CISA Certification Exam 2026 Latest Comprehensive
Study Guide with Practice Questions
Five Exam Domains (August 2024 Content Outline, effective 2026):
Domain Weight
Domain 1: Information Systems Auditing Process 18%
Domain 2: Governance and Management of IT 18%
Domain 3: Information Systems Acquisition, Development & Implementation 12%
Domain 4: Information Systems Operations and Business Resilience 26%
Domain 5: Protection of Information Assets 26%
Note: Domains 4 and 5 together account for 52% of the exam—these are the
highest-weighted areas and should receive significant study focus. The exam
follows ISACA's CISA Job Practice and references ITAF™ (ISACA IT Audit
Framework) , COBIT® 2019, and ISACA's Code of Professional Ethics.
SECTION 1: DOMAIN 1 — INFORMATION SYSTEMS AUDITING
PROCESS (18%) (Questions 1-20)
Question 1
Which of the following is the PRIMARY objective of an information systems
audit?
A) To identify all security vulnerabilities in an organization's IT infrastructure
B) To evaluate the design, effectiveness, and efficiency of controls over
information systems
,C) To ensure compliance with all applicable laws and regulations
D) To recommend cost-saving measures for IT operations
Correct Answer: B
Rationale: The primary objective of an IS audit is to evaluate the design,
effectiveness, and efficiency of controls over information systems. While
identifying vulnerabilities (A), ensuring compliance (C), and recommending cost
savings (D) may be part of an audit, they are not the primary objective. The IS
auditor's core responsibility is to assess whether controls are properly designed,
implemented, and operating effectively to protect organizational assets, ensure data
integrity, and support business objectives.
Question 2
An IS auditor is planning an audit of a financial system. According to ISACA
standards, which of the following should the auditor do FIRST?
A) Develop detailed audit procedures
B) Perform a risk assessment to determine the audit scope
C) Interview system users to gather evidence
D) Review the system's access control logs
Correct Answer: B
Rationale: According to ISACA auditing standards, the auditor should perform a
risk assessment to determine the audit scope as the first step in audit planning.
The risk assessment identifies areas of highest risk and informs the development of
the audit plan, including the scope, objectives, and procedures. Developing
detailed audit procedures (A), interviewing users (C), and reviewing logs (D) occur
after the risk assessment and scope definition.
Question 3
Which of the following ISACA standards addresses the auditor's responsibility to
maintain professional competence?
A) Standard S1 — Audit Charter
B) Standard S2 — Independence
,C) Standard S3 — Professional Skepticism
D) Standard S4 — Competence
Correct Answer: D
Rationale: Standard S4 — Competence addresses the IS auditor's responsibility
to maintain professional knowledge and skills to perform their duties effectively.
This includes ongoing professional development, staying current with emerging
technologies and threats, and knowing when to seek expert assistance. S1 (Audit
Charter), S2 (Independence), and S3 (Professional Skepticism) address other
aspects of professional practice.
Question 4
During an audit, an IS auditor identifies a material weakness in the organization's
access control system. What is the auditor's MOST appropriate course of action?
A) Document the finding and report it to senior management and the audit
committee
B) Fix the access control issue immediately
C) Ignore the finding since it is outside the audit scope
D) Report the finding only to the IT department manager
Correct Answer: A
Rationale: When a material weakness is identified, the IS auditor must document
the finding and report it to senior management and the audit committee.
Material weaknesses represent significant deficiencies that could materially affect
the organization's ability to achieve its objectives. The auditor's role is to report
and recommend, not to fix the issue directly (B). Ignoring the finding (C) violates
professional standards. Reporting only to the IT manager (D) may not ensure
appropriate oversight.
Question 5
Which of the following is the BEST example of a preventive control?
A) Intrusion detection system (IDS)
B) Firewall with access control rules
, C) Security incident response plan
D) Disaster recovery testing
Correct Answer: B
Rationale: A firewall with access control rules is a preventive control because
it is designed to prevent unauthorized access from occurring in the first place.
Preventive controls stop errors or irregularities before they happen. An intrusion
detection system (A) is a detective control—it identifies problems after they occur.
A security incident response plan (C) and disaster recovery testing (D) are
corrective controls—they address problems after they have been detected.
Question 6
When performing a risk-based audit, an IS auditor should prioritize audit activities
based on:
A) The age of the systems being audited
B) The preferences of the audit committee
C) The level of risk and the impact on business objectives
D) The cost of the audit procedures
Correct Answer: C
Rationale: In a risk-based audit, the auditor should prioritize audit activities
based on the level of risk and the impact on business objectives. This approach
ensures that the most critical areas—those with the highest potential impact on the
organization—receive the most attention. System age (A), committee preferences
(B), and audit cost (D) are not the primary drivers of audit prioritization in a risk-
based approach.
Question 7
An IS auditor is evaluating evidence collected during an audit. Which of the
following types of evidence is generally considered the MOST reliable?
