CISA Practice Questions with Answers and Explanations
These original practice questions teach CISA reasoning across all five domains.
- Each scenario asks for the best audit action, evidence, or control response, then explains why the answer fits and why alternatives do not.
- They are illustrative study items, not recalled or reproduced ISACA exam questions, and their results do not convert to an official scaled score.
On this page10 sections
- How to use these original questions
- Question 1: testing a termination control
- Question 2: third-party governance
- Question 3: system implementation readiness
- Question 4: resilience and dependencies
- Question 5: privileged access review
- Question 6: audit data analytics and completeness
- Question 7: incident evidence and response
- A method for reviewing explanations
- Practice responsibly and interpret results carefully
How to use these original questions
Try each question before reading its explanation. Pay attention to the requested actor and sequence: an auditor evaluates evidence and reports; management owns operations and accepts risk. Words such as FIRST, BEST, and MOST reliable narrow the decision. The explanations describe the reasoning, not a claim about the wording or scoring of any live CISA item.
All questions below are newly written practice scenarios aligned at a broad level to the public CISA outline. They do not reproduce, reconstruct, or paraphrase secured exam questions. The live exam includes 150 multiple-choice questions over four hours. ISACA reports a scaled score, so performance on this short practice set cannot predict an exact official score.
Question 1: testing a termination control
An audit objective is to determine whether access to a customer database is removed promptly when employees leave. The control owner says supervisors notify IT on the final workday. Which evidence best supports a conclusion about whether the control operated?
- A. The approved access-removal policy and a manager's description of the process.
- B. A complete population of employee terminations compared with account-disable timestamps for the relevant period.
- C. A list of current employees who have active database accounts.
- D. A presentation showing that IT staff received annual security training.
Best answer: B. The objective concerns timely removal for departing employees. The auditor needs a reliable population of terminations and evidence showing when each associated account was disabled. Comparing the dates directly tests operation against the stated timing expectation. Completeness of the departure population matters: a sample drawn only from IT's deactivation records could omit departures that were never reported.
A helps establish the intended design and can provide criteria, but a policy and interview do not demonstrate that the control operated for actual departures. C gives a current snapshot but does not establish when a person left or whether access was promptly removed. D is unrelated to account deprovisioning. The key lesson is to match evidence to the objective and obtain a population that can expose omissions.
Question 2: third-party governance
A company relies on a cloud supplier for a critical billing service. Management has not defined who reviews service availability reports or escalates repeated outages. What should the auditor do FIRST?
- A. Recommend terminating the supplier contract immediately.
- B. Determine the applicable service and governance criteria, then assess the assigned oversight responsibilities and available evidence.
- C. Accept the supplier's uptime statement because the service is externally hosted.
- D. Take over the monthly review until management hires a service owner.
Best answer: B. The auditor first needs criteria and an understanding of the governance arrangement. The scenario suggests an accountability gap, but the auditor should establish what the contract, internal policy, risk assessment, and service objectives require, then evaluate whether ownership and oversight are defined and evidenced. This supports a grounded finding and recommendation.
A jumps to a major management decision without evaluating contract terms, risk, or alternatives. C treats supplier reporting as self-validating and does not resolve who reviews exceptions. D improperly transfers an operational responsibility to the auditor, who must remain independent. A recommendation may later address accountable ownership, escalation thresholds, and review evidence, but the auditor should not perform the control.
Question 3: system implementation readiness
A payroll system has passed technical installation checks. The project team has not reconciled converted employee and pay data to the approved source totals, and the sponsor asks the auditor whether the system is ready to go live. What is the MOST appropriate response?
- A. Approve go-live because installation checks passed.
- B. Explain that installation evidence alone does not establish conversion completeness and accuracy; evaluate the reconciliation and acceptance evidence against approved criteria.
- C. Tell the sponsor to postpone the project for six months regardless of risk.
- D. Perform the reconciliation for the project team and certify the result.
Best answer: B. The audit conclusion should be based on evidence tied to readiness criteria. Successful installation confirms only a technical step; it does not show that critical payroll data was completely and accurately converted. The auditor should assess whether the project has defined acceptance criteria, reconciled source and target data, resolved exceptions, and documented appropriate approval.
A overstates what the installation test proves. C imposes an arbitrary delay without assessing risk or evidence. D makes the auditor responsible for project testing and creates an independence problem. Management or the project owner decides whether to launch; the auditor evaluates and communicates whether evidence supports readiness.
Question 4: resilience and dependencies
During a recovery exercise, a database is restored within the target time. The customer portal remains unavailable because its identity service was not included in the recovery sequence. Which recommendation BEST addresses the demonstrated weakness?
- A. Add the identity dependency to the recovery plan and test end-to-end restoration of the customer service against its objectives.
- B. Buy additional database storage to improve capacity.
- C. Mark the exercise successful because the database met its own restoration target.
- D. Remove the identity service from the dependency inventory to simplify the plan.
Best answer: A. The business objective is restoration of the customer service, and the scenario identifies an omitted dependency that prevents users from accessing it. The plan should reflect the identity service and its recovery sequence, and a future exercise should test the complete service against approved recovery objectives. This turns the finding into a testable improvement.
B does not address the missing dependency. C narrows success to one technical component even though the service is unavailable. D conceals the dependency and increases recovery risk. The auditor should connect recovery evidence to the business service and its dependencies, not accept a component-level result as proof of end-to-end resilience.
Question 5: privileged access review
A quarterly access certification is intended to identify inappropriate privileged access. The control owner provides signed review forms, but the auditor notices that several high-risk accounts were approved by the same administrator who uses them. What is the BEST next step?
