cisa scenario questionsEnglish9 min read

FIRST, BEST, GREATEST: Decoding CISA Qualifier Questions With Worked Examples

CISA questions hinge on qualifier words like FIRST, BEST, and GREATEST. Learn what each one demands, with worked examples and the auditor mindset behind them.

Marcus Chen
Marcus Chen
August 12, 20269 min readUpdated August 12, 2026

Most CISA questions have more than one answer that is technically correct, and the qualifier word in the question, FIRST, BEST, GREATEST, MOST, or PRIMARY, is what tells you which correct answer ISACA wants. The exam is 150 multiple-choice questions asking you to select the correct or best answer, per ISACA, and "best" is doing real work in that sentence. Miss the qualifier and you will pick a defensible answer that is still marked wrong. Read the qualifier deliberately and you can eliminate options that would otherwise look right. This guide explains what each qualifier demands and shows the reasoning on worked examples.

The candidates who struggle with CISA usually are not short on knowledge. They are answering the question they expected instead of the question on the screen, and the qualifier word is the part they skipped.

The qualifier word decides which correct answer is the credited one

Quick takeaways

  • CISA has 150 multiple-choice questions in four hours, and many ask for the best rather than the only correct answer, per ISACA.
  • Qualifier words (FIRST, BEST, GREATEST, MOST, PRIMARY) change which correct option is credited.
  • FIRST asks about sequence: what an auditor does before anything else.
  • BEST and MOST ask about effectiveness: the most effective control or action.
  • GREATEST asks about magnitude: the biggest risk or concern.
  • There is no penalty for wrong answers, so never leave a question blank, per ISACA. Practice qualifier reading on realistic questions with the PrepClubs CISA pack: one-time, 30-day access, 30-day Pass Guarantee.

Why CISA questions have more than one right answer

CISA is written to test judgment, not recall. That means questions are built so that two, three, or even all four options are plausible actions an information systems auditor might take. The exam is not asking whether an option is valid. It is asking which option is the most appropriate given the specific qualifier. This is why memorizing facts is necessary but not sufficient: you can know every fact in the option list and still choose the wrong one if you misread what the question is asking you to rank.

ISACA's own framing is "select the correct or best answer," per ISACA. When the correct answer and the best answer differ, the qualifier is your instruction for which one to give.

The qualifier words, decoded

Here is what each common qualifier is actually asking, in auditor terms.

Qualifier What it asks How to answer
FIRST Sequence and priority The action that should happen before the others
BEST / MOST Effectiveness The most effective control or response
GREATEST Magnitude The largest risk, concern, or exposure
PRIMARY Main purpose or driver The chief reason or the main objective
MOST LIKELY Probability The most probable cause or outcome

Read the qualifier before you read the options. It reframes the entire option list. The same four options can have different correct answers depending on whether the stem says FIRST or BEST.

CISA qualifier words FIRST BEST GREATEST PRIMARY and MOST LIKELY decoded for the exam

FIRST: sequence beats everything

When a question asks what an auditor should do FIRST, it is testing whether you understand the order of the audit process. The trap is an option that is a genuinely good action but is out of sequence. Assessing, planning, and understanding almost always come before acting.

Worked example. An auditor is assigned to review a new payroll system that just went live. What should the auditor do FIRST?

  • A. Test the payroll calculations for accuracy.
  • B. Interview the payroll staff about the process.
  • C. Understand the business process and its risks.
  • D. Review the access controls on the system.

All four are things an auditor legitimately does. But FIRST asks for sequence, and you cannot meaningfully test, interview, or review controls until you understand the process and where its risks are. The credited answer is C. Options A, B, and D are correct actions in the wrong position. The qualifier, not the content, is what eliminates them.

BEST and MOST: effectiveness beats plausibility

BEST and MOST ask which option is the most effective, not merely which ones would help. Several options may reduce a risk. Only one reduces it most.

Worked example. Which control is BEST for preventing unauthorized changes to production code?

  • A. Requiring a code review before deployment.
  • B. Logging all changes to production.
  • C. Separating the developer and deployment roles.
  • D. Running periodic access reviews.

Logging (B) and access reviews (D) detect problems after the fact. Code review (A) helps but relies on a person catching the issue. Separation of duties (C) structurally prevents a single person from both writing and deploying code, which is the most effective preventive control. The credited answer is C because BEST is asking for the strongest control, and a preventive, structural control beats a detective or discretionary one.

GREATEST: magnitude beats frequency

GREATEST asks about size of impact or risk. The trap here is an option describing something common but minor, next to an option describing something rare but severe. GREATEST wants the biggest concern, not the most frequent one.

Worked example. Which of the following presents the GREATEST risk to the confidentiality of customer data?

  • A. Employees occasionally forgetting to lock their screens.
  • B. An unencrypted database of customer records accessible over the internet.
  • C. A weak password policy for internal applications.
  • D. Infrequent security awareness training.

All four are real weaknesses. But GREATEST asks for magnitude, and an unencrypted, internet-accessible database of customer records (B) is a catastrophic, direct exposure, while the others are contributing weaknesses. The credited answer is B. The qualifier tells you to rank by severity, so the single largest exposure wins over the more common but smaller issues.

