Back to blog
Exam Guides16 min read

ISACA CISA Practice Questions: 25 Exam-Style Examples With Answers and Explanations (2026)

Twenty-five CISA practice questions written to the real domain weightings, with the reasoning behind every answer. Covers all five job practice domains, plus the exam format, pass mark and the auditor mindset ISACA actually tests.

Tom Ashford

Tom Ashford · Security Certifications Lead

17 September 2026

Most CISA practice questions you find online test whether you can recall a definition. The real exam rarely does that. It hands you a scenario, gives you four answers that are all technically true, and asks which one an auditor would do first, or which represents the greatest risk. Learning to spot that distinction is most of the work.

These 25 CISA practice questions are written to the current exam's domain weightings, so the balance here matches what you will actually see. Every answer includes the reasoning, not just the letter, because the reasoning is the transferable part.

The CISA Exam Format You Are Practising For

Before the questions, the numbers that shape how you should answer them.

ElementDetail
Questions150 multiple choice
Time limit240 minutes (4 hours)
Scoring scale200 to 800
Passing score450
DeliveryPSI test centre or remote proctored
Exam feeUS$575 members, US$760 non-members
Application fee after passingUS$50
Window to apply after passing5 years

Four hours for 150 questions works out at 96 seconds each. That is comfortable for recall questions and tight for the long scenario items, so the practical skill is deciding quickly which kind you are looking at.

Exam Tip: The 450 pass mark sits on a scaled 200 to 800 range, not a percentage. You cannot convert it to "how many did I get right", and a scaled score of 449 is a fail. Do not try to calculate a safety margin mid-exam.

Domain Weightings

The five domains are not equal, and candidates routinely over-revise Domain 1 because it is first in the book.

DomainTopicWeight
1Information Systems Auditing Process18%
2Governance and Management of IT18%
3Information Systems Acquisition, Development and Implementation12%
4Information Systems Operations and Business Resilience26%
5Protection of Information Assets26%

Domains 4 and 5 are 52% of the exam between them. If your revision time is uneven, that is where it should be uneven in your favour.

How to Use These CISA Practice Questions

Answer each one before reading the explanation. When you get one wrong, work out which of the four flavours of mistake it was:

  • You did not know the fact.
  • You knew the fact but missed the qualifier (first, best, greatest, most).
  • You answered as a security engineer rather than as an auditor.
  • You picked the technically strongest control when the question asked about evidence.

The last two account for most failures among people who already work in IT. The exam wants the auditor's answer.

Domain 1: Information Systems Auditing Process (Questions 1 to 4)

1. An IS auditor is planning an audit of a newly outsourced payroll process. What should be performed FIRST?

A. Review the service provider's SOC 2 report B. Perform a risk assessment of the outsourced process C. Test a sample of payroll transactions D. Interview the payroll manager

Answer: B. Risk assessment drives scope, and scope drives everything else. The SOC 2 report, the sampling approach and the interviews are all decisions you make after you know where the risk sits. Choosing A is the most common error here because reviewing the provider's report feels like a sensible opening move, but it presumes a scope you have not yet justified.

2. During fieldwork an IS auditor discovers a control deficiency that was not in scope. What is the BEST course of action?

A. Ignore it, since it falls outside the agreed scope B. Expand the audit scope to cover the deficiency C. Document it and report it to audit management D. Raise it informally with the process owner

Answer: C. An auditor does not unilaterally expand scope, and does not suppress a finding either. Documenting and escalating to audit management preserves both independence and the record. Audit management then decides whether to expand the engagement.

3. Which sampling method is MOST appropriate when an IS auditor wants to estimate the rate of deviation from a prescribed control?

A. Variable sampling B. Attribute sampling C. Stop-or-go sampling D. Discovery sampling

Answer: B. Attribute sampling answers yes or no questions about whether a control operated, which is exactly what a deviation rate is. Variable sampling estimates monetary amounts. Discovery sampling is aimed at finding at least one instance of a rare critical exception, not at estimating a rate.

4. An IS auditor finds that the audit evidence collected is insufficient to support a conclusion. What should the auditor do?

