ISACA · ITCA
Entry-level certification that validates fundamental knowledge in cybersecurity concepts, one of five certificates in the ITCA program.
Practice Questions
596
≈ 3 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Jul 2026
ISACA has retired the Information Technology Certified Associate (ITCA) certification for new candidates. The program originally bundled five fundamentals certificates, covering computing, networking and infrastructure, cybersecurity, software development, and data science, and awarded the full ITCA designation to anyone who passed all five. That pathway is now closed: existing holders can still maintain the credential, but nobody new can earn it. The one component still sold on its own is the Cybersecurity Fundamentals Certificate, and even that is on a clock. ISACA stops selling the exam on 1 December 2026 and sunsets the program on 1 June 2027, pointing new candidates to its Certified Cybersecurity Specialist (CCS) as the successor.
If you register before the cutoff, the current exam is 48 questions: 36 multiple choice worth 1 point each and 12 performance-based lab questions worth 2 points each, for 60 points total. You get 2 hours, and passing requires 65 percent, which works out to roughly 39 points. Securing Assets is the heaviest domain at 35 percent, followed by Information Security Fundamentals at 27 percent, Security Operations and Response at 20 percent, and Threat Landscape at 18 percent. The exam costs $120 for ISACA members and $144 for non-members, has no prerequisites, and runs online with remote proctoring through PSI.
Because the lab questions carry double points, 40 percent of the marks come from hands-on tasks rather than recall, so drill the multiple-choice side until it is automatic and keep time in reserve for the labs. Start with the 30 free questions here, then work through the full 596-question bank with explanations until your accuracy holds above 65 percent in Securing Assets and Information Security Fundamentals, the two domains that together decide 62 percent of your score.
The ISACA Cybersecurity Fundamentals Certificate is one of five stackable credentials that together comprise the Information Technology Certified Associate (ITCA) program. It validates foundational knowledge of cybersecurity principles, threat landscapes, asset security, and security operations — the core competencies required to begin a career protecting enterprise data and infrastructure. The exam blends knowledge-based multiple-choice questions with performance-based questions delivered in a virtual lab environment, ensuring candidates can demonstrate practical ability alongside theoretical understanding.
The certificate began as one of five stackable ITCA credentials, but ISACA has since retired the full ITCA certification for new applicants, and the Cybersecurity Fundamentals Certificate itself is being sunset: the last day to purchase the exam is 1 December 2026 and the program closes on 1 June 2027, with ISACA naming its Certified Cybersecurity Specialist (CCS) as the successor. The certificate does not expire for those who earn it and awards 9.5 CPE credits when the accompanying course is completed.
This certificate is designed for individuals at the very beginning of their IT or cybersecurity career journey, including recent graduates, college students, and professionals from non-technical fields looking to transition into cybersecurity. No prior work experience in IT is required, making it accessible to career changers who want a recognized credential to validate self-taught or academic knowledge.
It is also well-suited for IT generalists, help desk technicians, or junior administrators who want to formalize their cybersecurity knowledge and differentiate themselves for roles such as security analyst, IT support specialist, or junior SOC analyst. Organizations may also use it as a structured upskilling tool for existing technical teams.
There are no formal prerequisites for the Cybersecurity Fundamentals certificate. Candidates can register and sit for the exam at any time without prior certifications, work experience documentation, or educational requirements — distinguishing it from ISACA's more advanced credentials such as CISM or CISA.
While no prerequisites are mandated, candidates will benefit from a basic familiarity with computing concepts, networking fundamentals, and general IT terminology before attempting the exam. ISACA offers an optional self-paced online course (9.5 CPE credits) and a study guide authored by subject-matter experts to help candidates without a formal cybersecurity background build the necessary knowledge before sitting for the exam.
The exam consists of 48 questions delivered in a computer-based, remotely proctored format: 36 knowledge-based multiple-choice questions worth 1 point each and 12 performance-based questions worth 2 points each, set within a virtual lab environment, for 60 points in total. The time limit is 120 minutes, and a passing score of 65% (roughly 39 points) is required.
