ISACA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
18% of exam · 6 sample questions below
A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?
Implement a privileged access management (PAM) solution to control and monitor elevated access.
PAM directly prevents and controls unauthorized privileged access, addressing the root cause.
Increase logging and auditing of all user activities.
Deploy a security information and event management (SIEM) tool.
Terminate the employment of the insider who caused the breach.
A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?
ITIL 4 Service Value System
COBIT 2019
COBIT 2019 is a comprehensive framework for IT governance and management.
ISO/IEC 27001 Information Security Management
PMBOK Guide
An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?
Faster adoption of new technologies
Enhanced security posture
Reduced IT operational costs
Increased value of IT investments to business objectives
Alignment ensures IT delivers value that supports business strategy.
A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?
Chief Information Officer (CIO)
Project Management Office (PMO) director
IT Audit Committee
An independent audit committee provides objective oversight.
Chief Information Security Officer (CISO)
An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?
Accept the change and adjust the project timeline accordingly.
Initiate the formal change control process and escalate to the steering committee.
Proper change control ensures governance and stakeholder involvement.
Implement the change and inform the steering committee later.
Reject the change because it is outside the original scope.
An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?
System uptime percentage
Average server CPU utilization
Directly measures how efficiently computing resources are used.
Number of help desk tickets resolved per day
Percentage of projects completed on time
Want more Governance and Management of IT practice?
Practice this domain26% of exam · 6 sample questions below
An organization is implementing a new incident management process aligned with ITIL. The IT team discovers a critical system is down, affecting all users. According to ITIL, what severity level should be assigned to this incident?
P1
P1 incidents are critical and require immediate response.
P3
P2
P4
During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?
Review and approve the change
The CAB is responsible for reviewing and approving changes, especially those categorized as normal.
Implement the change directly
Reject the change as unnecessary
Defer the change to the next release cycle
An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?
Implement backup encryption
Use a different backup software
Perform periodic restore verification tests
Restore verification tests validate that backups are usable and complete.
Increase the frequency of full backups
In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?
To define the backup frequency
To calculate the mean time between failures (MTBF)
To establish service level agreements (SLAs)
To determine the recovery time objective (RTO)
MTD directly influences the RTO, which must be less than or equal to MTD.
An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?
Increase in unauthorized changes
Lack of CAB oversight for emergency changes can lead to unauthorized modifications.
Excessive documentation overhead
Delayed incident resolution
Inadequate backup procedures
A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?
Terminate the contract immediately
Renegotiate the SLA to 3 hours
Issue a non-compliance notice and require a remediation plan
This holds the vendor accountable and drives improvement.
Accept the performance as within acceptable variance
Want more Information Systems Operations and Business Resilience practice?
Practice this domain18% of exam · 6 sample questions below
Which of the following audit types is MOST likely to be performed by an organization's own employees?
External audit
IS audit
Internal audit
Internal audits are conducted by the organization's own staff.
Compliance audit
During which phase of the audit process does the auditor perform procedures such as inquiry, observation, and inspection?
Follow-up
Fieldwork
Fieldwork includes executing audit procedures like inquiry, observation, and inspection.
Reporting
Planning
An IS auditor is planning an audit of a financial system. The auditor identifies that the inherent risk is high due to the complexity of transactions, but control risk is low because of strong automated controls. Which component of audit risk will be MOST affected by the auditor's testing strategy?
Inherent risk
Detection risk
Detection risk is managed by the extent of testing.
Control risk
Audit risk
Which type of audit evidence involves the auditor independently performing a control procedure to verify its effectiveness?
Inspection
Observation
Re-performance
Re-performance is the auditor doing the control themselves.
Inquiry
In a risk-based audit approach, which of the following BEST describes how an IS auditor should prioritize audit coverage?
Focus on areas where management has requested review
Allocate more audit resources to areas with higher risk and lower control effectiveness
High risk and weak controls warrant more attention.
Concentrate solely on areas with the highest inherent risk
Focus equally on all areas of the audited entity
An IS auditor selects a sample of 50 transactions from a population of 1,000 using a random number generator. This is an example of which sampling method?
Stratified sampling
Random sampling
Random sampling uses a random selection method.
Systematic sampling
Judgmental sampling
Want more Information System Auditing Process practice?
Practice this domain12% of exam · 6 sample questions below
During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?
