dc dotCreds
ISACA CISA Practice Test — A+ Source-Backed Repaired Bank

ISACA CISA Practice Test

Start today’s free 10-question ISACA CISA set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 23, 2026, 8:12 PM CDT

Go Pro - One Time Unlock

Unlock the full CISA bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 ISACA CISA questions

Use this ISACA CISA practice test to review ISACA Certified Information Systems Auditor. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Evaluate security incident response management 5. Protection of Information Assets (26%)

A major incident requires additional forensic specialists and executive decisions, but the response team continues using the original staffing level because escalation criteria are undocumented. What should the auditor recommend?

Concept tested:
Question 2 of 10
Objective Conduct a post-implementation review 3. Information Systems Acquisition, Development and Implementation (12%)

Three months after a CRM launch, the system is technically stable, but expected sales-productivity benefits have not materialized. What should a post-implementation review focus on FIRST?

Concept tested:
Question 3 of 10
Objective Evaluate IT performance monitoring and reporting 2. Governance and Management of IT (18%)

Senior management receives dozens of operational metrics but cannot tell whether IT is supporting business objectives. Which improvement is MOST important?

Concept tested:
Question 4 of 10
Objective Collect sufficient and appropriate audit evidence 1. Information Systems Auditing Process (18%)

Management states that all terminated users are removed within 24 hours. Which evidence is MOST reliable for testing the claim?

Concept tested:
Question 5 of 10
Objective Evaluate database management 4. Information Systems Operations and Business Resilience (26%)

A database backup job reports success, but no one has restored a backup in the last year. What is the auditor's BEST conclusion?

Concept tested:
Question 6 of 10
Objective Evaluate control identification and design 3. Information Systems Acquisition, Development and Implementation (12%)

During requirements review for a new payroll application, security requirements are deferred until penetration testing because the team wants to avoid slowing design. What should the auditor recommend?

Concept tested:
Question 7 of 10
Objective Evaluate mobile, wireless, and Internet of Things devices 5. Protection of Information Assets (26%)

A hospital deploys network-connected medical IoT devices using vendor default passwords because changing credentials may complicate support. What should the auditor recommend?

Concept tested:
Question 8 of 10
Objective Evaluate enterprise risk management 2. Governance and Management of IT (18%)

The enterprise risk assessment has not been updated since before a major acquisition, despite substantial new suppliers and data flows. What is the BEST audit recommendation?

Concept tested:
Question 9 of 10
Objective Manage an information systems audit engagement 1. Information Systems Auditing Process (18%)

Halfway through fieldwork, the auditor discovers that a critical interface omitted from the original scope could materially affect the audit objective. What should the audit lead do?

Concept tested:
Question 10 of 10
Objective Evaluate IT components and enterprise operations 4. Information Systems Operations and Business Resilience (26%)

A data center operations team uses undocumented scripts to restart failed services automatically. The scripts are effective, but only one administrator understands them. What is the PRIMARY audit concern?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CISA Pro $4.99 one-time

50 Exam Practice Test $1.99 one-time

A 50-question CISA PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

ISACA Bundle $9.99 one-time

Unlock all 5 active ISACA Bundle practice banks in one permanent purchase.

What’s includedCISA, CISM, CRISC, CGEIT, CDPSE
All Access $6.99/month

Unlock every active practice exam, bundle and path experience, Pro course and study content, and included downloads.

What’s includedEvery current and future active practice exam, All active bundle and career-path practice content, Pro course lessons, study content, and supported paid downloads

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CISA bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CISA practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily ISACA CISA set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A major incident requires additional forensic specialists and executive decisions, but the response team continues using the original staffing level because escalation criteria are undocumented. What should the auditor recommend?

Answer choices

  1. A. Keep staffing fixed to maintain consistency across incidents, for the described technical objective and its associated operational control requirements, as presented.
  2. B. Define and use status, escalation, and elevation criteria so resources and management involvement change as incident needs evolve, for the described technical objective.
  3. C. Automatically escalate every event to the CEO, for the described technical objective and its associated operational control requirements, as presented.
  4. D. Delay escalation until recovery is complete, for the described technical objective and its associated operational control requirements, for review.

Correct answer

Define and use status, escalation, and elevation criteria so resources and management involvement change as incident needs evolve, for the described technical objective.

Incident status should be tracked and response resources or leadership elevated when severity, complexity, or strategy requires it.

