ISACA · CyberSec-Audit
Validates the ability to evaluate cybersecurity risk and audit organizational cybersecurity controls, covering cybersecurity operations, technology topics, governance, the audit role in cybersecurity, security frameworks, threat assessment, and regulatory requirements.
Practice Questions
597
≈ 3 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
AssociateLast Updated
Sep 2026
The Cybersecurity Audit Certificate weights four domains, and the split is lopsided: Cybersecurity Operations leads at 45 percent, Cybersecurity Technology Topics follows at 30 percent, Cybersecurity Governance takes 20 percent, and Cybersecurity and Audit's Role rounds it out at just 5 percent. Operations and Technology together decide 75 percent of your score, so asset and vulnerability management, incident response, identity and access, network and cloud security, and control testing dominate the question pool. This 597-question bank is built to match that split, so most of your practice time lands on the two domains that carry the exam rather than the thin governance and audit-role slices.
On test day you answer 75 multiple-choice questions in 2 hours, delivered as an online, closed-book, remotely proctored exam, and you need 65 percent or higher to pass. The number of questions per domain tracks each domain's percentage weight, so expect roughly a third of the exam on Operations alone. There is no scaled 200-to-800 scoring here like ISACA's CISA exam uses; the Cybersecurity Audit Certificate is a straight percentage, and you can schedule your appointment as early as 48 hours after paying.
There are no prerequisites, so you can register at any time, and your eligibility window runs 6 months from registration. The exam costs US$259 for ISACA members and US$299 for non-members. Note the word certificate: unlike ISACA's CISA certification, which demands five years of experience and 120 CPE hours every three years, this credential is earned once, never expires, and carries no CPE or annual maintenance fee, the same as ISACA's IT Audit Fundamentals and Cybersecurity Fundamentals certificates. It is a credible way to prove cybersecurity audit knowledge without committing to the full CISA pathway. Start with the 30 free questions, then work through the full 597-question bank until your accuracy holds steady across all 4 domains.
The ISACA Cybersecurity Audit Certificate is a certificate-level credential designed to validate a professional's ability to evaluate cybersecurity risk and audit organizational cybersecurity controls. The program is organized across four high-level domains—Cybersecurity Operations, Cybersecurity Technology Topics, Cybersecurity Governance, and Cybersecurity and Audit's Role—developed through extensive research and input from subject matter experts worldwide. It bridges the gap between traditional IT audit and modern cybersecurity practice, equipping candidates to assess threat environments, evaluate security controls, and align audits with established security frameworks and regulatory requirements.
This certificate is recognized globally and is particularly valued in industries where assurance over cybersecurity posture is critical, such as finance, healthcare, government, and technology. Unlike ISACA's full CISA certification, it does not require prior work experience, making it accessible to those earlier in their audit or security careers while still demonstrating verified, exam-tested competency through a shareable digital badge issued via the Credly platform.
The Cybersecurity Audit Certificate is primarily aimed at audit and assurance professionals who need to develop or formalize their cybersecurity audit skills, as well as IT risk professionals seeking a deeper understanding of cyber-related risks and mitigating controls. Security practitioners who want to understand the audit process from a cybersecurity lens are also well-served by this credential.
Suitable job roles include IT auditors, internal auditors, IT risk analysts, compliance officers, and information security analysts. ISACA recommends that candidates have a basic understanding of cybersecurity concepts and some prior industry experience, though neither is a formal requirement. The certificate is especially useful for professionals looking to add cybersecurity audit specialization without committing to the full CISA certification pathway.
There are no formal prerequisites for the Cybersecurity Audit Certificate. Candidates may register at any time without needing to demonstrate prior certifications, educational qualifications, or work experience. This makes it one of ISACA's most accessible credentials.
However, ISACA recommends that candidates possess a foundational understanding of cybersecurity concepts and some practical experience within the IT audit or security industry before sitting the exam. Familiarity with common security frameworks (such as NIST, ISO 27001, or COBIT) and basic knowledge of audit methodologies will assist in exam preparation and in understanding the context of the domains covered.
The Cybersecurity Audit Certificate exam is delivered online as a closed-book, remotely proctored assessment. It consists of 75 multiple-choice questions and must be completed within a 2-hour time limit. The number of questions per domain is proportional to each domain's assigned percentage weight. A passing score of 65% or higher is required.
Candidates can register at any time on a continuous basis, and exam scheduling is available as early as 48 hours after payment of registration fees. Upon registration, candidates have a 6-month eligibility window in which to sit the exam. Exam fees are US$259 for ISACA members and US$299 for non-members. Upon passing, candidates receive a digital badge credential managed through the Credly platform.
The Cybersecurity Audit Certificate positions holders to pursue or advance in roles such as IT auditor, internal auditor, IT risk analyst, compliance officer, and information security analyst. It serves as a strong entry point toward ISACA's flagship CISA certification, and professionals who later earn the CISA can expect significantly elevated earning potential—ISACA salary survey data indicates that certified professionals earn approximately 20% more than non-certified peers, with average U.S. CISA salaries exceeding $149,000 annually. Even at earlier career stages, IT audit and cybersecurity audit professionals in the U.S. typically earn between $63,000 and $100,000 depending on experience level.
