I've been chasing this certification for almost two years now and honestly considered giving up after my second fail. Both times I scored in the high 60s on risk response, which is maddening because that's supposed to be my wheelhouse — I work in IT risk management. My study approach was clearly broken though. I was treating it like a technical exam and kept getting burned by the ISACA way of thinking, where the "right" answer is sometimes the one that feels counterintuitive.
What turned things around was finding a solid CRISC practice test bank that actually explained the reasoning behind each answer choice, not just flagged correct vs. wrong. Combined with a proper study guide that walked through domain-by-domain frameworks, I finally started internalizing how ISACA frames risk ownership and control selection. I also gave myself a strict 10-week schedule: 8 hours a week minimum, no exceptions.
Passed with a 470 last month. Happy to share specifics on what resources I used and my exam tips if anyone's grinding through this right now.