Exampractice
Cybersecurity

CISA Exam Preparation Guide

How to prepare for the CISA exam: choosing between the Review Manual, QAE database and courses, domain-by-domain tactics, and answering like an auditor.

Alexander Novak · 10 min read
Overhead view of a study desk with a review manual, laptop question bank and colour-coded notes for the five CISA domains.

Effective CISA preparation comes down to three decisions: which materials you build your study around, how you divide effort across five unevenly weighted domains, and how early you start practising the exam's distinctive "what should the auditor do FIRST?" question style. Get those three right and the rest is consistency. This guide works through each in turn, assuming you already know what the Certified Information Systems Auditor (CISA) credential is and have a rough exam date in mind — if you need the full picture of domains, eligibility and costs first, start with our CISA certification guide.

One framing note before the detail. The CISA exam is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 to pass, and its current content is the 2024 job practice that took effect on 1 August 2024. That last fact drives your very first preparation decision: your materials must match the 2024 outline. Older editions cover the same domain names but the weightings changed, and ISACA's aligned resources — the CISA Review Manual, 28th Edition; the CISA Online Review Course 2024; and the QAE Database 2024 — are the versions built for the current exam.

Choose your core study materials first

Every successful CISA campaign is anchored to one primary content source plus one question bank. Adding more materials rarely adds more marks; it usually adds confusion, because different sources phrase the same control concepts differently. Here is how the main options compare:

ResourceWhat it isBest suited to
CISA Review Manual, 28th EditionISACA's official textbook for the 2024 outlineReaders who want the authoritative reference and can tolerate dense prose
CISA Online Review Course 2024ISACA's official self-paced coursePeople who learn better from structured lessons than from a manual
CISA QAE Database 2024ISACA's official questions, answers and explanations bankEvery candidate — practice questions are non-negotiable
Third-party books and video coursesIndependent summaries and lecturesSupplementing weak areas; a gentler first pass before the manual

The CISA Review Manual: read it like an auditor, not a novelist

The Review Manual is comprehensive and, candidly, dry. The mistake most candidates make is attempting a cover-to-cover close reading from day one. A better sequence: skim a chapter first for structure and headings, then do a block of practice questions on that domain, then return to the manual and read properly the sections your wrong answers exposed. The manual becomes dramatically more useful once questions have shown you what ISACA actually asks about, and this loop stops you spending three weeks perfecting the smallest domain.

Pay particular attention to the manual's emphasis on why controls exist and who is responsible for what. CISA questions rarely reward memorised definitions; they reward knowing that, say, management owns risk acceptance while the auditor reports and recommends. Whenever the manual describes a process, ask yourself two auditor questions: what could go wrong here, and what evidence would prove the control works? That habit converts passive reading into exam-relevant thinking.

Question banks: your single highest-value resource

Practice questions do two jobs: they teach you the question style, and they generate the data that tells you where to focus. ISACA's QAE Database 2024 is the closest match to official phrasing. Whatever bank you use, the working method matters more than the source: answer in small timed blocks, read the explanation for every question — including the ones you got right — and log which domain each miss belongs to. The explanations are where the learning happens; the score is just a by-product.

ExamPractice offers free sample CISA questions you can use to calibrate the question style before spending anything, with fuller sets and a timed simulation mode available to subscribers. How to sequence full-length mock exams, what scores to look for and how to mine wrong answers systematically is a discipline of its own — covered in depth in CISA Practice Test Strategy, so this guide will not duplicate it.

What about courses and bootcamps?

ISACA's Online Review Course and third-party courses suit candidates who struggle to self-direct through a 1,000-page manual. Treat any course as a guided tour of the content, not a substitute for question practice — no lecture can teach you the judgement calls that decide marks on this exam. If your employer funds training, a course plus the QAE database is a defensible combination; if you are self-funding, the manual plus a good question bank covers the same ground for less.

Domain-by-domain preparation tactics

The five domains are not equal, and neither is the preparation each one deserves. Weightings under the 2024 outline: Domain 1, Information Systems Auditing Process (18%); Domain 2, Governance and Management of IT (18%); Domain 3, Information Systems Acquisition, Development and Implementation (12%); Domain 4, Information Systems Operations and Business Resilience (26%); Domain 5, Protection of Information Assets (26%). A full topic-level breakdown of what each domain contains lives in CISA Exam Domains Explained; what follows is how to study each one.

Domain 1 — learn the audit process as a sequence

Domain 1 is the grammar of the whole exam: planning, evidence, sampling, reporting, follow-up. Study it first even though it is not the largest, because every other domain's questions are framed through an auditor's eyes. The tactic that works is learning the audit lifecycle as an ordered sequence and drilling order-sensitive questions — CISA loves asking what comes first, what to do next, and to whom findings are reported. Flashcards help less here than repeatedly walking the process end to end.

Domain 2 — think in responsibilities, not definitions

Governance questions turn on who does what: board versus senior management versus IT management versus audit. When you study frameworks, policies and organisational structures, build yourself a responsibility map rather than memorising framework contents. A typical trap answer assigns an oversight task to the people doing the work, or an operational task to the board. If you can catch that swap reliably, Domain 2 becomes one of the friendlier domains.

Domain 3 — smallest weight, so timebox it

At 12%, Domain 3 (systems acquisition, development and implementation) punishes over-investment. Candidates from development backgrounds often over-study it because it feels familiar; candidates from pure audit backgrounds fear it and sink weeks into SDLC minutiae. Timebox it. Concentrate on project governance, testing phases, conversion/migration approaches and post-implementation review — the recurring question territories — and accept that a rarely tested corner of this domain is a poor trade for time against Domains 4 and 5.

