Try 12 free ISACA CISA practice questions
Real exam-style questions taken word for word from the ISACA CISA study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.
Unlock the full sampler
Three questions to try right now
Work each one before you open the answer. These are the same style and depth as the Certified Information Systems Auditor (CISA) exam expects.
Question 1. Following a business divestiture that significantly reduced available IT resources, management wants to estimate staffing requirements for upcoming projects. Reviewing the IT staffing plan against which of the following would BEST guide these estimates?
- A. The human resources department's sourcing and recruitment strategy
- B. Historical records of actual time and effort logged against previous similar projects
- C. Staffing benchmarks published by peer organizations in the same industry
- D. The approved budget forecast for the next fiscal year
Show the answer
Answer: B. Actual time-tracking records from previous projects provide an empirical, organization-specific baseline for estimating how much effort each type of project activity consumes. They capture the realities of the organization's current environment, team competencies, and process maturity in a way that external benchmarks and budget forecasts cannot. After a divestiture, where internal capacity has changed materially, ground-truth historical data is the most reliable anchor for re-calibrating estimates. HR sourcing strategy and budget forecasts reflect plans and constraints but not the actual effort reality of project delivery.
- A: HR sourcing strategy describes how staff are recruited and contracted but does not provide data on how long project activities actually take to complete.
- C: Industry benchmarks are useful for general calibration but do not account for the specific processes, complexity, or maturity of the organization's own environment.
- D: The budget forecast reflects financial planning assumptions but is not necessarily based on accurate effort data; using it as the primary reference risks perpetuating unrealistic estimates.
Question 2. An IS auditor reviewing incident response management discovers that resolution times for recurring incidents have not improved over several review cycles. Which of the following is the BEST recommendation?
- A. Harden all IT systems and applications in line with industry security benchmarks.
- B. Deploy a security information and event management (SIEM) platform to support incident response activities.
- C. Conduct a survey to determine future incident response training needs among the response team.
- D. Introduce a formal problem management practice into the incident response process.
Show the answer
Answer: D. Recurring incidents that do not improve in resolution time indicate that root causes are not being identified and eliminated. Problem management is the discipline specifically designed to investigate the underlying causes of incidents, implement permanent fixes, and prevent recurrence, which directly addresses the observed pattern. Hardening and SIEM adoption are preventive and detective improvements respectively, but neither targets the root-cause analysis gap that problem management fills. Training may improve response skills but will not resolve the systemic cause of the repeating incidents.
- A: Hardening reduces the attack surface for future incidents but does not address the root cause of incidents that are already recurring.
- B: A SIEM improves detection and correlation but does not produce root-cause analysis or permanent fixes for known recurring issues.
- C: Training may improve individual responder capability but does not identify or eliminate the underlying technical or process cause driving the repeated incidents.
Question 3. An IS auditor wants to confirm that the organization's business continuity plan (BCP) is aligned with the business strategy. Which of the following documents would be MOST helpful to review?
- A. Results from the most recent disaster recovery plan (DRP) test
- B. The business impact analysis (BIA)
- C. The enterprise risk management (ERM) policy
- D. Key performance indicators (KPIs) for IT operations
Show the answer
Answer: B. The business impact analysis identifies which business processes are most critical, quantifies the financial and operational impact of their disruption, and establishes recovery priority and time objectives. Because the BIA is built from business strategy inputs, reviewing it allows the auditor to assess whether the BCP priorities genuinely reflect what the organization considers strategically essential. DRP test results show recovery capability but not strategic alignment. The ERM policy addresses risk broadly, not continuity priorities specifically. KPIs measure operational performance and do not reveal how the BCP maps to business strategy.
- A: DRP test results demonstrate how well systems can be recovered but do not show whether the processes selected for protection are strategically aligned with business priorities.
- C: The ERM policy frames the organization's overall approach to risk but does not specify which business processes are critical or establish continuity priorities.
- D: KPIs track operational and service performance and do not define or validate the strategic alignment of continuity plans.
Unlock the full 12-question sampler
All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.
What you get
The sampler is free. Here is exactly what lands in your inbox.
Print it or work it on screen, then score yourself against the answer key.
Nothing is written for marketing. Every question is lifted from the study guide itself.
A few days later we send one email with a code for the full study guide. That is the entire sequence.
The full ISACA CISA study guide
The complete guide covers the Certified Information Systems Auditor (CISA) exam objective by objective in plain English, with the full practice question bank behind these samples.
From $20.99
Simply Certified is an independent publisher. CISA is a trademark of ISACA, which does not sponsor or endorse this product. This page and the sampler are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.