A) Oral evidence from an employee interview
B) Documentary evidence from a third party (e.g., bank statement)
Study Guide with Practice Questions
Five Exam Domains (August 2024 Content Outline, effective 2026):
Domain Weight
Domain 1: Information Systems Auditing Process 18%
Domain 2: Governance and Management of IT 18%
Domain 3: Information Systems Acquisition, Development & Implementation 12%
Domain 4: Information Systems Operations and Business Resilience 26%
Domain 5: Protection of Information Assets 26%
Note: Domains 4 and 5 together account for 52% of the exam—these are the
highest-weighted areas and should receive significant study focus. The exam
follows ISACA's CISA Job Practice and references ITAF™ (ISACA IT Audit
Framework) , COBIT® 2019, and ISACA's Code of Professional Ethics.
SECTION 1: DOMAIN 1 — INFORMATION SYSTEMS AUDITING
PROCESS (18%) (Questions 1-20)
Question 1
Which of the following is the PRIMARY objective of an information systems
audit?
A) To identify all security vulnerabilities in an organization's IT infrastructure
B) To evaluate the design, effectiveness, and efficiency of controls over
information systems
,C) To ensure compliance with all applicable laws and regulations
D) To recommend cost-saving measures for IT operations
Correct Answer: B
Rationale: The primary objective of an IS audit is to evaluate the design,
effectiveness, and efficiency of controls over information systems. While
identifying vulnerabilities (A), ensuring compliance (C), and recommending cost
savings (D) may be part of an audit, they are not the primary objective. The IS
auditor's core responsibility is to assess whether controls are properly designed,
implemented, and operating effectively to protect organizational assets, ensure data
integrity, and support business objectives.
Question 2
An IS auditor is planning an audit of a financial system. According to ISACA
standards, which of the following should the auditor do FIRST?
A) Develop detailed audit procedures
B) Perform a risk assessment to determine the audit scope
C) Interview system users to gather evidence
D) Review the system's access control logs
Correct Answer: B
Rationale: According to ISACA auditing standards, the auditor should perform a
risk assessment to determine the audit scope as the first step in audit planning.
The risk assessment identifies areas of highest risk and informs the development of
the audit plan, including the scope, objectives, and procedures. Developing
detailed audit procedures (A), interviewing users (C), and reviewing logs (D) occur
after the risk assessment and scope definition.
Question 3
Which of the following ISACA standards addresses the auditor's responsibility to
maintain professional competence?
A) Standard S1 — Audit Charter
B) Standard S2 — Independence
,C) Standard S3 — Professional Skepticism
D) Standard S4 — Competence
Correct Answer: D
Rationale: Standard S4 — Competence addresses the IS auditor's responsibility
to maintain professional knowledge and skills to perform their duties effectively.
This includes ongoing professional development, staying current with emerging
technologies and threats, and knowing when to seek expert assistance. S1 (Audit
Charter), S2 (Independence), and S3 (Professional Skepticism) address other
aspects of professional practice.
Question 4
During an audit, an IS auditor identifies a material weakness in the organization's
access control system. What is the auditor's MOST appropriate course of action?
A) Document the finding and report it to senior management and the audit
committee
B) Fix the access control issue immediately
C) Ignore the finding since it is outside the audit scope
D) Report the finding only to the IT department manager
Correct Answer: A
Rationale: When a material weakness is identified, the IS auditor must document
the finding and report it to senior management and the audit committee.
Material weaknesses represent significant deficiencies that could materially affect
the organization's ability to achieve its objectives. The auditor's role is to report
and recommend, not to fix the issue directly (B). Ignoring the finding (C) violates
professional standards. Reporting only to the IT manager (D) may not ensure
appropriate oversight.
Question 5
Which of the following is the BEST example of a preventive control?
A) Intrusion detection system (IDS)
B) Firewall with access control rules
, C) Security incident response plan
D) Disaster recovery testing
Correct Answer: B
Rationale: A firewall with access control rules is a preventive control because
it is designed to prevent unauthorized access from occurring in the first place.
Preventive controls stop errors or irregularities before they happen. An intrusion
detection system (A) is a detective control—it identifies problems after they occur.
A security incident response plan (C) and disaster recovery testing (D) are
corrective controls—they address problems after they have been detected.
Question 6
When performing a risk-based audit, an IS auditor should prioritize audit activities
based on:
A) The age of the systems being audited
B) The preferences of the audit committee
C) The level of risk and the impact on business objectives
D) The cost of the audit procedures
Correct Answer: C
Rationale: In a risk-based audit, the auditor should prioritize audit activities
based on the level of risk and the impact on business objectives. This approach
ensures that the most critical areas—those with the highest potential impact on the
organization—receive the most attention. System age (A), committee preferences
(B), and audit cost (D) are not the primary drivers of audit prioritization in a risk-
based approach.
Question 7
An IS auditor is evaluating evidence collected during an audit. Which of the
following types of evidence is generally considered the MOST reliable?
A) Oral evidence from an employee interview
B) Documentary evidence from a third party (e.g., bank statement)