ISACA · CyberSec-Fund
Validates foundational cybersecurity knowledge across four domains: information security fundamentals, threat landscape, securing assets, and security operations and response, covering core security concepts, threat identification, data protection, and incident detection.
Practice Questions
596
≈ 3 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Aug 2026
The ISACA Cybersecurity Fundamentals Certificate does not expire. Once you pass the exam and earn it, it stays valid for life. There is no continuing professional education (CPE) requirement, no annual maintenance fee, and nothing to renew. That sets it apart from ISACA's professional certifications such as CISA, CISM, CRISC, and CGEIT, which must be renewed every three years and carry ongoing CPE obligations.
Because it is a foundational, knowledge-based credential, the goal is simply to pass the exam once. This practice set covers the four domains it tests: information security fundamentals, the threat landscape, securing assets, and security operations and response. Start with 30 free questions, then work through the full bank of 596 with detailed explanations and earn a certificate that never needs renewing.
The ISACA Cybersecurity Fundamentals Certificate validates foundational knowledge and practical skills across the core principles of cybersecurity. It covers the language, frameworks, and technologies that define the discipline, including information security fundamentals, data protection, threat identification, and security operations. The credential is designed to establish that a candidate understands both the theoretical underpinnings of cybersecurity and the practical role security professionals play in defending enterprise systems and data.
Unlike ISACA's more advanced practitioner certifications, this certificate is explicitly entry-level and carries no expiration date, making it a durable credential for those early in their cybersecurity journey. The exam blends traditional knowledge-based multiple-choice questions with performance-based questions set in a virtual lab environment, reflecting ISACA's emphasis on applied, real-world competency rather than purely memorized concepts.
This certificate is designed for students, recent graduates, and early-career IT professionals who want to establish a verified baseline in cybersecurity. It is also well-suited for IT professionals from adjacent disciplines—such as networking, systems administration, or software development—who are transitioning into security-focused roles and need to formalize their foundational knowledge.
Career changers from non-IT backgrounds entering the cybersecurity field will also find this credential valuable as a first step toward more advanced ISACA certifications such as the CSX-P (Cybersecurity Practitioner). Organizations looking to upskill staff or build internal cybersecurity awareness programs frequently use this certificate as a baseline benchmark for their teams.
There are no formal prerequisites for the Cybersecurity Fundamentals Certificate. ISACA allows candidates to register for and sit the exam at any time, with no required work experience, prior certifications, or formal education. This open-access policy reflects the foundational, entry-level nature of the credential.
While no prerequisites are mandated, candidates with some exposure to basic IT concepts—such as networking fundamentals, operating system basics, or general IT infrastructure—will find the material more approachable. Familiarity with concepts like access control, encryption basics, or network protocols is beneficial but not required to begin studying.
The exam consists of 60 scored questions delivered over 120 minutes, yielding roughly two minutes per question. It is administered online as a remotely proctored, closed-book exam, meaning candidates can take it from any suitable location without visiting a physical test center. The question format combines traditional knowledge-based multiple-choice questions with performance-based questions set in a virtual lab environment, testing practical application alongside conceptual understanding.
A passing score of 65% is required, meaning candidates must answer at least 39 of the 60 questions correctly. Exam eligibility is valid for 12 months from the date of registration. Candidates may reschedule their exam without penalty if they do so at least 48 hours before the scheduled appointment. The certificate itself does not expire once earned.
Earning the Cybersecurity Fundamentals Certificate signals to employers that a candidate has verified, baseline-level cybersecurity knowledge validated by ISACA—a globally recognized standards body also responsible for CISA, CISM, and CRISC. For entry-level roles such as Security Analyst, IT Security Technician, SOC Analyst (Tier 1), or Junior Penetration Tester, this credential helps candidates stand out in competitive applicant pools where many lack any formal cybersecurity validation. The digital badge issued through Credly allows holders to display their credential on LinkedIn and other professional platforms for immediate visibility to recruiters.
As a foundational certificate with no expiration date, it also serves as a stepping stone toward more advanced ISACA credentials. Candidates who go on to earn the CSX-P (Cybersecurity Practitioner) certification—ISACA's hands-on, performance-based practitioner credential—can expect significantly higher earning potential, with mid-career cybersecurity professionals commonly earning between $80,000 and $130,000 annually depending on role and region. The Cybersecurity Fundamentals Certificate positions candidates to begin that progression with a recognized, vendor-neutral credential accepted across industries.
5 sample questions with answers and explanations. The full bank has 596 questions, enough for 3 full-length practice exams.
Preview — answers shown1. An attacker sends fraudulent SMS messages claiming recipients have missed package deliveries and must click a link to reschedule. Which social engineering attack is being executed? (Select one!)
Explanation
Smishing is SMS-based phishing that uses text messages to deceive recipients into clicking malicious links or providing sensitive information. The attack leverages mobile messaging platforms. Phishing uses email as the delivery mechanism. Vishing uses voice calls. Pretexting involves creating fabricated scenarios but is not specific to SMS delivery.
2. A vulnerability scanner identifies CVE-2024-12345 with a CVSS v3.1 base score of 8.8 on a web server. The security team must prioritize remediation. Which severity rating does this vulnerability receive? (Select one!)
Explanation
CVSS scores between 7.0 and 8.9 are classified as High severity. A score of 8.8 falls within this range. Low severity ranges from 0.1 to 3.9, Medium from 4.0 to 6.9, and Critical from 9.0 to 10.0. High severity vulnerabilities require prompt attention but are less urgent than Critical vulnerabilities.
3. A security architect evaluates symmetric encryption algorithms for protecting data at rest. The solution must meet current security standards with 128-bit security strength. Which algorithm should be selected? (Select one!)
Explanation
AES-256 provides current standard protection with 256-bit keys offering 128-bit security strength against quantum attacks. AES is the current encryption standard approved by NIST for protecting sensitive data. DES uses 56-bit keys and is deprecated due to vulnerability to brute force attacks. 3DES is deprecated and being phased out despite using 168-bit keys. RC4 is a stream cipher with known vulnerabilities and is deprecated. AES-256 offers the strongest protection among options and is widely supported in hardware and software making it the appropriate choice for modern data protection requirements.
4. A security incident response team collects evidence from a compromised server. Which volatile data source should be collected first according to the order of volatility? (Select one!)
Explanation
System memory contains the most volatile data that is lost when power is removed and must be collected immediately. RAM contains running processes, encryption keys, network connections, and malware artifacts critical for investigation. Hard disk data persists after power loss and can be collected later. Network logs are typically stored on remote systems with lower volatility. Backup tapes represent archival media with minimal volatility. The order of volatility principle requires collecting evidence from most to least volatile starting with CPU registers and memory to preserve ephemeral evidence before system state changes or power loss occurs.
5. A cybersecurity team analyzes malware that self-replicates across the network by exploiting vulnerabilities in unpatched systems without requiring user interaction. Which malware type exhibits this behavior? (Select one!)
Explanation
Worms are self-replicating malware that propagate across networks by exploiting vulnerabilities without requiring user action or host files. Examples include WannaCry and the Morris worm which spread automatically by scanning for and exploiting unpatched systems. Viruses require host files and user action to spread. Trojans disguise themselves as legitimate software and require social engineering for delivery. Logic bombs are malicious code that triggers based on specific conditions like dates or system events.
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
COBIT Foundation Certificate
COBIT-Foundation · 600 questions
Cybersecurity Audit Certificate
CyberSec-Audit · 597 questions
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
Information Technology Certified Associate (ITCA)
ITCA · 596 questions
$17.99
One-time access to this exam