ISACA · CISA

ISACA CISA Exam Practice Questions

1,823 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 1,823 questions in this pack

Question 1

Which of the following should be of GREATEST concern to an IS auditor reviewing an organization's business continuity plan (BCP)?

  1. The BCP has not been tested since it was first issued.
  2. The BCP is not version-controlled.
  3. The BCP's contact information needs to be updated.
  4. The BCP has not been approved by senior management.
Show answer and explanation

Correct answer: A. The BCP has not been tested since it was first issued.

An untested BCP is fundamentally unreliable and poses the greatest risk because it has never been validated to actually work during a real incident. Testing is critical to identifying gaps, clarifying procedures, and ensuring recovery objectives can be met. While version control, updated contact information, and management approval are all important, they are secondary to proving the plan actually functions when needed.

Why the other options are wrong

  • B. Version control is a good practice but does not affect whether the BCP will actually work during a crisis.
  • C. Outdated contact information should be corrected, but this is a maintenance issue, not a fundamental validity concern.
  • D. Senior management approval is necessary for authority but does not validate that the plan will function effectively.

Question 2

Which of the following would be MOST useful when analyzing computer performance?

  1. Tuning of system software to optimize resource usage
  2. Operations report of user dissatisfaction with response time
  3. Statistical metrics measuring capacity utilization
  4. Report of off-peak utilization and response time ✅Correct Answer: C, Statistical metrics measuring capacity utilization Statistical metrics on capacity utilization give objective, quantifiable data across varied conditions and time periods, supporting trend analysis, bottleneck identification, and data-driven decisions. Subjective complaints and narrow off-peak reports offer only partial insight with no statistical basis. System tuning is an action taken after analysis, not an analysis tool.
Show answer and explanation

Answer and explanation for question 2

Question 3

Which of the following is the GREATEST risk if two users have concurrent access to the same database record?

  1. Entity integrity
  2. Availability integrity
  3. Referential integrity
  4. Data integrity
Show answer and explanation

Correct answer: D. Data integrity

When two users have concurrent access to the same database record without proper locking mechanisms, the greatest risk is data integrity, the loss or corruption of actual data values. This can result in lost updates, dirty reads, or inconsistent data states. Entity integrity, referential integrity, and availability integrity are all important, but data integrity is the broadest and most fundamental concern when concurrent modifications occur without proper synchronization controls.

Why the other options are wrong

  • A. Entity integrity (unique identification) is less threatened by concurrent access than data value integrity.
  • B. Availability integrity is not a standard integrity classification in database theory.
  • C. Referential integrity (foreign key relationships) is less directly threatened than the core data values themselves.

See all 10 free questions Get the full pack, US$39

1,823 practice questions for ISACA Certified Information Systems Auditor (CISA), with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a note on why each wrong option is wrong. Work through it once with the answers, then again with the questions-only copy under exam conditions.

  • 1,823 questions the largest question bank available for the CISA exam
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

The CISA costs US$575 for ISACA members and US$760 for non-members. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 1,823 questions

What makes the CISA hard

Every failed attempt costs the full fee again: US$575 for members, US$760 for non-members. The CISA is not an exam to cram through in a weekend. It requires five years of IS audit experience to be eligible, and covers five demanding domains across 150 questions in four hours.

Where the marks actually sit surprises people. Operations and business resilience, and protection of information assets, are 26% each, over half the exam between them, while acquisition, development and implementation is only 12%. Candidates who over invest in the SDLC material and skim operations pay for it.

ISACA’s answer style rewards an auditor’s independent, risk focused mindset over a technically correct but process blind option, and that is a skill built by seeing a lot of exam style questions. This pack gives 1823 of them.

About the exam

CISA is ISACA’s flagship certification for IS audit, control and security professionals, one of the most globally recognised and highest paying credentials in IT audit. It validates expertise across the full lifecycle of information systems, from auditing and governance through acquisition, development, operations and protection of information assets. Five years of relevant IS audit, control or security experience is required for full certification.

Exam domains

  • Information systems auditing process: 18%
  • Governance and management of IT: 18%
  • Information systems acquisition, development and implementation: 12%
  • Information systems operations and business resilience: 26%
  • Protection of information assets: 26%

150 questions, 4 hours, pass mark 450 out of 800, members US$575, non-members US$760, PSI testing centres and remote proctored, available in English, Chinese, Spanish, Japanese and Korean.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the ISACA CISA pack?

1,823 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.