ISACA certification

ISACA CISA (CISA) Practice Questions & Study Guide

Certified Information Systems Auditor — the global standard for IT auditors, frequently required for SOX, HIPAA, PCI-DSS, and ISO 27001 audit roles. Five years of audit experience required (waivers available).

What's included

27
concept lessons
110
practice questions
109
question mock exam
5
exam domains

Every CISA question includes a worked explanation and hints. Question formats mirror the real exam: multiple choice, multiple select, short answer and drag-and-drop matching. A full timed final exam reports per-domain analytics so you know exactly where you stand before test day.

A sample CISA lesson

Welcome to CISA

The Certified Information Systems Auditor (CISA) credential from ISACA validates expertise in auditing, controlling, and assuring an organization's information systems. This introduction explains who the certification serves, how the exam is structured, the experience and membership requirements, and how to plan an effective study program.

What CISA Is

The Certified Information Systems Auditor (CISA) is a globally recognized professional certification issued by ISACA (formerly the Information Systems Audit and Control Association). It establishes that the holder can assess vulnerabilities, report on compliance, and institute controls within an enterprise's information technology and business systems. Since its introduction in 1978, CISA has become the benchmark credential for professionals who audit, monitor, and assess IT and business systems, and it is frequently cited as a baseline requirement in job postings for IS audit and assurance roles.

CISA is organized around a job-practice analysis that ISACA periodically updates by surveying practitioners worldwide. That analysis is published as the CISA exam content outline, which defines the knowledge and tasks an IS auditor is expected to perform. Rather than testing one vendor's products, the certification is framework-neutral and draws on authoritative bodies of knowledge such as COBIT for governance and management of enterprise IT, COSO for internal control and enterprise risk, the ISO/IEC 27000 family for information security management, and NIST Special Publications for security and risk guidance.

This is one of 27 concept lessons in the full CISA track.

Exam facts

  • Exam codeCISA
  • VendorISACA
  • Format150 questions · 4 hours
  • Passing score450 / 800
  • Exam cost$760 USD (non-member) / $575 USD (member)
  • Renewal3 years (120 CPE hours)

Pricing

from $19 one-time
single CISA pass (or included in premium)
$10
/ month — all certifications
$100
/ year — all certifications

Your first foundational certification is free when you sign up — no card required.

CISA FAQ

How much does the ISACA CISA exam cost?
The official ISACA CISA exam voucher is $760 USD (non-member) / $575 USD (member). CyberStudy is separate, affordable practice and is not the exam voucher.
How many questions are on the CISA exam?
The CISA exam is 150 questions · 4 hours.
What score do I need to pass CISA?
The passing score is 450 / 800.
How long is CISA valid?
ISACA CISA is valid for 3 years (120 cpe hours).
How much CISA practice does CyberStudy include?
110 exam-style practice questions across every domain plus a full 109-question timed mock exam with analytics, and 27 concept lessons.