ISACA · CISA
Validates expertise in auditing, controlling, monitoring, and assessing an organization's information technology and business systems. The gold standard for IT audit professionals.
Practice Questions
895
≈ 5 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Oct 2026
CISA tests whether you can plan, execute, report, and follow up on information-systems audits while evaluating governance, delivery, operations, resilience, and asset protection. The current weights are Audit Process 18%, Governance and Management of IT 18%, Acquisition, Development and Implementation 12%, Operations and Business Resilience 26%, and Protection of Information Assets 26%.
The exam has 150 multiple-choice questions in four hours. ISACA scores it from 200 to 800 and requires 450 to pass; registration is $575 for members or $760 for nonmembers, and exam eligibility lasts six months. Anyone may sit the exam, but passing does not by itself satisfy the separate experience and application requirements for certification.
Use these 895 questions to practise the auditor's sequence: establish scope and criteria, gather sufficient and reliable evidence, identify the root control issue, assess risk and impact, and communicate a defensible recommendation. CISA rewards independent audit judgment, so distinguish what an auditor should verify or report from what an operational team should implement.
CISA validates the knowledge and judgment used to audit, control, monitor, and assess information technology and business systems. The current outline has five domains: audit process, governance and management, systems acquisition and implementation, operations and business resilience, and protection of information assets.
The exam has 150 multiple-choice questions in four hours, uses ISACA's 200-800 scale, and requires 450 to pass. Passing is only the exam step; use of the CISA designation requires a separate application and qualifying professional experience.
CISA targets working IT auditors, internal auditors, IS audit managers, risk and compliance leads, and security consultants, particularly at organizations under regulatory scrutiny — banking, healthcare, government, and critical infrastructure — where a documented, standards-bound audit function matters. Because ISACA places no eligibility bar on sitting the exam itself, students and career-changers do register and pass CISA well before they've accumulated audit experience; the July 2025 CISA Associate designation exists specifically to give this group formal interim standing while they build toward full certification.
That said, the credential still rewards people already doing audit-adjacent work: at least 2 years of direct, verifiable IS audit, control, or security experience is mandatory for full certification no matter how many degree or certification waivers you apply, so candidates with zero audit exposure face a longer runway to full CISA (as opposed to CISA Associate) than the exam-only barrier suggests. Professionals already holding CISM, CISSP, or CRISC, or a relevant bachelor's or master's degree, reach full certification fastest, since those credentials cut up to 3 of the 5 required years.
ISACA sets no prerequisite to register for or sit the CISA exam. Using the CISA designation is a separate step that requires an application and qualifying professional experience under ISACA's current certification rules.
Candidates may therefore pass the exam before completing the experience requirement, but should read the official experience substitutions and application deadline before planning their certification path.
The CISA exam is 150 multiple-choice questions, each with a single best answer among four options, to be completed in 4 hours (240 minutes). ISACA reports scores on a 200-800 scale; 450 or higher passes. The exam mixes recall-based items with scenario questions — ISACA's own item-writing guidance notes that a stem may hinge on a qualifier like MOST likely or BEST, not just a technically correct answer — and a subset of unscored pretest items is seeded throughout without being flagged, so every question should be treated as if it counts. There's no penalty for wrong answers, and domain-level results are provided for information only; the overall scaled score alone determines pass or fail.
Scheduling has its own rules worth knowing before you register: once you pay, your eligibility window is six months, appointments open as early as 48 hours out and as far as 90 days ahead, and you can reschedule free up to 48 hours before test day (a $75 fee buys one additional six-month extension). If you don't pass, the retake clock isn't a flat 30 days: attempt 2 requires waiting 30 days from attempt 1, but attempts 3 and 4 each require a 90-day wait, capped at 4 attempts in any rolling 12 months, with the registration fee due fresh each time. A post-fail rescore is available for $75 if requested within 30 days of receiving your results.
CISA signals competence in planning and performing information-systems audits, assessing governance and controls, evaluating evidence, and communicating risk-based findings. It is relevant to IT audit, internal audit, assurance, risk, compliance, and security-control assessment roles.
