CISA Practice Exam.
Free practice test — 24 verified questions, instant feedback.
Know the exam before you sit it
the facts most prep sites buryEvery free resource for this exam
family overview →Get a free CISA study plan
A week-by-week plan plus new practice questions, straight to your inbox.
Frequently asked questions
How much does the CISA exam cost and how long do I have to test?
The CISA exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Once you register, your exam eligibility period is 6 months from the date of registration, so plan your study timeline to sit for the exam within that window. If you don't schedule and take the exam before the eligibility period ends, you would generally need to re-register — so it's smart to only register once you're confident you can be exam-ready within six months.
How is the CISA exam structured and what score do I need to pass?
The CISA exam consists of 150 questions and is built around 5 job practice domains, with a total testing time of 240 minutes (4 hours). To pass, you need a scaled score of 450 or higher. With 150 questions across 240 minutes, that works out to roughly 1.6 minutes per question on average — a comfortable pace that still leaves time to flag and review tougher items before you submit.
Which CISA domains should I study the most?
The five content domains are the Information Systems Auditing Process, Governance and Management of Information Technology, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. They aren't weighted equally: Domain 1 (Information Systems Auditing Process) is 18%, Domain 2 (Governance and Management of IT) is 18%, Domain 3 (IS Acquisition, Development and Implementation) is 12%, Domain 4 (IS Operations and Business Resilience) is 26%, and Domain 5 (Protection of Information Assets) is 26%. Because Domains 4 and 5 together account for 52% of the exam content, prioritizing those two areas gives you the highest return on your study time, while Domain 3 at just 12% carries the least weight.
After I pass the exam, how do I get certified and keep the credential?
Passing the exam is not the final step. Candidates have 5 years from the date of passing the exam to apply for CISA certification, so don't let that window lapse after you pass. Once certified, professionals must adhere to ISACA's Continuing Professional Education (CPE) Policy to retain the credential — meaning CISA is not a one-and-done certification but requires ongoing professional education to stay active. It also helps to know the exam is current: the updated CISA exam became available on 1 August 2024 and emphasizes risk, security and controls related to disruptive technologies and emerging IT audit practices, so study from up-to-date materials aligned to that revision.
Browse all questions & answers
1. During the planning phase of an IS audit, an IS auditor discovers that a business process has never been formally risk-assessed. What should the auditor do FIRST?
- A. Perform a risk assessment of the process to determine audit scope and priority
- B. Exclude the process from the audit since no risk assessment exists
- C. Immediately report the missing risk assessment to the audit committee as a finding
- D. Ask management to sign off on the process as low risk before proceeding
Show answer & explanation
Answer: A
A risk-based audit approach requires the auditor to assess risk to determine scope, depth, and resource allocation; performing the assessment lets the auditor make an informed scoping decision. Excluding the process ignores potential exposure, reporting prematurely skips the auditor's own analysis, and asking management to self-certify risk undermines auditor independence and objectivity.2. An IS auditor is evaluating evidence gathered during fieldwork. Which characteristic of evidence is MOST important when the auditor must rely on it to support a significant audit finding?
- A. The evidence was easy and inexpensive to obtain
- B. The evidence is sufficient, reliable, and relevant to the audit objective
- C. The evidence was provided directly by the process owner
- D. The evidence confirms the auditor's initial expectations
Show answer & explanation
Answer: B
Audit evidence must be sufficient (enough in quantity), reliable (from a trustworthy source, ideally independently corroborated), and relevant (directly related to the objective) to support a conclusion. Ease of collection is irrelevant to quality, evidence solely from the process owner may lack independence, and evidence should be evaluated objectively rather than selected to confirm preconceptions, which introduces bias.3. An IS auditor finds that a control was operating effectively for 10 of 12 months tested, with two months showing exceptions due to a since-corrected configuration error. What is the MOST appropriate conclusion?
- A. The control can be rated fully effective because it is now corrected
- B. The control exceptions should be reported along with root cause, remediation, and residual risk during the exception period
- C. The finding should be dropped since the issue is already fixed
- D. The sample size is too small to draw any conclusion
Show answer & explanation
Answer: B
Auditors must report control exceptions even when subsequently remediated, because the risk existed during the exception window and stakeholders need to understand root cause and residual exposure. Marking it fully effective or dropping the finding hides real risk that occurred, and a 12-month sample with two exceptions is generally sufficient to support a conclusion, not too small.4. Which sampling method is MOST appropriate when an IS auditor wants every item in the population to have an equal chance of selection, without bias from the auditor's judgment?
