CISA exam domains
The CISA exam is weighted across 5 domains. Pick any domain below to drill it — or read the full breakdown in the FAQ.
| Exam domain | Exam weight | Practice |
|---|---|---|
| Information System Auditing Process | 18% | Practice this topic |
| Governance and Management of IT | 18% | Practice this topic |
| Information Systems Acquisition, Development and Implementation | 12% | Practice this topic |
| Information Systems Operations and Business Resilience | 26% | Practice this topic |
| Protection of Information Assets | 26% | Practice this topic |
Sample CISA questions
A sample of the CISA questions on this hub. Each links through to the full question, the correct answer, and an explanation of why every other option is wrong.
- An organization is replacing its core inventory management system. Project management has selected an abrupt (direct) changeover on a weekend, decommi…View question
- During a review of a perimeter firewall, an IS auditor finds that the rule base ends with an explicit 'permit any any' statement placed after several…View question
- An IS auditor is reviewing an agile software development project. The development team completes sprints every two weeks and demonstrates working feat…View question
- A financial analyst needs to send a confidential report to an external business partner and wants to ensure that only that partner can read the messag…View question
- A newly appointed IS audit manager discovers that the internal audit function has been operating without a formally approved audit charter for the pas…View question
- During a review of an organization's purchase-to-pay process, an IS auditor gains read-only access to the complete general ledger and accounts payable…View question
- During a fraud investigation, an IS auditor collects log files and a copy of a suspect employee's hard drive as potential evidence for possible legal…View question
- During an audit of a data center's physical access controls, an IS auditor observes badge-reader operation for one hour on the day of the visit and no…View question
- During a review of a company's procurement process, an IS auditor is evaluating several pieces of evidence to support a finding about unauthorized pur…View question
- During an information systems audit, a senior auditor completes the fieldwork and drafts preliminary conclusions on the effectiveness of change manage…View question
Key CISA terms
Start with these terms, then explore the full glossary. Each links to a plain-English definition written for the CISA exam.
CISA frequently asked questions
What is the CISA certification?+
CISA is widely regarded as the leading certification for IS audit, control, and assurance, and is a common requirement in audit and compliance job listings.
It emphasizes the auditing lifecycle and controls, so success rewards audit judgment and knowledge of governance and controls rather than tool-specific skills.
What topics are on the CISA exam?+
The CISA exam is organised into five weighted domains. The percentages below are ISACA’s official weightings for the current exam content outline, so bias your study toward the heavier domains — Information Systems Operations and Business Resilience and Protection of Information Assets are the two largest, each about a quarter of the exam.
Information System Auditing Process (18%)
Covers planning and executing IS audits to standards: risk-based audit planning, audit project management, sampling methodology, evidence collection, data analytics, reporting results, and control self-assessment (CSA).
Governance and Management of IT (18%)
Covers IT governance frameworks, policies, and organizational structure; enterprise architecture and IT strategy alignment; IT resource and third-party/SLA management; performance monitoring; and applicable laws, regulations, and standards.
Information Systems Acquisition, Development and Implementation (12%)
Covers project governance and business case analysis, system development methodologies and controls, control identification and design, testing and implementation readiness, and post-implementation review.
Information Systems Operations and Business Resilience (26%)
One of the two largest domains. Covers technology components and IT asset management, job scheduling, systems performance, incident and change/configuration/patch management, database management, and business resilience — BIA, backups, and disaster recovery (RTO/RPO).
Protection of Information Assets (26%)
One of the two largest domains. Covers security frameworks and controls, physical and environmental controls, identity and access management, network and endpoint security, encryption and data loss prevention, PKI, and security event management and forensics. (Data governance and classification sit in the Governance and Management of IT domain.)
Is the CISA hard?+
CISA is challenging because it demands the auditor’s mindset: you must choose the best answer based on independence, evidence, and control effectiveness rather than the most technical fix.
The five domains span the whole audit discipline, and the heavy weighting on operations/resilience and asset protection rewards judgment built from real audit experience.
How many questions are on the CISA exam and how long is it?+
The CISA exam consists of 150 multiple-choice questions to be completed in 4 hours (240 minutes).
Our full-length practice mock uses a 100-question, 180-minute session so you can rehearse pacing and audit-style reasoning across all five domains before test day.
What score do you need to pass the CISA?+
ISACA scores CISA on a scaled range of 200 to 800, and you need a scaled score of 450 to pass. Your raw performance is converted to this scaled score, and there is no penalty for guessing, so answer everything. Our practice mock uses a 70% threshold as a study checkpoint; aim comfortably beyond it before test day.
How much does the CISA exam cost?+
The CISA exam fee is set by ISACA and differs for members and non-members — check the ISACA site for current pricing. Certification also requires meeting the work-experience requirement and paying annual maintenance fees with continuing professional education (CPE). Everything on this hub is free.
Who should take the CISA?+
CISA is aimed at IS auditors, audit managers, and IT and compliance professionals who assess controls and assurance.
ISACA requires five years of IS audit, control, or security work experience, with defined waivers, to certify. You can pass the exam first and claim the experience within five years.
What jobs and salaries can the CISA lead to?+
CISA maps to roles such as IS auditor, IT audit manager, compliance analyst, and internal audit lead.
How much any certification affects pay depends heavily on geography, seniority, and experience, so treat any single salary figure with caution. CISA is best viewed as validation of IS audit and assurance competence.
How long does it take to study for the CISA?+
Experienced candidates often need two to three months of steady study, focused on adopting the auditor’s perspective the exam rewards.
Review every explanation, including for questions you answered correctly, because CISA distractors are built from plausible but sub-optimal audit choices. Use the per-domain results here to find your weakest area, then finish with full-length timed mocks.
How should you prepare for the CISA?+
Study the five domains above, giving the heaviest weight to Operations/Resilience and Protection of Information Assets, then drill scenario questions domain by domain. Every MockAPI question reveals a full explanation and tells you why each wrong answer is wrong.
When you can reason to the best audit answer comfortably, move to full-length timed mocks. Use the glossary to keep concepts like audit evidence, control self-assessment, SoD, and RTO/RPO straight, and aim to score consistently above the checkpoint before you book.
Can you take the CISA exam online?+
Yes. ISACA offers CISA through remote online proctoring as well as at in-person test centers, so you can choose the option that suits you. The online exam requires a private, quiet room, a clear workspace, a webcam and microphone, a stable connection, and government-issued photo ID, with a proctor monitoring you and a room scan before you start.
If you do not pass, ISACA lets you retake the exam, with a limited number of attempts allowed per rolling twelve-month period — check the current policy before rebooking.
What certification should you take after the CISA?+
After CISA, common next steps include ISACA’s CISM for security management, CRISC for risk, or CDPSE for data privacy, depending on your focus.
For many, the real next step is leading an audit function. Pairing CISA with hands-on audit experience is what turns the certificate into a career.