ISACA · Advanced

ISACA CISA — Certified Information Systems Auditor (CISA) practice exam & study guide

ISACA CISA (Certified Information Systems Auditor) is the benchmark certification for professionals who audit, control, and assure an organization’s information systems. It validates expertise across five domains — the auditing process, IT governance, systems acquisition and implementation, operations and resilience, and protection of information assets.

CISA is an auditor’s credential. Questions favor the independent auditor’s perspective — evidence, controls testing, and risk-based judgment — over hands-on technical implementation.

This free hub gives you everything you need to prepare: a syllabus breakdown by exam domain, realistic practice questions with teacher-style explanations, a glossary of the audit and assurance concepts the exam relies on, and full-length timed mock exams that mirror the real testing experience.

100
Questions
180 min
Time limit
70%
Mock pass %
5
Domains

Start studying CISA

New here? Follow the three steps below in order. Everything is free and needs no account.

  1. 1
    Learn the plan

    See all 5 domains in exam-weight order.

    Open study path
  2. 2
    Drill by domain

    Practice one topic at a time with explained answers.

    Start with the first domain
  3. 3
    Sit a timed mock

    100 questions · 180 min · 70% to pass our mock.

    Take the mock exam

All CISA study resources

CISA exam domains

The CISA exam is weighted across 5 domains. Pick any domain below to drill it — or read the full breakdown in the FAQ.

Exam domainExam weightPractice
Information System Auditing Process18%Practice this topic
Governance and Management of IT18%Practice this topic
Information Systems Acquisition, Development and Implementation12%Practice this topic
Information Systems Operations and Business Resilience26%Practice this topic
Protection of Information Assets26%Practice this topic

Sample CISA questions

A sample of the CISA questions on this hub. Each links through to the full question, the correct answer, and an explanation of why every other option is wrong.

Key CISA terms

Start with these terms, then explore the full glossary. Each links to a plain-English definition written for the CISA exam.

CISA frequently asked questions

What is the CISA certification?+

CISA is widely regarded as the leading certification for IS audit, control, and assurance, and is a common requirement in audit and compliance job listings.

It emphasizes the auditing lifecycle and controls, so success rewards audit judgment and knowledge of governance and controls rather than tool-specific skills.

What topics are on the CISA exam?+

The CISA exam is organised into five weighted domains. The percentages below are ISACA’s official weightings for the current exam content outline, so bias your study toward the heavier domains — Information Systems Operations and Business Resilience and Protection of Information Assets are the two largest, each about a quarter of the exam.

Information System Auditing Process (18%)

Covers planning and executing IS audits to standards: risk-based audit planning, audit project management, sampling methodology, evidence collection, data analytics, reporting results, and control self-assessment (CSA).

Governance and Management of IT (18%)

Covers IT governance frameworks, policies, and organizational structure; enterprise architecture and IT strategy alignment; IT resource and third-party/SLA management; performance monitoring; and applicable laws, regulations, and standards.

Information Systems Acquisition, Development and Implementation (12%)

Covers project governance and business case analysis, system development methodologies and controls, control identification and design, testing and implementation readiness, and post-implementation review.

Information Systems Operations and Business Resilience (26%)

One of the two largest domains. Covers technology components and IT asset management, job scheduling, systems performance, incident and change/configuration/patch management, database management, and business resilience — BIA, backups, and disaster recovery (RTO/RPO).

Protection of Information Assets (26%)

One of the two largest domains. Covers security frameworks and controls, physical and environmental controls, identity and access management, network and endpoint security, encryption and data loss prevention, PKI, and security event management and forensics. (Data governance and classification sit in the Governance and Management of IT domain.)

Is the CISA hard?+

CISA is challenging because it demands the auditor’s mindset: you must choose the best answer based on independence, evidence, and control effectiveness rather than the most technical fix.

The five domains span the whole audit discipline, and the heavy weighting on operations/resilience and asset protection rewards judgment built from real audit experience.

How many questions are on the CISA exam and how long is it?+

The CISA exam consists of 150 multiple-choice questions to be completed in 4 hours (240 minutes).

Our full-length practice mock uses a 100-question, 180-minute session so you can rehearse pacing and audit-style reasoning across all five domains before test day.

What score do you need to pass the CISA?+

ISACA scores CISA on a scaled range of 200 to 800, and you need a scaled score of 450 to pass. Your raw performance is converted to this scaled score, and there is no penalty for guessing, so answer everything. Our practice mock uses a 70% threshold as a study checkpoint; aim comfortably beyond it before test day.

How much does the CISA exam cost?+

The CISA exam fee is set by ISACA and differs for members and non-members — check the ISACA site for current pricing. Certification also requires meeting the work-experience requirement and paying annual maintenance fees with continuing professional education (CPE). Everything on this hub is free.

Who should take the CISA?+

CISA is aimed at IS auditors, audit managers, and IT and compliance professionals who assess controls and assurance.

ISACA requires five years of IS audit, control, or security work experience, with defined waivers, to certify. You can pass the exam first and claim the experience within five years.

What jobs and salaries can the CISA lead to?+

CISA maps to roles such as IS auditor, IT audit manager, compliance analyst, and internal audit lead.

How much any certification affects pay depends heavily on geography, seniority, and experience, so treat any single salary figure with caution. CISA is best viewed as validation of IS audit and assurance competence.

How long does it take to study for the CISA?+

Experienced candidates often need two to three months of steady study, focused on adopting the auditor’s perspective the exam rewards.

Review every explanation, including for questions you answered correctly, because CISA distractors are built from plausible but sub-optimal audit choices. Use the per-domain results here to find your weakest area, then finish with full-length timed mocks.

How should you prepare for the CISA?+

Study the five domains above, giving the heaviest weight to Operations/Resilience and Protection of Information Assets, then drill scenario questions domain by domain. Every MockAPI question reveals a full explanation and tells you why each wrong answer is wrong.

When you can reason to the best audit answer comfortably, move to full-length timed mocks. Use the glossary to keep concepts like audit evidence, control self-assessment, SoD, and RTO/RPO straight, and aim to score consistently above the checkpoint before you book.

Can you take the CISA exam online?+

Yes. ISACA offers CISA through remote online proctoring as well as at in-person test centers, so you can choose the option that suits you. The online exam requires a private, quiet room, a clear workspace, a webcam and microphone, a stable connection, and government-issued photo ID, with a proctor monitoring you and a room scan before you start.

If you do not pass, ISACA lets you retake the exam, with a limited number of attempts allowed per rolling twelve-month period — check the current policy before rebooking.

What certification should you take after the CISA?+

After CISA, common next steps include ISACA’s CISM for security management, CRISC for risk, or CDPSE for data privacy, depending on your focus.

For many, the real next step is leading an audit function. Pairing CISA with hands-on audit experience is what turns the certificate into a career.