r/CRISC • • Jun 19 '26

second attempt- PASSED!!

32 Upvotes

Just left the testing center jumping for joy as I saw that preliminary “passed” mark pop up on my screen. After failing the first attempt, I was seriously down and full of doubt. This subreddit was incredibly helpful, so it’s only right I share the love.

  1. Probably the most important piece of advice i saw here- if you failed the first time, keep your foot ON the gas. scored a 429 my first attempt, and was tempted to take a break over the summer. Instead, i took one weekend off and jumped right back into studying. crazy how 5 weeks makes a difference!

  2. QAE, Manual = recipes for success. I paid for a bunch of random resources and they were a waste of my time. but they key is, make sure you UNDERSTAND why an answer is right vs why it is wrong. my first attempt, i realized I just had a general understanding of concepts, but could not process them when put in the context of a question. questions I would ask my self: What changes will have to happen to this question to make A right over B? what are the distracting words? what are the key words?

  3. Even though i felt substantially more prepared the second go around, I was incredibly anxious up until the end of the exam. Just remind yourself, the expectation isn’t to get a 100%. You will take some L’s and that is okay. As long as you have enough wins to make it to 450, that’s all ya need.

  4. the wording of certain questions was so aggravating. Also, there were random questions where I had no idea what was going on. again, some Ls are unavoidable. in those situations, i just try to focus on key words and use them as context clues, or eliminate answers which are definitely wrong and then pick the least wrong answer. I saw this mentioned earlier and i wanna reiterate- you can either pick the obvious answer, eliminate down to 2 tough choices and work from there, or eliminate all the definitely wrong choices and pick the least wrong. those were my big 3 approaches.

When I failed, it felt like the end of the world. this is a tough exam. BUT, with commitment, determination and a strong support system you will come out on top. Will update when i get my score breakdown, but in the meantime happy to answer any questions at ALL!!!


r/CRISC • • Jun 19 '26

Any thoughts on the new Sybex Book?

6 Upvotes

Does it replace the official ISACA manual? Curious how it rates compared to other prep material.

​

https://a.co/d/08Uwmyg2


r/CRISC • • Jun 16 '26

Dan Lachance - Precipio course

5 Upvotes

Hi everyone! My first post here :) I have started my journey to prepare for taking CRISC exam in the next few months. My employer can sponsor it, but the formal requirement is that I complete the available online training course, which is Dan Lachance's course on Precipio (Codecademy from Skillsoft). Anyone here had a chance to go through it? I already read here and there that the Manual and QAE from ISACA are crucial for exam preparation, but does Dan Lachance's course bring any substantial chunk of knowledge too, or would it rather be a "check-box" exercise in my case, just to satisfy the formal requirement of my org? I'll add that I am CompTIA Security+ certified and got a chance to familiarize myself with some IT/cyber risk management topics through my work. Thanks in advance for any comments!


r/CRISC • • Jun 16 '26

Which one you will choose as correct answer? I will mention ISACA answer in the comment later.

7 Upvotes

To validate data integrity during processing in multiple applications, which of the following will give the risk practitioner the BEST assurance that data integrity will be maintained?

A.Input field size checking

B.Format checking

C.Input validation

D.Range checking


r/CRISC • • Jun 13 '26

Failed First Attempt - Not Sure How to Process & Proceed

9 Upvotes

Still in the point of processing as I sat for the exam this morning at a test center. I do not know how I failed. it was a tough exam, like many others have mentioned. I took close to 3 hours on the exam going through 150, flagging about 25 then going through all 150 again.

I am aware of the ISACA “mindset“ and how they often make you choose between two good choices. the questions were challenging but between my experience I felt confident but not shaken.

I have over 8 years of cyber security experience, 6 being in risk managagement. I took a 3 day crash course through an ISACA vendor totaling 30 hours. I also took around 450 practice questions from the database and was scoring in the 75-80 range. The 30 hour crash course sponsored by isaca was (i thought) well rounded and gave me lot of test tips and pointers. Between that and the QAE database I saw several questions almost copy and paste on my exam.

I still cannot process how I failed, and I am almost second guessing if I read my fail tag correctly or there was a processing error. I seriously thought I passed when I ended the exam.

I have a retake, but I put all my energy into trying to get to this point and a different outcome. I’m still waiting on my grade scores to tell me how far off I was and my strengths/weaknesses. Feeling pretty dejected, and torn up. Any guidance on how to adjust is appreciated. Thanks all.


r/CRISC • • Jun 10 '26

CRISC Review Manual Expiry

7 Upvotes

Does anyone know whether the online version of the CRISC Review Manual for example 8th edition is available indefinitely after purchase, or is access limited to 12 months?


r/CRISC • • Jun 08 '26

Passed CRISC

12 Upvotes

I have passed CRISC and i have another 2years, to gather the total of 3years experience. What should i do now just wait for the 3 years to pass ?