The auditor mindset underneath all of them

There is one habit that makes qualifier questions easier across the board: answer as an auditor, not as the engineer who would fix the problem. When a stem describes a control failure, the tempting options are the ones that fix it. The auditor's job is often to evaluate, report, and recommend, not to implement. So when two options are "fix it now" and "assess and report," the qualifier plus the auditor role usually points to the assess-and-report option, especially for FIRST and BEST questions. Keep asking yourself: what does an auditor do here, act, or observe and advise?

A practical reading routine

Bring this routine to every question:

  1. Read the stem and underline the qualifier word before looking at the options.
  2. Restate what the qualifier is asking for: sequence, effectiveness, magnitude, or purpose.
  3. Read all four options fully. Do not stop at the first one that looks right.
  4. Eliminate options that are correct but do not match the qualifier.
  5. If two remain, ask which the auditor role favors, and remember there is no penalty for guessing, so always answer, per ISACA.

Real example: the same options, two qualifiers

Take a stem about an organization that has just suffered a data breach, with these options: contain the incident, notify affected customers, investigate the root cause, and review the incident response plan. If the qualifier is FIRST, the credited answer leans toward containment, because sequence demands you stop the bleeding before anything else. If the qualifier is BEST for preventing a recurrence, the credited answer shifts toward reviewing and improving the incident response plan, because that is the most effective forward-looking control. Same four options, two different credited answers, decided entirely by the qualifier. Training your eye to catch that word is worth more points than another pass through the review manual.

FAQ

How many questions are on the CISA exam?

CISA has 150 multiple-choice questions, and you have four hours to complete them, per ISACA. The exam is scored on a scale of 200 to 800, with 450 required to pass.

What does BEST mean in a CISA question?

BEST asks for the most effective option, not merely a correct one. Several options may be valid actions or controls; the credited answer is the one that addresses the issue most effectively, which often means a preventive or structural control over a detective or discretionary one.

Why do CISA questions have more than one correct answer?

Because CISA tests judgment. Questions are written so that multiple options are plausible, and the qualifier word (FIRST, BEST, GREATEST, MOST, PRIMARY) tells you which correct answer ISACA wants. This is why reading the qualifier carefully matters as much as knowing the content.

Is there a penalty for wrong answers on CISA?

No. There is no penalty for incorrect answers, so you should never leave a question blank, per ISACA. If you are unsure, eliminate what you can and make your best choice.

How do I answer FIRST questions on CISA?

FIRST asks about sequence. The credited answer is the action that should come before the others in the audit process, which usually means understanding, assessing, or planning before testing or acting. Watch for good actions placed out of order; they are the common trap.

What is the auditor mindset for CISA questions?

It is the habit of answering as an information systems auditor who evaluates, reports, and recommends, rather than as an engineer who implements fixes. When options split between acting and assessing, the auditor role and the qualifier usually favor the assess-and-report choice.

Note: PrepClubs is an independent practice-test provider and is not affiliated with, endorsed by, or sponsored by ISACA. CISA is a trademark of ISACA. The worked examples above are original illustrations written to demonstrate qualifier reading and are not reproduced from any live exam. Exam format and scoring are set by ISACA and cited to ISACA's official pages; confirm current details with ISACA.

FAQ

Common questions

How many questions are on the CISA exam?

CISA has 150 multiple-choice questions, and you have four hours to complete them, per ISACA. The exam is scored on a scale of 200 to 800, with 450 required to pass.

What does BEST mean in a CISA question?

BEST asks for the most effective option, not merely a correct one. Several options may be valid actions or controls; the credited answer is the one that addresses the issue most effectively, which often means a preventive or structural control over a detective or discretionary one.

Why do CISA questions have more than one correct answer?

Because CISA tests judgment. Questions are written so that multiple options are plausible, and the qualifier word (FIRST, BEST, GREATEST, MOST, PRIMARY) tells you which correct answer ISACA wants. This is why reading the qualifier carefully matters as much as knowing the content.

Is there a penalty for wrong answers on CISA?

No. There is no penalty for incorrect answers, so you should never leave a question blank, per ISACA. If you are unsure, eliminate what you can and make your best choice.

How do I answer FIRST questions on CISA?

FIRST asks about sequence. The credited answer is the action that should come before the others in the audit process, which usually means understanding, assessing, or planning before testing or acting. Watch for good actions placed out of order; they are the common trap.

What is the auditor mindset for CISA questions?

It is the habit of answering as an information systems auditor who evaluates, reports, and recommends, rather than as an engineer who implements fixes. When options split between acting and assessing, the auditor role and the qualifier usually favor the assess-and-report choice. Note: PrepClubs is an independent practice-test provider and is not affiliated with, endorsed by, or sponsored by ISACA. CISA is a trademark of ISACA. The worked examples above are original illustrations written to demonstrate qualifier reading and are not reproduced from any live exam. Exam format and scoring are set by ISACA and cited to ISACA's official pages; confirm current details with ISACA.