CISA Exam Course Guide

CISA Exam Guide 2026: The Complete IS Audit Playbook

Master the Certified Information Systems Auditor exam — 5 domains, ISACA Job Practice 2024, and every deep-dive.

Quick answer: The Certified Information Systems Auditor (CISA) exam covers 5 domains under the 2024 Job Practice: IS Audit Process, Governance, Systems Acquisition, IT Operations, and Protection of Information Assets. This hub organizes every CISA resource.

Key facts

Passing score:
450 on a 200-800 scale
Structure:
150 MCQ across 5 domains
Total time:
4 hours
Domain weights (2024):
D1 18%, D2 18%, D3 12%, D4 26%, D5 26%
Official body:
ISACA

Overview

The CISA exam punishes technical experts who forget their role. It’s not a test of what you can do, but how you think as an auditor—evaluating risk, assessing controls, and providing assurance. Your biggest challenge isn't memorizing frameworks, but internalizing the specific, risk-based judgment ISACA expects on every single question.

What Makes the CISA Exam So Deceptive?

The CISA exam is designed to filter for a very specific perspective: the independent auditor's mindset. Many candidates, especially those with hands-on IT or security experience, fail because they answer questions from the perspective of a system administrator or a security analyst. They see a problem and their instinct is to choose the answer that fixes it. This is a trap.

The exam is not testing your ability to configure a firewall; it's testing your ability to determine if the firewall change management process is adequate, documented, and followed.

You'll face 150 situational questions where multiple answers seem technically correct. The key is to find the answer that reflects the auditor's primary duty. An auditor doesn't implement solutions. An auditor:

  • Assesses risk.
  • Evaluates the effectiveness of controls.
  • Gathers evidence.
  • Reports findings to management.
  • Recommends improvements to processes.

Your technical knowledge is the foundation, but the "ISACA way of thinking" is the lens through which you must view every scenario. If an answer involves taking direct operational action, it is almost certainly wrong.

Where to Focus Your First 40 Hours

With five domains and a vast body of knowledge, a smart initial plan is critical. While it's tempting to jump into the two largest domains, that approach skips the foundational mindset. Based on the 2024 Job Practice weights, here is how you should structure your first full week of study (approx. 40 hours) for maximum impact.

  1. Hours 1-10: Master Domain 1 (The IS Audit Process). This domain, at 18% of the exam, is your Rosetta Stone. It teaches you the language and lifecycle of an audit—from planning and evidence gathering to reporting and follow-up. Every single question in the other four domains assumes you understand the auditor's process and mandate. Mastering this first gives you the framework to correctly analyze questions in every other section.
  1. Hours 11-40: Deep Dive into Domains 4 & 5 (IT Operations & Protection of Information Assets). Combined, these two domains make up 52% of your total score. This is where the bulk of the technical concepts live—from network infrastructure and disaster recovery (D4) to encryption and identity management (D5). After building your auditor mindset in Domain 1, immediately apply it to these high-value areas. You need to be able to analyze a BCP test result or an access control list not as an engineer, but as an auditor evaluating its effectiveness against stated policy.

By front-loading your study this way, you build the correct analytical framework first, then apply it immediately to the majority of the exam's content. Domains 2 (Governance) and 3 (Systems Acquisition) can then be layered on top of this strong foundation.

The Practitioner-vs-Auditor Mindset Trap

The single biggest failure point on the CISA exam is answering questions as a hands-on practitioner. You must train yourself to pause and shift your perspective before selecting an answer. Your real-world experience is valuable, but it can also be a liability if you don't filter it through the auditor's lens.

Burn this table into your memory. For every question you practice, identify which column the potential answers fall into.

Practitioner's Instinct (Usually the WRONG Answer)Auditor's Mindset (Usually the RIGHT Answer)
"Fix the immediate technical problem.""Assess the root cause of the control failure."
"Implement a new security tool.""Determine if the current process is effective."
"Reconfigure the system for compliance.""Gather evidence to report on non-compliance."
"This configuration is insecure.""This configuration deviates from policy and increases risk."
Focus on the technology.Focus on the process, governance, and risk.

Before you finalize your answer on the exam, ask yourself one final question: "Does this action involve doing the work, or does it involve evaluating the work?" The CISA credential is for evaluators. Choose the answer that reflects that role, every time.

Study by section

Every guide in this cluster (26)

Every published article that belongs to this cluster, organized by type. New content is added continuously.

Study Guides (6)

Cheat Sheets (5)

Study Schedules (1)

Case Studies (1)

Salary Guides (1)

Course Reviews & Comparisons (3)

Exam News (1)

Comparison (1)

Pass Rates (1)

Exam Tips (1)

Topic Explainer (2)

Study Guide Section (2)

Free Practice (1)