CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingHow to prepare for the CISA exam: choosing between the Review Manual, QAE database and courses, domain-by-domain tactics, and answering like an auditor.

Effective CISA preparation comes down to three decisions: which materials you build your study around, how you divide effort across five unevenly weighted domains, and how early you start practising the exam's distinctive "what should the auditor do FIRST?" question style. Get those three right and the rest is consistency. This guide works through each in turn, assuming you already know what the Certified Information Systems Auditor (CISA) credential is and have a rough exam date in mind — if you need the full picture of domains, eligibility and costs first, start with our CISA certification guide.
One framing note before the detail. The CISA exam is 150 multiple-choice questions in four hours, scored on a 200–800 scale with 450 to pass, and its current content is the 2024 job practice that took effect on 1 August 2024. That last fact drives your very first preparation decision: your materials must match the 2024 outline. Older editions cover the same domain names but the weightings changed, and ISACA's aligned resources — the CISA Review Manual, 28th Edition; the CISA Online Review Course 2024; and the QAE Database 2024 — are the versions built for the current exam.
Every successful CISA campaign is anchored to one primary content source plus one question bank. Adding more materials rarely adds more marks; it usually adds confusion, because different sources phrase the same control concepts differently. Here is how the main options compare:
| Resource | What it is | Best suited to |
|---|---|---|
| CISA Review Manual, 28th Edition | ISACA's official textbook for the 2024 outline | Readers who want the authoritative reference and can tolerate dense prose |
| CISA Online Review Course 2024 | ISACA's official self-paced course | People who learn better from structured lessons than from a manual |
| CISA QAE Database 2024 | ISACA's official questions, answers and explanations bank | Every candidate — practice questions are non-negotiable |
| Third-party books and video courses | Independent summaries and lectures | Supplementing weak areas; a gentler first pass before the manual |
The Review Manual is comprehensive and, candidly, dry. The mistake most candidates make is attempting a cover-to-cover close reading from day one. A better sequence: skim a chapter first for structure and headings, then do a block of practice questions on that domain, then return to the manual and read properly the sections your wrong answers exposed. The manual becomes dramatically more useful once questions have shown you what ISACA actually asks about, and this loop stops you spending three weeks perfecting the smallest domain.
Pay particular attention to the manual's emphasis on why controls exist and who is responsible for what. CISA questions rarely reward memorised definitions; they reward knowing that, say, management owns risk acceptance while the auditor reports and recommends. Whenever the manual describes a process, ask yourself two auditor questions: what could go wrong here, and what evidence would prove the control works? That habit converts passive reading into exam-relevant thinking.
Practice questions do two jobs: they teach you the question style, and they generate the data that tells you where to focus. ISACA's QAE Database 2024 is the closest match to official phrasing. Whatever bank you use, the working method matters more than the source: answer in small timed blocks, read the explanation for every question — including the ones you got right — and log which domain each miss belongs to. The explanations are where the learning happens; the score is just a by-product.
ExamPractice offers free sample CISA questions you can use to calibrate the question style before spending anything, with fuller sets and a timed simulation mode available to subscribers. How to sequence full-length mock exams, what scores to look for and how to mine wrong answers systematically is a discipline of its own — covered in depth in CISA Practice Test Strategy, so this guide will not duplicate it.
ISACA's Online Review Course and third-party courses suit candidates who struggle to self-direct through a 1,000-page manual. Treat any course as a guided tour of the content, not a substitute for question practice — no lecture can teach you the judgement calls that decide marks on this exam. If your employer funds training, a course plus the QAE database is a defensible combination; if you are self-funding, the manual plus a good question bank covers the same ground for less.
The five domains are not equal, and neither is the preparation each one deserves. Weightings under the 2024 outline: Domain 1, Information Systems Auditing Process (18%); Domain 2, Governance and Management of IT (18%); Domain 3, Information Systems Acquisition, Development and Implementation (12%); Domain 4, Information Systems Operations and Business Resilience (26%); Domain 5, Protection of Information Assets (26%). A full topic-level breakdown of what each domain contains lives in CISA Exam Domains Explained; what follows is how to study each one.
