dc dotCreds
ISACA CISA Practice Test — A+ Source-Backed Repaired Bank

ISACA CISA Practice Test

Start today’s free 10-question ISACA CISA set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 17, 2026, 10:23 PM CDT

Go Pro - One Time Unlock

Unlock the full CISA bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 ISACA CISA questions

Use this ISACA CISA practice test to review ISACA Certified Information Systems Auditor. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective Evaluate systems availability and capacity management 4. Information Systems Operations and Business Resilience (26%)

A critical service experiences slowdowns every quarter-end. Capacity reports show average utilization is normal, but no peak-demand data is retained. What should the auditor recommend?

Concept tested:
Question 2 of 10
Objective Evaluate information system attack methods and techniques 5. Protection of Information Assets (26%)

A web application accepts user input that is concatenated directly into database queries. What attack risk should the auditor prioritize during security testing?

Concept tested:
Question 3 of 10
Objective Evaluate control identification and design 3. Information Systems Acquisition, Development and Implementation (12%)

A software team stores source code and infrastructure-as-code in a shared repository where contractors have write access to all projects. What control should the auditor prioritize?

Concept tested:
Question 4 of 10
Objective Evaluate information asset security frameworks and standards 5. Protection of Information Assets (26%)

A board dashboard reports the number of security controls implemented but not whether they reduce the organization's priority risks. What is the MOST important audit observation?

Concept tested:
Question 5 of 10
Objective Apply IS audit standards, guidelines, and codes of ethics 1. Information Systems Auditing Process (18%)

During an audit, a business unit offers the auditor a substantial gift after the auditor identifies a control weakness that may affect the unit's performance rating. What should the auditor do FIRST?

Concept tested:
Question 6 of 10
Objective Evaluate data governance and classification 2. Governance and Management of IT (18%)

Business units classify similar customer datasets differently, causing inconsistent retention and access controls. What should the auditor recommend FIRST?

Concept tested:
Question 7 of 10
Objective Select audit testing and sampling methodologies 1. Information Systems Auditing Process (18%)

An auditor needs to test whether a control operated consistently throughout the year. Which sampling approach is MOST appropriate?

Concept tested:
Question 8 of 10
Objective Evaluate disaster recovery planning 4. Information Systems Operations and Business Resilience (26%)

A DR test fails because the recovery site depends on the same identity service that was assumed unavailable in the test scenario. What is the MOST important corrective action?

Concept tested:
Question 9 of 10
Objective Evaluate IT resource management 2. Governance and Management of IT (18%)

A cybersecurity team is accountable for continuous monitoring but lacks staff and tooling needed to meet approved monitoring frequencies. What is the BEST audit recommendation?

Concept tested:
Question 10 of 10
Objective Evaluate the business case and feasibility analysis 3. Information Systems Acquisition, Development and Implementation (12%)

Management selects a new payment platform before documenting other viable solutions. What evidence would BEST support the reasonableness of the selection?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CISA Pro $4.99 one-time

Unlock all 200 ISACA CISA questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question CISA PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, Certified Ethical Hacker, ISC2 CISSP, ISC2 CCSP, ISACA CISM, ISACA CRISC, ISACA CISA, AWS Security Specialty, Cisco CyberOps Associate, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CISA bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CISA practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily ISACA CISA set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A critical service experiences slowdowns every quarter-end. Capacity reports show average utilization is normal, but no peak-demand data is retained. What should the auditor recommend?

Answer choices

  1. A. Buy additional capacity immediately based on user complaints.
  2. B. Measure and trend peak workload and resource utilization against business demand and service thresholds.
  3. C. Lower the service-level target during quarter-end periods.
  4. D. Collect only annual average capacity metrics to simplify reporting.

Correct answer

Measure and trend peak workload and resource utilization against business demand and service thresholds.

Average utilization can conceal predictable capacity constraints; planning should use workload patterns relevant to the service commitment.

Wrong-answer review

  • A. Buy additional capacity immediately based on user complaints.: This relies on an unsupported assumption rather than obtaining evidence.
  • C. Lower the service-level target during quarter-end periods.: Contract language alone does not demonstrate that the service is meeting operational or control requirements.
  • D. Collect only annual average capacity metrics to simplify reporting.: This response does not adequately address the material risk or control deficiency.

Extra learning features

Why candidates miss this

The distractor ‘Buy additional capacity immediately based on user complaints’ is tempting because it represents a reactive, short-term solution. However, it fails to address the underlying cause of the slowdowns – the lack of peak-demand data. The decisive clue that eliminates this distractor is the explicit statement that ‘no peak-demand data is retained,’ highlighting the need for proactive capacity management based on workload trends, not simply responding to user complaints. Likely wrong answer: Buy additional capacity immediately based on user complaints. Review focus: CISA Exam Content Outline (Current)

Objective/domain: 4. Information Systems Operations and Business Resilience (26%)

Source: CISA Exam Content Outline (Current)

Question 2 A web application accepts user input that is concatenated directly into database queries. What attack risk should the auditor prioritize during security testing?

Answer choices

  1. A. Cross-site request forgery caused solely by weak password length.
  2. B. Physical theft of the database server.
  3. C. Wireless jamming of the application network.
  4. D. Injection that allows attacker-controlled input to alter the intended database query.

Correct answer

Injection that allows attacker-controlled input to alter the intended database query.

Objective/domain: 5. Protection of Information Assets (26%)

Source: OWASP Web Security Testing Guide

Question 3 A software team stores source code and infrastructure-as-code in a shared repository where contractors have write access to all projects. What control should the auditor prioritize?

