About the Exam

CISA is ISACA's certification exam for information systems auditors and other IT assurance professionals. The exam has 150 questions across five domains: information system auditing process, governance and management of IT, information systems acquisition/development/implementation, information systems operations and business resilience, and protection of information assets. Passing demonstrates knowledge and ability to audit, monitor, and assess IT and business systems using a risk-based approach.

Exam Topics

  • Information System Auditing Process18%
  • Governance and Management of IT18%
  • Information Systems Acquisition, Development and Implementation12%
  • Information Systems Operations and Business Resilience26%
  • Protection of Information Assets26%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 12, 2026 at 4:21 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Protection of Information Assets

A business unit received an audit finding after an administrator made unauthorized emergency changes to a critical system. Which of the following would BEST prevent unauthorized changes in the future?

Explanation

Dual-control temporary emergency access accounts require participation by two authorized individuals before emergency access can be used. This enforces authorization in advance and prevents one administrator from independently making an unapproved emergency change.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

Protection of Information Assets

An employee misplaces a mobile device, resulting in the loss of sensitive corporate data. Which of the following would have BEST prevented data leakage?

Explanation

Encryption on a mobile device protects sensitive data at rest by rendering it unreadable to an unauthorized person who obtains the lost device. This directly mitigates disclosure of the device’s stored corporate data.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

Protection of Information Assets

What is the first step in creating a data-classification program?

Explanation

A data-classification policy establishes the classification framework: its levels, criteria, responsibilities, and required handling rules. Data process mapping and the categorization or prioritization of data are implementation activities that follow from that governing policy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Protection of Information Assets

The process of applying a hash function to a message, obtaining a digest, and ciphering that digest refers to:

Explanation

A digital signature applies a hash function to create a message digest and encrypts or signs that digest using the sender’s private key. This supports integrity verification and signer authentication.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Information Systems Operations and Business Resilience

As part of virtualized-environment architecture, a bare-metal or native virtualization hypervisor operates without:

Explanation

A bare-metal (Type 1) hypervisor runs directly on the underlying hardware, so it does not require a host operating system. It can still host guest operating systems and their applications in virtual machines.

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home