So I finally passed CISA last month after two brutal failures and I'm still kind of in shock. My first two attempts I was scoring around 425-440 on the actual exam (passing is 450), so I was close but not close enough. The problem was I kept studying the wrong way — just reading the ISACA manual cover to cover like it was a textbook, which is honestly useless without practice questions.
What changed everything for me was switching to a CISA practice test approach and doing minimum 30 questions a day with full explanations, not just checking if I got it right. Domain 2 (Governance and Management of IT) and Domain 5 (Protection of Information Assets) were my weak spots — if yours are too, focus there hard. I also picked up a solid study guide that broke down the "IT auditor mindset" concept, because CISA isn't testing what you'd DO, it's testing what the BEST PRACTICE answer is.
Anyone else have specific domain struggles they overcame? Happy to share my 8-week study plan if it helps. Took me about 200 hours total across all three attempts, which is humbling to admit.