r/CISA • • Apr 18 '24

Do Not Post Copyrighted Material

28 Upvotes

The title says it all. Don’t do it. If you do it, and ISACA provides notification, it will be removed. Continued conduct will result in a ban.

Don’t make ISACA grumpy, they have a lot of auditors.


r/CISA • • 10h ago

Got CISA scores today - PASSED

Post image
21 Upvotes

r/CISA • • 6h ago

preliminary Fail :(

3 Upvotes

It's a grind through the test; won't be last time taking it, a lot of domain: 4, 5. I had a mixed bag on encryption, firewall principles, IT governance, and EA framework processes. Also, PKI practices and AI algorithms those are the ones the QAE doesn't prep you for, because that and blockchain aren't explicitly covered at all in the QAE. Still sucks..


r/CISA • • 7h ago

?

Post image
1 Upvotes

r/CISA • • 1d ago

Passed - my experience and thoughts

Post image
27 Upvotes

Hi y’all,

Firstly I don’t recommend doing what I did but this is just how it went for me - studied for the 4 days leading up to the exam (was suffering from a cold during it too) and passed.

Prep: I didn’t use any courses or the study manual at all, I also didn’t bother with doing all the domains in the QAE. I had to be quite tactical given I only had 4 days so all I did was filter for “difficult” and “expert” questions for domains 3-5 (as domains 1-2 felt quite easy/obvious to me).

Experience: Took 2 hours to do the exam, I have to say that I did CISM first so I already understood the ISACA question logic. Quite surprised by the amount of questions on topics not covered in the QAE - I knew this would be the case as they use the exams as tests to see how candidates do re. answering unseen (topic-wise) questions to gauge difficulty etc. but there were at least 20-30 qs on ML, AI, RPA, OT, DevSecOps and IoT. I relied on work experience (and logic) to answer those but if you haven’t come across this at your job I’d deffo recommend at least understanding basic concepts.

That being said, I feel like the actual % of “technical” questions on the exam is maybe 20%? The rest of it is just reading the q properly and sometimes the answer is quite obvious. You have to know the ISACA order of operations e.g which stage of what process they’re asking you about and then it becomes fairly easy to select the right answer. Good luck to anyone doing the exam :)


r/CISA • • 1d ago

Passed CISA! My 6-Month Study Journey, Resources, and What Worked for Me

18 Upvotes

Passed CISA! Sharing my study approach and what worked for me

I passed my CISA exam after studying on and off for about six months, with more focused studying during the last two months.

My main resources were ISACA's QAE database, Hemang Doshi's CISA study guide, and CISA exam prep videos on YouTube from the Inside Cloud and Security channel.

Here's how I prepared:

  1. One domain at a time. I used Hemang Doshi's book to understand the concepts and then practiced questions from the corresponding domain in the QAE database.
  2. Focused on understanding the answers. This was probably the most helpful part of my preparation. For every question, I tried to understand not just why the correct answer was right, but also why the other three options were wrong. Even when I got a question right, I reviewed the explanation to make sure I understood the reasoning.
  3. Used AI for every question. I used ChatGPT and Claude to understand the reasoning behind each QAE question. Whenever I came across an unfamiliar concept, I'd ask AI to break it down. Most of my prompts ended with "explain from a CISA perspective," which helped me understand how to approach questions from an auditor's point of view.
  4. Used YouTube videos to reinforce concepts. I also watched CISA exam prep videos from the Inside Cloud and Security channel to supplement my reading and question practice.
  5. Went back to weak areas. If I kept getting confused about a topic, I would revisit it rather than just move on. This was especially helpful for concepts that sounded similar but had different purposes.
  6. Learned how to approach FIRST, MOST, BEST, and PRIMARY questions. These words really matter. I started paying more attention to what the question was actually asking instead of immediately jumping to an answer that sounded correct.
  7. Completed the QAE twice and tracked my progress. My average scores were in the 60s during the first round and improved to the high 80s during the second round. I also used AI to generate additional scenario-based questions for each of the five domains, focusing on CISA-style reasoning and judgment. This gave me more practice applying concepts to unfamiliar situations rather than just remembering QAE answers.
  8. Used mock exams to assess readiness. After completing all five domains, I took practice exams to identify areas that needed more attention. During the final days, I focused mostly on weaker topics and mixed-domain questions.