Domain 1 is the grammar of the whole exam: planning, evidence, sampling, reporting, follow-up. Study it first even though it is not the largest, because every other domain's questions are framed through an auditor's eyes. The tactic that works is learning the audit lifecycle as an ordered sequence and drilling order-sensitive questions — CISA loves asking what comes first, what to do next, and to whom findings are reported. Flashcards help less here than repeatedly walking the process end to end.
Governance questions turn on who does what: board versus senior management versus IT management versus audit. When you study frameworks, policies and organisational structures, build yourself a responsibility map rather than memorising framework contents. A typical trap answer assigns an oversight task to the people doing the work, or an operational task to the board. If you can catch that swap reliably, Domain 2 becomes one of the friendlier domains.
At 12%, Domain 3 (systems acquisition, development and implementation) punishes over-investment. Candidates from development backgrounds often over-study it because it feels familiar; candidates from pure audit backgrounds fear it and sink weeks into SDLC minutiae. Timebox it. Concentrate on project governance, testing phases, conversion/migration approaches and post-implementation review — the recurring question territories — and accept that a rarely tested corner of this domain is a poor trade for time against Domains 4 and 5.
Operations, resilience and information asset protection together carry 52% of the questions, so they deserve the majority of your content study. For Domain 4, prioritise incident and problem management distinctions, backup and recovery arrangements, and business continuity/disaster recovery concepts — and practise questions that hinge on recovery objectives, because they recur. For Domain 5, technical candidates should resist skimming: the exam tests controls and their audit implications, not hands-on security skills, so a network engineer still needs to learn how an auditor evaluates access management, encryption use and security monitoring. Non-technical candidates should build a plain-English mental model of each control family before touching practice questions, or the distractors will all look plausible.
CISA is famous for questions where every option is technically true. The examiners are testing judgement: which answer is most correct for an auditor in that scenario. Three techniques, practised deliberately, raise accuracy on these:
Time pressure, by contrast, is rarely the villain: four hours for 150 questions is around 96 seconds each, and most prepared candidates finish with time to spare. Build stamina with at least a couple of full-length timed sittings before exam day so that hour four feels normal, and rehearse a flag-and-return rule — spend no more than two minutes on any question in the first pass. The mechanics of exam day itself, from ID checks to break rules, are collected in the CISA Exam Day Checklist.
You are ready to take the exam when you can honestly tick all of these:
If several boxes are unticked with your exam date close, remember that ISACA lets you reschedule free of charge up to 48 hours before your appointment within your six-month eligibility period — moving a booking is cheaper than a retake at the full registration fee. And if a first attempt has already gone against you, the recovery route is different from first-time preparation: see the CISA Retake Preparation Guide.
This guide has deliberately not told you when to study what. How many weeks or months you need depends on your background and hours available — realistic estimates are in How Long Does CISA Preparation Take? — and if you want the tactics above arranged into a calendar, there are ready-made schedules for beginners and for working professionals.
No. The manual covers the content, but the exam tests judgement under the question format, which only practice questions build. The reverse is also true — a question bank alone leaves gaps the explanations do not fill. Plan on one content source plus one question bank as the minimum viable stack.
The official materials are the safest match for the 2024 outline, and the QAE database mirrors official phrasing most closely. Good third-party materials can substitute for the manual or course if they explicitly cover the 2024 job practice — verify that before buying, since older-outline materials are still widely sold.
Start with Domain 1 regardless, because the audit process frames everything else. After that, order matters less than allocation: give Domains 4 and 5 the largest share of your remaining time, and timebox Domain 3.
There is no official number, and quality of review beats quantity of questions. A useful rule: you have done enough when new, unseen questions in every domain feel routine — if you are still surprised by question styles, do more; if you are recognising recycled answers, change source rather than continuing.
The CISA exam is written by auditors, about judgement, in a fixed format — so preparation that mirrors those three facts wins. Anchor your study to 2024-outline materials, let practice-question data steer your reading rather than the other way round, weight your effort towards the 52% of the exam sitting in Domains 4 and 5, and drill the qualifier-word technique until choosing "what the auditor does FIRST" is reflex. When your unseen-question accuracy is solid across all five domains and a full four-hour simulation no longer intimidates you, book with confidence — a timed practice-test simulation is a sensible final benchmark before you commit to the date.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading