ISACA · ITCA
Entry-level certification that validates fundamental knowledge in cybersecurity concepts, one of five certificates in the ITCA program.
Practice Questions
596
≈ 3 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Jul 2026
ISACA has retired the Information Technology Certified Associate (ITCA) certification for new candidates. The program originally bundled five fundamentals certificates, covering computing, networking and infrastructure, cybersecurity, software development, and data science, and awarded the full ITCA designation to anyone who passed all five. That pathway is now closed: existing holders can still maintain the credential, but nobody new can earn it. The one component still sold on its own is the Cybersecurity Fundamentals Certificate, and even that is on a clock. ISACA stops selling the exam on 1 December 2026 and sunsets the program on 1 June 2027, pointing new candidates to its Certified Cybersecurity Specialist (CCS) as the successor.
If you register before the cutoff, the current exam is 48 questions: 36 multiple choice worth 1 point each and 12 performance-based lab questions worth 2 points each, for 60 points total. You get 2 hours, and passing requires 65 percent, which works out to roughly 39 points. Securing Assets is the heaviest domain at 35 percent, followed by Information Security Fundamentals at 27 percent, Security Operations and Response at 20 percent, and Threat Landscape at 18 percent. The exam costs $120 for ISACA members and $144 for non-members, has no prerequisites, and runs online with remote proctoring through PSI.
Because the lab questions carry double points, 40 percent of the marks come from hands-on tasks rather than recall, so drill the multiple-choice side until it is automatic and keep time in reserve for the labs. Start with the 30 free questions here, then work through the full 596-question bank with explanations until your accuracy holds above 65 percent in Securing Assets and Information Security Fundamentals, the two domains that together decide 62 percent of your score.
The ISACA Cybersecurity Fundamentals Certificate is one of five stackable credentials that together comprise the Information Technology Certified Associate (ITCA) program. It validates foundational knowledge of cybersecurity principles, threat landscapes, asset security, and security operations — the core competencies required to begin a career protecting enterprise data and infrastructure. The exam blends knowledge-based multiple-choice questions with performance-based questions delivered in a virtual lab environment, ensuring candidates can demonstrate practical ability alongside theoretical understanding.
The certificate began as one of five stackable ITCA credentials, but ISACA has since retired the full ITCA certification for new applicants, and the Cybersecurity Fundamentals Certificate itself is being sunset: the last day to purchase the exam is 1 December 2026 and the program closes on 1 June 2027, with ISACA naming its Certified Cybersecurity Specialist (CCS) as the successor. The certificate does not expire for those who earn it and awards 9.5 CPE credits when the accompanying course is completed.
This certificate is designed for individuals at the very beginning of their IT or cybersecurity career journey, including recent graduates, college students, and professionals from non-technical fields looking to transition into cybersecurity. No prior work experience in IT is required, making it accessible to career changers who want a recognized credential to validate self-taught or academic knowledge.
It is also well-suited for IT generalists, help desk technicians, or junior administrators who want to formalize their cybersecurity knowledge and differentiate themselves for roles such as security analyst, IT support specialist, or junior SOC analyst. Organizations may also use it as a structured upskilling tool for existing technical teams.
There are no formal prerequisites for the Cybersecurity Fundamentals certificate. Candidates can register and sit for the exam at any time without prior certifications, work experience documentation, or educational requirements — distinguishing it from ISACA's more advanced credentials such as CISM or CISA.
While no prerequisites are mandated, candidates will benefit from a basic familiarity with computing concepts, networking fundamentals, and general IT terminology before attempting the exam. ISACA offers an optional self-paced online course (9.5 CPE credits) and a study guide authored by subject-matter experts to help candidates without a formal cybersecurity background build the necessary knowledge before sitting for the exam.
The exam consists of 48 questions delivered in a computer-based, remotely proctored format: 36 knowledge-based multiple-choice questions worth 1 point each and 12 performance-based questions worth 2 points each, set within a virtual lab environment, for 60 points in total. The time limit is 120 minutes, and a passing score of 65% (roughly 39 points) is required.
The exam is available continuously through ISACA's proctoring partner PSI. Candidates can schedule as early as 48 hours after payment, and free rescheduling is permitted with at least 48 hours' notice. Your eligibility window starts at registration; ISACA's certificate page currently lists six months. Up to 4 attempts are allowed in a rolling 12-month period, paying the full fee each time. Exam fees are US$120 for ISACA members and US$144 for non-members.
Earning the Cybersecurity Fundamentals certificate signals to employers that a candidate has verified, baseline competency in protecting systems and data — a quality increasingly valued even for non-security IT roles. It serves as a credible entry point for positions such as junior security analyst, SOC tier-1 analyst, IT support specialist, or cybersecurity technician, particularly at organizations that recognize ISACA credentials (common in financial services, government, and enterprise technology sectors).
As a standalone certificate it complements ISACA's advanced certifications (CISM, CISA, CRISC), providing a documented foundation that can accelerate a candidate's path toward those credentials. The full five-badge ITCA certification is now retired for new applicants, so the Cybersecurity Fundamentals Certificate stands on its own, and candidates planning beyond the program's 1 June 2027 sunset can treat it as a bridge toward ISACA's successor credential, the Certified Cybersecurity Specialist (CCS).
5 sample questions with answers and explanations. The full bank has 596 questions, enough for 3 full-length practice exams.
Preview — answers shown1. A data center architect designs storage infrastructure for a financial trading platform requiring both high performance and data protection. The system must survive two simultaneous drive failures while maintaining acceptable write performance. The storage array has eight drives available. Which RAID configuration meets these requirements? (Select one!)
