7 min read

Understanding ISACA CISA Scoring

Learn how the CISA exam is scored and what you need to pass. Understand ISACA scoring methodology for better exam preparation.

CISAPractice|

How the CISA Exam Is Scored

Understanding how ISACA scores the CISA exam can help you prepare more effectively and manage expectations on exam day. The scoring methodology is designed to ensure fairness across different exam versions and testing dates.

Scaled Scoring

The CISA exam uses a scaled scoring system rather than a simple percentage:

  • Score range: Scores range from 200 to 800 on the scaled score.
  • Passing score: A scaled score of 450 is required to pass the exam.
  • Scaling purpose: The scaled score accounts for slight differences in difficulty across exam versions. A question that appears on a harder version of the exam may contribute differently to your score than the same question on an easier version.

What the Scaled Score Means

The scaled score is not a direct percentage of questions answered correctly. Instead, it represents your performance relative to the exam's difficulty level. A score of 450 indicates that you have demonstrated the minimum competency required to perform IS audit work. Scores significantly above 450 indicate stronger mastery of the material.

Exam Structure

The CISA exam consists of 150 questions to be completed in four hours:

  • Question format: All questions are multiple choice with four answer options.
  • No penalty for guessing: There is no negative scoring for incorrect answers, so you should answer every question even if you are unsure.
  • Pretest questions: Some questions are pretest items that are being evaluated for future exams. These do not count toward your score, but you cannot identify which questions are pretest items, so treat every question as if it counts.

Domain Weighting

The exam covers five domains, each weighted differently:

  • Domain 1: Information System Auditing Process: This domain covers the audit planning, execution, and reporting process.
  • Domain 2: Governance and Management of IT: This domain addresses IT governance structures, policies, and management practices.
  • Domain 3: Information Systems Acquisition, Development, and Implementation: This domain covers the SDLC, project management, and system implementation.
  • Domain 4: Information Systems Operations and Business Resilience: This domain addresses IT operations, service management, and business continuity.
  • Domain 5: Protection of Information Assets: This domain covers information security, access controls, and data protection.

Each domain contributes a specific percentage to the overall score. Domains with higher weights have more questions and a greater impact on your final score.

Receiving Your Results

ISACA typically provides preliminary pass or fail results on the screen immediately after you complete the exam. Official scores are sent via email within approximately ten business days. If you do not pass, the score report identifies your performance by domain, helping you focus your preparation for a retake.

Preparing Based on Scoring

Understanding the scoring system suggests several study strategies: focus preparation time proportionally to domain weights, ensure competency across all domains rather than relying on exceptional performance in one area, answer every question since there is no penalty for guessing, and practice pacing to ensure you complete all 150 questions within the time limit.

Related Tags

CISA ExamISACAExam ScoringCertification

Ready to practice?

Put this knowledge to work with scenario-based practice questions.

Start Free