CISA practice questions: 496 with full explanations
496 practice questions for CISA, grouped by exam domain. Every question below shows all four options, which one is correct, and why each of the other three is not — the wrong answers are where most candidates lose marks.
Not sure where you stand? Take the free 5-min CISA readiness check →
CISA exam format → · CISA passing score → · CISA exam cost →
Questions by domain
- Information Systems Operations and Business Resilience — 129 questions →
- Protection of Information Assets — 129 questions →
- Information Systems Auditing Process — 89 questions →
- Governance and Management of IT — 89 questions →
- Information Systems Acquisition, Development and Implementation — 60 questions →
Sample questions
It abstracts physical hardware and allocates CPU: In a virtualized server environment, what is the PRIMARY fun
In a virtualized server environment, what is the PRIMARY function of the hypervisor?
- It abstracts physical hardware and allocates CPU, memory, and I/O resources among multiple virtual machines. ✓Correct. A hypervisor (virtual machine monitor) sits between hardware and guest operating systems, partitioning and scheduling physical resources so several isolated VMs can share one host.
- It encrypts all data written to the storage area network before it reaches disk.Incorrect. Storage-level encryption is a function of the storage subsystem or an encryption appliance, not the hypervisor; the candidate is confusing resource abstraction with data-at-rest protection.
- It provides the relational query engine that guest databases use to execute SQL.Incorrect. The query engine is part of the DBMS running inside a guest VM; the hypervisor has no knowledge of database queries and only manages the virtual hardware presented to that guest.
- It performs application-layer load balancing across web front ends.Incorrect. Application load balancing is done by a load balancer or reverse proxy; this confuses distributing user requests with allocating hardware resources to VMs.
The trap
Assuming the hypervisor performs security or application services (encryption, load balancing, SQL) rather than the single job of virtualizing and scheduling physical hardware.All 129 Information Systems Operations and Business Resilience questions →
ISO/IEC 27001: Which standard is the correct answer?
A regional freight-forwarding company is pursuing formal certification of its information security management system (ISMS). During the audit, the security manager asks which standard defines the auditable requirements the organization must satisfy to become certified. Which standard is the correct answer?
- ISO/IEC 27001 ✓Correct. ISO/IEC 27001 specifies the mandatory, auditable requirements for establishing, operating, and continually improving an ISMS, and it is the standard against which organizations are certified.
- ISO/IEC 27002Incorrect. ISO/IEC 27002 is a code of practice that provides implementation guidance for the controls; it is advisory and organizations are not certified against it. Candidates confuse the guidance document with the certifiable requirements document.
- ISO/IEC 27005Incorrect. ISO/IEC 27005 provides guidance on information security risk management; it supports the ISMS but is not the certification basis. It is confused with 27001 because risk assessment feeds control selection.
- NIST SP 800-53Incorrect. NIST SP 800-53 is a U.S. federal control catalog, not an ISO certification standard. It is a control reference, not the requirements framework an ISO/IEC 27001 certificate is issued against.
The trap
Assuming the detailed control guidance document (27002) is the certifiable standard rather than the requirements document (27001).All 129 Protection of Information Assets questions →
Standards are mandatory requirements: Within ISACA's Information Technology Assurance Framework (ITAF), what i
Within ISACA's Information Technology Assurance Framework (ITAF), what is the defining difference between an IS audit standard and an IS audit guideline?
- Standards are mandatory requirements, while guidelines provide guidance on how to apply the standards. ✓Correct. In ITAF, standards define mandatory requirements for IS audit and assurance work, whereas guidelines offer non-mandatory direction on applying those standards.
- Standards apply only to external auditors, while guidelines apply only to internal auditors.Incorrect. ITAF applies to IS audit and assurance professionals regardless of internal or external status; the distinction is mandatory versus advisory, not audience.
- Guidelines are mandatory requirements, while standards describe optional leading practices.Incorrect. This reverses the relationship; guidelines are the advisory layer and standards are the mandatory layer.
- Standards are set by regulators, while guidelines are set by ISACA.Incorrect. Both ITAF standards and guidelines are issued by ISACA; regulators do not author ITAF.
The trap
Believing guidelines carry the same mandatory weight as standards, or reversing which layer is binding.All 89 Information Systems Auditing Process questions →
Would you pass CISA today?
Five minutes, and you get a score per domain — not one number, but which section to open tonight.
Test your CISA readiness — free
Certsqill CISA question bank · 496 questions across 5 domains ·
Every answer, right and wrong, comes with its own explanation.