The system deployment was delayed
The system performance is below expectations
The project was not completed within the planned budget
The system may not fully meet business requirements, leading to user workarounds
Unpassed test cases mean functionality gaps that users may bypass, increasing error and fraud risk.
An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?
The legacy system may be decommissioned prematurely
User acceptance testing may be delayed
The data migration may exceed the planned timeline
Incomplete or inaccurate data may be loaded into the new system
Without reconciliation, errors go unnoticed, leading to unreliable data.
In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?
Development phase
Requirements phase
Formal sign-off on requirements is a key control to prevent scope creep.
Design phase
Testing phase
An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?
The product backlog is managed by the product owner
Daily standup meetings are held to track progress
Retrospectives are conducted after each sprint
Each sprint concludes with a sprint review attended by stakeholders
Sprint review provides real-time user feedback and acceptance.
During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?
Negotiate a lower price to offset the risk
Evaluate compensating controls or seek an alternative vendor
Compensating controls may reduce risk, but alternative vendor might be safer.
Accept the risk because the vendor is well-known
Request a customized SOC 2 report
An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?
The project schedule shows spiral iterations
Each spiral iteration includes a risk analysis document
Documented risk analysis is direct evidence of the control.
The project manager has a risk management plan
The system has passed user acceptance testing
Want more Information Systems Acquisition, Development, and Implementation practice?
Practice this domain26% of exam · 6 sample questions below
An IS auditor is reviewing the logical access controls for a financial application. The auditor notices that user access reviews are performed annually by the application owner, but there is no documentation indicating that managers confirm the continued need for access. Which of the following is the MOST significant risk associated with this finding?
Unauthorized access to sensitive data due to excessive privileges
Without manager confirmation, users may retain access they no longer need, increasing the risk of unauthorized access.
Increased likelihood of successful social engineering attacks
Non-compliance with regulatory requirements for access controls
Inability to detect insider threats in a timely manner
During an audit of the information security program, the IS auditor reviews the organization's information security policy. Which of the following is the PRIMARY purpose of an information security policy?
To provide detailed step-by-step instructions for implementing security controls
To specify the technical configurations for security devices
To define the roles and responsibilities for information security
To communicate management's commitment and direction for information security
The policy is a high-level statement of management's intent and sets the tone for the security program.
An IS auditor is reviewing the privileged access management (PAM) process. The auditor finds that shared administrative accounts are used for critical system maintenance and that passwords are changed quarterly. Which of the following is the BEST recommendation to mitigate the risk of audit trail loss?
Implement a password vault with automatic checkout and check-in
Increase the frequency of password changes to monthly
Implement individual accounts with privilege escalation for administrative tasks
Individual accounts ensure each action is tied to a specific user, providing a complete audit trail.
Require two-factor authentication for shared account usage
An IS auditor is evaluating the effectiveness of a security awareness program. Which of the following metrics would BEST indicate that the program is achieving its objectives?
Scores on post-training quizzes
Reduction in the number of successful phishing attacks
This directly measures behavior change and the effectiveness of training.
Percentage of employees who completed the annual training
Number of security incidents reported by employees
An organization uses a public key infrastructure (PKI) to issue digital certificates. The IS auditor is reviewing the certificate lifecycle management. Which of the following is the GREATEST risk if certificate revocation lists (CRLs) are not updated in a timely manner?
Certificate authorities may lose their root key
Compromised certificates could still be used to establish trust
Delayed CRL updates mean revoked certificates are still considered valid, enabling misuse.
Certificates may expire without renewal
Users may not be able to verify certificate signatures
An IS auditor is reviewing the physical access controls at a data center. Which of the following is the MOST effective control to prevent tailgating?
Security guards at the entrance
CCTV cameras at the entrance
Mantrap
A mantrap physically prevents tailgating by allowing only one person through at a time.
Biometric readers at all entrances
Want more Protection of Information Assets practice?
Practice this domainThe CISA exam has 150 questions and must be completed in 240 minutes. The passing score is 450/1000.
Multiple-choice scenario questions on IS audit processes, IT governance, systems acquisition, operations, and information asset protection.
The exam covers 5 domains: Governance and Management of IT, Information Systems Operations and Business Resilience, Information System Auditing Process, Information Systems Acquisition, Development, and Implementation, Protection of Information Assets. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official ISACA CISA exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.