CISA:Certified Information Systems Auditor Practice Exam — CISA:Certified Information Systems Auditor

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Exam information

Basic Exam Information

- Exam Languages: Multiple language options are available, including Simplified Chinese, Traditional Chinese, English, Japanese, etc., with globally unified language selections.

- Registration Eligibility: There are no restrictions for exam registration, and all candidates may sit for the exam. However, formal CISA credential application is required after passing the exam. Credential application prerequisites:

 • Minimum 5 years of professional experience in information systems auditing, control, assurance or security

 • Education‑based experience exemptions: A 4‑year bachelor’s degree deducts 2 years; a master’s degree deducts 1 year; an information‑systems‑focused bachelor’s degree deducts 1 year

 • Relevant certifications (e.g., CISSP, CISM, CIA, CPA) deduct 1 year

 • Compliance with the ISACA Code of Professional Ethics

- Exam Fees: USD 575 for ISACA members, USD 760 for non‑members; an additional USD 50 certification fee is required for credential application upon passing the exam.

- Exam Duration: 4 hours (240 minutes), covering time for answering all exam questions.

- Exam Format: ISACA provides two global‑standard exam modes: remote‑proctored online exams (video proctoring via PSI, ISACA’s official exam vendor) and in‑person computer‑based testing (CBT).

Main exam formats by global region:

• Hong Kong: In‑person CBT

• Taiwan: In‑person CBT, online exam

• Macau: In‑person CBT

• Mainland China: In‑person CBT (arranged by ISACA‑authorized partners)

• Overseas international regions: Both remote proctoring and in‑person CBT are available

- Exam Content: Comprises 150 multiple‑choice questions, all scored with no unscored pre‑test items.

- Score Information:

 • A preliminary pass/fail score report is available immediately after the exam

 • Official exam results are sent via email within 10 working days post‑exam

 • Passing score: 450 out of a full score of 800 (200‑800 scoring scale)

- Exam Eligibility Validity: After successful registration, candidates must book and complete the exam within 12 months; exam eligibility expires if overdue.




Detailed Exam Content (Latest Exam Outline)

The CISA exam covers five core knowledge domains with a total weightage of 100%, focusing on the practical competencies of information systems auditors.


1. Information Systems Auditing Process ( 18% )Audit planning and execution, risk assessment, audit methodologies, report writing, compliance with ISACA standards and guidelines

2. Governance and Management of IT (18% )IT strategy‑business alignment, IT governance frameworks, risk management, resource management, performance evaluation, compliance management

3. Information Systems Acquisition, Development and Implementation (12% )System development lifecycle, requirement management, testing methodologies, change management, launch management, vendor management

4. Information Systems Operations and Business Resilience (26%)Operation management, service management, business continuity, disaster recovery, IT service continuity, incident response (increased by 3% from 23% in the 2024 August update)

5. Protection of Information Assets (26% ) Security architecture, access control, data security, network security, physical security, encryption technologies, security incident management




Registration Process

For Non‑Mainland China Candidates

1. Visit the [official ISACA website](https://www.isaca.org/) to create and log into a MyISACA account

2. Register for the CISA exam, fill in personal information, work experience and other relevant details

3. Pay the exam fee (USD 575 for members / USD 760 for non‑members)

4. Gain 12‑month exam eligibility validity upon successful payment

5. Book the exam time and venue via PSI or Pearson VUE (remote proctoring or in‑person CBT optional)

6. Present valid ID documents and take the exam as scheduled


For Mainland China Candidates

1. Register via the [ISACA China official website](https://www.isaca.org.cn/) or ISACA‑authorized partners such as ZhongShen Audit Online

2. Submit personal information, academic certificates and other documents for institutional‑assisted registration

3. Pay the exam fee (USD 575 for members / USD 760 for non‑members) and complete registration procedures via authorized institutions

4. Gain 12‑month exam eligibility validity after successful registration

5. Independently book exam time and test centers via PSI/Pearson VUE under institutional guidance (in‑person CBT is the primary mode in Mainland China)

6. Present valid ID documents (ID card or passport) on exam day




Supplementary Notes

1. Credential Validity: The CISA credential is valid for 3 years. Holders must earn 120 Continuing Professional Education (CPE) credits and pay renewal fees to maintain credential validity.

