ISACA

Free CISA Practice Questions

The CISA - Certified Information Systems Auditor exam is up to 150 questions in 240 minutes, and the voucher costs $575. CertCrush provides 450 syllabus-aligned practice questions across all 5 exam domains, each with a full explanation. Free to try, no account required.

The Certified Information Systems Auditor (CISA) course prepares professionals to audit, control, monitor, and assess an organisation’s information systems to ensure they are secure, compliant, and effectively governed.

Practice content last updated · Independently written and aligned to ISACA’s published exam objectives.

10

Sample questions

240 min

Exam time limit

70%

Practice pass mark

$575

Exam voucher

About the CISA - Certified Information Systems Auditor Exam

The Certified Information Systems Auditor (CISA) is ISACA's flagship certification for information systems audit, assurance, and control professionals, and the global standard for the IS audit profession. It validates that you can assess an organisation's information systems, evaluate IT governance, and report on whether controls are designed and operating effectively. CISA is aimed at internal and external auditors, IT compliance and assurance specialists, and risk professionals who need to evidence control effectiveness to boards, regulators, and external stakeholders. The credential requires five years of professional information systems auditing, control, assurance, or security experience, with waivers available for relevant degrees and certifications. It is widely required for audit and assurance roles and is recognised by regulators and employers worldwide. CertCrush helps you prepare with free CISA practice questions, timed practice tests across all five domains, and full mock exams with a clear explanation for every answer.

Exam Domains Covered

Information Systems Auditing Process · 18%Governance and Management of IT · 18%Information Systems Acquisition, Development, and Implementation · 12%Information Systems Operations and Business Resilience · 26%Protection of Information Assets · 26%

Exam Format & Details

The CISA exam consists of 150 multiple-choice questions over a 4-hour time limit. The passing score is 450 on a scale of 200–800. The exam covers five domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development, and Implementation (12%), Information Systems Operations and Business Resilience (26%), and Protection of Information Assets (26%). The exam is delivered through PSI test centres and online proctoring. Exam registration costs $575 USD for ISACA members and $760 for non-members. After passing, candidates must submit evidence of their work experience before the CISA designation is formally awarded.

Why Practice Questions Matter

CISA rewards audit judgement rather than technical recall. The exam repeatedly asks what an IS auditor should do first, what counts as sufficient audit evidence, or which finding matters most — with distractors that are technically sensible but wrong from an assurance standpoint. Candidates from a hands-on IT background often pick the operational fix instead of the audit response. CertCrush CISA questions are written to the ISACA domain weighting and build the auditor's mindset, with explanations that set out not just the correct answer but the control or assurance principle behind it.

Back to home
Free Sample

Try CISA - Certified Information Systems Auditor

Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.

Get full access to CISA - Certified Information Systems Auditor

All questions, timed exams, flashcards, PDF study guide download & progress tracking.

This course

$9.99

one-time

Buy Course

Monthly

$12.99

per month · all courses

Monthly Plan
Best value

Annual

$79.99

Save 49% · all courses

Annual Plan

Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in

Sample Practice Questions

The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CISA - Certified Information Systems Auditor exam — not actual exam content.

Q1.An IS auditor at a retailer is assessing alignment between the IT policy hierarchy and control objectives. A control objective states: 'Ensure that only authorised users have access to customer payment data.' An auditor identifies that the access control policy exists but the corresponding standard does not specify how 'authorised' is defined or how access is provisioned. What is the control risk created by this gap?

  • A.Access provisioning will be inconsistent and potentially unauthorised because no standard defines what 'authorised' means or the required provisioning process
  • B.The policy alone is sufficient to achieve the control objective; standards are supplementary and not required
  • C.Procedures are more important than standards in this situation; the organisation should create step-by-step access provisioning procedures immediately
  • D.The control objective should be removed because it cannot be met without a complete policy hierarchy in place

Domain: Governance and Management of IT

Q2.An IS auditor at a media company reviews the accounts-receivable aging report produced nightly. The auditor finds that the total receivables on the aging report differ from the general ledger control account balance by $42,000. Management says the reports are produced and sent to the collections team without any reconciliation step. Which output control is ABSENT and what is the correct auditor action?

  • A.A hash total control is absent; the auditor should implement the hash total in the next sprint
  • B.A report-balancing control is absent; the auditor should document the finding and recommend that management implement a reconciliation step before report distribution
  • C.A batch total control is absent; the auditor should halt report distribution immediately
  • D.A range check is absent; the auditor should recommend that accounts over 90 days be flagged automatically

Domain: Information Systems Acquisition, Development, and Implementation

Q3.A retail company's BIA team calculates that each hour of e-commerce downtime results in $85,000 in lost sales. Additionally, legal counsel advises that a downtime event exceeding six hours could trigger regulatory reporting requirements. The reputational impact from a major downtime event is estimated to range from $500,000 to $2 million in long-term brand damage. The IS auditor reviews the BIA and finds that recovery priorities were set based solely on financial revenue loss per hour. Which BIA methodology weakness does the IS auditor MOST likely identify?

  • A.The BIA should have been conducted quarterly rather than annually to capture revenue seasonality
  • B.The BIA methodology is too quantitative; qualitative impacts (regulatory triggers and reputational damage) should have been weighted alongside financial impacts in establishing recovery priorities
  • C.The e-commerce platform's RTO should be set to zero because any downtime is unacceptable
  • D.The IS auditor should recalculate the financial impact using a different revenue model before finalising the finding

Domain: Information Systems Operations and Business Resilience

Q4.An IS auditor at a financial services firm is constructing the risk-based audit plan for the coming year. She has completed a preliminary risk assessment and identified twelve auditable entities. The CFO requests that three specific low-risk systems be included in the plan for business convenience reasons. The IS auditor's plan already covers all high- and medium-risk systems within available resource constraints. What should the IS auditor do?