The credential is especially useful where employers or regulators expect an established audit methodology. Holders must maintain it with continuing professional education, annual maintenance, ethics compliance, and ISACA's auditing standards.
5 sample questions with answers and explanations. The full bank has 895 questions, enough for 5 full-length practice exams.
Preview — answers shown1. An IS auditor is evaluating an organization's compliance with the NIST Cybersecurity Framework 2.0. Which function represents the NEW addition that emphasizes enterprise-wide risk management strategy and oversight? (Select one!)
Explanation
The GOVERN function is the new addition in NIST Cybersecurity Framework 2.0, released in February 2024. This function sits at the center of the framework wheel, touching and influencing all other functions. GOVERN emphasizes that cybersecurity is an enterprise risk requiring senior leadership oversight, not just a technical IT problem. It requires organizations to establish and monitor cybersecurity risk management strategy, expectations, and policy. The Identify, Protect, Detect, Respond, and Recover functions existed in CSF 1.1, making the framework now comprise six core functions.
2. An organization categorizes their recovery site as having partial equipment installed with data that is days to weeks old and an activation time measured in hours to days. What type of disaster recovery site does this describe? (Select one!)
Explanation
A warm site has partial equipment installed with data that may be days or weeks old, and can be activated in hours to days. It represents a middle-ground approach balancing cost with recovery speed. A hot site is fully equipped with real-time data synchronization and can be activated within minutes to hours, representing the highest cost option. A cold site is an empty facility with no equipment or data on-site, requiring days to weeks for activation but at the lowest cost. Mobile sites are transportable facilities with variable capabilities depending on configuration.
3. According to COBIT 2019, which domain contains the governance objectives that establish direction and monitor achievement of enterprise goals? (Select one!)
Explanation
The EDM (Evaluate, Direct and Monitor) domain contains the five governance objectives in COBIT 2019. This domain is the responsibility of the board and executive management and includes setting governance framework, ensuring benefits delivery, risk optimization, resource optimization, and stakeholder engagement. APO, BAI, DSS, and MEA are management domains that execute the direction set by governance. The governance versus management distinction is fundamental to COBIT 2019.
4. During an IT audit, an IS auditor discovers that a programmer also has the ability to migrate code changes to the production environment without additional approval. This situation violates which fundamental control principle? (Select one!)
Explanation
Segregation of duties requires that incompatible functions be performed by different individuals to prevent fraud and errors. Application development and production operations are fundamentally incompatible functions. A programmer who can both develop code and move it to production could introduce malicious or unauthorized changes without detection. Proper segregation requires that the change requester, implementer, and approver be different individuals. Least privilege relates to minimum necessary access. Defense in depth involves multiple security layers. Need to know restricts information access based on job requirements.
5. During an audit of a cloud service provider, the IS auditor requests assurance that the provider's security controls have been operating effectively over the past nine months. Which type of report should the auditor request? (Select one!)
Explanation
A SOC 2 Type II report provides assurance on the design and operating effectiveness of controls over a period of time, typically 3-12 months. SOC 2 specifically addresses the Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy), which are relevant for cloud service providers. Type II reports test both design adequacy and operating effectiveness over the audit period. SOC 1 reports focus on controls relevant to internal control over financial reporting. Type I reports only assess controls at a point in time, not over a period. SOC 3 is a general use summary report without the detailed testing information needed for due diligence.
CISA has 150 multiple-choice questions and a four-hour time limit.
ISACA reports scores from 200 to 800 and requires 450 to pass.
Audit Process is 18%, Governance and Management 18%, Acquisition, Development and Implementation 12%, Operations and Business Resilience 26%, and Protection of Information Assets 26%.
ISACA lists $575 for members and $760 for nonmembers. Membership is not required to register.
Yes. Anyone may sit the exam, but the separate certification application requires qualifying experience under ISACA's current rules.
CISA centers on independent audit and assurance; CISM centers on governing and managing an information-security program.
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
$17.99
One-time access to this exam