ISACA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
18% of exam · 6 sample questions below
A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?
Implement a privileged access management (PAM) solution to control and monitor elevated access.
Privileged access management directly addresses insider misuse by vaulting, brokering and session-recording elevated accounts, enforcing least privilege and just-in-time elevation. This targets the root cause — uncontrolled privileged credentials — rather than merely detecting activity after the breach has already occurred.
Increase logging and auditing of all user activities.
Deploy a security information and event management (SIEM) tool.
Terminate the employment of the insider who caused the breach.
A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?
ITIL 4 Service Value System
COBIT 2019
COBIT 2019 provides a governance and management framework explicitly linking IT objectives to business goals, with defined processes and control practices for regulatory compliance. This satisfies the board's need for enterprise-wide governance across hybrid cloud rather than technology-specific operational guidance.
ISO/IEC 27001 Information Security Management
PMBOK Guide
An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?
Faster adoption of new technologies
Enhanced security posture
Reduced IT operational costs
Increased value of IT investments to business objectives
Aligning IT strategy with business strategy directs IT spending and initiatives toward organisational goals, maximising the business value delivered by IT investments. That outcome is the primary benefit, rather than cost reduction, technology standardisation or faster project delivery.
A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?
Chief Information Officer (CIO)
Project Management Office (PMO) director
IT Audit Committee
An independent audit committee provides objective oversight.
Chief Information Security Officer (CISO)
An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?
Accept the change and adjust the project timeline accordingly.
Initiate the formal change control process and escalate to the steering committee.
A scope increase without matching budget requires the formal change control process, since the change board and steering committee hold authority to approve, reject, or re-baseline scope, schedule, and funding. This satisfies the stem's constraint by preventing unilateral scope creep and preserving the approved baseline.
Implement the change and inform the steering committee later.
Reject the change because it is outside the original scope.
An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?
System uptime percentage
Average server CPU utilization
Average server CPU utilisation directly quantifies how much processing capacity is consumed versus available, giving a concrete efficiency measure of IT resource usage. It satisfies the manager's need to measure utilisation, unlike metrics such as incident counts or uptime that reflect availability rather than efficiency.
Number of help desk tickets resolved per day
Percentage of projects completed on time
Want more Governance and Management of IT practice?
Practice this domain26% of exam · 6 sample questions below
During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?
Review and approve the change
Normal changes require CAB review and authorisation before implementation. Even though the patch is low impact, the reboot and database scope mean the CAB must review and approve it, satisfying the stem's normal-category constraint rather than auto-approving it as standard.
Implement the change directly
Reject the change as unnecessary
Defer the change to the next release cycle
An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?
Implement backup encryption
Use a different backup software
Perform periodic restore verification tests
Periodic restore verification tests directly satisfy the stem's need to detect corruption before a disaster, since only an actual restore proves every incremental in the chain is readable. Checksums or media scans may pass while a corrupt incremental still breaks recovery, so rehearsed restoration is the control that validates end-to-end recoverability.
Increase the frequency of full backups
In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?
To define the backup frequency
To calculate the mean time between failures (MTBF)
To establish service level agreements (SLAs)
To determine the recovery time objective (RTO)
MTD defines the maximum time a process can be unavailable, and the RTO must be set at or below it to keep downtime tolerable. Deriving the RTO from the 4-hour MTD ensures recovery capabilities align with business tolerance.
An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?
Increase in unauthorized changes
Bypassing CAB review removes independent oversight, so the change manager alone authorises emergency changes. That concentrates approval authority in one person, enabling changes to be implemented without detection or challenge — directly increasing the risk of unauthorised changes, the specific risk the stem's missing segregation of duties creates.
Excessive documentation overhead
Delayed incident resolution
Inadequate backup procedures
A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?
Terminate the contract immediately
Renegotiate the SLA to 3 hours
Issue a non-compliance notice and require a remediation plan
The vendor's 3-hour average breaches the SLA's 2-hour P1 resolution target, so the auditor should raise non-compliance and require a remediation plan. This addresses the contractual gap directly rather than accepting or renegotiating the agreed service level.