The exam is available continuously through ISACA's proctoring partner PSI. Candidates can schedule as early as 48 hours after payment, and free rescheduling is permitted with at least 48 hours' notice. Your eligibility window starts at registration; ISACA's certificate page currently lists six months. Up to 4 attempts are allowed in a rolling 12-month period, paying the full fee each time. Exam fees are US$120 for ISACA members and US$144 for non-members.
Earning the Cybersecurity Fundamentals certificate signals to employers that a candidate has verified, baseline competency in protecting systems and data — a quality increasingly valued even for non-security IT roles. It serves as a credible entry point for positions such as junior security analyst, SOC tier-1 analyst, IT support specialist, or cybersecurity technician, particularly at organizations that recognize ISACA credentials (common in financial services, government, and enterprise technology sectors).
As a standalone certificate it complements ISACA's advanced certifications (CISM, CISA, CRISC), providing a documented foundation that can accelerate a candidate's path toward those credentials. The full five-badge ITCA certification is now retired for new applicants, so the Cybersecurity Fundamentals Certificate stands on its own, and candidates planning beyond the program's 1 June 2027 sunset can treat it as a bridge toward ISACA's successor credential, the Certified Cybersecurity Specialist (CCS).
5 sample questions with answers and explanations. The full bank has 596 questions, enough for 3 full-length practice exams.
Preview — answers shown1. A storage administrator designs a RAID array for a database server requiring high write performance. The team tests RAID 5 with six disks where each disk delivers 200 IOPS. Application monitoring shows actual write performance of only 300 IOPS total. What causes this performance degradation? (Select one!)
Explanation
RAID 5 has a write penalty of 4x because each write requires four operations: read old data block, read old parity block, write new data block, write new parity block. With six disks at 200 IOPS each (1200 total IOPS), the effective write performance is 1200/4 = 300 IOPS, matching the observed performance. This penalty exists because parity must be recalculated using XOR operations for every write. Cache memory might improve performance but does not explain the specific 4x degradation. Network bandwidth would affect all operations equally. Disk fragmentation affects HDDs but the calculation matches the RAID 5 write penalty exactly.
2. A cybersecurity team implements the NIST Cybersecurity Framework 2.0 to improve the organization's security posture. The CISO establishes a cybersecurity risk management strategy, defines roles and responsibilities across departments, integrates cybersecurity requirements into enterprise risk management processes, and establishes policies for supply chain risk assessment. These activities align with which core function of the NIST CSF 2.0? (Select one!)
Explanation
Govern function is correct because it was newly introduced in NIST CSF 2.0 as the sixth core function and specifically addresses organizational cybersecurity risk management strategy, roles and responsibilities, policies, and oversight. Govern sits at the center of the framework and influences all other functions by establishing the organizational context, strategic direction, and priorities for cybersecurity risk management including supply chain risk. The activities described—establishing strategy, defining roles, integrating with enterprise risk management, and supply chain policies—are all governance activities. Identify function focuses on developing organizational understanding of systems, assets, data, and capabilities to manage cybersecurity risk, not on establishing governance structures and policies. Protect function implements technical and administrative safeguards to limit or contain cybersecurity events. Detect function develops and implements activities to identify occurrence of cybersecurity events through monitoring and detection processes.
3. A data analyst performs exploratory data analysis on a dataset containing employee salaries with the following values in thousands: 45, 48, 50, 52, 53, 55, 58, 60, 62, 250. The mean salary is significantly higher than most values due to one executive's compensation. Which measure of central tendency should the analyst use for salary reporting? (Select one!)
