An unhandled error has occurred. Reload X

ISACA Certified Information Systems Auditor (CISA) Practice Test

300 questions available

The ISACA Certified Information Systems Auditor (CISA) certification is the globally recognized standard for professionals who audit, control, monitor, and assess an organization's information technology and business systems. Earning the CISA designation validates your expertise in identifying vulnerabilities, reporting on compliance, and implementing controls within an enterprise IT environment. It demonstrates a comprehensive understanding of the five core domains defined by ISACA: the Information Systems Auditing Process, Governance and Management of IT, Information Systems Acquisition, Development and Implementation, Information Systems Operations and Business Resilience, and Protection of Information Assets. CISA-certified professionals are trusted by employers and clients to provide assurance that critical assets are secured and aligned with organizational goals. The certification is consistently ranked among the highest-paying and most sought-after credentials in IT audit, risk, and cybersecurity, serving as a key differentiator in a competitive job market and a testament to a practitioner's commitment to the highest standards of professionalism and competence.

Certification exam
150 Exam questions
4 hours Time Limit
Career Opportunities & Salary
Entry – IT Auditor $68,000 - $104,000
Mid-Career – IT Audit Manager $97,000 - $148,000
Senior – Director of IT Audit $125,000 - $191,000
IT AuditorIT Audit ManagerDirector of IT Auditstable market
Why This Certification Opens Doors

Achieving the CISA certification is a pivotal career milestone that signifies mastery of a rigorous, internationally accepted body of knowledge. It provides immediate industry recognition, enhancing your professional credibility and marketability. For employers, a CISA credential serves as an objective benchmark of an individual's capability to manage IT-related risks and ensure compliance in complex regulatory environments. It directly correlates with career advancement, often being a prerequisite for senior roles in IT audit, risk management, and cybersecurity leadership. The certification opens doors to higher earning potential and positions you as a subject matter expert, enabling you to contribute strategically to organizational governance and resilience.

Exam Blueprint

Each domain is weighted to match the real certification exam, so a full practice simulation predicts your result.

01Protection of Information Assets
27%
02Information Systems Operations and Business Resilience
23%
03Information Systems Auditing Process
21%
04Governance and Management of IT
17%
05Information Systems Acquisition, Development, and Implementation
12%
Exam Details CISA | $760 USD | 4 hours
Exam Code CISA
Vendor ISACA
Exam Cost $760 USD
Passing Score 450
Time Limit 4 hours
Exam questions 150
Question Types Multiple Choice
Retake Policy Must wait 30 days before retaking. Maximum 3 exam attempts per 12-month period. Full exam fee required for each retake.
Exam Format Linear
Online Proctoring Available
Available In
EnglishChineseJapaneseKoreanSpanishGermanFrenchPortuguese
Study Resources
ISACA Exam Prep Resources
ISACAFree
Official review manuals, question databases, and virtual labs
View
ISACA Question, Answers & Explanations Database
ISACAFree
Official QA&E database with 1,000+ practice questions per exam
View
Frequently Asked Questions

What are the experience requirements to become CISA certified?

Candidates must submit verified evidence of a minimum of five years of professional work experience in information systems auditing, control, assurance, or security. Substitutions and waivers are available for up to three years: a maximum of one year can be waived for one year of non-IS auditing experience or one year of information systems/one year of university instructor experience. Additionally, a two-year substitution is granted for a master's degree in information security or information technology from an accredited university. All experience must be verified and gained within the 10-year period preceding the application date or within five years of passing the exam.

How is the CISA exam structured, and what is the passing score?

The CISA exam is a computer-based test comprising 150 multiple-choice questions, which must be completed within a 4-hour testing window. The questions are based on the five CISA job practice domains, with a weighted distribution. ISACA uses a scaled scoring model, where a score of 450 or higher on a scale of 200-800 represents a passing mark. This scaled score is a conversion of the raw score (number of questions answered correctly) to a standardized scale that accounts for slight variations in difficulty across different exam forms. The exact number of correct answers needed can therefore vary slightly.

How does CISA differ from other certifications like CISSP or CIA?

CISA is specifically focused on the audit, control, and assurance of information systems. It is the premier credential for IT auditors. CISSP (Certified Information Systems Security Professional) has a broader focus on designing, implementing, and managing a cybersecurity program. The CIA (Certified Internal Auditor) covers general internal audit principles across all business areas (finance, operations, IT), with IT being one component. While there is overlap, CISA provides deep, specialized expertise in IT audit processes, making it the definitive choice for professionals in that specific career path.

What is the CPE (Continuing Professional Education) requirement for maintaining the CISA?

To maintain your CISA certification, you must earn and report a minimum of 20 Continuing Professional Education (CPE) hours annually, and 120 CPE hours over a fixed three-year reporting period. These hours must be relevant to the CISA job practice areas or directly related to the profession. Activities include attending training courses, webinars, conferences, publishing relevant articles, teaching, and self-study. Compliance with the CPE policy and ISACA's Code of Professional Ethics is mandatory to keep the certification in good standing.

What are the primary resources recommended for CISA exam preparation?

ISACA strongly recommends using its official preparation materials, which are aligned directly with the exam content. The core resources include: 1) The CISA Review Manual, which provides comprehensive coverage of the domains; 2) The CISA Question, Answer, and Explanation (QAE) Database, which offers an extensive bank of practice questions with detailed explanations; and 3) The CISA Review Course, available online or in-person. Many candidates also supplement with study guides from reputable publishers and participate in study groups or online forums dedicated to CISA preparation.

Reviews & Ratings
No reviews yet

Be the first to review this exam and help other learners!


Share Your Experience