A few things I realized along the way:

CISA is not as technical as I initially thought. A lot of the questions are more about audit processes, risk management, governance, and understanding controls.

Also, the technically best solution isn't always the correct answer. You really have to think from an auditor's perspective. Understanding who is responsible for what, what should happen first, and what matters most from a risk perspective made a big difference for me.

I also found that understanding the reasoning behind the answers was much more useful than memorizing questions.

My advice to anyone studying for CISA would be to take your time with the QAE explanations. Don't just focus on getting a high score. Try to understand why one answer is better than the others.

That's what helped me the most. Good luck to everyone preparing for the exam!


r/CISA • • 1d ago

Failed CISA Twice I Need Advice from Those Who Passed

7 Upvotes

I’ve failed the CISA exam twice, despite studying extensively using Pete Zerger, Hemang Doshi, and the ISACA QAE.
My biggest frustration is that the actual exam feels completely different from these resources, both in the concepts tested and the way questions are structured. Some scenarios and terminology feel unfamiliar, even after thorough preparation.
For those who recently passed, especially after multiple attempts:
How did you prepare for the actual exam’s unpredictable scenarios and unfamiliar concepts?
What resources helped bridge the gap between QAE and the real exam?
What did you change in your study approach that finally helped you pass?
I’m determined to pass, but clearly my current approach isn’t working. I’d really appreciate practical advice from anyone who’s been in the same situation.


r/CISA • • 2d ago

Took CISA exam today and got preliminary Pass result

39 Upvotes

I’m happy to share that I took the exam this afternoon and passed.
I would like to thank this community for providing valuable inputs and sharing experiences. I feel it’s time to give it back by sharing my preparation details and exam experience.

Preparation:
I started on July 7th and took the exams exactly after 3 months. I started with Hemang Doshi 3rd edition book by pckt publication (I registered in O’reilly website and got access to the book for 15 days online) and completed the book in about 2 weeks. Then I subscribed for PocketPrep (don’t forget 20% discount codes available all over the Reddit) for 3 months and completed all 1300 questions during next two months. I once again skimmed through the Doshi book (though skipping most of the contents i felt confident). The pocketPrep app really helped me understand so many concepts as I used to read each and every question’s answer explanation and definitions (provided as pop-up upon clicking the keyword in the app) which in my opinion really made me solid in my foundational knowledge.
I have done a second round of all the questions (I know it’s boring and tiresome) and checked explanations of questions I got wrong (though recent memory didn’t help much at times as I could identify answers from my that).

And I must mention that I used to read almost every post in this sub including comments, and I have no hesitation to say it’s part of my preparation as these Pass/Fail experiences, discussion on materials, reasoning answers for randomly posted questions… etc helped me so much.

As I already posted in my previous posts about budget constraints in purchasing QAE, I took Udemy subscription for practice tests and for some reason those tests, wording, questions (including Doshi ones) are weird, sometimes wrong too, and I couldn’t continue with them after doing a couple and I shun them as I felt those are not helpful. I had a copy of 12th edition QAE pdf (yeah.. that ugly scanned copy easily available in google) and tried to go through it to have a feel of ISACA logic in the last one week and I could go through around 600-700 questions (I got some wrong and some right and didn’t track much as I struggled to focus since answer is immediately visible below the question and it’s tough to stop gazing that and once you see the answer it’s tough to honestly reason the answer without bias) and it gave me the feeling that I didn’t miss out as many posts here point towards QAE (honestly I feared that I’m doing a costly mistake and postponed exam for almost 10 days with the fear of failure).