Explanation
RAID 6 is the correct solution because it provides dual parity, allowing the array to survive two simultaneous drive failures. With eight drives in RAID 6, the system provides six drives worth of usable capacity while maintaining redundancy through two parity drives. RAID 5 with hot spare can only tolerate one drive failure at a time because RAID 5 uses single parity. If a second drive fails before the hot spare rebuilds the first failed drive, data is lost. RAID 10 provides excellent performance and can survive multiple drive failures, but only if the failures occur in different mirrored pairs. If both drives in a mirrored pair fail, all data is lost. Two separate RAID 1 arrays do not provide a unified storage solution and complicate management. RAID 6 specifically addresses the requirement for surviving two simultaneous failures through its dual parity mechanism, where parity information is distributed across all drives.
2. A company deploys a wireless network for a conference center hosting 1,000 simultaneous users. The network must support modern devices while providing the strongest available security against password-guessing attacks and protecting individual user traffic on the shared network. Legacy devices from 2018 must also connect. Which wireless security configuration should the administrator implement? (Select one!)
Explanation
WPA2/WPA3 transition mode allows modern devices to use WPA3 security (SAE authentication, 192-bit encryption, forward secrecy, protection against offline dictionary attacks) while maintaining backward compatibility with 2018 legacy devices that only support WPA2. This mixed mode satisfies both security and compatibility requirements. WPA2-Enterprise provides strong security through 802.1X but lacks WPA3 protections against password-guessing attacks and does not provide forward secrecy. WPA3-Personal offers the strongest security but would block legacy devices from 2018 that lack WPA3 support, violating the compatibility requirement. WPA3-Enhanced Open is designed for public networks without passwords using Opportunistic Wireless Encryption, not for password-protected conference networks requiring user authentication.
3. A security operations center monitors network traffic and identifies an attack where an adversary intercepts communication between a client and server, positioning themselves in the communication path to eavesdrop or modify traffic. The attacker uses ARP spoofing to redirect traffic through their system before forwarding it to the legitimate destination. Which attack type is being executed, and what protocol-level defense can prevent it on the local network? (Select one!)
Explanation
Man-in-the-Middle (MITM) attacks involve an adversary intercepting communication between two parties, with ARP spoofing being a common technique on local networks to redirect traffic. Dynamic ARP Inspection (DAI) is a switch security feature that validates ARP packets against a trusted binding table, preventing ARP spoofing attacks by dropping invalid ARP responses. DDoS attacks flood resources with traffic rather than intercepting communications. SQL injection targets database queries through malicious input. XSS exploits client-side scripting vulnerabilities. While TLS encryption provides end-to-end defense against MITM attacks, Dynamic ARP Inspection specifically prevents the ARP spoofing technique used to enable MITM at the data link layer.
4. A database administrator at AnalyticsCorp is designing an ETL pipeline to load sales data from multiple regional stores into a central data warehouse. The source data comes from MySQL databases at 200 store locations with varying network bandwidth. The warehouse uses a cloud-based columnar database optimized for analytical queries. The pipeline must transform data including currency conversion, date standardization, and product code mapping. Where should the transformation step occur for optimal performance? (Select one!)
Explanation
ELT approach loading raw data first then transforming in the cloud warehouse is optimal for cloud-based columnar databases. Cloud warehouses provide scalable compute for transformations, columnar storage enables efficient analytical processing, and this minimizes data transfer time from 200 locations. Traditional ETL with staging servers adds infrastructure cost and latency. Transforming at source stores burdens operational databases and consumes limited network bandwidth with complex processing. Transforming during queries creates unacceptable query performance for repeated analytical access.
5. A statistics team is analyzing customer satisfaction survey data that shows extreme outliers where a few customers gave unusually low ratings. The team needs to calculate a measure of central tendency that best represents typical customer satisfaction without being skewed by these outliers. Which statistical measure should they use? (Select one!)
Explanation
Median is resistant to outliers because it represents the middle value when data is sorted, making it the best choice when extreme values exist. Mean is heavily influenced by outliers and would be pulled down by the unusually low ratings. Mode shows the most common value but may not represent central tendency if the distribution is uniform or multimodal. Range measures spread, not central tendency, and is actually maximally affected by outliers.
Yes. ISACA states the ITCA certification is retired, though maintenance remains available for existing holders. New candidates can no longer earn the full ITCA designation by stacking the five fundamentals certificates.
Yes. ISACA will sunset the Cybersecurity Fundamentals Certificate program on 1 June 2027, and the last day to purchase the exam or exam prep is 1 December 2026. ISACA points new candidates to its Certified Cybersecurity Specialist (CCS) as the successor.
ISACA's Certified Cybersecurity Specialist (CCS), a vendor-neutral certification for early-career professionals and IT staff moving into cybersecurity. It covers three domains (Cybersecurity Principles and Techniques, Security Operations, Secure By Design) and launched in beta at $199.
48 questions worth 60 points: 36 multiple-choice questions at 1 point each plus 12 performance-based lab questions at 2 points each, with a 2-hour time limit.
65 percent, which works out to roughly 39 of the 60 available points. It is a straight percentage threshold, not a scaled score.
$120 for ISACA members. ISACA's certificate page lists $144 for non-members, while its April 2025 exam guide lists $150, so confirm the current non-member price at checkout.
Four domains: Securing Assets (35%), Information Security Fundamentals (27%), Security Operations and Response (20%), and Threat Landscape (18%).
ISACA allows 4 attempts within a rolling 12-month period, paying the full exam fee each time. You must wait 30 days before your second attempt and 90 days before each of the third and fourth attempts.
Cybersecurity Fundamentals Certificate
CyberSec-Fund · 596 questions
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
$17.99
One-time access to this exam