ISACA • COBIT-Foundation
Validates foundational knowledge of the COBIT 2019 framework, covering framework components, governance and management principles, performance management, governance objectives, tailored system design, and alignment of IT goals with strategic business objectives.
Questions
600
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Feb 2026
The COBIT Foundation Certificate, offered by ISACA, validates an individual's foundational knowledge of the COBIT 2019 framework — the globally recognized framework for the governance and management of enterprise information technology. Earning this certificate demonstrates proficiency in COBIT's core concepts, principles, and methodologies, including how governance systems are structured and how management and governance objectives are defined, organized, and applied. It also covers how organizations can design tailored governance systems that address their unique context and requirements.
The certification is grounded in COBIT 2019, which introduced significant updates over its predecessor COBIT 5, including a renewed focus on governance system components, a principles-based approach, and a flexible design toolkit for building bespoke governance solutions. Certificate holders are equipped to articulate how IT goals align with strategic business objectives and how performance management practices support continuous improvement across an enterprise's governance model.
The COBIT Foundation Certificate is appropriate for a wide range of professionals who interact with IT governance, risk, and compliance functions. Primary audiences include senior IT and business managers, IT auditors, risk and GRC (Governance, Risk, and Compliance) managers, regulators, and consultants who advise organizations on IT governance practices. Program managers responsible for governance-related initiatives also benefit from this credential.
The certificate is equally valuable for students and recent graduates seeking to establish credibility in IT governance, as well as professionals already holding related certifications such as CISA or CISM who want to formalize their COBIT knowledge. Because no prerequisites are required, professionals at any career stage can pursue this credential as an entry point into the ISACA certification ecosystem.
There are no formal prerequisites to register for the COBIT Foundation Certificate exam. Candidates can register at any time without restrictions, and eligibility is valid for 12 months from the date of registration. Testing appointments can be scheduled as early as 48 hours after payment of the exam registration fee and are available up to 90 days in advance.
While no prior certification or formal training is required, candidates will benefit from some familiarity with IT governance concepts and the general role of frameworks in enterprise IT management. ISACA recommends reviewing the official COBIT 2019 Foundation materials and taking advantage of available study resources such as the COBIT 2019 Foundation Online Course, which provides approximately 5 hours of self-paced content, before attempting the exam.
The COBIT Foundation Certificate exam is a computer-based, remotely proctored assessment consisting of 75 multiple-choice questions. Candidates are given 120 minutes (2 hours) to complete the exam. The exam is delivered online through ISACA's proctoring platform, allowing candidates to test from any location with a suitable internet connection. There is no in-person testing center option.
The passing score is 65% or higher, meaning candidates must answer at least 49 of the 75 questions correctly. The exam fee is US$175 for both ISACA members and non-members. Candidates may reschedule without penalty up to 48 hours before their scheduled appointment. The exam does not include unscored survey questions — all 75 questions contribute to the final score.
The COBIT Foundation Certificate provides professionals with a recognized credential that demonstrates IT governance competency to employers across industries. Certified practitioners report average salaries of approximately $114,949 according to ISACA data, with roles such as IT Auditor, Risk Management Analyst, Information Systems Audit Manager, Governance Risk Consultant, and IT Consultant among the most common job titles held by certificate holders. For more senior IT governance roles such as CISO or CTO, salaries can extend well beyond $150,000.
Beyond immediate salary benefits, the certificate serves as a stepping stone to ISACA's Certified in the Governance of Enterprise IT (CGEIT) certification — the only vendor-neutral, individual-focused IT governance certification globally recognized for C-suite and executive-level roles. CGEIT holders earn an average of 25% more than the North American IT professional average. Because COBIT is framework-agnostic and internationally recognized, the credential is valued across sectors including financial services, healthcare, government, and consulting, making it relevant for professionals seeking governance roles in any geography.
5 sample questions with correct answers and explanations. Start a practice session to test yourself across all 600 questions.
1. A transportation company is implementing BAI09 Managed Assets. The IT asset manager asks how this objective differs from BAI10 Managed Configuration. Which statement best explains the distinction? (Select one!)
Explanation
BAI09 Managed Assets focuses on accounting for all IT assets throughout their lifecycle, ensuring assets are used effectively, that asset value is optimized, and that assets are physically protected. BAI10 Managed Configuration focuses on defining and maintaining descriptions of important resources and relationships of the IT environment, establishing baselines and verifying configurations. BAI09 emphasizes asset lifecycle and value management while BAI10 emphasizes configuration accuracy and relationships. Both manage physical and logical assets.
2. A consulting firm is advising a client on COBIT 2019 adoption. The client asks what distinguishes COBIT from other frameworks. Which statement accurately describes COBIT 2019? (Select one!)
Explanation
COBIT 2019 is specifically defined as a framework for the governance and management of enterprise information and technology. It is not a full description of the entire IT environment, which would be impractical and overly prescriptive. COBIT provides governance and management guidance across all IT domains, not just security. It is not a software development methodology but rather an overarching governance framework that can integrate with various methodologies.
3. A manufacturing company is implementing MEA01 Managed Performance and Conformance Monitoring. The IT director needs to explain which domain this objective belongs to and its primary management activity cycle. Which statement is correct? (Select one!)
Explanation
MEA01 Managed Performance and Conformance Monitoring belongs to the MEA domain, which is one of four management domains. All management domains follow the Plan, Build, Run, Monitor cycle, which is the management responsibility cycle. The Evaluate, Direct, Monitor cycle applies only to the EDM governance domain, which is the Board's responsibility. MEA focuses on measuring how well the governance and management system works through KPIs, SLAs, and performance metrics.
4. A manufacturing company needs to select a governance objective that ensures adequate IT capabilities (people, process, technology) are available at optimal cost to support business objectives. Which EDM governance objective specifically addresses this requirement? (Select one!)
Explanation
EDM04 Ensured Resource Optimization is the governance objective that focuses on ensuring adequate capabilities (people, process, technology) are available at optimal cost. This board-level governance objective evaluates whether IT resources are sufficient and efficiently deployed. EDM02 Ensured Benefits Delivery focuses on optimal value from IT initiatives. EDM03 Ensured Risk Optimization ensures IT risk is within appetite and tolerance. EDM05 Ensured Stakeholder Engagement addresses communication and stakeholder involvement. Resource optimization is specifically about capability adequacy and cost efficiency.
5. A global logistics company is implementing COBIT 2019 management objectives to improve their IT service delivery. The IT director wants to understand BAI06 Managed IT Changes. The company needs rapid deployment of changes while protecting production systems from disruption. Which statement best describes what BAI06 aims to achieve? (Select one!)
Explanation
BAI06 Managed IT Changes focuses on enabling rapid, reliable change deployment while mitigating the risk of negative impact on production services and operations. This objective addresses technical change management processes including change evaluation, authorization, implementation, and documentation. DSS01 Managed Operations coordinates ongoing operational activities for service delivery. BAI07 Managed IT Change Acceptance and Transitioning handles operational readiness validation and safe implementation during transition. BAI05 Managed Organizational Change addresses enterprise-wide organizational transformation rather than technical IT changes.
One-time access to this exam