Try CISA - Certified Information Security Auditor
Get a taste before you commit — no account needed. Then a free account unlocks 25 questions with readiness tracking, no card required.
Get full access to CISA - Certified Information Security Auditor
All questions, timed exams, flashcards, PDF study guide download & progress tracking.
This course
$9.99
one-time
Monthly
$12.99
per month · all courses
Takes 30 seconds — create a free account, then straight to checkout. Already have an account? Sign in
ISACA · Exam reference
About the CISA - Certified Information Security Auditor exam
The Certified Information Systems Auditor (CISA) course prepares professionals to audit, control, monitor, and assess an organisation’s information systems to ensure they are secure, compliant, and effectively governed.
10
Sample questions
240 min
Exam time limit
70%
Passing score
$392
Exam voucher
CompTIA Security+ (SY0-701) is the most widely held entry-level cybersecurity certification in the world, and the baseline standard for IT security roles across both the private sector and US federal government. It is approved under DoD 8570/8140, making it a mandatory requirement for many defence and government contractor positions. Security+ validates that you can assess the security posture of an enterprise environment, recommend and implement appropriate security solutions, monitor and secure hybrid environments, and respond to security incidents. The exam covers five domains: Information Systems Auditing Process; Governance and Management of IT; Information Systems Acquisition, Development, and Implementation; Information Systems Operations and Business Resilience; and Protection of Information Assets. Security+ is vendor-neutral, meaning the skills it certifies apply across all technology platforms and cloud providers. It is the ideal next step after CompTIA Network+ or for IT professionals moving into a dedicated security role.
Exam Domains Covered
Exam Format & Details
The CompTIA Security+ exam (SY0-701) consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs). The time limit is 90 minutes. The passing score is 750 on a scale of 100–900. The exam is available at Pearson VUE test centres worldwide or via online proctoring. The exam voucher costs $392 USD. CompTIA recommends (but does not require) CompTIA Network+ certification and two years of IT experience with a security focus before sitting Security+. Results are available immediately for computer-based testing.
Why Practice Questions Matter
Security+ uses performance-based questions (PBQs) alongside multiple-choice, which means some questions require you to interact with simulated environments — configuring firewalls, analysing logs, or identifying vulnerabilities in a network diagram. You cannot pass Security+ through memorisation alone. Timed practice builds the fluency you need to move through scenario questions quickly and confidently. CertCrush questions are written to match the SY0-701 domain weighting, so your practice time targets the areas that actually appear on the exam.
Sample Practice Questions
The following questions are a preview of the type of syllabus-aligned questions you will practise in CertCrush. They reflect the format and reasoning style of the CISA - Certified Information Security Auditor exam — not actual exam content.
Q1.An IS auditor at a retailer is assessing alignment between the IT policy hierarchy and control objectives. A control objective states: 'Ensure that only authorised users have access to customer payment data.' An auditor identifies that the access control policy exists but the corresponding standard does not specify how 'authorised' is defined or how access is provisioned. What is the control risk created by this gap?
- A.Access provisioning will be inconsistent and potentially unauthorised because no standard defines what 'authorised' means or the required provisioning process
- B.The policy alone is sufficient to achieve the control objective; standards are supplementary and not required
- C.Procedures are more important than standards in this situation; the organisation should create step-by-step access provisioning procedures immediately
- D.The control objective should be removed because it cannot be met without a complete policy hierarchy in place
Domain: Governance and Management of IT
Q2.An IS auditor at a media company reviews the accounts-receivable aging report produced nightly. The auditor finds that the total receivables on the aging report differ from the general ledger control account balance by $42,000. Management says the reports are produced and sent to the collections team without any reconciliation step. Which output control is ABSENT and what is the correct auditor action?
- A.A hash total control is absent; the auditor should implement the hash total in the next sprint
- B.A report-balancing control is absent; the auditor should document the finding and recommend that management implement a reconciliation step before report distribution
- C.A batch total control is absent; the auditor should halt report distribution immediately
- D.A range check is absent; the auditor should recommend that accounts over 90 days be flagged automatically
Domain: Information Systems Acquisition, Development, and Implementation
Q3.A retail company's BIA team calculates that each hour of e-commerce downtime results in $85,000 in lost sales. Additionally, legal counsel advises that a downtime event exceeding six hours could trigger regulatory reporting requirements. The reputational impact from a major downtime event is estimated to range from $500,000 to $2 million in long-term brand damage. The IS auditor reviews the BIA and finds that recovery priorities were set based solely on financial revenue loss per hour. Which BIA methodology weakness does the IS auditor MOST likely identify?
- A.The BIA should have been conducted quarterly rather than annually to capture revenue seasonality
- B.The BIA methodology is too quantitative; qualitative impacts (regulatory triggers and reputational damage) should have been weighted alongside financial impacts in establishing recovery priorities
- C.The e-commerce platform's RTO should be set to zero because any downtime is unacceptable
- D.The IS auditor should recalculate the financial impact using a different revenue model before finalising the finding
Domain: Information Systems Operations and Business Resilience
Q4.An IS auditor at a financial services firm is constructing the risk-based audit plan for the coming year. She has completed a preliminary risk assessment and identified twelve auditable entities. The CFO requests that three specific low-risk systems be included in the plan for business convenience reasons. The IS auditor's plan already covers all high- and medium-risk systems within available resource constraints. What should the IS auditor do?
- A.Explain the risk-based audit planning methodology to the CFO and, if management insists, escalate the matter to the audit committee for resolution
- B.Add the three low-risk systems to the plan without question, since CFO requests take precedence in annual audit planning
- C.Refuse to discuss the matter with the CFO, as any management input into the audit plan compromises auditor independence
- D.Remove medium-risk systems from the plan to accommodate the CFO's three requested systems within resource constraints
Domain: Information Systems Auditing Process
Q5.During a review of an energy company's data governance controls, an IS auditor finds that the company replaces primary account numbers (PAN) in its billing system with randomly generated surrogate values stored in a secure vault. The original values are retrievable only by authorised vault lookups. Which data protection technique is described, and how does it differ from encryption?
- A.Encryption — the surrogate values are ciphertext that can be reversed using a decryption key stored in the vault
- B.Tokenisation — surrogate values have no mathematical relationship to originals; recovery requires a vault lookup, not a decryption key
- C.Hashing — a one-way cryptographic function generates the surrogate and can be reversed by the vault
- D.Data masking — original values are permanently replaced and cannot be retrieved under any circumstances
Domain: Protection of Information Assets
Frequently Asked Questions
What is included in the free CISA - Certified Information Security Auditor sample?
The free sample includes 10 syllabus-aligned practice questions, sample flashcards, and a preview chapter from the study guide. No account or payment is required to try the sample.
How many questions are in the full CISA - Certified Information Security Auditor course?
The full course includes a comprehensive question bank covering all exam domains. You can see the total question count on the CISA - Certified Information Security Auditor course page.
Are these official ISACA exam questions?
No. CertCrush questions are independently written and syllabus-aligned — they mirror the format, difficulty, and reasoning style of the official exam. We are not affiliated with or endorsed by ISACA.
Which domains does the CISA - Certified Information Security Auditor course cover?
The course covers 5 exam domains: Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development, and Implementation, Information Systems Operations and Business Resilience, Protection of Information Assets.
Can I study on mobile?
Yes. CertCrush is fully responsive and works on phones, tablets, and desktops. The timed exam, flashcards, and study guide all work on mobile without installing an app.
What happens when I create an account?
Creating a free account lets you access full courses, track your weak areas by domain, and resume practice sessions across devices. No credit card is required to register.