r/isaca

▲ 23 r/isaca+5 crossposts

Passed AAIR exam today. If I start studying AIGP today, is 4 week preparation realistic??

Hey guys, Passed my ISACA AAIR exam this morning! It was pretty intense on the threat modelling and model drift side but I'm excited to have it out of the way.
My next target is lAPP AIGP. My brain is already in "study mode" so I want to keep the momentum going and dive right in.

For those of you who've done both (or just the AIGP):

How much does the AAIR IT risk knowledge transfer to the AGP privacy and governance focus?

work full time but can provide around 2-3 hours a day. Can we get through the APP syllabus and the EU Al Act frameworks in 4 weeks?

What are the best practice exams available right now? I find I learn best by asking questions based on scenarios.

Thanks for the advice in advance!

reddit.com
u/Pitaya_Campbell — 1 day ago
▲ 3 r/isaca

Eligibility for AAIR

I have my CISSP and passed AAISM recently. Without CRISC or CISM, can i appear AAIR.

Official website says, Active holders of CISA CISM CRISC CGEIT CDPSE and other recognised certifications.

So should I consider CISSP too ☺️

In case of AAISM it was clearly mentioned either cism or cissp.

reddit.com
u/OddAd1791 — 1 day ago
▲ 16 r/isaca

Does anyone know if the ISACA Site has been compromised?

I am unable to successfully log in to my training, and their support.isaca.org site displays "ATTACKER CONTROLLED CONTENT"

u/salsero96 — 3 days ago
▲ 10 r/isaca+1 crossposts

Struggling with ISACA’s “best answer” logic more than the actual material

I’m scheduled to take the CISM exam at the end of August and wanted to get some feedback from people who have already passed.

For background, I work in OT/SCADA and cybersecurity and have Security+ along with some ICS cybersecurity training. I’ve also completed a GRC masterclass, so I don’t feel like I’m starting from zero on the concepts.

My main study resource has been the official ISACA CISM QAE/practice questions, along with videos and reviewing every question I get wrong. I’ve been doing mixed sets of roughly 25–30 questions and then going back through my misses to understand why ISACA preferred one answer over another.

I have used Udemy Jacob Bushongs Master class, watched Pete Zerger prep as well as Prabh Nairs master class. And feel pretty confident about the quizzes.

My scores have been pretty inconsistent. I’ve had sets around 60–67%, some better domain-specific results, and recently scored 77% on a set made up of questions I had previously gotten wrong. However, after taking a few days completely away from studying, I just did a fresh/cold 30-question mixed set and scored 47% (14/30).

What is frustrating is that I rarely feel like I’m blindly guessing. On most of the questions I miss, I can explain why I selected my answer, and usually my reasoning isn't completely wrong. The problem seems to be that ISACA has another answer that is more directly correct for the specific wording of the question.

A few examples of the mistakes I'm making:

  • A question asked what could circumvent a control that scans social media posts for inappropriate disclosures. I chose anonymous posting because I was thinking about attribution/identification. The correct answer was intentional misspellings, because the question was specifically about circumventing the text scanning control. I expanded the problem beyond what was actually being asked.
  • For who should approve access to business-critical application data, I chose business management because I was thinking about management authority. The answer was data owner, because the data owner is accountable for determining who has a legitimate business need for access.
  • On a business continuity question, I was between a succession plan and distributed key process documentation. I chose succession planning, but ISACA wanted the process documentation because personnel can't continue critical processes if they don't know how to perform them.
  • I confused an EDR function with a SIEM function on another question. That one I consider a legitimate knowledge miss and understand what I need to review.
  • I've also caught myself adding conditions that aren't actually in the question. For example, if an answer says an authorized spokesperson communicates a pre-drafted message during a crisis, I'll start thinking, “But what if the message hasn't been approved/drafted yet?” even though the answer already tells me that it has.

The pattern I'm starting to see is that I know a lot of the underlying concepts, but I sometimes choose a valid security answer that solves a slightly different or broader problem instead of answering exactly what ISACA asked.

I've been trying to change my approach from:

“Which answer can I justify?”

to:

“What EXACTLY is this question asking me to accomplish, and which answer most directly accomplishes that?”

I'm also working on separating things like:

accountability vs. responsibility vs. expertise,
risk vs. individual risk components,
activity/metrics vs. actual effectiveness, and
where I currently am in a FIRST/NEXT lifecycle question.

For those who passed CISM:

Did you experience this same problem with the QAE?

How did you make the mental shift from knowing the material to consistently picking ISACA's BEST/MOST/FIRST answer?

Also, how concerned would you be about a cold 47% set with roughly two weeks remaining if the problem seems to be answer selection/application rather than completely not knowing the concepts?

Any advice from people who had a similar issue and eventually passed would be appreciated.

reddit.com
u/Queasy_Piece5446 — 4 days ago
▲ 19 r/isaca

Help with "ISACA" mindset

tried posting to r/cism but got removed by reddit probably due to lack of karma.

want to know if anyone can help me out.

have 18 yoe in it and security. 6 in middle/senior management. want to get my cism and a few other isaca certs to give me the extra umph to make it into senior senior management.

currently have cissp and ccsp certifications (3 and 2 years ago respectively, finished both in about 100 minutes @ 100 questions). started studying for my cism this spring. have watched a couple of youtube and linkedin learning videos (Zerger and Kelly Handerhan(?) respectively.)

have read review guide cover to cover.

have done all 1100 questions in the QAE. Score in the low 70s overall. Best domains are incident response and info security program (high 70/low 80s). worst is info sec governance (65%). do okay in risk (70ish).

have been through the review guide and QAE multiple times. my scores are improving in the QAE but that is not due to concepts sinking in it is due to me recalling what the right answer to a question is that I happened to get wrong. qae usefulness is deteriorating at this point.

