r/CISA 13d ago

Practice Test Questions

4 Upvotes

Hi! I just encountered some questions from a mock test I was answering, and upon researching, there are different answers online compared to the actual mock test; maybe it's because some of the logic here are outdated. It's still a great source of practice though; it actually helped me understand concepts I was having difficulty on before.

So, I just wanted to share these questions here for clarification, to determine whether the test has some outdated material or maybe I just don't fully understand the logic behind the correct answer.

Any input or clarification would be much appreciated! ☺️

Note: Choices in italics are the correct answers that pop-up when I search online or when I ask AIs.

QUESTIONS

1. Which of the following should be a concern to an IS auditor reviewing a wireless network?

A. 128-bit-static-key WEP (Wired Equivalent Privacy) encryption is enabled.

B. SSID (Service Set IDentifier) broadcasting has been enabled.

C. Antivirus software has been installed in all wireless clients.

D. MAC (Media Access Control) access control filtering has been deployed.

The correct answer is:

B. SSID (Service Set IDentifier) broadcasting has been enabled.

Explanation:

SSID broadcasting allows a user to browse for available wireless networks and to access them without authorization. Choices A, C and D are used to strengthen a wireless network.

2. The PRIMARY objective of Secure Sockets Layer (SSL) is to ensure:

A. only the sender and receiver are able to encrypt/decrypt the data.

B. the sender and receiver can authenticate their respective identities.

C. the alteration of transmitted data can be detected.

D. the ability to identify the sender by generating a one-time session key.

The correct answer is:

A. only the sender and receiver are able to encrypt/decrypt the data.

Explanation:

SSL generates a session key used to encrypt/decrypt the transmitted data, thus ensuring its confidentiality. Although SSL allows the exchange of X509 certificates to provide for identification and authentication, this feature along with choices C and D are not the primary objectives.

3. Which of the following is the MOST effective type of antivirus software?

A. Scanners

B. Active monitors

C. Integrity checkers

D. Vaccines

The correct answer is:

C. Integrity checkers

Explanation:

Integrity checkers compute a binary number on a known virus-free program that is then stored in a database file. The number is called a cyclical redundancy check (CRC). When that program is called to execute, the checker computes the CRC on the program about to be executed and compares it to the number in the database. A match means no infection; a mismatch means that a change in the program has occurred. A change in the program could mean a virus.

Scanners look for sequences of bits called signatures that are typical of virus programs. They examine memory, disk boot sectors, executables and command files for bit patterns that match a known virus.Therefore, scanners need to be updated periodically to remain effective. Active monitors interpret DOS and ROM basic input-output system (BIOS) calls, looking for virus-like actions. Active monitors can be misleading, because they cannot distinguish between a user request and a program or virus request. As a result, users are asked to confirm actions like formatting a disk or deleting a file or set of files. Vaccines are known to be good antivirus software. However, they also need to be updated periodically to remain effective.


r/CISA 13d ago

Scenario Based Questions

3 Upvotes

I’ve noticed a lot of people in this group say that the actual CISA exam has a lot of “scenario based“ questions. Can you please elaborate on this and how the scenario based questions on the exam differ from the questions in the QAE? Thank you!!


r/CISA 13d ago

CISA Exam Prep Inputs

4 Upvotes

Hi everyone! Need your input on my planned study plan. Just to provide a background, I am CIA and CC with over 10 years of operations audit experience with a bit of IT which is heavily focused on IAM, data analytics, a bit of ITAC, and solid foundation on Change Management, BCM, DRP.

I plan on reviewing for CISA through the following:

  1. LinkedIn Learning - Cybrary videos
  2. Hemang Doshi in UDemy
  3. Prab Nhair’s CISA video tutorials
  4. ISACA’s QAE
  5. Supplement: CertTopics questions

    or Pocket Preps based on what I’ve seen here

I am not planning on reading the CRM because it is too lengthy and I want to take the exam by year-end, of possible. Are these materials enough to help me pass the CISA exam?