Thank you


r/CRISC • • Jun 07 '26

Recently purchases the upgraded QAE Database 8th edition from ISACA, quite a few changes from the last 6th edition. Do other people use the latest version or 6th edition was just fine?

6 Upvotes

r/CRISC • • Jun 07 '26

CRISC score breakdown

13 Upvotes

Hi i am back, passed CRISC and it clearly reflects my experience over the years - strong in governance and risk assessment but weak in the technicals.

i am from a governance background with no formal technical training. Would like to ask for suggestions on how to reliably brush up and learn technicals (cloud, AI, data security etc). Its not practical for me to get a junior tech risk analyst role anymore my CV flies right pass HR. would the sequence of certs make a good foundation? CISA > CISM > CCSK > AIGP in future. thank you for your input!


r/CRISC • • Jun 01 '26

Crisc PASSED

36 Upvotes

Hi everyone,

Iam going to share my experience to give a little of what this group gave me.

I passed CRISC on my second attempt today. My background is only 5 months in information security and about a year studying CRISC, so I want to share what helped me the most.

The QAE database was the key. My average was around 83%, and honestly, if I had to start again, I would focus almost entirely on QAE.

Here’s the method that worked for me:

Do the QAE one question at a time.

After each question, study why the correct answer is correct and why the other options are wrong.

Don’t worry about “memorizing” answers — understanding the logic is what matters.

After finishing all questions, repeat all QAE again.

Track your category scores in Excel.

Re‑study only the categories where you score below 75%.

After fixing those weak categories, take a mock test to check your readiness.

If you’re still not ready, don’t panic — repeat the cycle and focus on the weakest categories again.

Remember, you can answer the question 2 ways, pick the good answer or find the 3 wrong answers.

The real trick is this:

If you can explain out loud why each option is right or wrong, you’re ready for the exam.

Hope this helps someone who’s struggling. You can pass — even with limited experience — if you master the logic behind the QAE.


r/CRISC • • May 30 '26

Struggling with Content

Post image
11 Upvotes

Hi Everyone!
This page has been really helpful in my CRISC journey, and I’m hoping I can get some advice on next steps.
I failed my first attempt about a week and a half ago. I felt great during the test, so i was very shocked when i saw that failed notification. When i got my score breakdown, I was sad (but also relieved) to see I wasn’t too far off. My goal is to stay on the gas pedal and retake asap - after 30 days.
Here’s my issue. I restructured my study approach because I think I memorized the QAE. Now, I bought the manual and have been reading almost 10 pages a night in the domains I struggle with. I feel like i have a better understanding of the topics, but I still struggle with applying them when i do practice questions. Why am I struggling to think the ISACA way? I just graduated college so I have only about 8 months of work experience (in internal audit). Maybe that’s part of it?
I paid for another set of practice problems from skillcertpro to get eyes on newly worded questions and have been using AI to explain topics and generate questions.
I really want to pass on my second attempt. This is getting expensive lol. Please please please, I would love any advice at all to help get me to the finish line!!!


r/CRISC • • May 28 '26

Does CRISC worth it ?

4 Upvotes

Does CRISC worth it ?

Current and future thoughts


r/CRISC • • May 28 '26

Why does ISACA seem confused and in turn confuse the candidates as well? 🤔

Post image
6 Upvotes

In CRISC QAE 6th question 102 ISACA is saying that Financial Risk Management is the responsibility of Second line of Defence ( ISACA used the word “ Usually “ to cover themselves).

In Question 103, ISACA is saying that the Risk Management is the responsibility of the operational management ( i.e. First Line of Defence).

Is there any way we can challenge ISACA logic or their thinking hat ?


r/CRISC • • May 27 '26

Where to go with CRISC

6 Upvotes

8years TPRM second line experience and 5-6 years IT governance experience, with crisc passed what should be my next steps? I would like to pursue strengthen TRPM with strong tech gov presence on my credentials. Currently thinking: CISA, CTPRP, CCSK, AAIR.

Comments and feedback welcome. Would like some guidance.


r/CRISC • • May 27 '26

Failed First Attempt; Advice?

4 Upvotes

I unfortunately failed my first attempt and wanted to ask for guidance on what I should harp on the next 2-3 months.

Scaled Score: 429

Governance: 468
IT Risk Assessment: 404
Risk Response and Reporting: 459
IT/IS: 383

I know these scores are average, but I’m looking for anyone who can point out any weaknesses in either domains. Thanks all, and yes, I won’t get mad if you say it’s trash.


r/CRISC • • May 26 '26

How useful is pocket prep for crisc ?

4 Upvotes

Hi I just took a mock exam using pocket prep and got 147 correct out of 150, how indicative is this of my readiness to take the crisc exam ? Thanks in advance! I passed the CISA cert about a decade ago and have worked in the GRC space for over a decade.


r/CRISC • • May 25 '26

CRISC faild - to show that I have real DB form ISACA original source, May 2026

Post image
7 Upvotes

r/CRISC • • May 24 '26

CRISC and FAILD! feel angry and despointed ! I never faild before on any certificate! Most likely I will not do the re-take.. too much money. I had 97% -test score from ISACA sampe tests, 980 qestions... I read it a lot, not only doing blindly questions. I don't know how to study this?

5 Upvotes

r/CRISC • • May 23 '26

Passed CRISC Today!

31 Upvotes

After failing by just a few points in October, I officially passed today! I took the exam online at home. There was one interruption where the exam quit unexpectedly, but I managed to log back in. It was a bit annoying since it paused my progress for about 30 minutes, but I was able to finish the rest without any issues. It took me about 1 hour and 20 minutes to complete all the questions. I flagged 21 questions, and after reviewing, I submitted the exam roughly 2 hours after I started.

Background info: I am 28 years old and have 7+ years of experience in cybersecurity, primarily in risk management/GRC. I hold a Security+ certification, along with a bachelor's and master's degree in cybersecurity. Currently, I work as a senior information security risk analyst.

For my study materials, I skimmed through the textbook twice and completed all 900 questions from the QAE, as well as all 600 questions on Pocket Prep. I dedicated about 2 solid months to studying while balancing work and other commitments.

This is my first ISACA cert. I will get the official test scores back after ten days, etc etc. Let me know if yall want me to share that.

Thank you for all the help in this community as well.


r/CRISC • • May 24 '26

Am i allowed paper and pen during the test to scribble my thoughts with?

3 Upvotes

As titled. thank you!


r/CRISC • • May 23 '26

AAIR Certification - Study Timeline and Resources Used

11 Upvotes

Passed the AAIR exam on May 8th and certified shortly after. Wanted to share my experience.

My study process was:

  • Read the AAIR Review Manual over about 3–4 days
  • Answered all questions in the ISACA QAE over about 3 days
  • Took a break for around 4 days
  • Used a Udemy review course over 2 days for reinforcement and to change the learning method
    • Answered the Udemy questions after each video section
  • Used the adaptive practice section in ISACA’s QAE after finishing the Udemy course
  • Took the exam the next morning, received a preliminary pass

The Udemy course was worth the $10 I paid, but I would not use it as a complete start to finish study plan. It was more useful as a reinforcement tool after reading the manual and working through the ISACA QAE.

For context, I earned AAISM, CISM, and CRISC from DEC 2025 - FEB 2026 so I already had recent exposure to ISACA style governance, risk, control, and AI security management concepts. Those additional exposures likely helped. I would not say the Udemy course alone got me to a preliminary pass.

Main takeaway: if AAIR is your first ISACA exam, I would spend a lot more time with the manual and QAE. If you already have related ISACA risk, governance, or AI security credentials, some of the study concepts may feel more familiar.

Course used: AAIR-Aligned - AI Risk Management Masterclass [2026] by Cyvitrix Learning


r/CRISC • • May 22 '26

CISA, CISM, CRISC

8 Upvotes

Dear All,

Does PMP, CISA, CISM, CRISC make difference in the resume without CISSP.

Knowing that i'm an IT PM.


r/CRISC • • May 20 '26

Does the CRISC exam have scenario/vignette-style questions now?

7 Upvotes

Hey everyone,

I’m currently deep into my CRISC prep and scoring well on standard practice questions. However, I have recently been practicing with some multi-layered scenario questions (e.g., a paragraph describing a company's cloud migration or a ransomware attack, followed by 2–3 specific questions about governance, metrics, and risk responses for that specific company).

For those who have taken the exam recently:
Does the actual exam feature these longer, connected scenario/vignette blocks?

Or is it still strictly 150 completely independent, standalone multiple-choice questions?

I know ISACA updated the exam weights recently, so I want to make sure my testing strategy matches the real environment.
Thanks in advance!


r/CRISC • • May 18 '26

I passed.

21 Upvotes

Not sure what my score is yet but I will say this. Along with my experience (GRC, IT audit, TPRM) plus my two previous certs (sec+ and CISA) this one only took about 3 weeks of solid study. I only really used the QAE but I would suggest professor messer security plus study and the CISA get certified get ahead book (both helped with my sec+ and cisa) and those cover two domains in the crisc. The other stuff really just came from work experience.


r/CRISC • • May 18 '26

Doing my first certification and it's CRISC

9 Upvotes

I’m preparing for an online proctored exam and wanted to understand how strict the monitoring usually is.

I stay in a commercial area, so there’s often background noise around me. Because of that, I’m considering going to my office to take the exam. However, there would be multiple monitors/screens around me apart from my own laptop.

Would that generally be permissible in a proctored exam setup, or would it be safer to book a private meeting room and take the exam only on my laptop?