I am able to get the questions down to 2 choices but I am consistently making the wrong choice out of the two. I definitely have an "ISACA mentality" disconnect somewhere.

I can definitely see where both of the two choices make sense, but its just not sinking in as to why the choice they make is the "correct" one. many times i'm saying to myself "yeah, but ..." I wish I could post examples from the QAE but I do not want to violate any copyrights. Sometimes the answers just make absolutely zero sense to me. Other times I can see where ISACA is coming from, but the explanation adds words that further refine the answer which, had the word been there, I might have chosen it. As an example there was a question where the answer was "all members" but in the explanation it says "all applicable members". I didn't choose the answer because when I was analyzing the question I said to myself "well, not all members of X are going to be subject to Y"

I am sure where to go to from here. I am running out of time to schedule my exam, I'd like to take it before the exam changes this fall. I'm not sure what else to study or what is going to make things "click" for me.

Help?

reddit.com
u/MyLittleAutisticPony — 5 days ago
▲ 6 r/isaca+1 crossposts

CISA ques (doubt)

Can someone please explain why is it Administrative
Usually it's corrective is what I have heard..
So if we have both the options together should we choose corrective over administrative?

u/Pravallikadondapati — 7 days ago
▲ 20 r/isaca

AI Certs

Does anyone have any opinions on the AI certifications available through ISACA? Any one more valuable than the other? Curious to hear everyone’s thoughts.

Currently have CRISC and CISSP.

reddit.com
u/pineoakmaplee — 10 days ago
▲ 1 r/isaca

CISA

Can I pass CISA if I read and prepare in just 1 month?

My background is technical IT work (2 years) and 1 year of IT Security ?

reddit.com
u/ugandangeek — 10 days ago
▲ 2 r/isaca+1 crossposts

Isaca payment not reflecting

Wanted to book my CISA exam but Isaca has done me dirty. Paid the whole amount for the exam registration but it hasn't reflected on Myisaca site. Been told to raise ticket with them but no response.

What should I do guys. I need to do the paper ASAP.

reddit.com
u/Right_Season_1498 — 10 days ago
▲ 20 r/isaca+1 crossposts

CISA Study Notes Based on CRM 28th Edition | Atul Dhavale posted on the topic

Sharing My CISA Study Notes (Based on CRM – 28th Edition)

I'm pleased to share my personal CISA Study Notes, prepared during my journey towards the CISA certification.
These notes are based on the CISA Review Manual (CRM) – 28th Edition and represent my own understanding and interpretation of the concepts. My objective was to simplify key topics and create a concise revision guide that could also benefit fellow CISA aspirants.
I hope these notes serve as a useful supplementary reference for your exam preparation.

A few important points:
These are personal study notes prepared for learning and revision.
They are not an official ISACA publication and are not affiliated with or endorsed by ISACA.
They should be used only as a supplementary reference alongside the official ISACA study materials.
The official CISA Review Manual and QAE Database remain the primary and authoritative resources for CISA preparation.

I believe that knowledge becomes more valuable when it is shared. If these notes help even a few aspiring professionals in their learning journey, I will consider my effort worthwhile.

Your feedback, suggestions, and corrections are always welcome. They will help improve future versions of these notes.

Wishing every CISA aspirant the very best in their preparation and future career in Information Systems Audit, Governance, Risk Management, and Cyber Security.

#CISA #ISACA #InformationSecurity #CyberSecurity #InformationSystemsAudit #ITAudit #Governance #RiskManagement #GRC #Audit #Learning #KnowledgeSharing #ProfessionalDevelopment

linkedin.com
u/EquivalentMission11 — 13 days ago
▲ 1 r/isaca+1 crossposts

Some tips for the new guy

Hi everyone hope you guys are doing well. I am planning to appear in Cisa exam in the next couple of months and need some guidance from you guys. I have studied all the modules ans have used AI like deepseek and chatgpt to quiz me identify any knowledge gaps and at this pount im pretty much passing mock exams.
I have not explicitly read books regarding this and i wanted to ask will it be enough? I am going to register for the exam in a couple weeks. Should i go for it or should i prepare from other sources.
TIA

reddit.com
u/Individual_Gold_6114 — 14 days ago
▲ 4 r/isaca

CISM Fail -> Success

Recently failed ISACA CISM. Read the official manual and completed QAE 4 times. Felt extremely confident and cause answer why each answer was either right or wrong to every question on QAE (averaged closed to 90% on QAE and practice exams). However, I got provisional fail. The test questions seemed to be worded horribly.

  1. Did anyone else have similar issues with exam (whether pass or fail)?
  2. What sources beyond manual and QAE got exam questions to click and allow you to pass?
reddit.com
u/DeerDawg42 — 13 days ago
▲ 2 r/isaca

Read a book or take the test or ...?

Have CISSP and ISSMP.

Just finished InfoSec CISM course on LinkedIn and Zerger's videos on YouTube.

Do I bother to read the All In One or Mike Chapple books?

Or should I just sit for the exam now? I am used to how ISC2 words their questions, from the samples I saw it looks like ISACA is very similar.

I prefer not to drop $300 on the QAE database if I do not need to. Tempted to just sit for it now and see how I do.

reddit.com
u/__Mr_ED__ — 14 days ago