ISACA · Cloud-Fund
Validates foundational knowledge of cloud computing, covering cloud architecture, deployment models, security, risk assessment, and the ability to optimize cloud potential for business services across cloud concepts, governance, and service support.
Practice Questions
600
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Feb 2026
Use this Cloud-Fund practice exam to prepare for Cloud Fundamentals Certificate with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for ISACA Cloud-Fund, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA Cloud Fundamentals Certificate is a foundational-level credential that validates knowledge of core cloud computing principles, concepts, governance, security, and service support. The exam blends theoretical knowledge with practical, performance-based assessment in a virtual lab environment, distinguishing it from purely multiple-choice certifications. It covers how cloud architecture connects vital services and data to enable digital transformation and business agility, including an understanding of deployment models, risk assessment, and cloud optimization strategies.
Offered under ISACA's Certified in Emerging Technology (CET) certificate family, this credential is designed to affirm both conceptual understanding and practical skills. Candidates are tested across three domains: Cloud Computing Concepts (42%), Cloud Service Support (33%), and Cloud Governance (23%), ensuring a balanced assessment of technical and governance competencies relevant to modern cloud environments.
This certificate is ideal for students, recent graduates, and early-career IT professionals who want to establish a verified foundation in cloud computing. It is particularly well-suited for individuals who are new to IT or transitioning into cloud-related roles such as cloud analyst, cloud support specialist, or cloud security consultant.
Teams and organizations seeking to upskill employees on cloud fundamentals will also find this certificate valuable. Because there are no prerequisites, it is accessible to anyone motivated to demonstrate cloud competency, regardless of prior certifications or formal education in technology.
There are no formal prerequisites for the ISACA Cloud Fundamentals Certificate. Candidates can register for the exam at any time without needing to hold prior certifications or meet specific experience requirements.
While no prerequisites are mandated, candidates are expected to have at least a general familiarity with IT concepts. ISACA recommends using official preparation resources — including the self-guided online review course, hands-on lab package, and the official study guide — to build the practical and conceptual knowledge needed to pass the performance-based components of the exam.
The Cloud Fundamentals exam is computer-based and delivered as a remotely proctored online exam with a 2-hour (120-minute) time limit. It blends two question types: traditional multiple-choice (knowledge-based) questions and performance-based questions set within a virtual lab environment, which test hands-on application of cloud skills rather than purely theoretical recall.
Candidates must earn a passing score of 65% or higher. Exam eligibility is valid for 12 months from the date of registration, and appointments can be scheduled as early as 48 hours after payment. Rescheduling is permitted without penalty if done at least 48 hours before the scheduled appointment. The specific total number of questions is not published by ISACA.
The ISACA Cloud Fundamentals Certificate serves as a recognized entry point into cloud-focused roles, validating skills that are increasingly demanded as organizations accelerate cloud adoption. Job roles accessible with this credential include cloud analyst, cloud support specialist, and cloud security consultant, in both private sector technology firms and public sector agencies that use ISACA credentials as hiring benchmarks. Lightcast data cited by ISACA indicates that CET-related skills — the family this certificate belongs to — command salary premiums of up to US $15,000, with entry-level certified professionals typically earning between $65,000 and $80,000 annually.
Demand for cloud computing security skills specifically is projected to grow 90% over the next five years, making a foundational cloud credential an investment with long-term career relevance. Compared to vendor-specific foundational certifications such as AWS Cloud Practitioner or Microsoft Azure Fundamentals, the ISACA Cloud Fundamentals Certificate differentiates itself by emphasizing governance, risk, and compliance alongside technical concepts — a combination well-aligned with compliance-heavy industries such as finance, healthcare, and government.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A healthcare organization must ensure that Protected Health Information remains within the United States due to regulatory requirements. Which cloud governance consideration addresses this requirement? (Select one!)
Explanation
Data sovereignty refers to the legal jurisdiction governing data based on its physical storage location. Regulations like HIPAA may require data to remain within specific geographic boundaries. Data classification categorizes data by sensitivity but does not address location. Data encryption protects confidentiality but does not control geographic location. Data lifecycle management addresses retention and disposal but not jurisdictional requirements.
2. An organization implements cloud governance but fails to include audit rights provisions in provider contracts. Two years later, regulatory auditors require evidence of provider security controls. What risk materialized from this governance gap? (Select one!)
Explanation
Audit rights provisions in contracts ensure organizations can verify provider compliance through assessments and third-party assurance reviews. Without contractual audit rights, organizations cannot obtain evidence of provider security controls, compliance certifications, or operational practices required for regulatory compliance. This governance area specifically addresses the ability to conduct due diligence and maintain oversight of provider security posture. While providers may charge for audits, the primary risk is inability to verify compliance at all. Data residency issues relate to data governance provisions. SLA breaches relate to service level monitoring provisions. The fundamental risk is loss of visibility and verification capability for regulatory and security requirements.
3. An organization establishes a cloud governance framework using COBIT 2019. Which of the following are governance principles according to COBIT that should guide their implementation? (Select two!)
Multiple correct answersExplanation
COBIT 2019 operates on five core governance principles, including meeting stakeholder needs to ensure IT delivers value and separating governance from management to distinguish oversight from operational execution. Other principles include covering the enterprise end-to-end, applying a single integrated framework, and enabling a holistic approach. Maximizing resource utilization regardless of security contradicts risk management principles. Centralizing all authority prevents appropriate delegation and distributed accountability. Prioritizing speed over compliance violates governance requirements for regulatory adherence.
4. An incident response team investigates a security breach in cloud infrastructure. The team needs to collect forensic evidence including API activity logs, network flow data, and virtual machine disk snapshots. Which challenge is unique to cloud forensics compared to traditional on-premises investigations? (Select one!)
Explanation
Cloud forensics requires reliance on provider APIs for evidence collection since investigators lack physical access to hardware in multi-tenant environments. Traditional forensics allows direct hardware access for evidence acquisition. While cloud environments provide network flow logs and comprehensive logging, investigators must use provider-specific APIs and tools. Ephemeral resources like containers and serverless functions add complexity, but the fundamental distinction is API-based evidence collection versus physical access.
5. A Type 1 hypervisor is being evaluated for a private cloud deployment. What distinguishes a Type 1 hypervisor from a Type 2 hypervisor? (Select one!)
Explanation
Type 1 hypervisors are bare-metal hypervisors that run directly on physical hardware, providing lower overhead and better performance. Examples include VMware ESXi, Microsoft Hyper-V, and KVM. Type 2 hypervisors are hosted hypervisors that run on top of an existing operating system, providing more flexibility and easier setup. Examples include VirtualBox and VMware Workstation. The distinction is not related to cloud deployment models or operating system support, but rather the architectural layer where the hypervisor operates.
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
Cybersecurity Audit Certificate
CyberSec-Audit · 597 questions
$17.99
One-time access to this exam