2. Retake Policy: Candidates who fail the exam must wait 30 days for a retake; a 90‑day waiting period is required after two consecutive failures. Retake fees are the same as initial exam fees.

3. Exam Update: The August 2024 updated exam outline increases the weightage of business resilience and information asset protection, reflecting the growing importance of security operations and risk management in modern IT environments.


Wish all candidates success in their exams!

Sample questions

CISA:Certified Information Systems Auditor · Q1
Question #1
Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?
  • A.
    The BCP has not been tested since it was first issued.
  • B.
    The BCP is not version-controlled.
  • C.
    The BCP's contact information needs to be updated.
  • D.
    The BCP has not been approved by senior management.

Answer: A

Answer Analysis:
This question falls under CISA Domain 4 (Information Systems Operations and Business Resilience), which focuses on validating an organization's ability to maintain operational continuity and recover from disruptions. The core priority of an IS auditor reviewing a BCP is to confirm the plan will effectively enable recovery of critical business functions when needed. An untested BCP provides no objective evidence that procedures, resource allocations, recovery timelines, or stakeholder responsibilities are accurate or feasible. Even well-documented, approved, and updated BCPs often contain unforeseen gaps such as incompatible recovery tools, misaligned recovery time objectives (RTO)/recovery point objectives (RPO), or undocumented process dependencies that only testing can identify. The lack of testing eliminates all assurance of BCP effectiveness, which poses a far higher business risk than the other listed gaps, making this the greatest concern. Option Analysis:
A. Correct. BCP testing is a foundational control required to validate plan feasibility, accuracy, and alignment with business recovery objectives. Without testing, there is no guarantee the BCP will function as intended during an actual disruption, exposing the organization to unmitigated financial, operational, and reputational loss. This gap invalidates the core purpose of the BCP, making it the highest priority concern.
B. Incorrect. Lack of version control is an administrative process gap that can lead to distribution of outdated BCP copies, but it is a low-impact, easily remediated issue. Version control does not directly impact the core functionality of the BCP, so it is a lesser concern than an untested plan.
C. Incorrect. Outdated contact information is a minor operational gap that can cause minor delays during BCP activation, but it is simple to update and does not undermine the overall effectiveness of the recovery plan. This is a lower priority concern than lack of testing.
D. Incorrect. While senior management approval is a recommended governance control to formalize BCP accountability and resource allocation, an unapproved but thoroughly tested BCP can still effectively support recovery during a disruption. An approved but untested BCP provides no recoverability assurance, so lack of approval is a lower risk than lack of testing. Key Concepts:
1. BCP Effectiveness Validation: CISA guidance specifies that testing is the only reliable method to confirm a BCP meets RTO/RPO requirements and addresses all critical recovery dependencies, as documentation reviews cannot identify process or resource gaps that appear during real-world activation.
2. Risk Prioritization for IS Auditors: Auditors rank control gaps based on their impact to core business objectives. Gaps that eliminate all assurance of a critical control like BCP functionality are prioritized over administrative or governance gaps that only reduce control efficiency.
3. Business Resilience Maturity: A mature business continuity management (BCM) program requires regular testing, updates, and training as core components, with testing being the most critical metric of program effectiveness per ISACA frameworks. References:
ISACA CISA Exam Domains, ISACA Business Continuity Management Practical Guide, https://www.isaca.org/resources/isaca-journal/issues/2020/volume-3/business-continuity-management-a-practical-guide
CISA:Certified Information Systems Auditor · Q2
Question #2
Which of the following would be MOST useful when analyzing computer performance?
  • A.
    Tuning of system software to optimize resource usage
  • B.
    Operations report of user dissatisfaction with response time
  • C.
    Statistical metrics measuring capacity utilization
  • D.
    Report of off-peak utilization and response time

