ISACA · CISA
Validates expertise in auditing, controlling, monitoring, and assessing an organization's information technology and business systems. The gold standard for IT audit professionals.
Practice Questions
895
≈ 5 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
Use this CISA practice exam to prepare for Certified Information Systems Auditor (CISA) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 895 questions for ISACA CISA, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The Certified Information Systems Auditor (CISA) is ISACA's flagship certification and the globally recognized standard for IT audit, control, assurance, and security professionals. First introduced in 1978, the credential validates a professional's ability to assess vulnerabilities, report on compliance, and institute controls within an enterprise — covering the full scope of information systems auditing, governance, acquisition, operations, and asset protection. More than 151,000 professionals worldwide currently hold the CISA designation, and it has been shortlisted for Best Professional Certification Program by SC Awards Europe and SC Awards North America in 2025.
The certification is specifically designed to demonstrate competency across five critical job practice domains: the IS auditing process, IT governance and management, IS acquisition and development, IS operations and business resilience, and protection of information assets. It has evolved to address emerging technologies including artificial intelligence, cloud computing, blockchain, and IoT security, ensuring holders remain relevant in a rapidly changing threat landscape.
CISA is designed for mid-career to senior IT and information security professionals who perform or manage audit, control, assurance, or security functions. Typical roles include IT auditors, internal auditors, IS audit managers, IT risk and compliance managers, security consultants, and IT governance officers. The certification is particularly valuable for professionals at organizations subject to regulatory oversight — such as financial services, healthcare, and government — where IT audit and compliance functions are critical.
Candidates are not required to meet experience requirements before sitting the exam, making it accessible to professionals who are transitioning into IS audit roles. However, full certification requires five or more years of professional experience in IS auditing, control, or security, making it most appropriate for those with a solid foundation in IT operations, security, or internal audit.
ISACA has no formal educational prerequisites for sitting the CISA exam itself — any candidate may register and attempt the exam regardless of background. However, to achieve full CISA certification after passing, candidates must demonstrate a minimum of five years of professional work experience in information systems auditing, control, assurance, or security. This experience must be verified and submitted within five years of passing the exam.
ISACA offers experience waivers of up to three years for candidates who hold a relevant university degree (two-year or four-year), a graduate degree in IS or IT, or other recognized certifications such as CISM, CISSP, or CRISC. Recommended knowledge before attempting the exam includes a solid understanding of IT infrastructure, information security fundamentals, risk management frameworks (such as COBIT or NIST), and basic business auditing principles. Most successful candidates have at least two to three years of hands-on IT or audit experience prior to sitting the exam.
The CISA exam consists of 150 multiple-choice questions, all with four answer options (A, B, C, D), to be completed in 240 minutes (4 hours). Questions are a mix of knowledge-based items testing recall of frameworks and standards, and scenario-based questions — which typically comprise 60–70% of the exam — requiring candidates to apply audit principles to realistic workplace situations. A small number of questions are unscored research items used for future exam development and do not affect a candidate's score.
The exam is delivered via computer-based testing (CBT) at authorized PSI testing centers worldwide, or as a remotely proctored online exam. Scores are reported on a scale of 200 to 800, with a passing score of 450. The scaled scoring model accounts for question difficulty, so harder questions carry more weight. There is no penalty for incorrect answers. Preliminary pass/fail results are available immediately upon exam completion, with official scores typically posted to a candidate's ISACA account within 5–7 business days. Candidates who do not pass must wait 30 days before retaking and may sit the exam up to four times within a rolling 12-month period.
CISA consistently ranks among the highest-paying IT certifications globally. ISACA reports that CISA holders earn an average annual salary of US$149,000, and 22% of certified professionals report receiving a pay increase following certification. The credential opens doors to senior roles including IT Audit Manager, IS Audit Director, Chief Information Security Officer (CISO), IT Risk Manager, and Compliance Officer across industries with heavy regulatory requirements such as financial services, healthcare, government, and critical infrastructure.