Answer choices

  1. A. Encrypt every source file before it is committed.
  2. B. Require quarterly penetration testing of the repository server.
  3. C. Restrict repository access according to least privilege and ensure changes are attributable to individual identities.
  4. D. Move the repository to an internal network without changing permissions.

Correct answer

Restrict repository access according to least privilege and ensure changes are attributable to individual identities.

Objective/domain: 3. Information Systems Acquisition, Development and Implementation (12%)

Source: NIST SP 800-218 — Secure Software Development Framework

Question 4 A board dashboard reports the number of security controls implemented but not whether they reduce the organization's priority risks. What is the MOST important audit observation?

Answer choices

  1. A. More controls always indicate a stronger security posture.
  2. B. The board should receive only detailed technical vulnerability data.
  3. C. Control-count metrics do not demonstrate that the security program is achieving risk and business objectives.
  4. D. Control counts are sufficient if every business unit reports them consistently.

Correct answer

Control-count metrics do not demonstrate that the security program is achieving risk and business objectives.

Objective/domain: 5. Protection of Information Assets (26%)

Source: NIST Cybersecurity Framework (CSF) 2.0

Question 5 During an audit, a business unit offers the auditor a substantial gift after the auditor identifies a control weakness that may affect the unit's performance rating. What should the auditor do FIRST?

Answer choices

  1. A. Accept the gift because the finding was already identified.
  2. B. Refuse the gift and follow the organization's and audit function's ethics requirements for reporting the situation.
  3. C. Accept the gift but disclose it in the final report.
  4. D. Remove the finding so the gift cannot be perceived as influencing the audit.

Correct answer

Refuse the gift and follow the organization's and audit function's ethics requirements for reporting the situation.

Objective/domain: 1. Information Systems Auditing Process (18%)

Source: IT Audit Framework (ITAF), 5th Edition — ISACA

Question 6 Business units classify similar customer datasets differently, causing inconsistent retention and access controls. What should the auditor recommend FIRST?

Answer choices

  1. A. Apply the highest classification to all data permanently.
  2. B. Establish enterprise data-classification criteria, ownership, and governance so control requirements are applied consistently.
  3. C. Allow each application administrator to classify data independently.
  4. D. Encrypt all databases and stop performing classification.

Correct answer

Establish enterprise data-classification criteria, ownership, and governance so control requirements are applied consistently.

Objective/domain: 2. Governance and Management of IT (18%)

Source: CISA Exam Content Outline (Current)

Question 7 An auditor needs to test whether a control operated consistently throughout the year. Which sampling approach is MOST appropriate?

Answer choices

  1. A. Select only transactions from the final month because they are most recent.
  2. B. Use only exceptions already identified by management.
  3. C. Choose whichever items are easiest for the auditor to retrieve.
  4. D. Select items across the relevant period and population using a method that gives a defensible basis for evaluating control performance.

Correct answer

Select items across the relevant period and population using a method that gives a defensible basis for evaluating control performance.

Objective/domain: 1. Information Systems Auditing Process (18%)

Source: ISACA ITAF 5th Edition — Updated Audit Sampling Guidance

Question 8 A DR test fails because the recovery site depends on the same identity service that was assumed unavailable in the test scenario. What is the MOST important corrective action?

Answer choices

  1. A. Repeat the same test until it succeeds without changing the design.
  2. B. Exclude identity outages from future DR scenarios.
  3. C. Reassess recovery dependencies and redesign or provide alternate access so the recovery environment does not rely on the failed prerequisite.
  4. D. Classify the failed test as a documentation issue only.

Correct answer

Reassess recovery dependencies and redesign or provide alternate access so the recovery environment does not rely on the failed prerequisite.

Objective/domain: 4. Information Systems Operations and Business Resilience (26%)

Source: NIST SP 800-34 Rev. 1 — Contingency Planning Guide

Question 9 A cybersecurity team is accountable for continuous monitoring but lacks staff and tooling needed to meet approved monitoring frequencies. What is the BEST audit recommendation?

Answer choices

  1. A. Leave the requirement unchanged and accept persistent nonperformance.
  2. B. Have auditors perform the monitoring to fill the staffing gap.
  3. C. Stop monitoring low-risk controls without risk approval.
  4. D. Align resources with the approved risk strategy, responsibilities, and monitoring requirements or formally revise the requirements through governance.

Correct answer

Align resources with the approved risk strategy, responsibilities, and monitoring requirements or formally revise the requirements through governance.

Objective/domain: 2. Governance and Management of IT (18%)

Source: NIST Cybersecurity Framework (CSF) 2.0

Question 10 Management selects a new payment platform before documenting other viable solutions. What evidence would BEST support the reasonableness of the selection?

Answer choices

  1. A. A vendor presentation showing the selected platform's feature set.
  2. B. A documented analysis of alternatives using defined evaluation criteria, weighting, readiness, risk, and rationale.
  3. C. A project schedule showing the platform can be implemented quickly.
  4. D. A post-selection technical design approved by the architecture team.

Correct answer

A documented analysis of alternatives using defined evaluation criteria, weighting, readiness, risk, and rationale.

Objective/domain: 3. Information Systems Acquisition, Development and Implementation (12%)

Source: U.S. Department of Commerce — Acquisition Agile Program and Project Management Guidebook

Where to go after the daily web set

How are ISACA CISA questions generated?

dotCreds builds ISACA CISA practice questions from public exam objectives and ISACA exam and documentation references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start ISACA CISA practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.