CISSP Certification Guide for Beginners
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue readingAn honest look at CISA exam difficulty: what the 450/800 scaled score really means, why ISACA publishes no pass rate, and what actually trips candidates up.

Short answer: the CISA exam is moderately hard, and hard in an unusual way. The 150 multiple-choice questions contain no labs, no essays and little deep technical content — yet experienced IT professionals fail it, because most questions offer several defensible answers and ask which one an auditor should pick first or which is best. Difficulty here is judgement and breadth, not raw technical depth, which is exactly why it catches confident candidates off guard.
This article deals only with the difficulty question: how the scoring works, what can and cannot be said about pass rates, what genuinely trips candidates up, and how the challenge compares for different backgrounds. If you are looking for study methods, our CISA exam preparation guide covers those; if you are weighing whether the effort is justified at all, that verdict lives in Is CISA Worth It?
You pass the Certified Information Systems Auditor (CISA) exam with a score of 450 or higher on ISACA's 200–800 scale. A common misreading is to treat 450/800 as a percentage — it is not. The scale is a scaled score: 200 is the floor, 800 means every question was answered correctly, and the conversion between raw correct answers and scaled points is not published. ISACA provides no percent-correct equivalent, so any claim that you need "about X%" to pass is unofficial guesswork, and you should ignore it when judging the exam's difficulty.
What scaled scoring does tell you is useful in a different way. Because results are equated across exam forms, difficulty is standardised: a candidate sitting a slightly harder set of questions needs slightly fewer correct answers for the same scaled result. You are competing against a calibrated standard, not against the luck of the question draw — and not against other candidates in the room.
Two practical scoring facts complete the picture. You see a preliminary pass/fail on screen the moment you finish, so there is no agonising wait for the verdict itself, and the official score follows within 10 working days. And the exam gives you four hours for 150 questions — roughly 96 seconds each — which most candidates find sufficient, meaning time pressure is a manageable part of the difficulty rather than a defining one.
There is no official CISA pass rate. ISACA does not publish pass rates for any of its certification exams, so every percentage you see quoted in forums, course marketing or blog posts is an estimate with no verifiable basis — and figures that precise deserve suspicion when the only organisation holding the data has never released it.
The honest way to gauge difficulty without a pass rate is indirect evidence. Three signals are worth weighing. First, ISACA rations attempts: candidates get a maximum of four tries within a rolling twelve-month period, with a 30-day wait after a first failure and 90-day waits after the second and third — a policy that would be pointless if failure were rare. Second, each retake costs the full registration fee (US$575 for members, US$760 for non-members, as of 2026), and the candidate community treats first-attempt passes as an achievement worth planning for rather than a formality. Third, the credential's experience requirement means the typical candidate is a working professional with years in IT or audit — and the exam is calibrated to stretch exactly that population, not newcomers.
The defining difficulty is the question format. A typical CISA question describes a scenario and asks what the auditor should do FIRST, which finding is the GREATEST concern, or which control BEST addresses a risk. Frequently two or three options are genuinely correct actions — just not the most correct one for an auditor at that moment. Candidates used to exams with one clean right answer find this disorienting: you are not recalling a fact, you are ranking defensible choices against ISACA's model of how an auditor thinks. Reading 150 of these dense scenarios also makes the exam a sustained comprehension exercise; misread one qualifier word and a question you "knew" is gone.
The exam expects you to answer as an independent auditor — one who gathers evidence, reports, recommends and escalates, but does not fix, implement or decide for management. Hands-on professionals lose marks precisely because they choose the sensible operational action (patch the system, reconfigure the control) when the "correct" answer is to assess impact or report the finding. In effect, the exam penalises the instincts that make people good at their day jobs, until they retrain those instincts.
The five domains stretch from audit process and IT governance through systems development to operations, resilience and security — 52% of the questions sit in the operations/resilience and information-protection domains alone. Almost nobody's career covers all of it, so every candidate faces at least one domain that is foreign territory. The breadth is why the exam feels harder in practice than "150 multiple-choice questions" suggests on paper.
Stamina is the quiet difficulty. Holding scenario-level concentration for four hours is a skill in itself, and unforced errors cluster in the final hour. It is a smaller factor than judgement and breadth, but it is the one candidates most often fail to rehearse.
Difficulty is relative to where you start. Three common profiles illustrate the spread:
Notice that no profile finds the whole exam easy. That asymmetry — everyone strong somewhere, exposed somewhere else — is the fairest one-line description of CISA's difficulty.
Against the Certified Information Systems Security Professional (CISSP), most professionals who hold both describe CISSP as the broader and heavier lift: its security body of knowledge spans more ground than CISA's audit-centred five domains. But "harder" depends on your bearings — an auditor may pass CISA comfortably and struggle with CISSP's security-management depth, while a security architect experiences the reverse, tripping over CISA's audit judgement questions. The exams measure different professions, so treat any absolute ranking with caution.
Within ISACA's own stable, the Certified Information Security Manager (CISM) exam shares CISA's format — 150 questions, four hours, 450 to pass — and its difficulty likewise turns on judgement questions, though from a security-management seat; the fuller comparison of the two credentials is drawn in CISA vs CISM, and CISM's difficulty gets its own treatment in How Hard Is the CISM Exam?
Failure patterns are consistent enough to list. Candidates fail because they:
A useful self-test before you commit: read a handful of genuine-style CISA practice questions — ExamPractice's free samples let you reveal each answer as you go — and observe not whether you get them right, but whether you can see why the best answer beats the merely correct ones. If that distinction is visible to you, CISA's difficulty is very manageable; if every option looks equal, you now know precisely the skill your preparation must build.
If the worst happens, a failed attempt is a delay rather than a disaster — the 30-day wait and diagnostic rework are covered in the CISA Retake Preparation Guide.
450 on a scaled range of 200–800. The scale is not a percentage and ISACA publishes no percent-correct equivalent, so "how many questions can I miss" has no official answer.
Yes — a preliminary pass/fail result appears on screen when you finish, with the official score released within 10 working days.
Harder in a specific way: the content can be learned from materials, but the auditor's decision-making style the questions reward takes deliberate practice to absorb. Candidates without audit exposure should expect the judgement questions, not the technical ones, to be their main hurdle. Note that experience is only required for certification after passing — anyone may sit the exam.
Four attempts within a rolling twelve-month period: a 30-day wait after the first attempt, then 90 days after the second and third, at the full registration fee each time.
CISA sits in the demanding-but-predictable band of professional exams. It is hard because it examines judgement across five broad domains in a question style that punishes both inexperience and the wrong kind of experience — not because it hides obscure content or impossible time limits. The scoring is transparent in structure (450 on a 200–800 scale) even if pass rates are not published, the failure modes are well documented, and every one of them is trainable. Respect the exam enough to prepare for its style, not just its syllabus, and its difficulty becomes a planning problem rather than a gamble. For what that preparation should look like in practice, start with the CISA exam preparation guide.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·11 min read
A plain-English beginner's guide to CISSP — the eight domains, CAT exam format, experience rules, costs and the exact process from booking to endorsement.
Continue reading·9 min read
A practical CISSP exam preparation guide covering the managerial mindset, how to choose study materials, and how to use practice tests to measure readiness.
Continue reading·7 min read
What actually makes the CISSP exam hard — breadth, adaptive testing and managerial judgement — who struggles most, and how it compares with SSCP and CCSP.
Continue reading