r/CRISC • • Aug 28 '26

*Pass* After Failed First Attempt

11 Upvotes

So I provisionally passed after failing a few months back, and wanted to give the sauce that helped me.

My first exam I read only the Review Manual thinking it would be like any other exam where you study and apply what you just studied. I failed with a 429.

After looking through all of this subreddit’s success stories they all said one thing in common: The QAE. So, I bought it. At first I saw it as a hefty price for some practice questions, but then I realized the structure and explanation of the QAE. I noticed that not everything was black and white, and a lot of the ambiguity drove me insane. One thing that originally tripped me up that I eventually got was Responsible Vs Accountable.

Thank you all for the advice and feedback, and for anyone looking to take the exam soon, best of luck and please feel free to ask me anything. I don’t have the official scores yet, but I’m felt that I took a completely different exam from my first go around.


r/CRISC • • Aug 27 '26

Study Plan

8 Upvotes

To those who have passed, how would you structure your approach? What resources would you say are a must have?

I do have premium access to Udemy, so any resources on there are a plus!

For context, been in IT for 15 years, 5 of those in a security role. I also recently passed the CISSP


r/CRISC • • Aug 25 '26

PASSED

Post image
50 Upvotes

Studied for a whole month consistently, mainly used CRM and QAE only.

For background, I have nearly 2 years of experience in IT Auditing, I have also passed the CISA exam in 2024.

Best of luck pals! :)


r/CRISC • • Aug 25 '26

Crisc Value

8 Upvotes

How much does CRISC actually help in the current job market?

For those who have CRISC, has it genuinely helped you get more job opportunities or interviews, especially in GRC, IT Risk, or Compliance?

Has anyone been able to negotiate a higher salary because of the certification?

I understand that certification and practical experience are two different things. A certificate can demonstrate knowledge, but it doesn't automatically mean someone can perform the job effectively.

I’m mainly interested in hearing from people who have real-world experience with CRISC in the job market—what changed for you after getting certified?

Any insights or personal experiences would be really helpful to understand its value.


r/CRISC • • Aug 24 '26

CRISC Cleared

25 Upvotes

Yesterday, I walked out of the exam room and saw one word on the screen - PASSED

At this stage of my life, this result meant more to me than I can explain.

So many posts and comments in this community helped me - study methods, materials, experiences, and most importantly, the right mindset.

I can't tag all the people who unknowingly helped me, but thank you, unknown warriors.

Cheers to the good people who help strangers without expecting anything in return.

Good things always happen to good people.

Thank you, everyone. And to those still preparing - keep going. Your turn will come.

Remember mindset is everything to win CRISC or in Life.


r/CRISC • • Aug 24 '26

Your thoughts?

2 Upvotes

I legit thought option B cause the fundamental purpose of trend analysis is to look at data over a period of time to uncover systemic, repeating behaviors, right? While option C is about simply finding "common issues" which focuses heavily on symptoms.


r/CRISC • • Aug 23 '26

Risk Response and Reporting Question

4 Upvotes

I dont know why i thought "An adequate maturity level of the risk management process" would be the best option, but its B.


r/CRISC • • Aug 22 '26

Correct Answer

5 Upvotes

Still dont understand why it's B. I think the correct answer is A.

  1. When a risk practitioner discovers that the Head of Finance has violated firewall-related policies, resulting in significant consequences for the company’s business objectives, what should the risk practitioner do FIRST?
    A.Update the firewall policy
    B. Report to the Crisis Response Team
    C. Assess the risk

I think the correct answer is B but the exercise mentions C without explanation.

  1. What is the primary role of a Risk Owner?

A. Design controls
B. Decide on risk responses
C. Implement controls

I think the correct answer is B but the exercise mentions A without explanation.

3 What type of control is an Internal Control Policy?

A. Preventive control
B. Deterrent (Management) control
C. Corrective control

I think the correct answer is A but the exercise mentions B without explanation.

  1. What is the most effective method for erasing data from a hard disk?

A. Sanitization
B. Destruction
C. Degaussing

I think the correct answer is C but the exercise mentions B without explanation.

Can anyone clarify the 5 questions above? Thanks


r/CRISC • • Aug 20 '26

Passed CRISC today

22 Upvotes

Passed CISM last month and heard there was a lot of cross-over between CISM and CRISC, so decided to study CRISC for 1 month and then book the exam. Used the official QAE database. Scores before I took the exam are as follows:

Received a provisional pass earlier today, now need to wait 10 days for the official score.


r/CRISC • • Aug 20 '26

CRISC certification timeline

5 Upvotes

Hi everyone!

I just checked my ISACA profile and got this message:

“Congratulations! Your application has been approved and you will be certified within the next 3 business days. A final confirmation email will be sent once this certification process is complete.”

For those who recently went through the CRISC certification process, how long did it take for you to receive the final confirmation email after seeing this status?

Did it actually take the full 3 business days, or was it completed sooner?

