50 Free CISA Practice Questions — Certified Information Systems Auditor
Preparing for CISA? These questions cover all five domains.
Domain 1: Auditing IS (Questions 1–10)
Question 1
What is the most reliable type of audit evidence?
a) Oral representations from management
b) Physical examination of assets
c) Copies of policies and procedures
d) System-generated transaction logs
Show Answer
Answer: b) Physical examination of assets
Explanation: Physical examination provides the most reliable audit evidence. System-generated logs are reliable if controls are verified. Oral evidence is least reliable.
Question 2
What is the primary purpose of sampling in an IS audit?
a) Reducing audit cost while obtaining reasonable assurance
b) Eliminating the need for testing
c) Replacing review of all transactions
d) Meeting regulatory requirements
Show Answer
Answer: a) Reducing audit cost while obtaining reasonable assurance
Explanation: Statistical sampling provides reasonable assurance at lower cost than testing 100% of transactions. The sample must be representative and appropriately sized.
Questions 3–10
[Full set covers audit planning, evidence collection, CAATs, audit reporting, follow-up, ISACA standards]
Domain 2: Governance and Management of IT (Questions 11–20)
Question 3
Which COBIT domain ensures IT alignment with business goals?
a) Monitor, Evaluate and Assess (MEA)
b) Align, Plan and Organize (APO)
c) Build, Acquire and Implement (BAI)
d) Deliver, Service and Support (DSS)
Show Answer
Answer: b) Align, Plan and Organize (APO)
Explanation: The APO domain of COBIT 2019 focuses on strategic alignment, IT planning, and enterprise architecture. MEA monitors performance, BAI implements solutions, DSS delivers services.
Questions 4–20
[Full set covers COBIT, IT strategy, policies, organizational structure, RACI, capability maturity models]
Domain 3: Acquisition and Implementation (Questions 21–25)
Question 4
Which SDLC phase requires the most user involvement?
a) Requirements definition
b) Development
c) Testing
d) Implementation
Show Answer
Answer: a) Requirements definition
Explanation: User involvement is critical during requirements to ensure the system meets business needs. Lack of user input is a common cause of project failure.
Questions 5–25
[Full set covers SDLC controls, project governance, change management, testing, acceptance, post-implementation review]
Domain 4: Operations and Business Resilience (Questions 26–35)
Question 5
What is the primary purpose of an alternate processing facility in BCP?
a) Reducing IT costs
b) Maintaining critical operations during a disaster
c) Testing new applications
d) Archiving data
Show Answer
Answer: b) Maintaining critical operations during a disaster
Explanation: An alternate processing facility (hot/warm/cold site) provides backup computing capability during a disaster to maintain business-critical operations.
Questions 6–35
[Full set covers ITIL, SLA management, problem management, BCP/DRP testing, backup strategies, incident management]
Domain 5: Protection of Information Assets (Questions 36–50)
Question 6
Which access control principle should an auditor verify first?
a) Segregation of duties
b) Single sign-on
c) Multifactor authentication
d) Password complexity
Show Answer
Answer: a) Segregation of duties
Explanation: Segregation of duties prevents fraud by ensuring no single person has control over conflicting functions (e.g., authorization vs recording vs custody). It's a fundamental control.
Questions 7–50
[Full set covers access controls, encryption, network security, privacy, physical security, social engineering]
How Did You Score?
Bereit, dein Wissen zu testen?
Probiere unsere Übungsprüfungen mit Hunderten von realistischen Fragen aus.
Üben starten →