ISACA · ITCA
Entry-level certification that validates fundamental knowledge in cybersecurity concepts, one of five certificates in the ITCA program.
Practice Questions
596
≈ 3 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Jul 2026
ISACA has retired the Information Technology Certified Associate (ITCA) certification for new candidates. The program originally bundled five fundamentals certificates, covering computing, networking and infrastructure, cybersecurity, software development, and data science, and awarded the full ITCA designation to anyone who passed all five. That pathway is now closed: existing holders can still maintain the credential, but nobody new can earn it. The one component still sold on its own is the Cybersecurity Fundamentals Certificate, and even that is on a clock. ISACA stops selling the exam on 1 December 2026 and sunsets the program on 1 June 2027, pointing new candidates to its Certified Cybersecurity Specialist (CCS) as the successor.
If you register before the cutoff, the current exam is 48 questions: 36 multiple choice worth 1 point each and 12 performance-based lab questions worth 2 points each, for 60 points total. You get 2 hours, and passing requires 65 percent, which works out to roughly 39 points. Securing Assets is the heaviest domain at 35 percent, followed by Information Security Fundamentals at 27 percent, Security Operations and Response at 20 percent, and Threat Landscape at 18 percent. The exam costs $120 for ISACA members and $144 for non-members, has no prerequisites, and runs online with remote proctoring through PSI.
Because the lab questions carry double points, 40 percent of the marks come from hands-on tasks rather than recall, so drill the multiple-choice side until it is automatic and keep time in reserve for the labs. Start with the 30 free questions here, then work through the full 596-question bank with explanations until your accuracy holds above 65 percent in Securing Assets and Information Security Fundamentals, the two domains that together decide 62 percent of your score.
The ISACA Cybersecurity Fundamentals Certificate is one of five stackable credentials that together comprise the Information Technology Certified Associate (ITCA) program. It validates foundational knowledge of cybersecurity principles, threat landscapes, asset security, and security operations — the core competencies required to begin a career protecting enterprise data and infrastructure. The exam blends knowledge-based multiple-choice questions with performance-based questions delivered in a virtual lab environment, ensuring candidates can demonstrate practical ability alongside theoretical understanding.
The certificate began as one of five stackable ITCA credentials, but ISACA has since retired the full ITCA certification for new applicants, and the Cybersecurity Fundamentals Certificate itself is being sunset: the last day to purchase the exam is 1 December 2026 and the program closes on 1 June 2027, with ISACA naming its Certified Cybersecurity Specialist (CCS) as the successor. The certificate does not expire for those who earn it and awards 9.5 CPE credits when the accompanying course is completed.
This certificate is designed for individuals at the very beginning of their IT or cybersecurity career journey, including recent graduates, college students, and professionals from non-technical fields looking to transition into cybersecurity. No prior work experience in IT is required, making it accessible to career changers who want a recognized credential to validate self-taught or academic knowledge.
It is also well-suited for IT generalists, help desk technicians, or junior administrators who want to formalize their cybersecurity knowledge and differentiate themselves for roles such as security analyst, IT support specialist, or junior SOC analyst. Organizations may also use it as a structured upskilling tool for existing technical teams.
There are no formal prerequisites for the Cybersecurity Fundamentals certificate. Candidates can register and sit for the exam at any time without prior certifications, work experience documentation, or educational requirements — distinguishing it from ISACA's more advanced credentials such as CISM or CISA.
While no prerequisites are mandated, candidates will benefit from a basic familiarity with computing concepts, networking fundamentals, and general IT terminology before attempting the exam. ISACA offers an optional self-paced online course (9.5 CPE credits) and a study guide authored by subject-matter experts to help candidates without a formal cybersecurity background build the necessary knowledge before sitting for the exam.
The exam consists of 48 questions delivered in a computer-based, remotely proctored format: 36 knowledge-based multiple-choice questions worth 1 point each and 12 performance-based questions worth 2 points each, set within a virtual lab environment, for 60 points in total. The time limit is 120 minutes, and a passing score of 65% (roughly 39 points) is required.
The exam is available continuously through ISACA's proctoring partner PSI. Candidates can schedule as early as 48 hours after payment, and free rescheduling is permitted with at least 48 hours' notice. Your eligibility window starts at registration; ISACA's certificate page currently lists six months. Up to 4 attempts are allowed in a rolling 12-month period, paying the full fee each time. Exam fees are US$120 for ISACA members and US$144 for non-members.
Earning the Cybersecurity Fundamentals certificate signals to employers that a candidate has verified, baseline competency in protecting systems and data — a quality increasingly valued even for non-security IT roles. It serves as a credible entry point for positions such as junior security analyst, SOC tier-1 analyst, IT support specialist, or cybersecurity technician, particularly at organizations that recognize ISACA credentials (common in financial services, government, and enterprise technology sectors).