Demand for cybersecurity audit skills is strong across regulated industries including financial services, healthcare, and government, where assurance over cybersecurity controls is a compliance and governance requirement. The certificate's digital badge, shareable via LinkedIn and Credly, provides verifiable proof of competency that is recognized by employers globally. For professionals who are not yet ready for the full CISA, this certificate offers a credible intermediate credential that demonstrates practical knowledge of cybersecurity audit without requiring years of documented work experience.
5 sample questions with answers and explanations. The full bank has 597 questions, enough for 3 full-length practice exams.
Preview — answers shown1. During a risk assessment, an auditor calculates that a particular system has an Asset Value of 500000 dollars, Exposure Factor of 40 percent, and Annual Rate of Occurrence of 0.25. What is the Annual Loss Expectancy for this risk? (Select one!)
Explanation
Annual Loss Expectancy is calculated as ALE = SLE × ARO, where SLE = AV × EF. First calculate SLE: 500000 × 0.40 = 200000 dollars. Then calculate ALE: 200000 × 0.25 = 50000 dollars. This represents the expected annual loss from this risk. The calculation shows that while a single loss event would cost 200000 dollars, the expected frequency of 0.25 times per year results in an annualized expectancy of 50000 dollars.
2. An organization implements Zero Trust Architecture with identity verification, device health validation, and MFA. However, users can access any resource once authenticated. What Zero Trust principle is violated? (Select one!)
Explanation
The organization violates the least privilege access principle by allowing users to access any resource after authentication. Zero Trust requires that access be limited to only the specific resources each user needs for their role, with granular authorization enforced at every access attempt. Simply verifying identity and device health is insufficient without resource-level access controls. Never trust, always verify is being followed through continuous verification. Assume breach relates to network segmentation and monitoring, which may or may not be present. Verify explicitly is being implemented through identity verification, device health validation, and MFA. The critical gap is the lack of authorization controls limiting resource access.
3. During a cybersecurity audit, the auditor evaluates the organization's implementation of CIS Controls v8.1 and notes that the organization has recently updated its documentation practices. Which security function was newly added in CIS Controls v8.1 to bring the total to six security functions? (Select one!)
Explanation
Governance was added as the sixth security function in CIS Controls v8.1, released in June 2024. The six security functions are now Govern, Identify, Protect, Detect, Respond, and Recover. Governance topics are specifically identified as recommendations to enhance cybersecurity program governance and oversight. This update aligns with NIST CSF 2.0, which also added Govern as a new function. Identify, Protect, and Recover were already existing security functions in previous versions of CIS Controls.
4. A healthcare provider implements a backup strategy where the first backup of the week is a full backup on Sunday, and subsequent backups Monday through Saturday only copy files modified since Sunday. Which backup type is used Monday through Saturday? (Select one!)
Explanation
Differential backups copy all files that have changed since the last full backup, which matches the described strategy where Monday through Saturday backups capture everything modified since Sunday's full backup. Incremental backups only copy files changed since the most recent backup of any type, requiring restoration from the full backup plus every incremental backup in sequence. Synthetic full backups combine previous backups to create a virtual full backup without reading production data. Continuous data protection captures changes in near real-time, not on a daily schedule.
5. During a cybersecurity audit, the auditor discovers that the organization uses the STRIDE threat modeling methodology for application security assessments. Which threat category in STRIDE addresses an attacker's ability to deny performing malicious actions due to insufficient logging? (Select one!)
Explanation
Repudiation threats in the STRIDE model involve users denying actions they performed due to insufficient audit trails, logging, or non-repudiation controls. This occurs when systems cannot prove what actions a user took. Spoofing involves identity theft or impersonation. Tampering addresses unauthorized data modification. Information Disclosure covers data leaks and unauthorized data exposure. The STRIDE acronym (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) provides a systematic approach to identifying security threats across Microsoft applications.
75 multiple-choice questions, and you have 2 hours to complete them. The number of questions in each domain matches that domain's percentage weight.
65 percent or higher. Scoring is a straight percentage, not the scaled 200-to-800 model ISACA uses for CISA.
US$259 for ISACA members and US$299 for non-members.
Four domains: Cybersecurity Operations (45%), Cybersecurity Technology Topics (30%), Cybersecurity Governance (20%), and Cybersecurity and Audit's Role (5%).
No. You can register at any time with no required work experience, degree, or prior certification, which sets it apart from ISACA's CISA.
No. It is a certificate, not a certification, so there is no expiry, no CPE requirement, and no annual maintenance fee, unlike CISA or CISM.
Online only. It is a closed-book, remotely proctored exam you can schedule as early as 48 hours after paying, within a 6-month eligibility window from registration.
CISA is a full certification requiring 5 years of experience and ongoing CPE; IT Audit Fundamentals is an entry-level certificate. The Cybersecurity Audit Certificate sits between them, focused specifically on auditing cybersecurity controls with no experience requirement.
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
Cybersecurity Fundamentals Certificate
CyberSec-Fund · 596 questions
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
$17.99
One-time access to this exam