ISACA

Certified Information Systems Auditor (CISA) practice questions

Audit-focused certification covering the IS audit process, governance and management of IT, systems acquisition and implementation, operations and resilience, and protection of information assets for the ISACA CISA exam.

New to CISA? Read the how to pass Certified Information Systems Auditor (CISA) study guide for a domain breakdown, a study plan, and exam-day tips.

Revising? The CISA cheat sheet puts the domain weightings, key facts, and easy-to-confuse traps on one printable page.

Prefer flashcards? See a free sample of the CISA flashcard deck, concept and misconception cards side by side.

150
Questions
240 min
Time allowed
450 / 800
Pass mark
$760
Exam cost (USD)
293
Practice questions

Exam domains and weighting

The CISA blueprint is split across 5 domains. See the official exam guide for the authoritative breakdown.

CISA exam domain weighting - each domain's share of the exam. Full breakdown with links below.
CISA domains by share of the exam
DomainWeight
Information Systems Auditing Process18%
Governance and Management of IT18%
Information Systems Acquisition, Development and Implementation12%
Information Systems Operations and Business Resilience26%
Protection of Information Assets26%

Free sample questions

No account needed. Every question has a worked explanation, just like the full bank.

Free sampleInformation Systems Auditing Processmedium

An IS auditor is preparing the annual audit plan for a mid-sized retail bank. Senior management has asked that prior-year findings drive the selection of auditable units, while the audit committee has asked for coverage that reflects the bank's current risk profile. Which approach should the IS auditor adopt as the PRIMARY basis for selecting auditable units?

  • AAssess inherent risk, control risk and detection risk for each auditable unit and allocate effort to the highest residual risk areas. Correct
  • BSchedule each auditable unit on a fixed three-year rotation so every system is covered at least once in the cycle.
  • CRe-audit every area where the previous year's report contained a high-rated finding before considering any new auditable units.
  • DPrioritise the auditable units that the available audit staff have the strongest technical familiarity with for the coming year.
Risk-based audit planning selects auditable units from inherent, control and detection risk rather than rotation, prior findings or auditor availability. ISACA IS Audit and Assurance Standards require the annual plan to reflect the organisation's current risk profile. The auditor combines inherent risk in each unit, the strength of related controls and the residual detection risk to rank units, so that scarce assurance effort lands where the chance and impact of material misstatement or control failure is greatest.

Why A is correct: This is the risk-based audit planning model required by ISACA standards; effort is concentrated where residual risk is highest, which is the defensible basis for an annual plan.

Why B is wrong: Fixed-rotation cycles are tempting because they look fair and predictable, but ISACA standards require selection driven by current inherent and control risk, not calendar rotation that ignores threat changes.

Why C is wrong: Following up prior findings is necessary but partial; it anchors the plan on history rather than the current risk profile and leaves emerging high-risk areas uncovered.

Why D is wrong: Staffing convenience is tempting in a resource-constrained team, but ISACA requires the plan to be driven by risk; auditor availability informs delivery, not selection.

Free sampleInformation Systems Operations and Business Resilienceeasy

An IS auditor is reviewing the IT asset management process at a logistics firm and finds that the configuration management database (CMDB) records hardware ownership, location, and warranty status, while the software asset register records licence entitlements and deployment counts. Which statement BEST describes how these two records should relate within a mature IT asset management programme?

  • AThe software asset register should be reconciled against the CMDB so that entitlements are compared with deployments and unsupported or unlicensed software is identified. Correct
  • BThe CMDB should replace the software asset register because configuration items already include installed software components and their version data.
  • CThe two records should remain independent to preserve segregation of duties between operations staff who maintain the CMDB and procurement staff who maintain the licence register.
  • DThe CMDB should be updated only when a software audit by the vendor is announced, so that the operational record matches the entitlement position at that moment.
Recognise that periodic reconciliation between the software asset register and the CMDB is the primary control for identifying licensing and deployment exposures. Software asset management relies on comparing contractual entitlements with actual deployments. The software asset register captures rights granted by licences, while the CMDB captures the operational footprint. Without reconciliation, an organisation cannot evidence licence compliance, plan renewals, or detect unsupported software that increases security and continuity risk.