A. Issue a qualified opinion B. Perform additional procedures to obtain sufficient evidence C. Rely on management's representations D. Report the scope limitation and conclude anyway

Answer: B. Insufficient evidence is a prompt to gather more, not a licence to conclude. Management representations are not a substitute for evidence. A scope limitation is only reported when additional procedures are genuinely unavailable to you.

Domain 2: Governance and Management of IT (Questions 5 to 8)

5. An IT steering committee's PRIMARY responsibility is to:

A. Approve IT project budgets and priorities in line with business strategy B. Design the enterprise security architecture C. Manage day-to-day IT operations D. Conduct post-implementation reviews of IT projects

Answer: A. A steering committee governs. It decides what gets funded and in what order, and it holds those decisions to the business strategy. Architecture design and daily operations are management activities, not governance ones.

6. Which of the following provides the BEST evidence that IT strategy is aligned with business objectives?

A. An IT balanced scorecard linking IT metrics to business goals B. A signed IT strategic plan C. Minutes of IT steering committee meetings D. An IT organisation chart

Answer: A. A signed plan states intent. A scorecard demonstrates that the link is being measured and tracked over time, which is stronger evidence. Watch the qualifier: the question asks for the best evidence of alignment, not the document that describes it.

7. An organisation has no formal data classification scheme. The GREATEST risk is that:

A. Storage costs will increase B. Protection may be inconsistent with data sensitivity C. Backup windows will lengthen D. Data retention periods will be inaccurate

Answer: B. Classification exists to match control strength to sensitivity. Without it, the likely failure is that sensitive data gets weak controls while trivial data gets expensive ones. The other options are real consequences but minor beside inappropriate protection.

8. Which is the MOST important factor when an IS auditor evaluates a third-party vendor's contract?

A. The contract includes a right-to-audit clause B. The vendor holds ISO 27001 certification C. The contract specifies penalties for downtime D. The vendor's financial statements are audited annually

Answer: A. Without a right-to-audit clause you have no contractual mechanism to obtain assurance directly. Certification and penalties are useful, but both leave you dependent on what the vendor chooses to show you.

Domain 3: Information Systems Acquisition, Development and Implementation (Questions 9 to 11)

9. When is the involvement of an IS auditor in a system development project MOST valuable?

A. During the requirements definition phase B. During user acceptance testing C. During post-implementation review D. During the parallel run

Answer: A. Controls designed in at the requirements stage cost a fraction of controls retrofitted later. The auditor's value is highest earliest, provided the auditor advises rather than designs, which would compromise independence.

10. An organisation is migrating from a legacy system using a parallel changeover. The PRIMARY advantage is:

A. Lower cost than other changeover methods B. Reduced risk, because the old system remains available if the new one fails C. Faster implementation D. Less staff training required

Answer: B. Parallel running is the most expensive and the slowest changeover method, because both systems run at once and staff process everything twice. You accept that cost specifically to buy the fallback.

11. During a post-implementation review of an ERP system, an IS auditor's PRIMARY concern should be whether:

A. The project was delivered on budget B. The system delivers the business benefits stated in the business case C. The vendor met all contractual milestones D. Users are satisfied with the interface

Answer: B. Budget and milestones are project management measures. A post-implementation review asks whether the investment achieved what it was approved to achieve. A project can land on time and on budget and still deliver nothing.

Domain 4: Information Systems Operations and Business Resilience (Questions 12 to 18)

12. An organisation's recovery time objective (RTO) is 4 hours and its recovery point objective (RPO) is 24 hours. This means:

A. Backups run every 4 hours and recovery takes 24 hours B. The system must be restored within 4 hours, and up to 24 hours of data loss is tolerable C. Recovery must complete within 24 hours with no data loss D. The system can be unavailable for 24 hours

Answer: B. RTO is time to restore service. RPO is the age of the data you are willing to lose. They are independent numbers, and a short RTO with a long RPO is a deliberate, common choice for systems where availability matters more than recency.

