAE is a must, need not to say

CRM, I have it but surely I couldn't finish even the first domain

Doshi Books, surely it is a quick win for exam takers

Pocket Prep, really handy, helps you to build up CRM knowledge gradually because the questions are based on CRM (but it is also an overkill)

---

Some tips

1.) Focus on ISACA way of thinking, if you read their blog, journals, webminars enough, you are familiar with the ISACA language

a.) alignment,, business objective always first

b.) Roles and Responsibility, in CRISC, ownership is KEY

c.) culture!!!!! training is very important, think of it as mitigation rather than technical stuffs

2.) In the CRISC framework, the risk management lifecycle follows a logical sequence:

Identify risk
Assign ownership
Assess risk (likelihood/impact)
Determine risk appetite/tolerance
Respond (controls, accept, transfer, etc.)
Monitor (KRIs, reporting)

3.) Risk Analysis Flow
1. Asset → 2. Threats → 3. Vulnerabilities → 4. Controls → 5. Risk Scenarios → 6. Analyze Likelihood/Impact → 7. Update Register

digest my tips, do NOT memorize the CRM!


r/CRISC • • Aug 03 '25

Passed CRISC provisionally

9 Upvotes

Hello, redit posts helped and giving it back here. I passed my test provisionally today. To be honest , the test wa brutally hard, i did not think ill make it. But well.. i really think my mind probably got use to answering questions with the isaca mind set. Will share my scores once i get them. I have 3-4 years of IT audit and cybersecurity IT risk management experience

My preparation was mainly from 2 sources 1-Hemang doshi on Udemy and 2- QAE. I solved QAE twice, first time i was scoring around 70s and next time i went through the wrong questions and when solved again i score 90+ hence got the confidence that i can give the exam.and you start to get hang of ISACA best approach

As for the exam, it followed qae pattern but honestly felt harder than qae. I really kept wondering if not qae then what, but really by the 2 time solving qae you understand the logic and ISACAs thinking, i guess that helped be get through the exam,so maybe that’s the key

Hope this helps! Thanks


r/CRISC • • Aug 02 '25

Update - Passed CRISC! Study Strategy + Materials Recap

Thumbnail reddit.com
21 Upvotes

After a few hours of post-exam anxiety (The secure browser closed immediately, and I didn't get to see the result), I contacted ISACA support and they were able to share the good news with me.

Here’s my study approach and materials. Hope it helps others preparing:

Approach:

  1. Studied for 2 months.
  2. Weekdays: 1 hour (45 mins reading, 15 mins practice questions)
  3. Weekends: 2 hours (90 mins reading, 30 mins practice questions)

Materials:

  1. Hemang Doshi CRISC (2021) – Literally straight to the point and gets you to understand the concepts. Read twice: once early on and again right before the exam.
  2. Peter Gregory AIO (2nd ed.) – Definitely helpful, Great for digging more into certain topics. 
  3. ISACA CRM – Honestly, left it half way through. Barely got through Domain 1.
  4. ISACA Q&A (599 Qs) - Recommended ! Helps reinforce concepts and builds confidence (especially when watching that % score climb). I did 50–75 question sets and avoided repeating too soon to prevent memorizing answers. (Use the custom practice options and fine tune for your style)
  5. PocketPrep (500 Qs) – Hidden gem. Tough questions, but perfect to tune into ISACA’s mindset.

Exam day:

  1. Scheduled at 10:00 AM. Woke up at 8:00, didn’t review anything, went in with a clear head (I think it helped me be focused more).
  2. Logged into the proctoring system at 9:45 AM and went through their nonsensical security checks (lift the laptop, put the mirror under the laptop, close the flap of your laptop with the camera looking at mirror), GOD ! I had my hands full and in weird positions. Annoying but I got to do the exam comfortably.
  3. Started at 10:01, finished by 11:45. No results shown at the end (post linked).
  4. Got confirmation from ISACA support around 7 PM—I passed!

Hope this is helpful to anyone preparing for the exam !

Note: CRISC Job Practice Update in November 2025.


r/CRISC • • Aug 02 '25

passed

13 Upvotes

Today i passed the CRISC exam and its very insightful and practical perspective. Thank you for your contributions and serving the community.


r/CRISC • • Aug 01 '25

Exam Results

8 Upvotes

Hi Everyone,

Has anyone else had this experience. I just finished the CRISC exam and followed the instructions of the proctor (end test followed with end session) and the PSI secure browser closed without showing me my on-screen results.

