ISACA · COBIT-Foundation
Validates foundational knowledge of the COBIT 2019 framework, covering framework components, governance and management principles, performance management, governance objectives, tailored system design, and alignment of IT goals with strategic business objectives.
Practice Questions
600
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Sep 2026
ISACA weights the COBIT Foundation exam across eight domains: Governance System and Components leads at 30%, followed by Governance and Management Objectives at 23%, Principles at 13%, Framework Introduction at 12%, Implementation at 8%, Designing a Tailored Governance System at 7%, Performance Management at 4%, and Business Case at 3%. The top two domains alone account for 53% of your score, so knowing the seven governance system components and the 40 governance and management objectives cold matters more than anything else. This practice bank of 600 questions is built to match that split, so components and objectives scenarios get real depth instead of a token handful of questions.
Test day is straightforward but has quirks worth knowing. You get 75 multiple-choice questions in 120 minutes, delivered online only through ISACA's remote proctoring platform (there is no test-center option). Passing requires 65%, which works out to 49 correct answers out of 75. Prep guides consistently note that questions use three answer options rather than the usual four, which changes the guessing math in your favor. ISACA does not publish a scored versus unscored question split, and you can reschedule your appointment without penalty up to 48 hours before it starts.
There are no prerequisites, and the exam costs US $175 whether or not you are an ISACA member (this is one of the few ISACA exams without a member discount). Your exam eligibility lasts 6 months from registration, so do not register before you are ready to study. Once earned, the certificate does not expire and carries no CPE maintenance requirements, unlike ISACA's full certifications such as CISA or CGEIT, and it is the required first step toward the COBIT Design and Implementation certificate. Start with the 30 free questions, then work through the full 600-question bank until your accuracy holds steady across all 8 domains.
The COBIT Foundation Certificate, offered by ISACA, validates an individual's foundational knowledge of the COBIT 2019 framework — the globally recognized framework for the governance and management of enterprise information technology. Earning this certificate demonstrates proficiency in COBIT's core concepts, principles, and methodologies, including how governance systems are structured and how management and governance objectives are defined, organized, and applied. It also covers how organizations can design tailored governance systems that address their unique context and requirements.
The certification is grounded in COBIT 2019, which introduced significant updates over its predecessor COBIT 5, including a renewed focus on governance system components, a principles-based approach, and a flexible design toolkit for building bespoke governance solutions. Certificate holders are equipped to articulate how IT goals align with strategic business objectives and how performance management practices support continuous improvement across an enterprise's governance model.
The COBIT Foundation Certificate is appropriate for a wide range of professionals who interact with IT governance, risk, and compliance functions. Primary audiences include senior IT and business managers, IT auditors, risk and GRC (Governance, Risk, and Compliance) managers, regulators, and consultants who advise organizations on IT governance practices. Program managers responsible for governance-related initiatives also benefit from this credential.
The certificate is equally valuable for students and recent graduates seeking to establish credibility in IT governance, as well as professionals already holding related certifications such as CISA or CISM who want to formalize their COBIT knowledge. Because no prerequisites are required, professionals at any career stage can pursue this credential as an entry point into the ISACA certification ecosystem.
There are no formal prerequisites to register for the COBIT Foundation Certificate exam. Candidates can register at any time without restrictions, and eligibility is valid for 6 months from the date of registration. Testing appointments can be scheduled as early as 48 hours after payment of the exam registration fee and are available up to 90 days in advance.
While no prior certification or formal training is required, candidates will benefit from some familiarity with IT governance concepts and the general role of frameworks in enterprise IT management. ISACA recommends reviewing the official COBIT 2019 Foundation materials and taking advantage of available study resources such as the COBIT 2019 Foundation Online Course, which provides approximately 5 hours of self-paced content, before attempting the exam.
The COBIT Foundation Certificate exam is a computer-based, remotely proctored assessment consisting of 75 multiple-choice questions. Candidates are given 120 minutes (2 hours) to complete the exam. The exam is delivered online through ISACA's proctoring platform, allowing candidates to test from any location with a suitable internet connection. There is no in-person testing center option.
The passing score is 65% or higher, meaning candidates must answer at least 49 of the 75 questions correctly. The exam fee is US$175 for both ISACA members and non-members. Candidates may reschedule without penalty up to 48 hours before their scheduled appointment. ISACA does not publish whether any of the 75 questions are unscored; the passing bar is 65 percent (49 of 75).
The COBIT Foundation Certificate provides professionals with a recognized credential that demonstrates IT governance competency to employers across industries. Certified practitioners report average salaries of approximately $114,949 according to ISACA data, with roles such as IT Auditor, Risk Management Analyst, Information Systems Audit Manager, Governance Risk Consultant, and IT Consultant among the most common job titles held by certificate holders. For more senior IT governance roles such as CISO or CTO, salaries can extend well beyond $150,000.