The CISA's international recognition — backed by ISACA's global presence and more than four decades of credentialing history — makes it particularly valuable for professionals working in multinational organizations or seeking roles across different regulatory jurisdictions. Compared to alternatives such as the Certified Internal Auditor (CIA) or CRISC, CISA's specific focus on IS audit and control gives it a distinct advantage in technology-forward audit functions. Seventy percent of CISA holders report measurable on-the-job improvement after certification, reflecting the credential's direct applicability to daily audit and governance responsibilities.
5 sample questions with answers and explanations. The full bank has 895 questions, enough for 5 full-length practice exams.
Preview — answers shown1. Contoso Financial Services is conducting an IS audit of its loan processing system. The IS auditor determines that the audit risk should be set at 5%. After assessment, inherent risk is evaluated at 80% and control risk at 50%. What detection risk level should the IS auditor target to achieve the desired audit risk? (Select one!)
Explanation
Using the audit risk formula DR = AR / (IR × CR), detection risk = 0.05 / (0.80 × 0.50) = 0.05 / 0.40 = 0.125 or 12.5%. This calculation determines how much testing the auditor needs to perform—the lower the detection risk target, the more extensive the testing required. A 6.25% calculation would result from incorrect formula application. A 20% result would occur if using AR / IR only. A 40% result would mean simply dividing by control risk alone without considering inherent risk in the denominator calculation.
2. Cascade Technology Solutions' IS auditor is reviewing the organization's implementation of control types. The company implemented the following controls: automated system logs that record all privileged user activities, security awareness training for all employees, cable locks securing laptop computers to desks, and warning banners displayed at system login. Which classification correctly matches each control to its type? (Select one!)
Explanation
System logs are detective-technical controls because they record events for later review to identify unauthorized activities, implemented through technology. Security awareness training is preventive-administrative because it aims to prevent security incidents through education and policy compliance before problems occur. Cable locks are preventive-physical controls because they physically prevent laptop theft. Warning banners are deterrent-technical controls because they discourage unauthorized access by displaying warnings through technology, but they do not prevent access. The key distinction is that deterrent controls warn or discourage while preventive controls actually stop the action from occurring.
3. Tidewater Logistics Corporation uses a relational database to manage its warehouse inventory. During an audit of the database design, the IS auditor notes that the inventory table contains a product category description that depends on the product category code, which itself depends on the product ID (the primary key). This represents what type of database normalization issue? (Select one!)
Explanation
Third normal form (3NF) violations occur when a non-key attribute depends on another non-key attribute, creating a transitive dependency. In this case, the category description depends on the category code, which depends on the product ID, creating a chain of dependencies where one non-key attribute determines another. First normal form addresses atomic values and repeating groups. Second normal form addresses partial dependencies where non-key attributes depend on part of a composite primary key. Boyce-Codd normal form addresses issues where every determinant is a candidate key.
4. Northwind Financial's IS auditor is reviewing data privacy controls to ensure GDPR compliance. The audit checklist includes verification that a specific individual has been designated to oversee data protection compliance, handle data subject requests, and serve as the contact point for supervisory authorities. Which role is the auditor verifying has been established? (Select one!)
Explanation
The Data Protection Officer (DPO) is a role mandated by GDPR for certain organizations to oversee data protection strategy and implementation, handle data subject requests, serve as the contact point for supervisory authorities, and ensure GDPR compliance. The responsibilities described align specifically with the DPO role. Data Owners are typically business executives responsible for data classification and protection decisions but not regulatory compliance oversight. Data Custodians are IT personnel responsible for technical data handling, storage, and backups. The Chief Information Security Officer oversees overall security strategy but the DPO role is specifically focused on data privacy and GDPR compliance.
5. An organization is implementing role-based access control (RBAC) for their enterprise resource planning system. The IS auditor is reviewing the access control design. Which characteristic BEST demonstrates proper RBAC implementation? (Select one!)
Explanation
Role-based access control assigns users to roles based on their job functions, and permissions are granted to roles rather than individual users. This approach simplifies administration and ensures consistent access provisioning based on job responsibilities. Users granting access to others describes discretionary access control (DAC). Access based on security clearance levels describes mandatory access control (MAC). Individual configuration of user access rights is a manual process that does not leverage the role-based approach and would be administratively burdensome in large environments.
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
$17.99
One-time access to this exam