Wrong-answer review

  • A. Keep staffing fixed to maintain consistency across incidents, for the described technical objective and its associated operational control requirements, as presented.: This response does not adequately address the material risk or control deficiency.
  • C. Automatically escalate every event to the CEO, for the described technical objective and its associated operational control requirements, as presented.: This response is disproportionate to the evidence and could create unnecessary operational risk.
  • D. Delay escalation until recovery is complete, for the described technical objective and its associated operational control requirements, for review.: This response does not adequately address the material risk or control deficiency.

Extra learning features

Why candidates miss this

The distractor ‘Automatically escalate every event to the CEO.’ is tempting because it seems to ensure rapid action. However, it overwhelms leadership with irrelevant alerts and can delay critical decisions. Likely wrong answer: Automatically escalate every event to the CEO. Review focus: NIST SP 800-61 Rev. 3 — Incident Response Recommendations

Objective/domain: 5. Protection of Information Assets (26%)

Source: NIST SP 800-61 Rev. 3 — Incident Response Recommendations

Question 2 Three months after a CRM launch, the system is technically stable, but expected sales-productivity benefits have not materialized. What should a post-implementation review focus on FIRST?

Answer choices

  1. A. Close the review because technical availability targets are being met, under the stated technical, operational, and governance constraints.
  2. B. Recommend replacing the CRM because benefits are below forecast, for the stated security, delivery, and accountability requirements.
  3. C. Compare actual outcomes and usage against the approved business case and identify causes of the benefit shortfall, within the described operational context.
  4. D. Review only whether the project stayed within implementation budget, as the recommended implementation across the complete governed service lifecycle.

Correct answer

Compare actual outcomes and usage against the approved business case and identify causes of the benefit shortfall, within the described operational context.

Objective/domain: 3. Information Systems Acquisition, Development and Implementation (12%)

Source: U.S. Department of Commerce — Acquisition Agile Program and Project Management Guidebook

Question 3 Senior management receives dozens of operational metrics but cannot tell whether IT is supporting business objectives. Which improvement is MOST important?

Answer choices

  1. A. Increase the number of metrics so no operational detail is omitted, for the stated implementation and support requirements.
  2. B. Link a focused set of KPIs and KRIs to business objectives, service outcomes, risk tolerance, and decision needs, within the stated policy framework.
  3. C. Report only technical uptime because it is easy to measure, within the documented operational, security, ownership, and validation requirements.
  4. D. Send raw monitoring data without interpretation, for the described technical objective and its associated operational control requirements, within the defined security and accountability boundaries.

Correct answer

Link a focused set of KPIs and KRIs to business objectives, service outcomes, risk tolerance, and decision needs, within the stated policy framework.

Objective/domain: 2. Governance and Management of IT (18%)

Source: NIST Cybersecurity Framework (CSF) 2.0

Question 4 Management states that all terminated users are removed within 24 hours. Which evidence is MOST reliable for testing the claim?

Answer choices

  1. A. Independent system records showing termination times and corresponding account-disable times for an appropriate sample or population, in the described situation.
  2. B. A manager's verbal statement that the process usually works, under the described . information systems auditing process (18%) criteria.
  3. C. A policy requiring accounts to be disabled within 24 hours, for the described technical objective and its associated operational control requirements, within this design.
  4. D. A training slide explaining why timely termination is important, for the described technical objective and its associated operational control requirements, in context.

Correct answer

Independent system records showing termination times and corresponding account-disable times for an appropriate sample or population, in the described situation.

Objective/domain: 1. Information Systems Auditing Process (18%)

Source: ISACA Interactive Glossary — Audit Evidence

Question 5 A database backup job reports success, but no one has restored a backup in the last year. What is the auditor's BEST conclusion?

Answer choices

  1. A. The control is effective because the backup software reports success, under the stated technical, operational, and governance constraints.
  2. B. All backups should be considered corrupt until a disaster occurs, for the specified implementation requirement.
  3. C. The database should be migrated to a different platform, for the stated . information systems operations and business resilience (26%) requirement.
  4. D. Backup completion does not provide sufficient assurance of recoverability without periodic restore validation, under this approach.

Correct answer

Backup completion does not provide sufficient assurance of recoverability without periodic restore validation, under this approach.

Objective/domain: 4. Information Systems Operations and Business Resilience (26%)

Source: NIST SP 800-34 Rev. 1 — Contingency Planning Guide

Question 6 During requirements review for a new payroll application, security requirements are deferred until penetration testing because the team wants to avoid slowing design. What should the auditor recommend?

