TechNuggets Academy
CISA

Free Certified Information Systems Auditor Practice Test

12 exam-style questions with full explanations — no sign-up. Score yourself, then close your gaps with the full course.

Exam fee ~$5755 exam domainsLevel Advanced2 timed practice tests in the course
✅ Free practice — no sign-up📝 Real exam-style questions💡 Detailed explanations💸 30-day money-back via Udemy
Question 1 of 12 · Domain 1: Information Systems Auditing Process
An IS auditor is developing an annual audit plan using a risk-based approach. Which of the following should be given the HIGHEST priority for inclusion in the audit plan?
Risk-based audit planning prioritizes areas with the highest residual risk. A new system supporting critical financial reporting combined with weak change control represents high inherent risk that is not mitigated, resulting in the highest residual risk.
Question 2 of 12 · Domain 2: Governance and Management of IT
During an IS audit, the auditor finds that the IT steering committee reviews and approves every individual application code change before deployment to production. Which of the following is the BEST recommendation?
The IT steering committee is a governance body that should set strategic direction, approve budgets, and resolve resource conflicts. Operational change approvals are a management-level activity that belongs with a change advisory board (CAB), preserving the governance/management distinction central to frameworks such as COBIT.
Question 3 of 12 · Domain 3: Information Systems Acquisition, Development, and Implementation
During an audit of a system development project, the IS auditor discovers that a single developer has access to modify source code, compile it, and migrate the compiled code directly into the production environment without independent review. Which of the following is the GREATEST concern?
Allowing a single individual to develop, compile, and migrate code to production without independent review is a segregation-of-duties failure that permits unauthorized, erroneous, or malicious changes to reach production undetected — the most significant risk in the scenario.
Question 4 of 12 · Domain 4: Information Systems Operations and Business Resilience
A financial services company's business impact analysis (BIA) determined that the maximum tolerable downtime (MTD) for its core trading application is 4 hours. The current disaster recovery plan specifies a recovery time objective (RTO) of 6 hours for this application. Which of the following should the IS auditor conclude?
The RTO is the target time within which systems must be restored, and it must always be less than or equal to the MTD, which represents the maximum time the business can tolerate the application being unavailable before suffering unacceptable damage. An RTO that exceeds the MTD means the recovery strategy cannot meet business survival requirements and must be redesigned (e.g., faster failover, hot site, improved replication).
Question 5 of 12 · Domain 5: Protection of Information Assets
A financial services company uses a Hardware Security Module (HSM) to manage encryption keys for its database encryption. During an audit, the IS auditor discovers that database administrators (DBAs) have access to both the encrypted data and the encryption keys stored in the HSM. Which of the following is the GREATEST concern?
The core control objective for key management is separation of duties between those who manage the keys (custodians) and those who access the encrypted data. If DBAs hold both, they can bypass encryption controls entirely, undermining the confidentiality control's effectiveness.
Question 6 of 12 · Domain 1: Information Systems Auditing Process
An IS auditor needs to test whether purchase orders exceeding $10,000 received proper managerial approval throughout the year. Which sampling technique is MOST appropriate?
Attribute sampling is used for compliance testing to estimate the rate of occurrence of a binary characteristic, such as whether a control (approval) was or was not applied — exactly the scenario described.
Question 7 of 12 · Domain 2: Governance and Management of IT
An enterprise wants to adopt a framework that explicitly separates governance objectives (Evaluate, Direct, Monitor) from management objectives (Align/Plan/Organize; Build/Acquire/Implement; Deliver/Service/Support; Monitor/Evaluate/Assess). Which framework should the auditor recommend?
COBIT 2019 explicitly structures its objectives into a governance domain (EDM: Evaluate, Direct, Monitor) and four management domains (APO, BAI, DSS, MEA), matching the description exactly.
Question 8 of 12 · Domain 3: Information Systems Acquisition, Development, and Implementation
Which type of testing is performed by end users to confirm that a new system meets business requirements and functions as expected prior to go-live?
UAT is performed by end users (business representatives) in a production-like environment to confirm the system satisfies functional and business requirements before it is accepted for release.
Question 9 of 12 · Domain 4: Information Systems Operations and Business Resilience
During an audit of the incident management process, the IS auditor notes that a specific application generates the same recurring incident every few weeks. Each time, IT staff apply the identical workaround to restore service, but the underlying cause of the fault has never been formally investigated or eliminated. This is a control deficiency in which process?
Problem management is responsible for performing root cause analysis on recurring incidents and implementing permanent fixes or known-error records to prevent recurrence. Repeatedly applying a workaround without addressing the underlying cause is a classic problem management failure.
Question 10 of 12 · Domain 5: Protection of Information Assets
An organization needs to grant access to resources based on multiple dynamic factors such as user department, data sensitivity classification, and time of access, evaluated at the moment of the request. Which access control model BEST supports this requirement?
ABAC evaluates policies against multiple attributes (subject, object, environment such as time) in real time, making it the only model suited to dynamic, multi-factor access decisions like department, classification, and time of day simultaneously.
Question 11 of 12 · Domain 1: Information Systems Auditing Process
Which of the following forms of audit evidence provides the HIGHEST level of assurance to an IS auditor?
Per the evidence reliability hierarchy, evidence the auditor obtains directly through independent testing, recalculation, or observation is the most reliable because it does not depend on assertions from the auditee.
Question 12 of 12 · Domain 2: Governance and Management of IT
When developing a RACI chart for the enterprise IT risk management process, who should be assigned as 'Accountable' for ensuring IT risk is managed within the enterprise's risk appetite?
Per governance principles (e.g., COBIT), accountability for enterprise risk oversight, including alignment with risk appetite, ultimately rests with the governing body — the board of directors and senior executive management — even though execution is delegated.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →

CISA exam — quick answers

How much does the CISA exam cost?

The exam fee is approximately $575 and varies by region — confirm current pricing with the certification vendor before you book.

What topics are on the exam?

It covers 5 domains: Information Systems Auditing Process (18%), Governance and Management of IT (18%), Information Systems Acquisition, Development, and Implementation (12%), Information Systems Operations and Business Resilience (26%), Protection of Information Assets (30%). The full course has a dedicated chapter, lab and practice-test coverage for each.

Is this practice test really free?

Yes — all questions on this page are free with explanations and no sign-up. The paid Udemy course adds two full-length timed exams, video lessons and hands-on labs.

Will this prepare me for the real exam?

The questions mirror the real exam's style and are mapped to the official domains. This is exam-focused preparation — combine the free test with the full course's timed simulations to gauge your readiness.

More free practice by exam domain:
Information Systems Auditing Process →Governance and Management of IT →Information Systems Operations and Business Resilience →Protection of Information Assets →