Explanation
Median is the most appropriate measure for skewed distributions with outliers because it represents the middle value when data is sorted, providing a better representation of typical salary (approximately 54) compared to the mean which is heavily influenced by the 250 value. The mean is mathematically accurate but misleading in skewed distributions, reporting approximately 73.3 which is higher than 90% of actual salaries. Mode identifies the most frequent value which may not exist or be representative in continuous salary data. Range measures dispersion (spread) from 45 to 250, not central tendency, and does not indicate typical values.
4. A financial institution's security operations center receives an alert from the Security Information and Event Management (SIEM) system indicating a correlation pattern matching potential credential stuffing attack. The SIEM detected 10,000 failed login attempts from 200 different IP addresses targeting customer accounts over a 30-minute period, with username-password pairs appearing to come from a previously breached credential database. Which two SIEM capabilities enabled detection of this attack pattern? (Select two!)
Multiple correct answersExplanation
Log aggregation is correct because SIEM systems collect and centralize logs from distributed sources including web application servers, authentication systems, firewalls, and other security devices. Without aggregating authentication logs from multiple servers, the SIEM could not analyze the full scope of login attempts occurring across the infrastructure. Event correlation is correct because it analyzes relationships and patterns across multiple events to detect complex attacks that individual events would not reveal. Correlating failed logins across different source IPs targeting multiple accounts within a compressed timeframe matches the signature of credential stuffing attacks using distributed infrastructure. Vulnerability scanning identifies system weaknesses and missing patches but does not detect active attack attempts based on authentication log patterns. Packet capture provides network traffic forensics but does not perform the log analysis and pattern correlation required to identify credential stuffing attacks from authentication events. Firewall rule enforcement is a prevention control that blocks traffic based on configured rules but does not provide the detection and analysis capabilities that identified the attack pattern.
5. A network engineer troubleshoots connectivity issues between two branch offices connected via IPsec VPN over the internet. The VPN tunnel establishes successfully, but encrypted traffic fails to pass through a newly installed NAT gateway. Which IPsec component and port are required for NAT traversal to function correctly? (Select one!)
Explanation
ESP (Encapsulating Security Payload) protocol provides encryption and integrity for IPsec VPN traffic, and UDP port 4500 is specifically designed for NAT traversal (NAT-T) which encapsulates ESP packets inside UDP to pass through NAT devices. UDP port 500 is used for IKE (Internet Key Exchange) negotiation but not for NAT traversal. AH (Authentication Header) protocol does not support NAT traversal because it includes the IP header in its integrity check, which breaks when NAT modifies IP addresses.
Yes. ISACA states the ITCA certification is retired, though maintenance remains available for existing holders. New candidates can no longer earn the full ITCA designation by stacking the five fundamentals certificates.
Yes. ISACA will sunset the Cybersecurity Fundamentals Certificate program on 1 June 2027, and the last day to purchase the exam or exam prep is 1 December 2026. ISACA points new candidates to its Certified Cybersecurity Specialist (CCS) as the successor.
ISACA's Certified Cybersecurity Specialist (CCS), a vendor-neutral certification for early-career professionals and IT staff moving into cybersecurity. It covers three domains (Cybersecurity Principles and Techniques, Security Operations, Secure By Design) and launched in beta at $199.
48 questions worth 60 points: 36 multiple-choice questions at 1 point each plus 12 performance-based lab questions at 2 points each, with a 2-hour time limit.
65 percent, which works out to roughly 39 of the 60 available points. It is a straight percentage threshold, not a scaled score.
$120 for ISACA members. ISACA's certificate page lists $144 for non-members, while its April 2025 exam guide lists $150, so confirm the current non-member price at checkout.
Four domains: Securing Assets (35%), Information Security Fundamentals (27%), Security Operations and Response (20%), and Threat Landscape (18%).
ISACA allows 4 attempts within a rolling 12-month period, paying the full exam fee each time. You must wait 30 days before your second attempt and 90 days before each of the third and fourth attempts.
Cybersecurity Fundamentals Certificate
CyberSec-Fund · 596 questions
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
$17.99
One-time access to this exam