- A. Judgmental sampling
- B. Statistical (random) sampling
- C. Haphazard sampling
- D. Discovery sampling only
Show answer & explanation
Answer: B
Statistical sampling uses random selection so every item has a known, equal probability of being chosen, allowing the auditor to mathematically project results and evaluate sampling risk. Judgmental sampling relies on auditor discretion and introduces bias, haphazard sampling is not truly random and cannot be statistically evaluated, and discovery sampling is a specific technique aimed at detecting at least one occurrence of a critical exception, not general unbiased selection.5. During an audit, management disagrees with a draft finding and provides additional documentation not previously available to the auditor. What is the BEST course of action?
- A. Ignore the new documentation since the audit fieldwork is complete
- B. Evaluate the new evidence objectively and revise the finding if warranted before finalizing the report
- C. Remove the finding automatically to maintain a good working relationship with management
- D. Escalate immediately to the audit committee without reviewing the documentation
Show answer & explanation
Answer: B
An IS auditor must remain objective and consider all relevant evidence before finalizing conclusions; if new documentation is credible and relevant it should be evaluated and the finding adjusted as warranted. Ignoring evidence or removing a finding to preserve relationships compromises independence and integrity, and escalating without review skips due professional care.6. An organization's internal audit charter grants the CISA-certified auditor authority to review all IT systems but is silent on access to third-party service providers used for payroll processing. What is the BEST way to address this gap?
- A. Assume authority extends automatically to any vendor touching company data
- B. Update the audit charter or contractual right-to-audit clauses to explicitly cover third-party providers
- C. Rely solely on the vendor's own internal audit reports without independent verification
- D. Decline to audit any process that involves a third party
Show answer & explanation
Answer: B
Audit authority should be clearly documented; when third parties are in scope, the charter or vendor contracts should include explicit right-to-audit clauses so the scope of authority is unambiguous. Assuming authority is risky without documentation, relying only on vendor self-reported audits lacks independent assurance, and simply declining to audit ignores real risk in outsourced processes.7. An IT steering committee is reviewing whether a proposed enterprise system project aligns with the organization's strategic objectives. This activity is a core function of which governance concept?
- A. IT service level management
- B. IT governance and strategic alignment
- C. Change management
- D. Configuration management
Show answer & explanation
Answer: B
IT governance ensures IT investments and initiatives are aligned with and support enterprise strategic objectives, typically overseen by bodies like an IT steering committee. Service level management concerns ongoing service performance agreements, change management concerns controlled implementation of changes, and configuration management tracks the state of IT assets and configurations, none of which address strategic project alignment.8. A company's IT risk register lists a risk as 'high likelihood, high impact' but no owner or treatment plan is assigned. From a governance perspective, what is the MOST significant concern?
- A. The risk register format does not use a heat map
- B. Without an assigned owner and treatment plan, accountability for managing the risk to an acceptable level is unclear
- C. The risk should be removed from the register since it lacks an owner
- D. High likelihood and high impact risks cannot coexist in a valid register
Show answer & explanation
Answer: B
Effective risk governance requires that each identified risk have a clearly assigned owner accountable for treatment decisions and monitoring; absent this, high risks may go unmanaged. Heat-map formatting is a presentation preference, not a control gap; removing an unmanaged risk from the register hides rather than resolves the exposure; and high-likelihood/high-impact risks are a valid and common combination requiring urgent attention.9. Which of the following BEST describes the purpose of segregation of duties (SoD) within an IT organization's governance structure?
- A. To reduce the number of employees required to run IT operations
- B. To ensure no single individual can both perform and conceal an error or irregularity through incompatible functions
- C. To guarantee compliance with all software licensing agreements
- D. To eliminate the need for management review of transactions
Show answer & explanation
Answer: B
Segregation of duties splits incompatible responsibilities (e.g., initiating, authorizing, recording, and reconciling) across different people so that no one person can both commit and conceal an error or fraudulent act without collusion. It is not aimed at reducing headcount, does not itself address software licensing compliance, and does not eliminate the need for management oversight — SoD complements, not replaces, review.10. An organization outsources its data center operations. Under an effective IT governance framework, which statement about accountability is MOST accurate?
- A. Accountability for the outsourced function transfers entirely to the service provider
- B. The organization retains ultimate accountability for outcomes even though operational responsibility is delegated to the provider
- C. No governance oversight is needed once a contract is signed
- D. Accountability is shared equally and cannot be defined further
Show answer & explanation
Answer: B
A foundational governance principle is that accountability cannot be outsourced — while day-to-day operational responsibility can be delegated to a third party, the organization remains ultimately accountable for outcomes, risk, and compliance. Believing accountability transfers entirely, assuming no oversight is needed post-contract, or leaving accountability undefined all create governance gaps and regulatory exposure.11. A CIO wants to measure whether IT investments are delivering expected business value. Which approach BEST supports this governance objective?