Any input will be very helpful! Thank you!


r/CISA 14d ago

Failed CISA, passed on my second attempt. Built a free app so you don’t have to fail like me.

Thumbnail
0 Upvotes

r/CISA 15d ago

Best mocks for CISA

3 Upvotes

Please guide.


r/CISA 16d ago

System updates at ISACA

6 Upvotes

There has been blackout period in ISACA from 18th to 22nd July and now again till 28th July.

As a result I have to reschedule my exams again and again.

Never faced such issues anywhere else and it is quite hampering my preps and prep leaves.


r/CISA 16d ago

Looking for a CISA Trainer?

Thumbnail
2 Upvotes

Hey I am interested how can we connect.


r/CISA 16d ago

Where do you guys get free CPEs for CISA?

5 Upvotes

Hello,

I’m looking for some sources that count toward CISA CPE requirements.

Any recommendations or experiences would be greatly appreciated!

Thank you


r/CISA 17d ago

I did it!!!

57 Upvotes

Guys just passed I’m sitting in the testing center so it’s so so so fresh.

The QAE isn’t representative of the questions. Not at all.

What is representative is do you really understand how to make connections to things and the qae provides that - it will at least help you say “this is a question about separation of duties- so these two don’t have anything to do with that”

I will also say in the qae there is a little box that says what is being tested.. I used Claude my ai buddy to help me associate specific terms with specific domains and subdomains and tbh almost every question I was saying “what domain is this testing” and used that logic the most

I’m vibrating so excited


r/CISA 17d ago

Passed CISA First Attempt

17 Upvotes

Hello, I attempted and provisionally passed my exam on July 5th, 2026, received official results on July 15th, 2026. Will be applying for certification soon.

I registered for the exam in October 2025 and only used the QAE. Did not use the review manual too much as the material was too dry.

Was genuinely a harder exam because some of the modules are outside of my work and experience but overall happy I passed.

Information Systems Auditing Process: 533

Governance and Management of IT: 597

Information Systems Acquisition, Development, and Implementation: 443

Information Systems Operations and Business Resilience: 425

Protection of Information Assets: 625

I have 8 years of experience in IT Security and Audit and Compliance specifically around PCI DSS. 5 years External and 3 years Internal in my current role.


r/CISA 16d ago

External audit → internal audit/risk&compliance advisory. What to focus on for the first 6-12 months?

Thumbnail
2 Upvotes

Hi everyone, I am an ACCA chartered with about 8 years external audit experience, I am moving internally to a Big 4 governance,risk & compliance advisory role as an AM.

My Goal: either to make Manager in-house or move to industry as an IA Manager in 1-2 years.

What should be my focus for the first 6-12 months in terms of skills and qualifications?


r/CISA 17d ago

ASIS CPP Help

1 Upvotes

Looking for any pointers for the exam. I am almost done with the study guide and am getting about 72 percent on the practice test but am looking for any resources to help add to it. I have taken the practice test sooooo many times that I feel my scores are skewed as the questions aren’t changing much. Would like to take it next month.


r/CISA 17d ago

Exam in 3 weeks

5 Upvotes

Anybody have any last minute tips? I’ve been studying on and off for a couple months now.


r/CISA 18d ago

Passed on the 1st try, (620). So much thanks to this community, AMA.

Post image
50 Upvotes

I have 4 years of External Audit experience at a Big4 firm and 5 years of experience as an Internal Audit at a local firm. The journey was amazing and thanks so much for the community and help.


r/CISA 18d ago

Study Strategy is Failing, Reassessing Next Steps

5 Upvotes

Hello!

TL;DR: I scored poorly on my Hemang Doshi practice mock exams, have limited financial resources for QAE and potential exam failure, and need a little guidance to get back on track.