Domains 4 and 5 — over half the exam lives here

Operations, resilience and information asset protection together carry 52% of the questions, so they deserve the majority of your content study. For Domain 4, prioritise incident and problem management distinctions, backup and recovery arrangements, and business continuity/disaster recovery concepts — and practise questions that hinge on recovery objectives, because they recur. For Domain 5, technical candidates should resist skimming: the exam tests controls and their audit implications, not hands-on security skills, so a network engineer still needs to learn how an auditor evaluates access management, encryption use and security monitoring. Non-technical candidates should build a plain-English mental model of each control family before touching practice questions, or the distractors will all look plausible.

Train the exam technique, not just the content

CISA is famous for questions where every option is technically true. The examiners are testing judgement: which answer is most correct for an auditor in that scenario. Three techniques, practised deliberately, raise accuracy on these:

  1. Find the operative word. BEST, FIRST, MOST likely, PRIMARY, GREATEST concern — the capitalised qualifier is the actual question. Two answers usually survive elimination; the qualifier picks between them.
  2. Answer as the auditor ISACA describes, not as yourself. The exam's ideal auditor is independent, evidence-driven, and escalates rather than fixes. If an option has the auditor implementing a control, remediating an issue or making a management decision, it is almost always wrong regardless of how sensible it sounds in real life.
  3. Eliminate by role and by scope. Wrong answers are commonly wrong because the actor is wrong (management's job, not audit's) or the scope is wrong (a detailed fix when the question asks about planning, or vice versa). Practise articulating why each rejected option fails — in writing at first — until the elimination is automatic.

Time pressure, by contrast, is rarely the villain: four hours for 150 questions is around 96 seconds each, and most prepared candidates finish with time to spare. Build stamina with at least a couple of full-length timed sittings before exam day so that hour four feels normal, and rehearse a flag-and-return rule — spend no more than two minutes on any question in the first pass. The mechanics of exam day itself, from ID checks to break rules, are collected in the CISA Exam Day Checklist.

Common preparation mistakes to avoid

  • Studying to the old weightings. Materials predating the 1 August 2024 outline overweight Domain 1 and underweight Domain 4. Check editions before buying second-hand.
  • Reading without questioning. Weeks of manual reading with no practice questions produces confident candidates who score poorly. Interleave from week one.
  • Memorising answers instead of reasoning. Cycling a question bank until you recognise the answers destroys its diagnostic value and teaches nothing transferable. If your bank scores rise but new-question accuracy does not, this is why — a practice test is a study aid for testing understanding of the exam objectives, not a script to learn.
  • Answering from personal experience. "That's not how we do it at my company" is the most expensive sentence in CISA preparation. The exam rewards ISACA's model answer, which lives in the Review Manual, not in your organisation's practices.
  • Ignoring explanations for correct answers. A right answer reached by luck is a wrong answer waiting for exam day. Read every explanation.
  • Treating all domains equally. Equal time across five domains means over-preparing 12% of the exam and under-preparing 52% of it.

A readiness checklist before you sit

You are ready to take the exam when you can honestly tick all of these:

  • Consistently comfortable across timed question blocks in all five domains, with no domain persistently dragging — and you have confirmed this on questions you have never seen before, not recycled ones.
  • You have completed at least one, preferably two, full-length four-hour timed simulations and held concentration to the end.
  • You can explain the audit lifecycle from planning to follow-up without notes, and state who owns risk acceptance, control implementation and reporting.
  • Qualifier-word questions (BEST/FIRST/MOST) no longer feel like coin-flips — you can verbalise the elimination.
  • Your wrong answers now cluster around genuinely obscure content rather than misread questions or role confusion.

If several boxes are unticked with your exam date close, remember that ISACA lets you reschedule free of charge up to 48 hours before your appointment within your six-month eligibility period — moving a booking is cheaper than a retake at the full registration fee. And if a first attempt has already gone against you, the recovery route is different from first-time preparation: see the CISA Retake Preparation Guide.

This guide has deliberately not told you when to study what. How many weeks or months you need depends on your background and hours available — realistic estimates are in How Long Does CISA Preparation Take? — and if you want the tactics above arranged into a calendar, there are ready-made schedules for beginners and for working professionals.

Frequently asked questions

Is the CISA Review Manual enough on its own?

No. The manual covers the content, but the exam tests judgement under the question format, which only practice questions build. The reverse is also true — a question bank alone leaves gaps the explanations do not fill. Plan on one content source plus one question bank as the minimum viable stack.

Do I need the official ISACA materials, or are third-party ones acceptable?

The official materials are the safest match for the 2024 outline, and the QAE database mirrors official phrasing most closely. Good third-party materials can substitute for the manual or course if they explicitly cover the 2024 job practice — verify that before buying, since older-outline materials are still widely sold.

Should I study the domains in exam order?

Start with Domain 1 regardless, because the audit process frames everything else. After that, order matters less than allocation: give Domains 4 and 5 the largest share of your remaining time, and timebox Domain 3.

How many practice questions should I get through?

There is no official number, and quality of review beats quantity of questions. A useful rule: you have done enough when new, unseen questions in every domain feel routine — if you are still surprised by question styles, do more; if you are recognising recycled answers, change source rather than continuing.

Preparing like the exam is written

The CISA exam is written by auditors, about judgement, in a fixed format — so preparation that mirrors those three facts wins. Anchor your study to 2024-outline materials, let practice-question data steer your reading rather than the other way round, weight your effort towards the 52% of the exam sitting in Domains 4 and 5, and drill the qualifier-word technique until choosing "what the auditor does FIRST" is reflex. When your unseen-question accuracy is solid across all five domains and a full four-hour simulation no longer intimidates you, book with confidence — a timed practice-test simulation is a sensible final benchmark before you commit to the date.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like