ISACA · CISA
Validates expertise in auditing, controlling, monitoring, and assessing an organization's information technology and business systems. The gold standard for IT audit professionals.
Practice Questions
895
≈ 5 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
CISA weights Information Systems Operations and Business Resilience and Protection of Information Assets tied at 26 percent each, followed by Information System Auditing Process and Governance and Management of IT tied at 18 percent each, and Information Systems Acquisition, Development and Implementation at 12 percent. This practice bank of 895 questions is built to match that split, so operations, resilience, and asset-protection scenarios get proportionally more coverage than any single domain.
On test day you face 150 questions in 4 hours, scored on a scale of 200 to 800, and you need 450 or higher to pass. Every question is multiple choice with one best answer among four options, often scenario-based rather than pure factual recall — CISA tests audit judgment, not just knowledge of controls.
As with ISACA's other certifications, passing the exam is only part of it. Full CISA certification also requires 5 or more years of IS or IT audit, control, assurance, or security work experience within CISA job practice areas, earned within the 10 years before you apply (experience waivers cover up to 3 years). If you don't yet have the experience, ISACA offers a CISA Associate designation in the meantime. The exam costs $575 for members and $760 for non-members, plus a $50 application fee once you certify. Renewal requires 120 CPE hours over a 3-year cycle, adherence to ISACA's auditing standards, and an annual maintenance fee ($45 members, $85 non-members). Start with the 30 free questions, then work through the full 895-question bank until your accuracy holds steady across all five domains.
The Certified Information Systems Auditor (CISA) is ISACA's flagship certification and the globally recognized standard for IT audit, control, assurance, and security professionals. First introduced in 1978, the credential validates a professional's ability to assess vulnerabilities, report on compliance, and institute controls within an enterprise — covering the full scope of information systems auditing, governance, acquisition, operations, and asset protection. More than 151,000 professionals worldwide currently hold the CISA designation, and it has been shortlisted for Best Professional Certification Program by SC Awards Europe and SC Awards North America in 2025.
The certification is specifically designed to demonstrate competency across five critical job practice domains: the IS auditing process, IT governance and management, IS acquisition and development, IS operations and business resilience, and protection of information assets. It has evolved to address emerging technologies including artificial intelligence, cloud computing, blockchain, and IoT security, ensuring holders remain relevant in a rapidly changing threat landscape.
CISA is designed for mid-career to senior IT and information security professionals who perform or manage audit, control, assurance, or security functions. Typical roles include IT auditors, internal auditors, IS audit managers, IT risk and compliance managers, security consultants, and IT governance officers. The certification is particularly valuable for professionals at organizations subject to regulatory oversight — such as financial services, healthcare, and government — where IT audit and compliance functions are critical.
Candidates are not required to meet experience requirements before sitting the exam, making it accessible to professionals who are transitioning into IS audit roles. However, full certification requires five or more years of professional experience in IS auditing, control, or security, making it most appropriate for those with a solid foundation in IT operations, security, or internal audit.
ISACA has no formal educational prerequisites for sitting the CISA exam itself — any candidate may register and attempt the exam regardless of background. However, to achieve full CISA certification after passing, candidates must demonstrate a minimum of five years of professional work experience in information systems auditing, control, assurance, or security. This experience must be verified and submitted within five years of passing the exam.
ISACA offers experience waivers of up to three years for candidates who hold a relevant university degree (two-year or four-year), a graduate degree in IS or IT, or other recognized certifications such as CISM, CISSP, or CRISC. Recommended knowledge before attempting the exam includes a solid understanding of IT infrastructure, information security fundamentals, risk management frameworks (such as COBIT or NIST), and basic business auditing principles. Most successful candidates have at least two to three years of hands-on IT or audit experience prior to sitting the exam.
The CISA exam consists of 150 multiple-choice questions, all with four answer options (A, B, C, D), to be completed in 240 minutes (4 hours). Questions are a mix of knowledge-based items testing recall of frameworks and standards, and scenario-based questions — which typically comprise 60–70% of the exam — requiring candidates to apply audit principles to realistic workplace situations. A small number of questions are unscored research items used for future exam development and do not affect a candidate's score.
The exam is delivered via computer-based testing (CBT) at authorized PSI testing centers worldwide, or as a remotely proctored online exam. Scores are reported on a scale of 200 to 800, with a passing score of 450. The scaled scoring model accounts for question difficulty, so harder questions carry more weight. There is no penalty for incorrect answers. Preliminary pass/fail results are available immediately upon exam completion, with official scores typically posted to a candidate's ISACA account within 5–7 business days. Candidates who do not pass must wait 30 days before retaking and may sit the exam up to four times within a rolling 12-month period.
CISA consistently ranks among the highest-paying IT certifications globally. ISACA reports that CISA holders earn an average annual salary of US$149,000, and 22% of certified professionals report receiving a pay increase following certification. The credential opens doors to senior roles including IT Audit Manager, IS Audit Director, Chief Information Security Officer (CISO), IT Risk Manager, and Compliance Officer across industries with heavy regulatory requirements such as financial services, healthcare, government, and critical infrastructure.
The CISA's international recognition — backed by ISACA's global presence and more than four decades of credentialing history — makes it particularly valuable for professionals working in multinational organizations or seeking roles across different regulatory jurisdictions. Compared to alternatives such as the Certified Internal Auditor (CIA) or CRISC, CISA's specific focus on IS audit and control gives it a distinct advantage in technology-forward audit functions. Seventy percent of CISA holders report measurable on-the-job improvement after certification, reflecting the credential's direct applicability to daily audit and governance responsibilities.