- A. Conclude the review is effective because every form contains a signature.
- B. Determine the intended review criteria and evaluate whether approvals were independent, informed, and followed by remediation of exceptions.
- C. Disable every privileged account immediately.
- D. Replace the access review with a general security awareness campaign.
Best answer: B. A signature is evidence that a form was completed, not that the review provided effective challenge. The auditor should understand the control design, identify required approvers and criteria, test whether reviewers had sufficient information and independence, and trace identified exceptions through resolution. The self-approval pattern may indicate a design or operating deficiency that needs evidence-based evaluation.
A confuses completion evidence with substantive control performance. C is a disruptive response that bypasses risk assessment and management authority. D does not address privileged entitlements. The auditor may recommend independent review or compensating controls if evidence supports that conclusion, but first needs to establish the applicable criteria and extent of the issue.
Question 6: audit data analytics and completeness
An auditor uses an analytics script to identify duplicate vendor bank accounts. The script returns no exceptions. Before concluding that duplicate accounts do not exist, what should the auditor do MOST importantly?
- A. Validate the completeness and accuracy of the source data and test that the script logic addresses the defined duplicate criteria.
- B. Conclude there are no duplicates because the analytics tool returned an empty result.
- C. Ask the vendor master administrator whether duplicates are likely.
- D. Expand the sample only if management objects to the result.
Best answer: A. An empty output is meaningful only if the input population is complete and accurate and the query correctly implements the audit criteria. The auditor should validate source data fields and record counts, understand filters and exclusions, and test the logic using known cases or other suitable procedures. Then the result can be interpreted in relation to the objective.
B treats the tool as proof without validating inputs or logic. C is an inquiry, not sufficient evidence that duplicates are absent. D makes testing dependent on management reaction rather than audit risk and evidence. Analytics can efficiently examine large populations, but the auditor remains responsible for whether data and procedures support the conclusion.
Question 7: incident evidence and response
A monitoring alert indicates possible unauthorized changes to a production system. The operations manager wants to delete the alert records after restoring service because the logs consume storage. What should the auditor recommend FIRST?
- A. Preserve relevant records under the incident and evidence-handling process, then ensure the authorized response team investigates and documents the event.
- B. Delete the records after the system is restored to reduce storage cost.
- C. Publicly identify a suspected employee before validating the facts.
- D. Close the alert because service availability has returned.
Best answer: A. The records may be necessary to determine what happened, assess impact, and support a controlled response. Follow established incident, retention, and evidence-handling procedures, and ensure the authorized team investigates. Restoring service addresses availability, but does not resolve whether unauthorized changes occurred or what data or systems were affected.
B destroys potentially relevant evidence. C makes an unsupported accusation and bypasses the investigation process. D confuses service restoration with incident resolution. The auditor should recommend preserving evidence and assess whether response procedures are followed, while leaving incident command and disciplinary decisions with management.
A method for reviewing explanations
After each item, say in one sentence why the correct option answers the exact question. Then identify the flaw in each distractor. A distractor may be technically useful but wrong because it answers a later step, belongs to management, lacks reliable evidence, or does not address the stated risk. This review is more valuable than simply recording the letter.
| Observed error | Review question |
|---|---|
| Chose a recommendation before establishing criteria | What standard, objective, or approved requirement defines the expected state? |
| Accepted an interview or signature as proof | What independent or direct evidence demonstrates operation? |
| Picked a technically plausible but unrelated control | Does the option address the stated risk and requested decision? |
| Took over management's task | Is the auditor evaluating and advising, or operating the control? |
| Missed a qualifier such as FIRST or MOST | What sequence or comparison does the question require? |
| Trusted analytics output without validation | Are the input population and query logic complete and accurate? |
Practice responsibly and interpret results carefully
Use original questions, authorized ISACA materials, and legitimate learning resources. Do not seek, repeat, or share alleged live exam questions. ISACA's candidate rules prohibit disclosure of examination content. A practice item should teach a concept in a new setting rather than imitate the phrasing of a secured question.
Track practice performance by task and reasoning error. A high percentage on a small set may reflect familiarity with those items, not readiness across the full outline. A low result may reveal a specific concept to repair. The official exam uses a scaled score from 200 to 800, with 450 passing; practice percentages do not convert to that scale. Use full-length timed practice to build stamina and pacing, then review explanations in depth.
The strongest preparation combines knowledge with judgment. Be able to identify criteria, select evidence that addresses an audit objective, distinguish design from operating effectiveness, follow the appropriate sequence, and preserve management's responsibility for decisions. When you can explain both why the best answer works and why plausible alternatives fail, practice is building transferable CISA reasoning.
Common questions
Are these actual CISA exam questions?
No. They are original illustrative practice scenarios written from public exam topics. They are not recalled, copied, or represented as live ISACA questions.
Do CISA practice percentages predict the official score?
No. ISACA reports a scaled score from 200 to 800, and a practice-set percentage does not convert to an official score.
What makes a good CISA practice question?
It presents a realistic audit decision, asks a clear question, and explains why the best option fits the objective and why other choices fail.
Should the auditor approve a system launch or operate a control?
No. Management makes operational decisions and owns controls. The auditor evaluates evidence, reports conclusions, and recommends improvements while maintaining independence.
How should I review a missed scenario?
Identify the objective, requested actor and sequence, evidence needed, and reason each alternative is weaker. Then connect the error to a specific outline task or knowledge gap.