Answer choices

  1. A. Integrate risk-based security requirements and practices throughout the SDLC rather than adding them only at final testing, under the stated decision criteria.
  2. B. Accept the approach if a qualified penetration tester is engaged, within the documented scope, ownership, and validation boundaries.
  3. C. Require all developers to hold a security certification before coding begins, under the stated technical, operational, and governance constraints.
  4. D. Move penetration testing earlier but leave security requirements outside design, as the proposed design for the complete governed operational workflow.

Correct answer

Integrate risk-based security requirements and practices throughout the SDLC rather than adding them only at final testing, under the stated decision criteria.

Objective/domain: 3. Information Systems Acquisition, Development and Implementation (12%)

Source: NIST SP 800-218 — Secure Software Development Framework

Question 7 A hospital deploys network-connected medical IoT devices using vendor default passwords because changing credentials may complicate support. What should the auditor recommend?

Answer choices

  1. A. Leave default credentials in place because patient care devices are exempt from security controls, under the stated technical, operational, and governance constraints.
  2. B. Disconnect every device from the network permanently, for the described technical objective and its associated operational control requirements, for the required business outcome.
  3. C. Assess and remediate default credential risk through supported secure configuration and compensating controls where direct change is not feasible, in context.
  4. D. Rely only on staff awareness not to disclose the default password, within the documented operational, security, ownership, and validation requirements.

Correct answer

Assess and remediate default credential risk through supported secure configuration and compensating controls where direct change is not feasible, in context.

Objective/domain: 5. Protection of Information Assets (26%)

Source: NIST SP 800-53 Rev. 5 — Security and Privacy Controls

Question 8 The enterprise risk assessment has not been updated since before a major acquisition, despite substantial new suppliers and data flows. What is the BEST audit recommendation?

Answer choices

  1. A. Update the organization-wide risk assessment using current business, threat, supplier, and system information.
  2. B. Retain the prior assessment until the next three-year strategic cycle, for the specified implementation requirement.
  3. C. Perform only a penetration test of the acquired network, within the documented operational, security, ownership, and validation requirements.
  4. D. Replace the risk methodology before evaluating whether the existing one is adequate, within the described operational context.

Correct answer

Update the organization-wide risk assessment using current business, threat, supplier, and system information.

Objective/domain: 2. Governance and Management of IT (18%)

Source: NIST SP 800-37 Rev. 2 — Risk Management Framework

Question 9 Halfway through fieldwork, the auditor discovers that a critical interface omitted from the original scope could materially affect the audit objective. What should the audit lead do?

Answer choices

  1. A. Ignore the interface because the scope was approved before fieldwork, for the described technical objective and its associated operational control requirements, in context.
  2. B. Expand the scope informally without documenting the change, for the described technical objective and its associated operational control requirements, under the stated decision criteria.
  3. C. Assess the risk, document the scope impact, and obtain appropriate approval for the necessary change to the audit plan, for this task.
  4. D. Stop the entire audit until next year's planning cycle, under the described . information systems auditing process (18%) criteria.

Correct answer

Assess the risk, document the scope impact, and obtain appropriate approval for the necessary change to the audit plan, for this task.

Objective/domain: 1. Information Systems Auditing Process (18%)

Source: IT Audit Framework (ITAF), 5th Edition — ISACA

Question 10 A data center operations team uses undocumented scripts to restart failed services automatically. The scripts are effective, but only one administrator understands them. What is the PRIMARY audit concern?

Answer choices

  1. A. Automated restarts should be prohibited for critical services, for the described technical objective and its associated operational control requirements.
  2. B. The scripts should be rewritten in a different programming language, for the required operational result and control objective.
  3. C. Operational resilience depends on undocumented, person-dependent automation that may not be supportable or controlled, for the stated implementation and support requirements.
  4. D. The administrator should be given permanent elevated access to avoid delays, under the described . information systems operations and business resilience (26%) criteria, for review.

Correct answer

Operational resilience depends on undocumented, person-dependent automation that may not be supportable or controlled, for the stated implementation and support requirements.

Objective/domain: 4. Information Systems Operations and Business Resilience (26%)

Source: NIST Cybersecurity Framework (CSF) 2.0

Where to go after the daily web set

How are ISACA CISA questions generated?

dotCreds builds ISACA CISA practice questions from public exam objectives and ISACA exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start ISACA CISA practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.