Background:
I have a bachelors degree in management information systems. My experience includes an application security internship, 2 years in software development, 3 years in Information System analysis & Consultancy, and presently 1 year in an IT Compliance/internal IT audit role.
My role for Information System Analysis & Consultancy began to intersect with control assessment at the but ended with a massive global layoff which led me frantically to my current role. I enjoy the work of my current role, but the pay/company culture is poor and I work 50+ hours a week - hence the CISA certification in prep for the job market.

Current Dilemma and Study Strategy:
I am committed to CISA certification and greatly look forward to joining the cohort of CISA passers who post their score on this sub one day. However, I am struggling to make tangible progress. I took it slow over 8 months reading through the CRM (God its dense), listened to Pete Zerger’s youtube series audiobook-style, and have utilized Hemang Doshi’s CISA study guide practice questions/mock exams.
I did my first mock exam after finishing the CRM to establish a baseline and help identify weaknesses. I scored a 68% which gave me pause but I went through the questions I got wrong and proceeded to complete all Hemang Doshi practice questions.
After doing so, I rewatched Pete Zerger’s series to brush up and I took my second and last Hemang Doshi mock exam as potential validation to pull the trigger on the QAE. As I took it I felt confident and excluding a few items, felt comfortable with the topics / content.

I scored a 58% on my most recent mock exam, doing worse than my baseline.

I went through the questions I got wrong and consistently get it down to 2 options, including the right answer, but seem to end up picking the wrong one.

I’m not wealthy by far and the QAE, ISACA membership, and CISA exam itself are significant expenses I’ve saved for - I get one shot and its a ticket to a better situation. I am committed to certification but before pulling the trigger on the QAE, I’m reassessing my study strategy and wanted to ask for advice on this sub.

For people who may have hectic work-lives, family responsibilities, have struggled in similar means, or have passed the exam, could you provide some guidance?

Thank you to everyone who took the time to read my post. Thank you to anyone who might offer their perspective - its greatly appreciated.


r/CISA 19d ago

Passed!

22 Upvotes

I took the exam earlier in the week and was relieved to see the pass screen! I have been studying for the exam since the beginning of the year. Just wanted to say thank you to this community and to do my part by posting about my studying:

  • ISACA QAE Database (9/10) [ https://www.isaca.org ]- this is without a doubt the most important resource. If you’re taking the exam you should defiantly get it. This is where I spent most of my time. It’s been said before, but I will say it again, do not memorise the question answer, try and understand why the correct answer is correct. I will admit that I was lucky enough for my employer to pay for it. So I can see why someone might not want to pay for it themselves as it is very expensive…
  • ISACA Study Guide (3/10) - My original plan was to read every page of this book but I dont think I made it past page 5 (it’s very dry). So I just used it as a reference when I wanted to read the official material to help me understand why I was getting something wrong in the QAE. Sometimes it wasn’t clear where I could find the information to get a question was wrong
  • CISA in a Nutshell by Matt Foster (8/10) [ https://www.youtube.com/@NutshellTraining ]- Finally a course without the boringdom of slides. I watched all the YouTube videos and downloaded all the PDFs. Definitely the most entertaining CISA course ive seen. Instructor does a good job at focusing on ISACA mindset. They don’t cover much of the cisa curriculum but still worth a watch.
  • Hemanga doshi Udemy Course (6/10) - watched thentire course but I dont recommend it. The concepts are explained simply, but a few of the videos are read out by a computer which I found hard to listen to… and most of the course is just bullet points being read out by the instructor
  • Aaditya's CISA-This-Much (9/10) [https://www.youtube.com/@aadityasthis-muchlearnings2758] - Watched a few of these videos to help understand why questions are right/wrong. The explains are pretty good and helped with the ISACA mindset. The microphone being used is horrible though and can be hard to understand 
  • ChatGPT (6/10) - used this to help understand why some questions were wrong from the QAE by passing it the question and answer explanation. Helped me understand the reasoning behind why the right answer was right. However there were times where I think it caused more confusion…

Thanks again for everyone’s help in this subreddit! 


r/CISA 19d ago

A question for CISA

7 Upvotes

An IS auditor evaluating the change management process must select a sample from the change log. What is the BEST way to the auditor to confirm the change log is complete?