Answer: C

Answer Analysis:
This question aligns with CISA Domain 4 (Information Systems Operations and Business Resilience), which covers performance and capacity management as core operational governance activities. The most useful input for analyzing computer performance is objective, consistent, and comprehensive empirical data that captures system behavior across all workload cycles. Statistical capacity utilization metrics meet this requirement, as they provide quantifiable visibility into resource consumption (CPU, memory, storage I/O, network bandwidth) over time, enabling auditors and IT teams to identify bottlenecks, correlate usage patterns with performance issues, validate baseline adherence, and forecast future performance needs. Unlike partial or subjective inputs, these metrics support data-driven root cause analysis and performance optimization decisions, which are central to CISA's focus on efficient, reliable IS operations. Option Analysis:
A. Incorrect. Tuning of system software to optimize resource usage is a corrective action performed after performance analysis is complete, not a tool or input used to conduct performance analysis. It addresses identified performance gaps rather than supporting the analysis process itself.
B. Incorrect. User dissatisfaction reports are subjective, anecdotal indicators that a potential performance issue exists, but they provide no granular, verifiable data about the root cause of the performance problem. User complaints may stem from factors unrelated to core computer performance (e.g., end-user device issues, network connectivity problems, poorly designed application interfaces) so they are not useful for in-depth system performance analysis.
C. Correct. Statistical metrics measuring capacity utilization are objective, standardized measurements of core system resource consumption collected consistently across all operational periods. These metrics allow analysts to compare current performance against established baselines, identify resource bottlenecks, track usage trends over time, and isolate the root cause of performance degradation. This aligns with CISA guidance requiring empirical, quantifiable data for IS operational analysis and capacity management activities.
D. Incorrect. A report limited to off-peak utilization and response time only captures system performance during low-demand periods, when performance issues are least likely to occur. Most performance degradation events happen during peak workload hours, so this partial dataset lacks the context needed to conduct a full, accurate analysis of overall computer performance. Key Concepts:
1. Capacity Management: A core component of CISA Domain 4, capacity management is the process of monitoring, measuring, and planning IT resource capacity to meet current and future business performance requirements cost-effectively. Statistical utilization metrics are the primary input for all capacity and performance analysis activities.
2. Performance Baselines: CISA emphasizes the use of statistically derived performance baselines, which are established using historical capacity utilization metrics, to identify abnormal performance deviations, diagnose issues, and measure the effectiveness of performance optimization efforts.
3. Objective Operational Metrics: CISA prioritizes quantifiable, empirical operational data over subjective or anecdotal inputs for IS audit and analysis activities, as objective metrics provide consistent, verifiable insights that reduce bias and support accurate root cause analysis. References:
ISACA CISA Exam Domains, NIST SP 800-137: Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, https://csrc.nist.gov/publications/detail/sp/800-137/final
CISA:Certified Information Systems Auditor · Q3
Question #3
Which of the following is the GREATEST risk if two users have concurrent access to the same database record?
  • A.
    Entity integrity
  • B.
    Availability integrity
  • C.
    Referential integrity
  • D.
    Data integrity

