ISACA free flashcards

Free CISA flashcards

8 real CISA flashcards, sampled across every domain the exam tests. Each concept card is paired with the misconception card built from the tempting wrong answer - the trap most decks skip. No account, no card.

The full deck has 720 flashcards. For a domain-by-domain breakdown and a study plan, read the CISA study guide.

ConceptInformation Systems Operations and Business Resilience

How should the software asset register and the CMDB relate in a mature IT asset management programme?

The software asset register (which captures licence entitlements and deployment counts) should be reconciled periodically against the CMDB (which captures the operational footprint of installed software). This reconciliation is the primary control that surfaces under-licensing, over-licensing, and unsupported software, evidencing licence compliance, supporting renewal planning, and detecting unsupported versions that increase security and continuity risk.

MisconceptionInformation Systems Operations and Business Resilience

The CMDB can replace the software asset register because configuration items already include installed software components and version data.

Although the CMDB does record installed software as configuration items, it tracks operational state for service management, not licence entitlements or contractual rights. A CMDB cannot satisfy software asset management obligations on its own; a separate software asset register is required to capture rights granted by licences, and the two records must be reconciled to evidence compliance.

ConceptProtection of Information Assets

How do ISO/IEC 27001 and ISO/IEC 27002 relate to each other in an information security framework?

ISO/IEC 27001 specifies the certifiable requirements for an information security management system, including risk assessment, risk treatment and Annex A controls. ISO/IEC 27002 is the companion guidance that explains how each Annex A control may be implemented. They are complementary, not alternatives.

MisconceptionProtection of Information Assets

a committed future remediation date downgrades a current policy breach from a finding to an observation.

Acknowledgement and a future fix do not change the present state. Audit findings reflect the control's condition during the audit period, so a current breach exposing personal data remains a finding with risk rated on present exposure.

ConceptInformation Systems Auditing Process

On what basis does ISACA require an IS auditor to select auditable units for the annual audit plan?

ISACA IS Audit and Assurance Standards require the annual plan to reflect the organisation's current risk profile. The auditor combines inherent risk in each unit, the strength of related controls and residual detection risk to rank units, so scarce assurance effort lands where the chance and impact of material misstatement or control failure is greatest.

MisconceptionInformation Systems Auditing Process

Fixed three-year rotation of auditable units is the defensible basis for the annual plan because it guarantees coverage.

Fixed-rotation cycles are tempting because they look fair and predictable, but ISACA standards require selection driven by current inherent and control risk, not calendar rotation that ignores threat changes. Predictable coverage is not the same as risk-relevant coverage.

ConceptGovernance and Management of IT

How does COBIT 2019 and ISO/IEC 38500 distinguish IT governance from IT management within an enterprise?

IT governance is the board-level activity of evaluating, directing and monitoring the use of IT so that it supports stakeholder needs and strategic objectives, while IT management plans, builds, runs and monitors IT activities within the direction set by governance. COBIT 2019 codifies this split by labelling EDM objectives as governance and APO, BAI, DSS and MEA objectives as management. ISO/IEC 38500 frames the same separation as the three governance tasks of evaluate, direct and monitor. The two roles are linked but distinct, and adopting a control framework does not collapse the distinction; segregation of decision rights is preserved by design.

MisconceptionGovernance and Management of IT

IT governance is the daily oversight of IT operations exercised by the chief information officer, while IT management is the strategic stewardship exercised by the audit committee.

This inverts the recognised roles. The board and its committees govern by evaluating, directing and monitoring the use of IT, while the chief information officer manages day-to-day delivery within governance constraints. Treating the chief information officer as the governance actor and the audit committee as a management actor undermines the segregation of decision rights established by COBIT 2019 and ISO/IEC 38500.

Get all 720 CISA flashcards free

Drop your email and we will keep you posted as new CISA study material ships. No spam - we mail you only when it is worth your time.

Frequently asked questions

Are these CISA flashcards free?

Yes. Every card on this page is free to read with no sign-up. The full deck has 720 flashcards; drop your email below and we will keep you posted, or create a free account to study the rest.

What is a misconception card?

A card built from a tempting wrong answer in our question bank, naming the trap and explaining why it fails. Most flashcard decks only drill the fact (a concept card); we pair each one with the misconception the exam actually tests you against.

Are these real CISA exam questions or vendor content?

No. These are original flashcards written from our own blueprint-aligned practice questions. We never reproduce live exam items or vendor material.

How many flashcards are in the full CISA deck?

720 cards spread across all 5 domains. For the full domain-by-domain breakdown, read the study guide.

Examworthy is not affiliated with or endorsed by ISACA. All flashcards are original, drawn from our own blueprint-aligned practice questions. We never reproduce live exam items. CISA and related marks belong to their respective owners.