13. Which BCP test provides the highest assurance that recovery procedures work, with the greatest operational risk?

A. Checklist review B. Structured walkthrough C. Simulation test D. Full interruption test

Answer: D. A full interruption test actually takes production down and recovers it. It proves the plan, and it is the only test that can cause a genuine outage if the plan fails. The ordering from lowest to highest assurance and risk runs checklist, walkthrough, simulation, parallel, full interruption.

14. An IS auditor reviewing a data centre observes that backup tapes are stored in a fireproof safe in the same building. The GREATEST risk is:

A. Tapes could degrade over time B. A site-wide disaster would destroy both production data and backups C. Restoration would be slow D. Tape encryption may be absent

Answer: B. A fireproof safe protects against fire in the room, not against the loss of the site. Offsite storage exists precisely to break the shared fate between primary data and its copies.

15. Which control BEST detects unauthorised changes made directly to a production database?

A. Segregation of duties between developers and DBAs B. A change management policy requiring approval C. Database activity monitoring with independent log review D. Restricting production access to DBAs only

Answer: C. The question asks for a detective control. Segregation of duties, policy and access restriction are all preventive. Only monitoring with independent review tells you that something happened when the preventive controls were bypassed.

16. An IS auditor notes that the job scheduler runs a critical batch job with a generic service account shared by three administrators. The PRIMARY concern is:

A. The password may be weak B. Accountability for actions taken cannot be established C. The job may fail outside working hours D. The account may have excessive privileges

Answer: B. Shared accounts break the link between an action and a person. Weak passwords and excessive privileges are separate issues that may or may not be present. Loss of accountability is inherent to the sharing itself.

17. Which metric BEST indicates the effectiveness of an incident management process?

A. Number of incidents logged per month B. Mean time to resolve incidents C. Number of open incidents D. Percentage of incidents reported by users rather than monitoring

Answer: B. Volume tells you about demand, not performance. Mean time to resolve measures how well the process converts a reported incident into a restored service. Option D is a genuinely useful detection-quality metric, but it measures monitoring rather than incident management.

18. An organisation uses a hot site for disaster recovery. An IS auditor should be MOST concerned if:

A. The hot site is 20 miles from the primary site B. The hot site's hardware configuration has not been updated to match recent production changes C. The hot site is shared with another organisation D. The hot site contract renews annually

Answer: B. A hot site is defined by being ready to run now. Configuration drift quietly turns it into a warm site without anyone deciding to make that trade. Distance, sharing and contract terms are all judgement calls that may be perfectly reasonable.

Domain 5: Protection of Information Assets (Questions 19 to 25)

19. Which provides the STRONGEST assurance of message integrity and non-repudiation?

A. Symmetric encryption of the message B. A digital signature created with the sender's private key C. A message authentication code (MAC) D. Transmission over TLS

Answer: B. Non-repudiation requires something only the sender could have produced, which means a private key. A MAC gives integrity and authenticity but both parties hold the shared key, so either could have created it. TLS protects the channel, not the message once it arrives.

20. An IS auditor reviewing logical access finds that terminated employees' accounts remain active for up to 30 days. The GREATEST risk is:

A. Licensing costs for unused accounts B. Unauthorised access by former employees C. Inaccurate user access reports D. Breach of the organisation's HR policy

Answer: B. An active account belonging to someone with no legitimate business reason to use it is an open door, and departing employees sometimes have motive. The other options are real but secondary.

21. Which is the MOST effective control against SQL injection?

A. A web application firewall B. Parameterised queries in application code C. Regular vulnerability scanning D. Restricting database account privileges

Answer: B. Parameterised queries remove the vulnerability rather than filtering attempts to exploit it. A WAF is a compensating control that can be bypassed. Scanning detects, and least privilege limits the damage, but neither prevents the injection.

22. In a public key infrastructure, the PRIMARY role of the certificate authority is to:

A. Generate the private keys of all subscribers B. Vouch for the binding between an identity and a public key C. Encrypt data in transit between parties D. Store subscribers' private keys in escrow

Answer: B. The CA's entire value is that a third party attests that this public key belongs to this identity. A CA that generated or held subscriber private keys would undermine non-repudiation, which is why option A and option D are wrong by design rather than by practice.