- A. Tracking IT spend against budget only
- B. Establishing a benefits realization framework with defined metrics tied to business objectives
- C. Counting the number of IT projects completed each year
- D. Relying on vendor satisfaction surveys
Show answer & explanation
Answer: B
Value delivery, a key governance focus area, requires linking IT investments to measurable business benefits through a defined benefits realization framework, not just financial or activity metrics. Tracking spend to budget measures cost control, not value; counting completed projects measures throughput, not benefit; and vendor satisfaction surveys reflect the vendor relationship, not business value delivered to the organization.12. An IS auditor is reviewing a new system development project and notes that user acceptance testing (UAT) was skipped due to schedule pressure. What is the MOST significant risk of this omission?
- A. The project may be delivered slightly under budget
- B. Business requirements may not be validated, increasing the risk the system fails to meet user needs in production
- C. The development team will need to write less code
- D. System documentation will automatically be more accurate
Show answer & explanation
Answer: B
UAT is the phase where business users validate that the system meets functional requirements before go-live; skipping it significantly raises the risk of deploying a system that does not meet actual business needs, potentially requiring costly post-implementation fixes. The other options describe unrelated or implausible outcomes not caused by omitting UAT.13. During a post-implementation review, an IS auditor finds that the project's original business case benefits were never re-measured after go-live. What should the auditor recommend?
- A. No action is needed since the system is functioning technically
- B. Perform a benefits realization assessment comparing actual outcomes to the original business case
- C. Cancel the project retroactively
- D. Rewrite the business case to match whatever was delivered
Show answer & explanation
Answer: B
Post-implementation review should include comparing actual realized benefits against the original business case to confirm the investment delivered expected value and to capture lessons learned; technical functionality alone does not confirm business value was achieved. Retroactive cancellation is not meaningful after go-live, and rewriting the business case to match delivery defeats the purpose of accountability and would misrepresent the original justification.14. Which system development life cycle (SDLC) phase is MOST critical for identifying and documenting security requirements to avoid costly rework later?
- A. Requirements definition
- B. Post-implementation support
- C. Final user training
- D. Decommissioning
Show answer & explanation
Answer: A
Security requirements should be defined during the requirements phase so that security is designed into the system from the start; addressing security late in the lifecycle is far more expensive and often incomplete. Post-implementation support and user training occur after the system is built and cannot retroactively embed foundational design decisions, and decommissioning addresses end-of-life disposal, not development.15. An organization is migrating from a legacy system to a new ERP. Which data conversion control provides the STRONGEST assurance that all records were migrated completely and accurately?
- A. A verbal confirmation from the project manager that migration is complete
- B. Independent reconciliation of record counts and control totals between the old and new systems
- C. Reviewing the migration tool's marketing documentation
- D. Confirming the new system's user interface looks similar to the old one
Show answer & explanation
Answer: B
Reconciling record counts and control totals (e.g., financial balances, transaction counts) between source and target systems provides objective, verifiable evidence of completeness and accuracy of data conversion. Verbal confirmation lacks evidentiary support, vendor marketing material is not audit evidence of what actually occurred, and UI similarity says nothing about underlying data integrity.16. A project team wants to select a system development methodology that allows for iterative delivery and frequent stakeholder feedback on a project with evolving requirements. Which approach is MOST appropriate?
- A. Traditional waterfall model with a single delivery at project end
- B. Agile methodology with iterative sprints and regular stakeholder review
- C. A big-bang cutover with no phased releases
- D. A methodology with no defined requirements process
Show answer & explanation
Answer: B
Agile methodologies use short iterative cycles (sprints) with frequent stakeholder feedback, making them well suited to projects with evolving or unclear requirements. Waterfall assumes requirements are fixed upfront and delivers only at the end, a big-bang cutover concerns deployment strategy rather than requirements evolution, and a methodology lacking any requirements process would create significant risk regardless of requirement stability.17. An IS auditor reviewing change management for a production ERP system notes that emergency changes are deployed without prior testing but are documented after the fact. What is the BEST recommendation?
- A. Eliminate the emergency change process entirely
- B. Require post-implementation review and retrospective approval with documented justification for each emergency change
- C. Allow emergency changes to bypass all documentation requirements permanently
- D. Require the same multi-week testing cycle for emergency changes as standard changes
Show answer & explanation
Answer: B
Emergency change processes exist precisely because full standard testing isn't feasible under time pressure, but a well-controlled process requires retrospective review, approval, and documented justification to ensure accountability and to identify any issues introduced. Eliminating the process removes a legitimate business need, permanently skipping documentation removes accountability entirely, and requiring standard multi-week testing defeats the purpose of an emergency process.18. An organization's business continuity plan (BCP) specifies a recovery time objective (RTO) of 4 hours for its order-processing system. What does this RTO represent?