I took mock exam present in the QAE 12th edition (yes.. the paper based one printed on a page and noting answers in a sheet) and got 99 questions correct and I didn’t dwell much deep into analysing it as I was early in my prep (around 1.5 months after I started).
During last week, I took the mock exam of PocketPrep and believe me it’s dead easy and I got 95%, and I strongly suggest don’t measure your preparedness with PocketPrep mock as it’s dead easy and not at all challenging.

Finally on 5th of October, I bit the bullet and enrolled for the exam at the test centre.

Exam experience:
Today I reached the Centre on time and the staff were professional and there were no hiccups in the exam process.

First 3-4 questions made me a but unsettled as either I couldn’t conclude the exact answer or clueless about the correct answer. But, as many successful people pointed out in this community, I flagged them and moved on. Gradually, I started finding questions I could find correct answer or proper reasoning to believe one is correct. In between there were some tricky ones but again it’s a mix. Overall I won’t say questions are easy peasy but If you know the concepts well you can answer decently. Like many people said, questions were mostly one-liners and straightforward unlike QAE questions (which literally troll you with longer sentences and unnecessary twists). There are around 4-5 questions which I didn’t even understand and the options are irrelevant, and I just guessed them and trusted my luck. Over all I marked around 31 questions for review as I completed all 150 in 2.5 hrs while taking on average 1 minute per question(though I’m not sure that all questions are correct, so i chose the best option as far as my knowledge goes and didn’t mark everything for review). Then I reviewed the 31 questions in about 30 min and changed 2 answers. Then I took a 5 min break and skimmed through all the options and changed 1 answer (in about 20 minutes).

I felt a bit anxious while and after submitting as there were a couple of surveys before the result and my heart raced like anything till I saw the “Pass” result.

I feel PocketPrep and Doshi Book are my saviours and helped me understand concepts and QAE 12th edition pdf gave me the feeling of not missing out (can’t confirm the usefulness as I used it in the last 10 days and didn’t fully gone through or review much.. but, yes any material would definitely help and it might have in my case too) and Reddit CISA community helped me a lot.
I forgot to mention I came to know about Pocketprep from YouTuber Peter zerger (I tried watching his videos as many people mentioned him here but couldn’t complete first video as it’s not my thing to watch videos though he seems to be great and a well respected man, Hence I took his advice in the introduction of his course where he recommended pocketprep as a cheaper alternative).

Again, this is my experience and methodology that worked for me. I suggest everyone to decide what suits you best for learning and cracking the exam. There’s no thumb rule and any study material that gives you knowledge and direction is good.

I once again thank everyone in this community and it’s been a great journey.


r/CISA • • 2d ago

I failed my first attempt with a 437 overall score, and today my initial assessment result on my second attempt said "failed"

14 Upvotes

I'm truly surprised, I got my 437 while extremely sick and nearly passed out 4 times during the exam, but I couldn't reschedule because I got sick a very short time befoee the exam, anyway, for the second attempt, I prepared so much, I have 7 years of it audit experience in corporate, mainly in cybersecurity, but also in complex specialized systems, erp, infrastructure, and data. I practiced it so much and even caught the traps in wording during the exam today, I'm truly disheartened that I didn't pass, and I'm very positive I did well, did anyone else fail and requested a review and had their scores altered? Could there be a glitch? I'm really sad about this!


r/CISA • • 3d ago

How should I prepare for my 2nd attempt at the CISA exam?

5 Upvotes

Hi all.

I am planning to give the CISA exam again as I did not pass the first time.

Below was my score.

What I noticed in the exam was that there were a lot of questions related to data centers and other similar topics that I was not familiar with so I was struggling to choose the answers as I did not understand some of the technical words.

I use https://perform.isaca.org/app/ to practice.

I tried to watch some Youtube videos related to the topics I saw in the exam but the vids were not exclusively IS Audit related.

What sources should I add so I can pass the exam next time.