Answer: D

Answer Analysis:
This question aligns with CISA Domain 3 (Information Systems Acquisition, Development and Implementation) and Domain 4 (Information Systems Operations and Business Resilience), which cover database security controls and operational data reliability. When two users access and modify the same database record concurrently without appropriate controls such as row-level locking, transaction isolation, or optimistic concurrency checks, common issues include lost updates, dirty reads, non-repeatable reads, and phantom reads. These events result in stored data no longer reflecting the accurate, intended state of information, which undermines organizational decision-making, regulatory compliance, and operational reliability. The greatest risk in this scenario is the compromise of data integrity, as there are no default schema-level controls that prevent conflicting modifications from rendering the record inaccurate. Option Analysis:
A. Entity integrity refers to the rule that every table record must have a unique, non-null primary key to ensure each record is uniquely identifiable. This constraint is enforced at the database schema level, and concurrent access to an existing record does not typically violate entity integrity, as primary keys are rarely modified during standard record updates. This option is incorrect.
B. Availability integrity is not a recognized formal database integrity or information security concept. Availability, a core component of the CIA triad, refers to the accessibility of systems and data when needed, while integrity refers to the accuracy and consistency of data. This is a distractor option and is incorrect.
C. Referential integrity enforces that foreign key values in a table match existing primary key values in a related table to preserve relationships between tables. Concurrent modification of a single record does not pose a material risk to referential integrity, which is enforced via schema-level foreign key constraints that operate independently of user access concurrency. This option is incorrect.
D. Data integrity refers to the accuracy, completeness, and consistency of data throughout its lifecycle. Concurrent unregulated access to the same record allows conflicting modifications that can overwrite valid changes, or present invalid data to users, directly compromising data integrity. This is the greatest risk in the scenario, so this option is correct. Key Concepts:
1. Data Integrity: A core component of the CIA (Confidentiality, Integrity, Availability) triad, defined by ISACA as the property that data is accurate, complete, consistent, and protected from unauthorized modification. Breaches of data integrity render organizational data unreliable for operational and decision-making purposes.
2. Concurrency Control: Database management system controls designed to prevent data integrity issues when multiple users access or modify the same data simultaneously. Common controls include row-level locking, transaction isolation levels, and optimistic concurrency checks that validate record state before committing changes.
3. Database Integrity Constraints: Formal rules enforced at the database schema level to preserve different aspects of data reliability, including entity integrity (primary key rules) and referential integrity (foreign key relationship rules), which are separate from the transaction-level data integrity risks posed by concurrent user access. References:
ISACA Official Glossary, https://www.isaca.org/resources/glossary
CISA Review Manual 2024
CISA:Certified Information Systems Auditor · Q4
Question #4
Which of the following is the MOST effective way for an organization to help ensure agreed-upon action plans from an IS audit will be implemented?
  • A.
    Ensure ownership is assigned.
  • B.
    Test corrective actions upon completion.
  • C.
    Ensure sufficient audit resources are allocated.
  • D.
    Communicate audit results organization-wide.

Answer: A

Answer Analysis:
This question falls under the CISA Information Systems Auditing Process domain, specifically covering audit follow-up and remediation management best practices. The core challenge in ensuring audit action plan implementation is establishing clear accountability, as unassigned responsibilities are often deprioritized, overlooked, or delayed due to diffusion of ownership across teams. Assigning formal ownership for each action item is the most foundational and effective step, as it establishes a single point of responsibility for driving execution, securing required resources, addressing barriers, and reporting progress to both management and audit teams. Without assigned ownership, even well-defined action plans rarely meet implementation timelines or deliver expected outcomes. Option Analysis:
A. Correct. Assigning clear, formal ownership for each audit action item establishes explicit accountability, which is the prerequisite for successful plan implementation. The assigned owner is responsible for prioritizing the remediation, coordinating cross-team efforts as needed, accessing required resources, and communicating status updates, which directly drives execution of the agreed-upon plan. This aligns with ISACA's official audit follow-up standards that identify ownership assignment as the first critical step in remediation management.
B. Incorrect. Testing corrective actions upon completion is a post-implementation validation activity that only verifies the effectiveness of actions after they are executed. It has no impact on whether the action plan is actually implemented in the first place, so it is not a measure to ensure implementation occurs.
C. Incorrect. Allocation of audit resources supports the ability to conduct the initial audit and perform post-implementation validation of remediations, but implementation of action plans is the responsibility of auditee management, not audit teams. Audit resource levels have no direct impact on ensuring auditees complete agreed-upon remediation actions.
D. Incorrect. Organization-wide communication of audit results raises general awareness of findings, but it does not assign specific accountability for individual action items. Awareness alone does not guarantee teams will prioritize or execute required remediation, so this is a supporting activity, not the most effective measure to ensure implementation. Key Concepts:
1. ISACA Standard 2400 (Engagement Follow-up): This official audit standard requires audit teams to establish a structured process to monitor remediation of audit findings, with explicit requirements to confirm ownership is assigned for each agreed-upon action item to drive accountability.
2. Remediation Accountability Principle: This core CISA concept holds that every audit action item must have a single, identifiable owner with the appropriate operational authority, resource access, and subject matter knowledge to complete the required remediation, as diffusion of responsibility is the leading cause of missed remediation deadlines and incomplete actions.
3. IS Audit Remediation Lifecycle: The end-to-end process for addressing audit findings includes action plan agreement, ownership assignment, implementation, effectiveness validation, and finding closure. Ownership assignment is the critical early control point that enables all subsequent lifecycle steps to proceed as planned. References:
ISACA IT Audit and Assurance Standard 2400: Engagement Follow-up, ISACA Journal: Audit Remediation Best Practices for IT and Business Leaders, https://www.isaca.org/resources/isaca-journal/issues/2021/volume-4/audit-remediation-best-practices-for-it-and-business-leaders
CISA:Certified Information Systems Auditor · Q5
Question #5
Which of the following issues associated with a data center's closed circuit television (CCTV) surveillance cameras should be of MOST concern to an IS auditor?
  • A.
    CCTV recordings are not regularly reviewed.
  • B.
    CCTV records are deleted after one year.
  • C.
    CCTV footage is not recorded 24 x 7.
  • D.
    CCTV cameras are not installed in break rooms.