  • A.Explain the risk-based audit planning methodology to the CFO and, if management insists, escalate the matter to the audit committee for resolution
  • B.Add the three low-risk systems to the plan without question, since CFO requests take precedence in annual audit planning
  • C.Refuse to discuss the matter with the CFO, as any management input into the audit plan compromises auditor independence
  • D.Remove medium-risk systems from the plan to accommodate the CFO's three requested systems within resource constraints

Domain: Information Systems Auditing Process

Q5.During a review of an energy company's data governance controls, an IS auditor finds that the company replaces primary account numbers (PAN) in its billing system with randomly generated surrogate values stored in a secure vault. The original values are retrievable only by authorised vault lookups. Which data protection technique is described, and how does it differ from encryption?

  • A.Encryption — the surrogate values are ciphertext that can be reversed using a decryption key stored in the vault
  • B.Tokenisation — surrogate values have no mathematical relationship to originals; recovery requires a vault lookup, not a decryption key
  • C.Hashing — a one-way cryptographic function generates the surrogate and can be reversed by the vault
  • D.Data masking — original values are permanently replaced and cannot be retrieved under any circumstances

Domain: Protection of Information Assets

Q6.An IS auditor is evaluating the enterprise architecture governance at a large NGO transitioning from a legacy mainframe to a cloud-based platform. The organization uses TOGAF as its enterprise architecture framework. The auditor finds that individual project teams are making technology decisions independently, creating architectural fragmentation. Which governance mechanism MOST effectively addresses this issue within the TOGAF framework?

  • A.Establish an Architecture Review Board (ARB) with authority to review all significant technology decisions for compliance with the target architecture
  • B.Create a project management office to standardize project delivery methodology across all technology initiatives
  • C.Mandate a technology standards committee to publish approved technology lists that project teams must select from
  • D.Enforce a single-vendor strategy to reduce architectural complexity and eliminate fragmentation through standardization

Domain: Governance and Management of IT

Q7.A real estate company integrates its property management system with a payment gateway via a REST API. During an IS audit, the auditor discovers that the API accepts requests from any IP address, uses HTTP Basic Authentication with a shared credential, and does not enforce message-level integrity checks. Which combination of controls would BEST address the THREE identified weaknesses?

  • A.IP allowlisting, OAuth 2.0 with short-lived tokens, and HMAC message signing
  • B.TLS encryption, field-level validation, and password complexity requirements
  • C.API rate limiting, role-based access control, and batch reconciliation totals
  • D.Two-factor authentication, database encryption, and input sanitization

Domain: Information Systems Acquisition, Development, and Implementation

Q8.A media company undergoes a BIA as part of its BCM program. The BIA team identifies 47 business processes. After analysis, 12 are classified as critical (recovery required within 24 hours), 20 as essential (recovery within 72 hours), and 15 as deferrable (recovery within 30 days). During audit, the IS auditor finds that the BIA was based on self-assessments by process owners with no independent validation. Three of the 12 critical processes share a single database server not flagged as critical infrastructure. Which TWO findings should the IS auditor PRIORITISE in the audit report?

  • A.The absence of third-party validation of BIA results and the undisclosed database dependency create significant risk that recovery priorities and plans are unreliable
  • B.The 12/20/15 split is not aligned with ISACA guidance on BIA process classification ratios
  • C.The BIA was not conducted by the IT department, which is a governance violation
  • D.The deferrable process recovery window of 30 days exceeds the maximum tolerable downtime for regulatory compliance

Domain: Information Systems Operations and Business Resilience

Q9.An IS auditor is reviewing disaster recovery test documentation at a financial institution. The documentation was prepared by the IT disaster recovery team and signed off by the IT manager. The auditor also interviews the IT manager and reviews the test scripts. Applying evidence reliability principles, which of the following represents the MOST reliable evidence regarding whether the disaster recovery test was successful?

  • A.System-generated logs produced during the disaster recovery test, reviewed independently by the auditor, corroborated by the test scripts
  • B.The disaster recovery test documentation prepared and signed by the IT manager, as it represents the official record
  • C.The IT manager's verbal assurance during the interview that the test was completed successfully
  • D.The test scripts alone, as they document the procedures that were supposed to be executed during the test

Domain: Information Systems Auditing Process

Q10.An IS auditor at a logistics company reviews the web application for OWASP Top 10 compliance. Testers find that when a logged-in user is tricked into clicking a malicious link on an external site, the application automatically executes a funds-transfer request using the user's active session credentials without the user's knowledge. Which OWASP category is this, and what is the MOST effective control?

  • A.SQL Injection — prevented by parameterised queries ensuring user input is not interpreted as SQL commands
  • B.Cross-Site Request Forgery (CSRF) — prevented by embedding unpredictable anti-CSRF tokens in all state-changing requests
  • C.Cross-Site Scripting (XSS) — prevented by output encoding all user-supplied data before rendering in the browser
  • D.Broken Authentication — prevented by enforcing HTTPS on all pages to prevent session cookie theft

Domain: Protection of Information Assets

Frequently Asked Questions

What is included in the free CISA - Certified Information Systems Auditor sample?

The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.

How many questions are in the full CISA - Certified Information Systems Auditor course?

The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CISA - Certified Information Systems Auditor course page.

Are these official ISACA exam questions?

No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.

Which domains does the CISA - Certified Information Systems Auditor course cover?

The course covers 5 exam domains: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development, and Implementation, Information Systems Operations and Business Resilience, Protection of Information Assets.

Can I study on mobile?

Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.

What happens when I create an account?

Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.