← All Cheat Sheets
CISA Exam Format Guide
Question count, time limit, scoring, domain weights, and pass criteria.
CISA Exam Format Guide
Everything you need to know about the CISA exam structure, scoring, and logistics before test day.
Exam Overview
| Detail | Value |
|---|---|
| Total Questions | 150 multiple-choice questions |
| Scored Questions | 150 (no unscored/pretest items currently disclosed) |
| Time Limit | 4 hours (240 minutes) |
| Time per Question | ~1.6 minutes (96 seconds) |
| Question Format | Four answer choices, one best answer |
| Passing Score | 450 on a scale of 200 to 800 |
| Scoring Method | Scaled scoring (not a simple percentage) |
| Penalty for Guessing | None (answer every question) |
| Delivery | Computer-based at PSI testing centers or remote proctored |
| Languages | English, Japanese, Chinese (Simplified), Spanish, and others |
Domain Weights
| Domain | Topic | Weight | Approx. Questions |
|---|---|---|---|
| 1 | Information Systems Auditing Process | 21% | ~31 |
| 2 | Governance and Management of IT | 17% | ~26 |
| 3 | Information Systems Acquisition, Development, and Implementation | 12% | ~18 |
| 4 | Information Systems Operations and Business Resilience | 23% | ~35 |
| 5 | Protection of Information Assets | 27% | ~40 |
Scoring Details
- ISACA uses scaled scoring, not raw percentage
- The passing score of 450 roughly corresponds to answering about 60-65% correctly
- Questions are weighted differently based on difficulty
- There is no penalty for wrong answers, so never leave a question blank
- Results are available within 10 business days
Test Day Tips
- Pace yourself: flag difficult questions and return to them
- Look for the "best" answer, not just a correct one
- Think like an IS auditor, not a technician or manager
- When two answers seem correct, choose the one that addresses risk first
- Read all four options before selecting your answer
- Eliminate obviously wrong answers to improve your odds
Certification Requirements
- Pass the exam with a score of 450 or higher
- 5 years of professional IS auditing, control, or security experience (substitutions available)
- Agree to the Code of Professional Ethics
- Agree to the Continuing Professional Education (CPE) policy
- Apply for certification within 5 years of passing the exam
Ready to test your knowledge?
Put this cheat sheet to work with scenario-based CISA practice questions.
Start Free