Answer: A

Answer Analysis:
This question aligns with CISA Domain 4: Information Systems Operations and Business Resilience, specifically the evaluation of physical security controls. A core responsibility of an IS auditor is to verify that implemented controls deliver their intended risk mitigation value, rather than only confirming the control exists. Closed circuit television (CCTV) in data centers functions as both a detective and deterrent control, designed to identify unauthorized access, monitor sensitive areas, and support incident investigation. If CCTV recordings are not regularly reviewed, the control fails to fulfill its core purpose: security incidents will not be detected timely, malicious activity will remain unaddressed, and there is no validation that the CCTV system is operating as intended. This represents a complete failure of the control's utility, making it the highest priority concern for the IS auditor. Option Analysis:
A. Correct. Regular review of CCTV recordings is required to realize the security benefit of the CCTV control. Without consistent review, security events such as unauthorized access to server aisles, hardware tampering, or staff policy violations will not be identified in a timely manner, and the deterrent effect of CCTV is eliminated if personnel know recordings are never checked. This renders the entire CCTV investment nearly useless for risk mitigation, which is the most severe risk presented.
B. Incorrect. A one-year retention period for CCTV records aligns with most industry standards and regulatory requirements, as nearly all physical security incidents are detected and investigated within 90 days or less. No specific regulatory requirement for longer retention is noted in the scenario, so this is a low-risk finding and not a top concern.
C. Incorrect. While 24x7 recording is a common best practice, many organizations use motion-activated recording or restrict recording to periods when the data center is accessible, with compensating controls such as on-site security guards or perimeter alarm systems during non-recording windows. This gap can be mitigated with compensating controls, making it less critical than the total lack of control effectiveness from unreviewed recordings.
D. Incorrect. Break rooms are non-sensitive, staff-only areas where CCTV recording often raises privacy compliance concerns. CCTV deployments in data centers are appropriately focused on high-risk areas including entry/exit points, server rack aisles, and utility rooms, so the absence of cameras in break rooms is not a material security concern. Key Concepts:
1. Control Effectiveness Assessment: This core CISA knowledge domain requires auditors to evaluate if implemented controls actually reduce risk as intended, rather than just confirming the control is present. A deployed control with no process to leverage its output delivers no risk mitigation value.
2. Detective Control Objectives: CCTV is classified as a detective physical security control, whose core function is timely identification of security events. Without regular review of its output, a detective control cannot meet its intended purpose.
3. Risk Prioritization: IS auditors rank findings based on the magnitude of risk they introduce. Failures that completely negate the value of a security control are higher priority than gaps in policy parameters or non-implementation of controls in low-risk areas. References:
ISACA CISA Review Manual 27th Edition, ISACA Auditing Physical Access Controls Guide, https://www.isaca.org/resources/isaca-journal/issues/2019/volume-3/auditing-physical-access-controls

FAQ

How many practice questions are available for CISA:Certified Information Systems Auditor ?

This question bank includes 1823 CISA:Certified Information Systems Auditor practice questions covering single and multiple choice, each with answers and explanations.

Are CISA:Certified Information Systems Auditor practice questions available in Chinese and English?

Yes, CISA:Certified Information Systems Auditor practice questions are provided in both Chinese and English.

Can I try CISA:Certified Information Systems Auditor practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.