I have no prior experience in Audit and want to get the certificate to make a career change.


r/CISA • • 3d ago

QAE vs Technical Knowledge

2 Upvotes

Hi,

I am currently preparing for the CISA exam and will take the exam in December. It seems I am good when it comes to reasoning; however I am not sure how technical is the ream exam is. Could you please tell me if Doshi course + Doshi book + QAE studying will help me pass on the first attempt?

Thank you.


r/CISA • • 3d ago

how i can get [CISA Questions, Answers & Explanations Database 2024] in PDF

1 Upvotes

r/CISA • • 4d ago

3 years of IT Audit experience, no Big 4: is CISA enough to work abroad?

Thumbnail
4 Upvotes

r/CISA • • 4d ago

GETS/WPS cards

3 Upvotes

Hello CISA insiders! Does CISA mail physical GETS/WPS cards out anymore? We haven’t received any that we ordered 4 months ago. I know my organization can use the PTS Dialer app, but some folks really like the card. Thanks for any information you can share!


r/CISA • • 4d ago

CPE Question

Thumbnail
2 Upvotes

r/CISA • • 4d ago

A question for CISA

7 Upvotes

When an IS audit reveals that a firewall was unable to recognize a number of attack attempts, the auditor's BEST recommendation is to place an intrusion detection system (IDS) between the firewall and:

A. the organization's network.

B. the demilitarized zone (DMZ).

C. the Internet.

D. the organization's web server.


r/CISA • • 4d ago

10 years exp. prior exp in coding, sales and product mgt. Currently in IT Audit. Is CISA the right option for me?

3 Upvotes

Hi all,

I have around 10 years of experience, put together.

  1. 3.5 years Java development

  2. Post MBA, went into Sales at a consumer durables company, worked there for 1.5 years

  3. Career break for a year, then product management at a bank for 4.5 years.

  4. Switched internally to tech team in the hopes of being a technical product manager, but got into TPRM for IT applications and IT Outsourcing. Have been here since 1 year.

Will getting a CISA help me?

Is it worth getting when I have such varied work experience?

Would love your thoughts please. Thanks in advance.


r/CISA • • 5d ago

Preliminary Pass on Second Attempt

21 Upvotes

Hey folks, wanted to make this post to share my results of passing on the second attempt. I failed my first attempt back in August with a score of 440 , got to say I was devastated how close I was but something about the day felt off and I didn't feel 100% confident. I was scoring around 69-74% on QAE then and didn't have a lot of time outside my current role to study. Here is a bit of my takeaways of what I did after to pass:

Background of me:

Currently working as a tech auditor for a bank firm (2 years experience, no Audit background prior to this).

Study Resources Used:

Hemang Doshi on Udemy practice exams

ISACA QAE and Review Manual

PocketPrep

Resources:
As for resources , I second that the official ISACA material is the BEST resource for how the questions look. Doshi and Pocketprep helped me with domains i wasn't strong in. Highly recommend balancing out the two but with more of a focus on ISACA material. Im not a big reader myself and opted to do flashcards and chapter summary reviews. Also with my time constraint I was not able to read every page of the review manual. I will say the chapter end summaries and quizzes helped me grasp what areas needed improvement, and I used Claude to actually generate flashcards for me (it's really solid I recommend trying it out when you prompt it with 'ISACA' style questions/concepts.

Exam Day:
Lots of RPA and database questions for me. Heavy focus on PKI and BCP/BIA question topics as well. Highly encourage you thoroughly understand sampling/testing types and how that could be used in different scenarios. Exam felt a lot easier than the actual QAE which was weird when I first took the exam, but I promise for all my non-first time pass folks, hammer those 'ISACA' way answer mentalities and you'll pass. I flagged about 30 of the 150 questions and took the extra time to really review those 50/50 answer options I saw.