Accept the performance as within acceptable variance
During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?
Mean time to repair (MTTR) and mean time between failures (MTBF)
Recovery time objective (RTO) and recovery point objective (RPO)
The 8-hour disruption tolerance defines the recovery time objective, the maximum acceptable downtime before the process must be restored. The 15-minute data loss limit defines the recovery point objective, the maximum tolerable data loss measured backwards from the incident.
Service level objective (SLO) and service level agreement (SLA)
Maximum tolerable downtime (MTD) and working recovery time (WRT)
Want more Information Systems Operations and Business Resilience practice?
Practice this domain18% of exam · 6 sample questions below
Which of the following audit types is MOST likely to be performed by an organization's own employees?
External audit
IS audit
Internal audit
Internal audit is performed by the organisation's own employees, who report to management or the audit committee. This contrasts with external audit, delivered by independent third parties, directly satisfying the stem's requirement for work conducted by staff within the organisation.
Compliance audit
During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?
Follow-up
Fieldwork
Fieldwork is the phase where the auditor gathers evidence by performing inquiry, observation, inspection and reperformance against the audit programme. Planning establishes scope and risk, while reporting communicates findings, so these procedures occur during fieldwork.
Reporting
Planning
An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?
Inherent risk
Detection risk
Detection risk is the component the auditor directly controls through the nature, timing and extent of substantive testing. With inherent risk high and control risk low, the auditor adjusts testing to keep detection risk at a level that holds overall audit risk within acceptable bounds.
Control risk
Audit risk
Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?
Inspection
Observation
Re-performance
Re-performance requires the auditor to independently execute the control procedure, such as recalculating a total or re-running an authorisation check, and compare the result with the organisation's output. This directly tests operating effectiveness rather than relying on documentation or inquiry.
Inquiry
In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?
Focus on areas where management has requested review
Allocate more audit resources to areas with higher risk and lower control effectiveness
Risk-based auditing directs limited resources toward exposures with the greatest likelihood and impact, weighted by how weakly existing controls mitigate them. Prioritising high-risk, low-control-effectiveness areas satisfies the stem's requirement, since coverage then targets residual risk rather than spreading effort uniformly.
Concentrate solely on areas with the highest inherent risk
Focus equally on all areas of the audited entity
An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?
Stratified sampling
Random sampling
Random sampling gives every transaction in the 1,000-item population an equal, non-zero chance of selection, which the random number generator enforces. This satisfies the stem's requirement for a statistically valid, unbiased sample, unlike haphazard or judgmental methods, and supports extrapolating the 50-transaction results to the full population.
Systematic sampling
Judgmental sampling
Want more Information System Auditing Process practice?
Practice this domain26% of exam · 6 sample questions below
An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?
Unauthorized access to sensitive data due to excessive privileges
Annual owner reviews without manager confirmation mean access is never validated against current job need, so transferred or terminated staff retain entitlements. Accumulated excessive privileges let users reach sensitive financial data beyond their remit, the specific risk the undocumented confirmation step leaves unmitigated.
Increased likelihood of successful social engineering attacks
Non-compliance with regulatory requirements for access controls
Inability to detect insider threats in a timely manner
During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?
To provide detailed step-by-step instructions for implementing security controls
To specify the technical configurations for security devices
To define the roles and responsibilities for information security
To communicate management's commitment and direction for information security
The policy exists to articulate management's commitment and strategic direction for information security, authorising the programme and setting expectations. This satisfies the stem's constraint by establishing the mandate from which standards, procedures and controls derive their authority.
An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?
Implement a password vault with automatic checkout and check-in
Increase the frequency of password changes to monthly
Implement individual accounts with privilege escalation for administrative tasks
Individual accounts with privilege escalation tie each administrative action to a named user, so logs attribute activity to a person rather than an anonymous shared login. This preserves accountability and satisfies the audit trail requirement that shared credentials destroy.