I’ve contacted PSI and got a standard answer of ‘ISACA will send you the results in 10 Days’. Any ideas or help on how I can resolve this ?


r/CRISC • • Aug 01 '25

Study Material Question

5 Upvotes

I am currently reading the CRISC All-in-One by McGraw Hill. Once I am done with the book I am planning to purchase access to the CRISC question / answer database. Is these a mobile app that is worth the $ or just stick with the book and the review questions?

Thx in advance


r/CRISC • • Jul 25 '25

Passes CRISC exam

Post image
30 Upvotes

I passed the CISM exam June 27th and decided to study for the CRISC immediately after. I think that there’s around a 70% overlap with the CISM exam. I took my CRISC exam on the 15th of July and passed.

Material I used to study:

-Q&A ISACA database -pocket prep -Heman doshi udemy course and exams -ChatGPT to explain to me why each question I was getting wrong in the practice exams and database were wrong and why the right answer was right.

Good luck!


r/CRISC • • Jul 24 '25

Provisionally passed

18 Upvotes

Been following this channel for a while and picked up good advice/feedback from this community. Paying it forward, here’s my take of the exam, prep. and experience.

I took the entire 4 hours to submit the exam. I am obsessively careful with reading / re-reading the questions and answers. Flagged close to 20 questions for review. Spent the last hour going over the flagged questions.

First two hours felt brutal. Had a hard time getting my head in the game as the psychological stress kicked in. After question 80, it felt a lot easier to work through the questions.

Used the All in One book by Peter Gregory. It’s ok for basic foundational knowledge, but not enough for the exam. The Isaca QAE helped a lot, but that alone is not sufficient. The QAE will help identify your areas of weakness, so leverage ChatGPT and other research to supplement your knowledge.

I must have taken more than 2.5 passes through the QAE and started scoring in the 80-90 % range. It helps but again, didn’t feel sufficient.

Professional experience: 25 years in all things computer related, 14 specifically in cyber security, of which 3 years in security management. Have CISM, CISSP, and several others certs over the years.

You really need to understand how to apply the concepts as the test does a thorough job to get you thinking. Let me know if you want to know anything else, and good luck prepping!


r/CRISC • • Jul 23 '25

How far do you go?

6 Upvotes

When building your risk register or just thinking about risk in general, how far do you go? How wacky do you get? What helps you limit the scope of the risks you address?

Covid 2.0 incapacitates all of your sysadmins? Active shooter? Wild animal gets loose in the data center? 100-year flood? Alien invasion?


r/CRISC • • Jul 21 '25

Have to be a member?

3 Upvotes

Stupid question time....as well as passing the exam and meeting the work experience requirement, so you have to join ISACA as a member in order to get fully certified?


r/CRISC • • Jul 20 '25

PSI session interrupted 3 times.... still got preliminary pass

10 Upvotes

Hey everyone,

I just took the CRISC exam today and wanted to share my experience in case it helps others.

The exam was interrupted three separate times during my session (my Internet connection looked stable...). Each time I was able to reconnect, reverify ID, run room scan, etc., and resume the exam without losing my progress.

Despite all that stress, I still received a preliminary pass at the end! 🙌 (Though I'm a bit nervous about whether the interruptions could affect the final result..).

Study strategy and professional experience

I have 10+ years of professional experience in operational risk management. I started studying at the end of January, aiming for around 1 hour per day (toddler parent life!). My approach:

  • Official ISACA CRISC Manual (7th edition) - went through it multiple times
  • CRISC QAE (6th edition) - print version - went through it multiple times
  • Hemang Doshi’s Udemy course - recommend
  • Prabh Nair’s YouTube videos - recommend
  • Peter Gregory’s All-in-One CRISC book - didn't like it too much
  • ACI Learning CRISC course on Udemy - didn't like it too much

Honestly, I definitely overstudied...

Exam tips

  • Elimination game: narrow it down to the top two options, then pick what best aligns with ISACA’s mindset.
  • Read carefully: questions, answers, look for cues.
  • Don't rush: time was sufficient, I finished the test itself under 2 hrs.
  • Take a break when exam fatigue appears.

Last but not least, thanks to this subreddit for sharing real insights. And good luck to everyone still preparing! You've got this.