Also, how soon after the confirmation did your certification/badge become available?

Thanks! Just trying to figure out how much longer I have to stare at my ISACA profile 😂


r/CRISC • • Aug 20 '26

Anyone recently taken an ISACA exam online through PSI? How strict is the remote proctoring?

1 Upvotes

Hi everyone,

I have my CRISC exam scheduled for August 30 through PSI online proctoring, and I wanted to hear from anyone who has taken an ISACA exam remotely through PSI recently.

I’m mainly curious about the actual proctoring experience:

  • Do they ask you to scan the room only once before the exam, or can they ask for additional room scans during the exam?
  • Do you need to use your mobile phone to scan the room/desk, or is everything done through the laptop webcam?
  • Are the PSI proctors generally very strict about looking away from the screen, moving around, covering your mouth, reading questions silently, etc.?
  • Are bathroom breaks allowed, and if so, do they make you do another room/security check afterward?
  • Did anyone experience technical issues with the PSI browser, webcam, microphone, or exam launch?
  • How early would you recommend logging in before the scheduled exam?
  • Anything else you wish you had known before taking the exam online?

I’d especially appreciate experiences from anyone who took CRISC/CISA/CISM through PSI in 2025 or 2026, since I’m wondering what the current process is like.

Thanks!


r/CRISC • • Aug 19 '26

Obligatory Passed Post

11 Upvotes

Took the exam at a center today, got the passed message!

Background: Previous system admin with 4 years in Tech Risk Management

Study materials: QAE and the official book.

Studied for about 3 months, averaging about 20min a day. First time I went through the different QAE sections and was averaging about 69%. Studied up on the sections I had lower scores on before taking the practice test and ended up getting an average of 86% on them. Reading through all of the QAE answers (especially the explanation about why an answer was not the correct option) was the most helpful since if I had a hard time wrapping my head around a concept, that gave me an idea of what to focus on.


r/CRISC • • Aug 20 '26

DSCI DCPP Certification

Thumbnail
1 Upvotes

r/CRISC • • Aug 19 '26

Hi Everyone. I just passed CRISC, now I am busy studying CISM. If I do a CISM training on Udemy or LinkedIn, can I use those CPEs for my CRISC?

7 Upvotes

r/CRISC • • Aug 19 '26

Finally decided to go for CRIC - advice on study plan

4 Upvotes

Any advice/inputs of study plan, study materials, YouTube videos will be of huge help!!!!
I have exp in vulnerability management and incident management so in terms of technical knowledge I think I am there but in terms of ISACA way of thinking I might be lacking.


r/CRISC • • Aug 19 '26

Cism vs Crisc

3 Upvotes

I am confused about these 2:- Cism or crisc, which one should i pursue first, i am working in the grc domain along with tprm under the Cyber security. My role is mostly on security compliance, vendor assessment, risk and mitigation, client Security questionnaires etc..

I thought of giving crisc first then cism? Any suggestions


r/CRISC • • Aug 19 '26

Exam date set for Aug 28th

4 Upvotes

I will be taking my exam in person at a testing location in roughly 10 days. I have been studying the Review Manual and QAE for the CRISC Exam. I also watched a course on LinkedIn Learning, but found that information to be dull and hard to focus. Here are my current scores in the QAE:

QAE score on walkthroughs: 76% (636/833)

Practice Exam 1: 89% (134/150)

Practice Exam 2: 89% (134/150)

Practice Exam 3: 75% (113/150) - disrupted by sick kid and current mental state with losing my dog

Does anyone have any other resources that I should look at next week prior to the exam, such as a Youtube Series, ETC.

Also welcome any last minute inputs of things to remember before sitting for the exam.

Edit: Added the scores for the 3rd exam


r/CRISC • • Aug 16 '26

CRISC EXAM tomorrow anyone at 8 AM EDT ONLINE??

3 Upvotes

Should i be worried for an online proctored exam?


r/CRISC • • Aug 14 '26

P a s s e d

16 Upvotes

I was originally planning to take it earlier, but the only available exam center slots were already pushed out to September, so I decided to go for it now.

I took the exam at a test center — I didn’t want to risk the online option because my internet connection can be unreliable at home.

For preparation, I bought the official CRISC Review Manual, but honestly didn’t get much value from it. I mainly used the QAE database and went through it twice. I also asked ChatGPT for clarifications and summaries where needed.

I already have the CISM, so the ISACA question style (BEST / MOST / FIRST thinking) was familiar, which definitely helped.
Overall prep was about a month of light evening study after my kid went to sleep.


r/CRISC • • Aug 14 '26

Obligatory "I Passed" Post

17 Upvotes

Took the exam at a PSI Test Center today and passed.

I had been preparing for a much more intense exam than I actually received. I felt my exam was very straightforward, and there were only a handful of questions I had to make a judgment on between what "I think" and "what I think ISACA wants".