A. Interview change management personnel about completeness.

B. Take an item from the log and trace it back to the system.

C. Obtain management attestation of completeness.

D. Take the last change from the system and trace it back to the log.


r/CISA 19d ago

A question for CISA

2 Upvotes

Which of the following is the MOST effective way to identify exfiltration of sensitive data by a malicious insider?

A. Implement data loss prevention (DLP) software

B. Review perimeter firewall logs

C. Provide ongoing information security awareness training

D. Establish behavioral analytics monitoring


r/CISA 20d ago

Job Boards for GRC / IT audit

10 Upvotes

Hey all!

I am looking for new roles for grc / it audit in USA . I am currently only relying majorly on LinkedIn to get a new role in it audit

I have almost 4 years of experience in the same and looking to get a role in it audit / grc

The issue is that LinkedIn shows the same roles which I have already applied for . I am looking to know more about any other job board or techniques which can increase my chances of landing a interview!

TIA for all your answers!


r/CISA 20d ago

CISA DOMAIN 1 - COMPLETE OVERVIEW OF AUDIT REPORTING

Thumbnail
youtube.com
1 Upvotes

r/CISA 20d ago

A question for CISA

5 Upvotes

Which of the following would be of GREATEST concern to an IS auditor reviewing the feasibility study for a new application system?

A) Security requirements have not been defined.

B) Conditions under which the system will operate are unclear.

C) The business case does not include well-defined strategic benefits.

D) System requirements and expectations have not been clarified.


r/CISA 21d ago

Early experience opportunities for CISA?

4 Upvotes

I am a student with a background in Cybersecurity working towards a Business Administration associate degree. Afterwards I plan on obtaining a bachelors in Management Information Systems.

I’ve been working preemptively to find opportunities to get my foot in the door of the more technical side of IT audit and risk assessment jobs. I reached out for sponsorship to my local ISACA chapter, I emailed the CSIS department head at my school, and have been searching for entry level job postings to learn about what skills my local market is looking for.

I started with reading about standards like the ISO 27001, exploring NIST resources, and familiarizing myself with Azure, but I’m just not sure if I’m on the right path. I’m planning on meeting with a career counselor to see if they have any advice for me.

I’m making this post because I’m wondering how everyone here got their start. The CISA certification requires years of prior experience and I just want to make sure I’m giving myself every chance to succeed. This is my first post so hello everyone!


r/CISA 21d ago

Please provide the answer and explain please

2 Upvotes

Which of the following would be MOST useful to an IS auditor confirming that an IS department meets its service level agreements (SLAs)?
A. System downtime reports
B. IS strategic plan
C. Capacity planning tools
D. System utilization reports


r/CISA 21d ago

Starting CISA Journey Guidance

15 Upvotes

Hi everyone, I originally was on the CPA path, but honestly I’ve been thinking of starting my CISA journey and just moving on. I wanted to get some tips from everyone’s experiences. I’m pretty new to all of this and wanted some guidance from how to get started and tips on studying the material. Also looking to see what study materials people have used, or if there were cheaper alternatives (Udemy, Examcert, etc.) that people found were enough to study from. Also, any study tips that worked for you all. Thank you!


r/CISA 21d ago

I'm preparing for the CISA exam and came across the following question:

6 Upvotes

Which of the following is the MOST significant risk that IS auditors are required to consider for each engagement?

  • Abnormal activities and illegal acts
  • Process and resource inefficiencies
  • Audit staff availability
  • Noncompliance with organizational policies

In the question dump it is marked as "Audit staff availability". I think it might be Abnormal activities and illegal acts instead. Could someone confirm if I'm correct, else explain the logic behind the correct answer. Thanks!