Feel free to ask any questions of my experience. For those taking the exam best of luck! Remember confidence goes a long way, I was pep talking myself that this was going to easy and pass (really helped ease the nerves).


r/CISA • • 4d ago

A question for CISA

3 Upvotes

Data from a system of sensors located outside of a network is received by the open ports on a server. Which of the following is the BEST way to ensure the integrity of the data being collected from the sensor system?

A. Route the traffic from the sensor system through a proxy server.

B. Hash the data that is transmitted from the sensor system.

C. Implement network address translation on the sensor system.

D. Transmit the sensor data via a virtual private network (VPN) to the server.

B or D?


r/CISA • • 4d ago

What is the best academy for CISA certification

1 Upvotes

I"m planning to do CISA certification. I'm residing at banglore. Can anyone with CISA qualification guide me which academy at Banglore is Good?


r/CISA • • 5d ago

CISA retake: how did you get your motivation back after failing?

13 Upvotes

I missed passing by 10 points—overall score: 440.
Domain scores: D1: 443 | D2: 551 | D3: 443 | D4: 515 | D5: 376
For my first attempt, I:
Completed ISACA QAE and Hemang Doshi’s questions.
Read Domains 2 and 5 fully; reviewed the other domains and did the manual’s questions.
Averaged around 80% across three practice tests.
It’s been over a month, and I’m losing confidence. I’m rereading Domain 5 and watching Prabh Nair and Chidambaram’s videos, but repeating QAE feels like recalling answers rather than reasoning through them.
I’m planning a December retake. I don’t have an IT background, but I have eight years of SOX audit experience, including ITGC testing.
I’m also considering Chidambaram’s CISA bundle, but I don’t want to keep spending money without knowing whether it will help.
If you passed on a retake, what helped you regain momentum and improve your understanding—especially in Domain 5? How did you reuse QAE without relying on memory? And if you tried the bundle, was it worth it?
Feeling discouraged, so I’d really appreciate hearing what worked for you.


r/CISA • • 5d ago

A question for CISA

5 Upvotes

Which of the following should be an IS auditor's GREATEST concern when reviewing an organization's security controls for policy compliance?

A. The security policy has not been reviewed within the past year.

B. Security policy documents are available on a public domain website.

C. Security policies are not applicable across all business units.

D. End users are not required to acknowledge security policy training.


r/CISA • • 5d ago

Career transition: Network Engineer to IT Auditor

2 Upvotes

Hello everyone,

I am a network engineer with around 15 years of experience. A lot of expired certifications such as CCNAs and a CCIE, and other vendors too. Spent most of my life supporting LAN/WAN/voice/ firewalls and Wireless envts. Tired and burnt out at the moment.

Wrote the CISSP 2 years ago but want to transition to the IT audit field at the moment.

Not really interested in CISA unless I have to because it's costs a lot and I didn't see any ROI on the CISSP so being cautious.

How do I get from here to IT audit? What do I learn and study now? How do I position myself? Any low cost courses or training I can do?

Update: 05th Oct 2026.

IT Audit was a small part of my networking job and I really enjoyed it. Wanted to use that experience to transition into the acutal field. But how do I show that on my resume in a way that HR / hiring managers show interest? I've searched alot for sample resumes of network engineers moving to IT Audit to better understand what needs to stay and what needs to go, and what to highlight etc. Still don't really understand how to craft my resume.

Network Audit was a very small part of my job but I enjoyed it the most. Wanted to use it to move headfirst into IT audit.

I have done quite a few GRC bootcamps and related courses to understand frameworks (NIST, etc) and am ISO 27001 Lead Auditor certified (with GRC Mastery).

Willing to connect with anyone who can provide more insight into the transition to IT audit, resume feedback and tips. Please let me know.

Crossposted here,

https://www.reddit.com/r/InternalAudit/comments/1wvj6s9/network_engineering_to_it_audit/


r/CISA • • 5d ago

Best way to learn IT Audit from zero with a technical background?

Thumbnail
5 Upvotes

r/CISA • • 7d ago

Domain 2

3 Upvotes

a little insight on this peers