Certified Information Systems Auditor
CISA Practice Examination
150 Questions | 2026/2027 Edition
Aligned with ISACA CISA Job Practice Domains | COBIT 2019 | Pearson VUE
, CISA Practice Examination 2026/2027
Introduction .................................................................................................................................................. 2
Exam Structure and Administration ........................................................................................................... 2
Examination Questions ................................................................................................................................ 2
Domain 1: Information Systems Auditing Process ................................................................................. 2
Domain 2: Governance and Management of IT .................................................................................... 11
Domain 3: Information Systems Acquisition, Development, and Implementation ............................ 18
Domain 4: Information Systems Operations and Business Resilience ............................................... 25
Domain 5: Protection of Information Assets ........................................................................................ 38
References and Professional Standards ..................................................................................................... 51
Page 1 of 52
, CISA Practice Examination 2026/2027
Introduction
The Certified Information Systems Auditor (CISA) designation is a globally recognized certification
awarded by ISACA (Information Systems Audit and Control Association). It validates an individual's
expertise in information systems auditing, control, and security. The CISA examination is designed to
test a candidate's ability to manage vulnerabilities, ensure compliance with regulatory frameworks,
and implement effective IT governance processes within an enterprise environment.
This practice examination is aligned with the ISACA CISA Job Practice Domains effective 2024 and is
structured around five core domains: (1) Information Systems Auditing Process, (2) Governance and
Management of IT, (3) Information Systems Acquisition, Development, and Implementation, (4)
Information Systems Operations and Business Resilience, and (5) Protection of Information Assets.
The exam follows a criterion-referenced scoring model with a passing threshold of 450 out of 800
scaled points, ensuring candidates demonstrate a thorough understanding across all domains rather
than competing against one another.
The regulatory and professional framework underpinning this examination draws from ISACA
Standards, Guidelines and Procedures, COBIT 2019 for governance and management objectives, ITIL
4 for IT service management best practices, ISO/IEC 27001:2022 for information security
management, and the NIST Cybersecurity Framework. This practice set includes 150 carefully crafted
multiple-choice questions that reflect the depth and rigor of the actual CISA exam, providing
candidates with a comprehensive self-assessment tool for certification preparation.
Exam Structure and Administration
Parameter Details
Total Questions 150 multiple-choice (single best answer)
Testing Time 4 hours (240 minutes)
Format Computer-based, proctored (Pearson VUE / online remote)
Passing Score 450/800 (scaled, criterion-referenced)
CPE Maintenance 20 CPEs annually, 120 over 3-year cycle
Regulatory Framework ISACA Standards, COBIT 2019, ITIL, ISO 27001
Exam Domains 5 domains per ISACA Job Practice (effective 2024)
Table 1: CISA Examination Parameters
Examination Questions
Domain 1: Information Systems Auditing Process
1. According to ISACA Standards, what is the PRIMARY purpose of an information
systems audit?
A. To ensure IT systems generate maximum revenue
B. To provide reasonable assurance that an organization's IT governance, risk
management, and control processes are adequately designed and operating
effectively
Page 2 of 52
, CISA Practice Examination 2026/2027
C. To replace management's responsibility for internal controls
D. To verify that all IT projects are completed on time and within budget
Correct Answer: B.
Rationale: ISACA Standards define the primary purpose of an IS audit as providing reasonable
assurance to stakeholders that IT governance, risk management, and control processes are
adequate and effective. Auditors provide independent assessment but do not assume management
responsibility for control design or operation.
2. Which ISACA Code of Professional Ethics principle requires IS auditors to perform
their duties with due care and in accordance with applicable standards?
A. Independence
B. Due professional care
C. Confidentiality
D. Objectivity
Correct Answer: B.
Rationale: ISACA's Code of Professional Ethics mandates due professional care, requiring auditors
to perform their work in accordance with applicable auditing standards, exercise professional
judgment, and maintain the competence necessary to carry out their responsibilities. This principle
ensures audit quality and reliability.
3. During the planning phase of an IS audit, what is the MOST important factor in
determining audit scope?
A. The audit budget approved by the board
B. A risk-based assessment of the auditable units and their significance to business
objectives
C. The number of available audit staff
D. The physical location of IT facilities
Correct Answer: B.
Rationale: ISACA Standards require a risk-based approach to audit planning. The scope should be
determined by assessing the relative risk of auditable units, their impact on business objectives,
regulatory requirements, and prior audit findings. Resource constraints inform feasibility but
should not define the scope itself.
4. When planning an audit of a cloud-based application, which of the following is the
MOST critical governance concern?
A. The color scheme of the cloud provider's management console
B. Data sovereignty, privacy regulations, and contractual responsibility for data
protection
C. The brand reputation of the cloud service provider
D. The geographic location of the provider's corporate headquarters
Page 3 of 52