Require two-factor authentication for shared account usage
An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?
Scores on post-training quizzes
Reduction in the number of successful phishing attacks
Awareness programmes aim to change behaviour, so fewer successful phishing attacks demonstrates that staff actually recognise and resist real threats. This outcome metric reflects genuine risk reduction, unlike completion rates or quiz scores, which measure attendance rather than effectiveness.
Percentage of employees who completed the annual training
Number of security incidents reported by employees
An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?
Certificate authorities may lose their root key
Compromised certificates could still be used to establish trust
CRLs are the mechanism relying parties use to learn that a certificate is revoked. If they are stale, a compromised certificate's serial number is absent, so systems continue trusting it and attackers can still authenticate or decrypt traffic until the CRL is refreshed.
Certificates may expire without renewal
Users may not be able to verify certificate signatures
An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
Security guards at the entrance
CCTV cameras at the entrance
Mantrap
A mantrap permits only one person through an interlocking door sequence at a time, physically preventing an unauthorised individual from following an authenticated person. This directly satisfies the stem's constraint by eliminating the single-entry tailgating vector that badge readers alone cannot address.
Biometric readers at all entrances
Want more Protection of Information Assets practice?
Practice this domain12% of exam · 6 sample questions below
During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?
The system deployment was delayed
The system performance is below expectations
The project was not completed within the planned budget
The system may not fully meet business requirements, leading to user workarounds
Passing only 60% of UAT cases means 40% of tested business scenarios failed, so the system may not satisfy requirements and users will adopt manual workarounds that undermine controls and reporting integrity. This is the most significant risk.
An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?
The legacy system may be decommissioned prematurely
User acceptance testing may be delayed
The data migration may exceed the planned timeline
Incomplete or inaccurate data may be loaded into the new system
Skipping full reconciliation removes the control that detects records lost, duplicated or corrupted during migration. Without it, incomplete or inaccurate data enters the ERP and may drive incorrect transactions and reporting, making data integrity the auditor's primary concern.
In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?
Development phase
Requirements phase
Requirements are baselined and formally approved by the business owner before design begins, since later phases build directly on that frozen scope. Sign-off here authorises the project to proceed, whereas design and testing approvals occur within their own phases.
Design phase
Testing phase
An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?
The product backlog is managed by the product owner
Daily standup meetings are held to track progress
Retrospectives are conducted after each sprint
Each sprint concludes with a sprint review attended by stakeholders
Sprint reviews provide evidence that stakeholders inspect the increment each sprint, satisfying the need for continuous user acceptance in agile delivery. Unlike a single end-of-project sign-off, this recurring stakeholder validation demonstrates acceptance controls operate throughout development, directly addressing the stem's requirement for adequate user acceptance evidence.
During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?
Negotiate a lower price to offset the risk
Evaluate compensating controls or seek an alternative vendor
An adverse SOC 2 opinion means the vendor's controls failed to meet trust services criteria, so the auditor should recommend evaluating compensating controls or selecting an alternative vendor. This directly addresses the assurance gap the adverse opinion creates for a critical system.
Accept the risk because the vendor is well-known
Request a customized SOC 2 report
An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?
The project schedule shows spiral iterations
Each spiral iteration includes a risk analysis document
The spiral model's defining feature is iteration-level risk analysis, so a risk analysis document produced within each spiral iteration provides direct, repeatable evidence that risk assessment occurs at every cycle, not merely at project initiation.
The project manager has a risk management plan
The system has passed user acceptance testing
Want more Information Systems Acquisition, Development, and Implementation practice?
Practice this domainThe CISA exam has 150 questions and must be completed in 240 minutes. The passing score is 450/1000.
Multiple-choice scenario questions on IS audit processes, IT governance, systems acquisition, operations, and information asset protection.
The exam covers 5 domains: Governance and Management of IT, Information Systems Operations and Business Resilience, Information System Auditing Process, Protection of Information Assets, Information Systems Acquisition, Development, and Implementation. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CISA exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.