Courseiva
Free · No account needed · No credit card

Certified Information Systems Auditor CISA Practice Test

934 questions with instant explanations, domain breakdown, and wrong-answer analysis. Built for the real exam.

Instant feedback after each answer
Full explanations included
Domain score breakdown
Real exam: 240 min
Pass mark: 450/1000

Sample questions with explanations

This is exactly what you see during practice — question, options, and a full explanation after you answer.

During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?

AInstruct the business to work around the issue until the next release
BAuthorize the development team to fix the bug immediately and re-deploy
CRoll back to the previous version of the application
Log the defect and perform impact analysis before approving a fixCorrect

In the UAT phase, any defect must be formally logged and subjected to impact analysis before a fix is approved. This ensures that the proposed change does not introduce new risks, break other functionality, or violate regulatory compliance—critical for a financial application han…Read full explanation

An organization is implementing a data loss prevention (DLP) solution. Which of the following is the BEST approach to reduce false positives during initial deployment?

AUse default policies without modification
BLimit scope to one department to minimize noise
Deploy in monitor-only mode and analyze alerts for a periodCorrect
DBlock all sensitive data transmissions immediately

Deploying a DLP solution in monitor-only mode allows the organization to observe what data is being transmitted and generate alerts without blocking any traffic. This enables security teams to analyze the alerts against actual business workflows, fine-tune policies, and eliminate…Read full explanation

During an audit, an IS auditor finds that the organization uses a cloud-based identity provider (IdP) for single sign-on (SSO) but does not enforce multi-factor authentication (MFA) for all users. Which of the following is the BEST recommendation to reduce risk?

ARequire MFA only for external-facing applications
BDisable SSO and require separate passwords for each application
CReduce session timeout to 15 minutes
Enforce MFA for all users accessing any applicationCorrect

Enforcing MFA for all users accessing any application is the best recommendation because it directly addresses the lack of a second authentication factor, which is the primary control to mitigate credential theft and unauthorized access. In a cloud-based IdP SSO environment, a si…Read full explanation

Untimed Practice

Answer at your own pace. Explanation and domain tag shown immediately after each answer.

Timed Practice

Countdown timer starts immediately. Results and domain scores shown at the end — just like the real exam.

Why practice here?

Full explanations on every question

Not just the right answer — you get exactly why each wrong option is wrong, so you learn the concept, not the answer.

Domain score breakdown

After each session see your score by exam domain so you know exactly where to focus study time.

100% free, forever

No subscription, no trial, no email wall. Start a session in under 10 seconds.

Exam-style questions

Scenario-based, precise wording, realistic distractors — written to match what you actually see on exam day.

← All CISA questionsCISA exam guideStudy guidePractice by domain