Everything needed to plan for the CISA (CISA) exam: number of questions, time limit, passing score, and the official domain weightings. For the study checklist itself, see the CISA study guide.
CISA (CISA) is a Professional level ISACA certification exam with about 150 questions in 240 minutes, requiring a scaled score of 450 to pass. It covers 5 official domains: Protection of Information Assets (25%); Information Systems Auditing Process (21%); Information Systems Operations and Business Resilience (20%); Information Systems Acquisition, Development and Implementation (18%); Governance and Management of IT (16%).
Exam code
CISA
Questions
~150
Time limit
240 min
Passing score
450
Official domains
5
Level
Professional
Provider
ISACA
Practice questions
300+ on CertStud
| Domain | Weight | What it covers |
|---|---|---|
| Protection of Information Assets | 25% | Provide assurance that the organization's information security policy, standards and controls protect information assets |
| Information Systems Auditing Process | 21% | Provide audit services in accordance with IT audit standards |
| Information Systems Operations and Business Resilience | 20% | Provide assurance that IT operations and business resilience processes support organizational objectives |
| Information Systems Acquisition, Development and Implementation | 18% | Provide assurance that systems acquisition, development and implementation practices meet organizational objectives |
| Governance and Management of IT | 16% | Provide assurance that the enterprise's IT governance and management support organizational strategies |
Percentages reflect published official domain weightings. Prerequisite knowledge and current scoring rules are confirmed on the ISACA exam page before booking.
The CISA exam has approximately 150 questions. Question counts can vary slightly between deliveries, so treat 150 as the planning figure rather than a fixed number.
Candidates get about 240 minutes to complete the CISA exam, which works out to roughly 2 minute(s) per question at 150 questions.
The CISA exam requires a scaled score of 450 to pass. Scores are reported on a scaled rather than a raw percentage basis, so a passing result does not correspond to a simple count of correct answers.
The CISA exam covers 5 official domains: Information Systems Auditing Process (21%), Governance and Management of IT (16%), Information Systems Acquisition, Development and Implementation (18%), Information Systems Operations and Business Resilience (20%), Protection of Information Assets (25%).
Protection of Information Assets carries the heaviest weighting on the CISA exam at 25% of the exam. Provide assurance that the organization's information security policy, standards and controls protect information assets
CISA is the exam code for CISA (CISA - Certified Information Systems Auditor), a Professional level ISACA certification exam covering 5 domains.
The CISA exam reports a scaled score of 450 on a scaled score. Plan for roughly 150 questions across 240 minutes, weighted by domain: 25% Protection of Information Assets, 21% Information Systems Auditing Process, 20% Information Systems Operations and Business Resilience, 18% Information Systems Acquisition, Development and Implementation, 16% Governance and Management of IT.
CertStud offers free CISA practice questions with detailed explanations, plus full-length practice exams and flashcards at https://certstud.com/certifications/isaca/cisa. Start with 10 free questions at https://certstud.com/try-free.