My first two mock attempts were rough. I kept treating it like a memorization exam, learning clause numbers and control names without connecting them to actual risk scenarios. That approach doesn't work here, the real exam wants you to apply ISMS concepts, not recite them.
What turned it around was switching to scenario-based practice through CertBoosters their questions forced me to think through risk treatment decisions the way an actual implementer would, not just match definitions. Passed on my third-week attempt after that shift. If you're stuck memorizing instead of applying, that's probably your gap too.