ISACA · Cloud-Fund
Validates foundational knowledge of cloud computing, covering cloud architecture, deployment models, security, risk assessment, and the ability to optimize cloud potential for business services across cloud concepts, governance, and service support.
Practice Questions
600
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Feb 2026
Use this Cloud-Fund practice exam to prepare for Cloud Fundamentals Certificate with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for ISACA Cloud-Fund, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA Cloud Fundamentals Certificate is a foundational-level credential that validates knowledge of core cloud computing principles, concepts, governance, security, and service support. The exam blends theoretical knowledge with practical, performance-based assessment in a virtual lab environment, distinguishing it from purely multiple-choice certifications. It covers how cloud architecture connects vital services and data to enable digital transformation and business agility, including an understanding of deployment models, risk assessment, and cloud optimization strategies.
Offered under ISACA's Certified in Emerging Technology (CET) certificate family, this credential is designed to affirm both conceptual understanding and practical skills. Candidates are tested across three domains: Cloud Computing Concepts (42%), Cloud Service Support (33%), and Cloud Governance (23%), ensuring a balanced assessment of technical and governance competencies relevant to modern cloud environments.
This certificate is ideal for students, recent graduates, and early-career IT professionals who want to establish a verified foundation in cloud computing. It is particularly well-suited for individuals who are new to IT or transitioning into cloud-related roles such as cloud analyst, cloud support specialist, or cloud security consultant.
Teams and organizations seeking to upskill employees on cloud fundamentals will also find this certificate valuable. Because there are no prerequisites, it is accessible to anyone motivated to demonstrate cloud competency, regardless of prior certifications or formal education in technology.
There are no formal prerequisites for the ISACA Cloud Fundamentals Certificate. Candidates can register for the exam at any time without needing to hold prior certifications or meet specific experience requirements.
While no prerequisites are mandated, candidates are expected to have at least a general familiarity with IT concepts. ISACA recommends using official preparation resources — including the self-guided online review course, hands-on lab package, and the official study guide — to build the practical and conceptual knowledge needed to pass the performance-based components of the exam.
The Cloud Fundamentals exam is computer-based and delivered as a remotely proctored online exam with a 2-hour (120-minute) time limit. It blends two question types: traditional multiple-choice (knowledge-based) questions and performance-based questions set within a virtual lab environment, which test hands-on application of cloud skills rather than purely theoretical recall.
Candidates must earn a passing score of 65% or higher. Exam eligibility is valid for 12 months from the date of registration, and appointments can be scheduled as early as 48 hours after payment. Rescheduling is permitted without penalty if done at least 48 hours before the scheduled appointment. The specific total number of questions is not published by ISACA.
The ISACA Cloud Fundamentals Certificate serves as a recognized entry point into cloud-focused roles, validating skills that are increasingly demanded as organizations accelerate cloud adoption. Job roles accessible with this credential include cloud analyst, cloud support specialist, and cloud security consultant, in both private sector technology firms and public sector agencies that use ISACA credentials as hiring benchmarks. Lightcast data cited by ISACA indicates that CET-related skills — the family this certificate belongs to — command salary premiums of up to US $15,000, with entry-level certified professionals typically earning between $65,000 and $80,000 annually.
Demand for cloud computing security skills specifically is projected to grow 90% over the next five years, making a foundational cloud credential an investment with long-term career relevance. Compared to vendor-specific foundational certifications such as AWS Cloud Practitioner or Microsoft Azure Fundamentals, the ISACA Cloud Fundamentals Certificate differentiates itself by emphasizing governance, risk, and compliance alongside technical concepts — a combination well-aligned with compliance-heavy industries such as finance, healthcare, and government.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An organization evaluates the CSA Cloud Controls Matrix for their security framework. How many control domains are included in CCM v4.0? (Select one!)
Explanation
The Cloud Security Alliance Cloud Controls Matrix version 4.0 contains 197 controls across 17 domains specifically designed for cloud computing security. These domains include Audit Assurance and Compliance, Application and Interface Security, Business Continuity Management, Change Control and Configuration, and Identity and Access Management among others. The CCM provides comprehensive coverage mapped to major frameworks including ISO 27001, NIST 800-53, and PCI DSS, making it a foundational tool for cloud security governance.
2. According to CSA Cloud Controls Matrix version 4.0, how many control domains are defined to address cloud-specific security requirements? (Select one!)
Explanation
Cloud Controls Matrix version 4.0 contains 197 controls organized across 17 domains including Audit Assurance and Compliance, Application and Interface Security, Business Continuity Management, Data Security and Privacy Lifecycle, Identity and Access Management, and others. The CCM provides a cybersecurity control framework specifically designed for cloud computing environments and maps to multiple standards including ISO 27001, NIST 800-53, and PCI DSS.
3. According to GDPR Article 33, organizations must report personal data breaches to supervisory authorities within what timeframe after becoming aware of the breach? (Select one!)
Explanation
GDPR requires organizations to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals. This is one of GDPR most specific and strict notification requirements. The 72-hour timeframe begins when the organization becomes aware of the breach, not when the breach occurred. Twenty-four or forty-eight hours are too short and not specified in GDPR. Seven days exceeds the regulatory requirement.
4. An organization negotiates a cloud service agreement requiring 99.95 percent availability. Approximately how much monthly downtime is acceptable under this SLA? (Select one!)
Explanation
An SLA guaranteeing 99.95 percent availability allows approximately 22 minutes of downtime per month. This is calculated from the 0.05 percent unavailability allowance applied to roughly 43,200 minutes in a 30-day month. Four minutes corresponds to 99.99 percent availability. Forty-three minutes corresponds to 99.9 percent availability. Eighty-seven minutes would represent lower availability than 99.95 percent and would violate the SLA commitment.
5. An organization evaluates cloud providers and examines their CSA Cloud Controls Matrix v4.0 compliance documentation. How many control domains does CCM v4.0 contain? (Select one!)
Explanation
CSA Cloud Controls Matrix v4.0 contains 197 controls across 17 domains. The 17 domains include Audit Assurance and Compliance, Application and Interface Security, Business Continuity Management, Change Control and Configuration, Cryptography and Key Management, Datacenter Security, Data Security and Privacy Lifecycle, Governance Risk and Compliance, Human Resources, Identity and Access Management, Infrastructure and Virtualization Security, Interoperability and Portability, Logging and Monitoring, Security Incident Management, Supply Chain Management, Threat and Vulnerability Management, and Universal Endpoint Management. CCM is cross-referenced to frameworks like ISO 27001, NIST 800-53, PCI DSS, and SOC 2.
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Security Manager (CISM)
CISM · 1196 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
Cybersecurity Audit Certificate
CyberSec-Audit · 597 questions
$17.99
One-time access to this exam