Why A is correct: Reconciling entitlements held in the software asset register against deployment data in the CMDB is the recognised control that surfaces under-licensing, over-licensing, and unsupported versions, satisfying both audit and compliance objectives.

Why B is wrong: This is tempting because the CMDB does record installed software as configuration items; however, a CMDB tracks operational state for service management, not licence entitlements or contractual rights, so it cannot satisfy software asset management obligations on its own.

Why C is wrong: Segregation of duties applies to who can authorise and record asset changes, not to whether two registers may be reconciled; keeping the records permanently disconnected defeats the purpose of asset management.

Why D is wrong: Updating the CMDB only in response to vendor audits is reactive and undermines day-to-day service management; the CMDB must reflect the current operational state continuously, regardless of audit timing.

Free sampleGovernance and Management of ITmedium

Which statement BEST distinguishes IT governance from IT management within an enterprise?

  • AIT governance is the daily oversight of IT operations by the chief information officer, while IT management is the strategic stewardship exercised by the audit committee.
  • BIT governance is performed only by external auditors providing assurance over IT, while IT management is performed by internal audit through control self-assessment.
  • CIT governance is identical to IT management once a control framework such as COBIT 2019 has been adopted across the enterprise.
  • DIT governance directs and evaluates the enterprise so that IT supports strategic objectives, while IT management plans, builds and runs IT services to deliver agreed outcomes. Correct
Distinguish IT governance from IT management as separate but linked accountabilities defined by COBIT 2019 and ISO/IEC 38500. Governance is the board-level activity of evaluating, directing and monitoring the use of IT to meet stakeholder needs, while management plans, builds, runs and monitors IT activities within the direction set by governance. COBIT 2019 codifies this split by labelling EDM objectives as governance and APO/BAI/DSS/MEA objectives as management, and ISO/IEC 38500 frames the same separation as the three governance tasks.

Why A is wrong: This inverts the recognised roles. The board and its committees govern, and the chief information officer manages; conflating the two undermines the separation of decision rights established by COBIT 2019.

Why B is wrong: Assurance providers do not govern or manage IT; they evaluate it. Treating audit as the governance function removes accountability from those charged with governance and is a common candidate trap.

Why C is wrong: Adopting a framework does not collapse the distinction. COBIT 2019 explicitly separates the governance objectives from the management objectives precisely to preserve segregation of decision rights.

Why D is correct: This reflects the ISO/IEC 38500 and COBIT 2019 distinction: governance sets direction, evaluates performance, and monitors compliance through the board, whereas management executes the plans within governance constraints.

More free CISA practice questions with worked answers

Frequently asked questions

How many questions are on the CISA exam?
The Certified Information Systems Auditor (CISA) exam has 150 questions and runs for 240 minutes. The format is multiple choice, computer-based at psi testing centres or remote proctored.
What score do I need to pass CISA?
The pass mark is 450 / 800. Examworthy gives you a per-domain readiness score so you can see which domains are holding you back before you book.
How much does the CISA exam cost?
The exam costs 760 USD to sit. Practising on Examworthy is free to start, with a worked explanation on every question.
Is there a CISA practice exam?
Yes. Examworthy's exam mode runs a timed CISA practice exam (mock) paced to match the real exam, scored per domain so you can see exactly where you stand against the blueprint. Timed mocks are free with an account.
How does Examworthy help me prepare for CISA?
Every practice question carries a worked explanation and a per-distractor rationale, mapped to the official blueprint domains. You learn why each answer is right or wrong, not just the letter.
Is Examworthy affiliated with ISACA?
No. Examworthy is not affiliated with or endorsed by ISACA. Our questions are original, blueprint-aligned practice material; we never reproduce live exam items.

Related certifications

More certifications you can practise on Examworthy, related to Certified Information Systems Auditor (CISA).

Browse all certifications

Examworthy is not affiliated with or endorsed by ISACA. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. CISA and related marks belong to their respective owners.