Beyond immediate salary benefits, the certificate serves as a stepping stone to ISACA's Certified in the Governance of Enterprise IT (CGEIT) certification — the only vendor-neutral, individual-focused IT governance certification globally recognized for C-suite and executive-level roles. CGEIT holders earn an average of 25% more than the North American IT professional average. Because COBIT is framework-agnostic and internationally recognized, the credential is valued across sectors including financial services, healthcare, government, and consulting, making it relevant for professionals seeking governance roles in any geography.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A biotechnology company is implementing Design Factor 3 Risk Profile. The risk management team identifies several I&T-related risk exposures. How many distinct risk criteria does COBIT 2019 provide for evaluating I&T-related risks in the risk profile assessment? (Select one!)
Explanation
COBIT 2019 provides 19 risk criteria for evaluating I&T-related risk exposure against the enterprise's risk appetite. These criteria are categorized across IT Investment and Portfolio risks, Data Management risks, Compliance risks, Technology risks, and Operational risks. Organizations assess their risk exposure using these 19 criteria to determine which governance and management objectives require higher target capability levels based on their specific risk profile.
2. An insurance company has identified Enterprise Goal EG02 Managed Business Risk as a top priority. The governance team needs to determine which alignment goals support this enterprise goal. Using the goals cascade mechanism, which two alignment goals would have the strongest relationship to EG02? (Select two!)
Multiple correct answersExplanation
AG01 I&T compliance and support for business compliance and AG02 Managed I&T-related risk are the alignment goals most directly connected to Enterprise Goal EG02 Managed Business Risk. The goals cascade translates enterprise goals into alignment goals, and risk management at the enterprise level requires both managing IT-specific risks and ensuring compliance which reduces legal and regulatory risks. AG05 focuses on service delivery rather than risk. AG07 addresses security which is one aspect of risk but not the primary alignment goal. AG12 relates to human resources and capability rather than business risk management.
3. A telecommunications company is implementing APO02 Managed Strategy. The strategy team wants to understand the primary purpose of this management objective. Which statement best describes the purpose of APO02? (Select one!)
Explanation
APO02 Managed Strategy provides a holistic view of the current and future business and IT environment, defining strategic initiatives for migrating from the current state to the target state. This includes understanding business objectives, IT capabilities, and the roadmap for transformation. Executing strategic direction through portfolio management is the purpose of APO05 Managed Portfolio. Defining building blocks and interrelationships of enterprise architecture is the purpose of APO03 Managed Enterprise Architecture. Maintaining competitive advantage through awareness of emerging technologies is the purpose of APO04 Managed Innovation.
4. A telecommunications operator is implementing APO04 Managed Innovation to maintain competitive advantage. The innovation team asks which areas this objective addresses. What is the primary focus of APO04? (Select one!)
Explanation
APO04 Managed Innovation focuses specifically on achieving competitive advantage, improving customer experience, and enhancing operational effectiveness through awareness and adoption of IT developments and emerging technologies. This objective ensures the organization systematically evaluates innovations for potential business value. Optimizing business process functionality relates to enterprise goal EG08 but is not APO04's specific focus. Managing budget allocation is the purpose of APO06 Managed Budget and Costs. Ensuring technology-related compliance relates to MEA03 Managed Compliance with External Requirements and alignment goal AG01 rather than innovation management.
5. A manufacturing company is assessing a focus area for maturity level. The assessment reveals planning and measurement occur but are not standardized across the enterprise. Which maturity level does this represent? (Select one!)
Explanation
Maturity Level 2 Managed indicates that planning and measurement occur but are not yet standardized across the enterprise. At this level, basic management practices exist but lack enterprise-wide consistency. Level 1 Initial means work is completed but full goals are not achieved. Level 3 Defined means enterprise-wide standards provide consistent guidance across the organization. Level 4 Quantitative means the enterprise is data-driven with quantitative performance management. Understanding maturity assessment helps organizations identify current state and define improvement paths for focus areas.
75 multiple-choice questions in 120 minutes. Prep guides note each question offers three answer options rather than four.
65%, which means at least 49 of the 75 questions must be answered correctly. Results are provided after the remotely proctored exam.
US $175 for both ISACA members and non-members - there is no member discount on this exam. Exam eligibility lasts 6 months from registration.
Eight domains: Governance System and Components (30%), Governance and Management Objectives (23%), Principles (13%), Framework Introduction (12%), Implementation (8%), Designing a Tailored Governance System (7%), Performance Management (4%), and Business Case (3%).
No. Anyone can register and take the exam. ISACA recommends studying the COBIT 2019 Framework: Introduction and Methodology publication or taking its foundation course first.
No. It is a certificate rather than a full ISACA certification, so it never expires and has no CPE or annual maintenance fee requirements.
Yes. As of 2026 the exam still tests the COBIT 2019 framework; ISACA has released complementary guidance (AI governance, ITAF 5th edition) but no replacement version of COBIT 2019.
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
Cybersecurity Audit Certificate
CyberSec-Audit · 597 questions
Cybersecurity Fundamentals Certificate
CyberSec-Fund · 596 questions
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
$17.99
One-time access to this exam