23. An IS auditor finds that a firewall rule base has grown to over 800 rules with no documented business justification for many of them. The GREATEST concern is:

A. Firewall performance may degrade B. Unnecessary rules may permit unintended traffic C. Rule review takes significant staff time D. The firewall vendor may not support that rule count

Answer: B. Undocumented rules accumulate because nobody dares remove them, and each one is a permission somebody granted for a reason that may no longer exist. The security exposure outranks the performance and administrative costs.

24. Which is the BEST way to verify that a data loss prevention (DLP) tool is working as intended?

A. Review the DLP vendor's product documentation B. Review the DLP policy configuration C. Attempt to transmit test data that should be blocked D. Interview the security team about alert volumes

Answer: C. Testing the control observes the outcome. Documentation and configuration review tell you what should happen, which is a design test rather than an effectiveness test. CISA questions frequently separate "is the control designed correctly" from "does the control actually work", and reperformance is the answer to the second.

25. An organisation is adopting a bring-your-own-device policy. Which control should the IS auditor recommend FIRST?

A. Mobile device management with remote wipe B. A signed acceptable use agreement defining the organisation's rights over the device C. Full disk encryption on all personal devices D. Network access control for mobile devices

Answer: B. The technical controls all depend on the organisation having the legal right to apply them to equipment it does not own. Without the agreement in place, remote wiping a personal phone is a liability rather than a control.

Scoring Yourself

There is no published mapping from raw score to the 450 scaled pass mark, so treat any percentage from a practice set as a rough signal rather than a prediction.

Score out of 25What it suggests
21 to 25Strong. Focus on timing and on the domains you missed
17 to 20On track. Drill Domains 4 and 5, which are 52% of the exam
13 to 16More study needed before booking
Under 13Work through the material properly before returning to question practice

The more useful measure is not the number. It is whether the questions you got wrong share a pattern. Four misses spread across five domains is noise. Four misses that were all "which comes FIRST" questions is a habit you can fix in an afternoon.

Frequently Asked Questions

How difficult is the CISA exam?

CISA is difficult because of how it asks rather than how much it covers. The material is broad but not deeply technical, and candidates with IT experience usually know the underlying concepts. What catches people out is being asked to choose between four defensible answers based on a single qualifier, and being asked to think as an auditor assessing evidence rather than as an engineer fixing a problem.

How many questions does the CISA exam have?

The CISA exam has 150 multiple-choice questions with a 240-minute time limit, which is four hours. That averages 96 seconds per question, so the pacing is workable if you do not get stuck re-reading the long scenario items.

Where can I find free questions for the CISA exam?

The 25 above are a start, and ISACA's own Questions, Answers and Explanations database draws on a pool of more than 1,000 items if you want the official phrasing. Avoid sites advertising "real exam questions" or dumps: the content is frequently outdated, the explanations are often wrong, and using them breaches ISACA's certification agreement.

How do you pass CISA on the first attempt?

Two habits do most of the work. First, weight your revision to the domain percentages rather than to the chapter order, which means Domains 4 and 5 get the most time. Second, practise reading the qualifier before the options: underline FIRST, BEST, GREATEST or MOST, then eliminate answers that are correct but do not satisfy it.

Ready to Start Practising?

Twenty-five questions will show you where the gaps are. Closing them takes volume, and specifically volume with explanations that tell you why the other three options were wrong.

CertCrush's CISA practice exam gives you domain-weighted question banks that mirror the real 18/18/12/26/26 split, with a written rationale for every option. If you are still choosing between ISACA's credentials, CISA vs CISM covers which one fits your career first, and the 12-week CISA study plan gives you a schedule to hang the revision on.

Create a free account and start drilling the domains you missed.

CISAISACApractice questionsIT auditexam prepcertification
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Practise for CISA - Certified Information Systems Auditorfree

10 real exam-style questions with full explanations, no account needed. Then unlock the complete bank with an exam-readiness score and a daily plan built around your exam date.