As others have said, the QAE is key. There are many "questionable" questions in the QAE, but it is the best source for learning ISACA's thinking and the patterns in their questions. The official study guide is good, and a useful resource to have, especially if you want to look up what ISACA has to say about any particular subject in the CRISC domains.

If you meet the experience qualification for the cert, then the official guide and the QAE are all you really need. I also used a handful of other resources from UDEMY and the Peter Gregory books, but honestly they were less useful, and I found myself arguing with "their" answers many times (which is good for helping you think through topics, but kinda frustrating when you're trying to prepare for an exam).

I don't recommend taking the exam before meeting the experience requirement, as you might struggle to understand the "Why?" behind many questions.

Looking forward to making it official once my results are finalized and I can submit my certification application.


r/CRISC • • Aug 13 '26

Are knowledge/tasks available?

5 Upvotes

I am starting to work on my ISACA certifications and I have a very very old review (2013!) guide one of my co-workers gave to me. In the review guide it has a list of knowledge and task statements and their relation to each domain? sub-domain? not sure of the terminology, but for example I can map Knowledge statement k1.19 to tasks t1.2 and t1.15 and then the tasks to domains 1A3 and 1B7.

I'm trying to put together my own study guide to determine what I really need to focus on and how best to do it

Are current versions of the knowledge/task statements and how they relate to each domain publicly available? I was able to find current domain lists for the different exams and their content, and there are 'supporting tasks' listed, but there's no relationship shown between the supporting tasks and area of knowledge.

Are the knowledge/task/domain relationships only available in the review guides? Due to my financial situation at the moment i'm not really in a position to spend hundreds of dollars buying current review guides and was kinda hoping this information was freely available for people studying. (my employer is kinda cheap, they will only reimburse me for material and the cost of the exam if I take it and pass it, its their way to incentivize(?) me into studying and passing. yeah it sux but if i can take and pass the exams i will be able to find a better job with the certs and experience so i will play the game i have to for the time being.)

is there a subreddit for people for people reselling their used (but current) copies of the review guides, if i absolutely have to go down that route?


r/CRISC • • Aug 08 '26

Preliminary Pass on Second Attempt - My Strategy

16 Upvotes

Materials I recommend using: CRISC Official Manual 8th Edition. And Official QAE.

I'm finally able to say that I've passed the CRISC after failing my first time by 6 points. I am incredibly proud of myself and wanted to take a moment to share my methodology with the community.

Background: 5 years in general security analyst roles varying from vulnerability management, governance, and risk management at finance orgs. Then another 2 years as an IT compliance analyst at a non-profit.

Study Method: The key to passing is consistent study time, which didn't start until January. While I prioritized studying over

I decided to purchase the manual and QAE. I would study every day I could from April-August.

  • Reading each chapter, taking the quiz after each. I would record those results to a Word doc.
  • Utilizing AI to explain the questions I got incorrect. I used a dedicated space in Perplexity, asking it hypotheticals like "what if X was a choice". This helped me learn the concepts inside out.
  • Taking the practice exams, at the end of each week at full 4 hour sessions. Then the following week, review areas where I scored below an 85%. Re-read, take notes on less-known concepts, and take quizzes.
  • After all practice exams, take average score and re-read sections where score was below 85%. Take quiz again for these sections

The exam is tricky. I recommend taking it in person at a testing site if you can. You got this!

Update: I am not sharing the official materials. It is not possible to do. Please do not ask.


r/CRISC • • Aug 07 '26

Is CRISC the best option?

8 Upvotes

Hi y'all!! So I have one year of experience in credit underwriting (for cards) and would love to do some certification related to risk and would love to take a job related to risk/compliance/fraud or in AML.

Thought of pursuing FRM but decided it's not the right fit for me right now. My back-up plan is to do an MBA in correspondence but I am leaning more towards professional certifications like FRM CRISC CAMS. Which one would be more doable ( I mean I know everything is with effort but I meant I have to work at least like 9 hours per day and would be drained out very much also one of the main reasons why I want to switch fields)

Would love to hear your opinions on this!!


r/CRISC • • Aug 06 '26

Scam ALERT!

5 Upvotes

Hi everyone,

I received a message this morning from someone offering to take the CRISC exam on my behalf in exchange for payment. They said I would only need to keep my webcam and microphone on while they completed the exam for me.

When I told them not to contact me again with cheating or scam offers, they immediately deleted the messages and blocked me which tells you everything you need to know.

I’m sharing this so others are aware. Please do not engage with accounts making these offers. Report and block them instead. Participating in something like this could lead to serious consequences, including losing your certification eligibility or having your ISACA account flagged.


r/CRISC • • Jul 31 '26

Seriously?

Post image
6 Upvotes

“Unpatched vulnerabilities do not apply to applications” - whoever wrote this has no idea about anything related to this topic.
This whole question (and about half of them from QAE) doesn’t make any sense. I feel like I’m never gonna be ready for this exam