- A. The maximum acceptable amount of data loss measured in time
- B. The maximum acceptable time the system can be unavailable before causing unacceptable business impact
- C. The frequency at which backups must be taken
- D. The total time allotted for annual disaster recovery testing
Show answer & explanation
Answer: B
Recovery Time Objective (RTO) defines the maximum tolerable downtime — how quickly a system or process must be restored after a disruption to avoid unacceptable business impact. Maximum acceptable data loss is described by the Recovery Point Objective (RPO), not RTO; backup frequency is a control used to help meet RPO/RTO targets but isn't itself the RTO; and DR test duration is a separate operational planning detail.19. During a review of an organization's incident management process, an IS auditor finds that security incidents are resolved but root cause analysis is rarely performed. What is the MOST significant long-term risk?
- A. Increased helpdesk ticket volume in the short term only
- B. Recurring incidents from the same underlying cause, since the true source of the problem is never addressed
- C. Faster incident closure times going forward
- D. Improved compliance with service level agreements
Show answer & explanation
Answer: B
Without root cause analysis, underlying weaknesses that caused an incident remain unaddressed, leading to recurrence of the same or similar incidents — this is the core rationale for problem management within IT service management. Ticket volume in isolation isn't the central risk, and neither faster closure nor better SLA compliance would logically result from skipping root cause analysis; if anything, recurring incidents tend to degrade both.20. An organization performs full backups weekly and incremental backups daily. If a server fails on a Thursday (3 days after the last full backup), what is required to fully restore data to the most recent point?
- A. Only the most recent incremental backup
- B. The last full backup plus each incremental backup taken since, applied in sequence
- C. Only the original full backup from initial system setup
- D. No backups are needed if the system has RAID storage
Show answer & explanation
Answer: B
With a full-plus-incremental backup strategy, restoring to the most recent point requires the last full backup followed by every incremental backup taken since, applied in chronological order, because each incremental captures only changes since the previous backup. Using only the latest incremental omits earlier changes, the original setup backup is far too outdated, and RAID protects against disk-level hardware failure but does not substitute for backups against data corruption, deletion, or logical errors.21. Which of the following is the PRIMARY reason organizations conduct periodic disaster recovery (DR) testing rather than relying solely on a documented DR plan?
- A. To satisfy an annual budget requirement
- B. To validate that the plan actually works in practice and to identify gaps before a real disaster occurs
- C. To reduce the need for a documented plan going forward
- D. To replace the need for offsite data backups
Show answer & explanation
Answer: B
A documented plan alone does not guarantee recoverability; testing validates assumptions, uncovers gaps (e.g., outdated contact lists, untested dependencies, insufficient capacity), and builds team readiness, which is the primary rationale for DR testing. Budget justification is not the driving purpose, testing does not eliminate the need for documentation, and it does not substitute for maintaining offsite backups, which testing itself typically relies on.22. An IS auditor reviewing capacity management notes that a critical database server has consistently run at 95% CPU utilization for the past quarter with no capacity plan in place. What is the MOST significant risk?
- A. The server may be under warranty expiration soon
- B. Performance degradation or an outage as demand grows, potentially disrupting critical business operations
- C. The vendor may increase software licensing costs
- D. Users will need additional training on the application
Show answer & explanation
Answer: B
Sustained near-maximum utilization without a capacity plan risks performance degradation or outright failure as workload grows further, directly threatening availability of a critical business system — the core concern of capacity and availability management. Warranty status, licensing costs, and user training are unrelated secondary considerations that do not address the immediate operational risk of resource exhaustion.23. Which access control model grants permissions based on a user's assigned job function rather than granting permissions to each individual user directly?
- A. Discretionary access control (DAC)
- B. Role-based access control (RBAC)
- C. Mandatory access control (MAC)
- D. Rule-based routing
Show answer & explanation
Answer: B
RBAC assigns permissions to roles that correspond to job functions, and users inherit access by being assigned to a role, simplifying administration and supporting least privilege and segregation of duties. DAC lets resource owners grant access at their discretion to individual users, MAC enforces access based on fixed security labels/classifications set by a central authority rather than job function, and 'rule-based routing' is a networking concept, not an access control model.24. An IS auditor discovers that terminated employees' network accounts remain active for an average of 30 days after departure. What is the MOST significant risk this presents?
- A. Increased software licensing costs only
- B. Unauthorized access to systems and data by former employees or others using their still-active credentials
- C. Slower network performance due to unused accounts
- D. Increased helpdesk password reset requests
Show answer & explanation
Answer: B
Active accounts for departed employees represent a direct access control failure, creating risk of unauthorized access, data theft, or sabotage by the former employee or anyone who obtains their credentials — this is why timely deprovisioning is a fundamental logical access control. Licensing cost, network performance, and helpdesk volume are minor or unrelated secondary effects compared to the core security exposure.