5 sample questions with answers and explanations. The full bank has 895 questions, enough for 5 full-length practice exams.
Preview — answers shown1. A healthcare organization is planning to migrate patient records to a cloud-based SaaS electronic health record system. The IS auditor must advise on data security responsibilities under the cloud shared responsibility model. Which security responsibility will remain with the healthcare organization regardless of the SaaS service model? (Select two!)
Multiple correct answersExplanation
Under the cloud shared responsibility model, the customer always retains responsibility for data classification, determining who should have access to data, and configuring user access controls regardless of the service model. In SaaS environments, the cloud provider is responsible for physical infrastructure security, operating system management, and application security. However, customers must still determine appropriate data classifications, make access management decisions, configure user permissions, and ensure proper authentication settings within the SaaS application. These responsibilities cannot be transferred to the provider.
2. Meridian Insurance Group is evaluating their IT governance structure against COBIT 2019 principles. The board of directors wants to ensure proper oversight of IT investments and value delivery. Which COBIT governance domain objective specifically addresses the board's responsibility for ensuring stakeholder needs are identified and IT delivers agreed-upon value? (Select one!)
Explanation
EDM02 Ensured Benefits Delivery is the COBIT 2019 governance objective that addresses optimizing the contribution to business value from IT-enabled investments. This objective ensures stakeholder needs are captured, IT delivers value, and performance is monitored. EDM objectives represent governance activities performed by the board, while APO, BAI, DSS, and MEA objectives represent management activities. APO02 focuses on strategy alignment at the management level. MEA01 addresses performance monitoring but is a management objective. BAI01 concerns program management implementation rather than governance oversight of value delivery.
3. Westbrook Manufacturing's IS auditor is evaluating hash controls in batch processing. The accounts receivable system processes customer invoices in daily batches. The system calculates and compares totals of customer account numbers before and after processing. What type of control is being described, and what is its PRIMARY purpose? (Select one!)
Explanation
A hash total is the sum of a non-meaningful numeric field, such as customer account numbers, used solely as a control mechanism to verify that all records were processed correctly. Unlike financial totals that have inherent business meaning, hash totals have no significance outside their control purpose. Comparing hash totals before and after processing detects whether records were lost, duplicated, or altered during batch processing. If the totals match, all records were likely processed correctly. Document counts verify the number of documents but not data integrity. Financial totals sum monetary values that have business meaning. Batch totals typically refer to record counts. Hash totals are unique because the calculated sum of customer account numbers has no business significance except as a processing verification control.
4. Bayside Healthcare Network's disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for the electronic health records system. The current backup strategy performs full backups nightly at midnight and differential backups every 6 hours. A disaster occurs at 11:00 AM. Which statement BEST describes the situation? (Select one!)
Explanation
The RPO of 1 hour means the maximum acceptable data loss is one hour of transactions. With differential backups every 6 hours, a disaster at 11:00 AM would result in restoring from the 6:00 AM differential backup, losing 5 hours of data. This significantly exceeds the 1-hour RPO requirement. To meet a 1-hour RPO, backups or replication must occur at least hourly. The RTO concerns recovery time, not data loss, and cannot be determined solely from backup frequency. Differential backups being faster than incremental for restoration is true but irrelevant to whether the RPO is met. The auditor should recommend more frequent backups or continuous data replication to meet the stated RPO.
5. Adatum Financial's IS auditor is reviewing the organization's backup strategy for the core banking database. The recovery point objective requires no more than one hour of data loss, and the system generates approximately 50GB of new data daily. Which backup approach would BEST meet the RPO requirement while minimizing backup storage and network bandwidth consumption? (Select one!)
Explanation
Daily full backups with hourly incremental backups best meets the one-hour RPO requirement while minimizing storage and bandwidth consumption. Incremental backups capture only changes since the last backup (whether full or incremental), resulting in smaller backup sizes and faster completion times. With hourly incrementals, maximum data loss is limited to approximately one hour. Weekly full backups alone would result in up to one week of data loss. Daily full backups alone could lose up to 24 hours of data. Differential backups capture all changes since the last full backup, making each subsequent differential progressively larger throughout the day, consuming more storage and bandwidth than incrementals.
150 questions in 4 hours, all multiple choice with one best answer among four options.
450 or higher on ISACA’s scaled score of 200 to 800.
$575 for ISACA members, $760 for non-members, plus a $50 application fee once you certify.
Information Systems Operations and Business Resilience (26%), Protection of Information Assets (26%), Information System Auditing Process (18%), Governance and Management of IT (18%), and Information Systems Acquisition, Development and Implementation (12%).
Yes — passing the exam alone is not enough. You need 5 or more years of IS/IT audit, control, assurance, or security experience within CISA job practice areas, earned in the 10 years before applying. Experience waivers cover up to 3 years.
ISACA offers a CISA Associate designation for candidates who pass the exam but haven’t yet met the experience requirement.
Yes. Renewal requires 120 CPE hours over a 3-year cycle, adherence to ISACA’s auditing standards, and an annual maintenance fee ($45 members, $85 non-members).
ISACA does not publish a pass rate. It tests audit judgment across scenario-based questions rather than pure control recall, which is where most unprepared candidates lose points.
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
$17.99
One-time access to this exam