As a standalone certificate it complements ISACA's advanced certifications (CISM, CISA, CRISC), providing a documented foundation that can accelerate a candidate's path toward those credentials. The full five-badge ITCA certification is now retired for new applicants, so the Cybersecurity Fundamentals Certificate stands on its own, and candidates planning beyond the program's 1 June 2027 sunset can treat it as a bridge toward ISACA's successor credential, the Certified Cybersecurity Specialist (CCS).
5 sample questions with answers and explanations. The full bank has 596 questions, enough for 3 full-length practice exams.
Preview — answers shown1. A DevOps team is implementing agile methodology using Scrum framework. The product owner has identified 50 user stories for the next release. The team needs to plan work for a two-week iteration. What is this two-week iteration called in Scrum? (Select one!)
Explanation
A Sprint is the Scrum term for a time-boxed iteration, typically 1-4 weeks (in this case, two weeks), during which the team completes a potentially shippable product increment. The sprint is the fundamental unit of development in Scrum. A Release is a larger deployment of multiple sprints' work to production. An Increment is the sum of all completed product backlog items during a sprint, representing the deliverable output, not the time period. An Epic is a large user story that spans multiple sprints and needs to be broken down into smaller stories. Only Sprint correctly describes the two-week iteration time period.
2. A data analyst examines quarterly revenue data from 50 retail stores and calculates that 68 percent of stores fall between $450,000 and $550,000 in revenue. Assuming normal distribution, what is the standard deviation of the revenue distribution? (Select one!)
Explanation
In a normal distribution, 68 percent of values fall within one standard deviation of the mean according to the 68-95-99.7 rule. The range from $450,000 to $550,000 spans $100,000 total, which represents two standard deviations, one above and one below the mean of $500,000. Therefore, one standard deviation equals $50,000. A $25,000 standard deviation would only span $50,000 total, not matching the range. A $75,000 standard deviation would span $150,000. A $100,000 standard deviation would span $200,000 and represent the full range rather than one standard deviation.
3. A software development team follows Agile Scrum methodology. The team completes a two-week sprint and needs to demonstrate the increment to stakeholders and gather feedback. Which Scrum ceremony serves this purpose? (Select one!)
Explanation
Sprint Review is the Scrum ceremony where the team demonstrates the completed increment to stakeholders and gathers feedback. During Sprint Review, the development team presents working software produced during the sprint, stakeholders examine functionality, and participants discuss what was accomplished and what should be done next. This ceremony enables inspection and adaptation of the product, ensuring alignment with stakeholder expectations and allowing course correction based on feedback. Sprint Review is typically time-boxed to one hour per week of sprint length, so a two-week sprint would have a two-hour Sprint Review. Sprint Planning occurs at the beginning of the sprint where the team selects work from the product backlog and plans sprint execution. Daily Standup is a brief daily synchronization meeting where team members share progress, plans, and impediments. Sprint Retrospective occurs after Sprint Review and focuses on process improvement, where the team reflects on how they worked together and identifies improvements for the next sprint. Each ceremony serves distinct purposes in the Scrum framework, with Sprint Review specifically designed for stakeholder demonstration and product feedback.
4. An organization implements the NIST Cybersecurity Framework 2.0. Management wants to establish cybersecurity governance policies, define risk management strategy, and identify supply chain security requirements. Which framework function addresses these activities? (Select one!)
Explanation
Govern is the new sixth function added in NIST CSF 2.0 that specifically addresses cybersecurity governance, risk management strategy, policies, and supply chain risk management at the organizational level. It establishes the foundation for the other five functions. Identify focuses on asset management and risk assessment of specific assets. Protect implements safeguards like access control and encryption. Detect handles continuous monitoring and anomaly detection for security events.
5. A Git developer is working on a feature branch and needs to incorporate recent changes from the main branch. The developer wants to maintain a linear commit history without merge commits. Which Git command should they use? (Select one!)
Explanation
git rebase main reapplies the feature branch commits on top of the latest main branch commits, creating a linear history without merge commits. Rebase rewrites commit history by moving the entire feature branch to begin at the current tip of main. git merge main creates a merge commit that combines the branches, resulting in a non-linear history with a visible merge point. git pull origin main fetches and merges changes, which also creates merge commits rather than a linear history. git cherry-pick is for selectively applying individual commits, not for incorporating an entire branch's changes.
Yes. ISACA states the ITCA certification is retired, though maintenance remains available for existing holders. New candidates can no longer earn the full ITCA designation by stacking the five fundamentals certificates.
Yes. ISACA will sunset the Cybersecurity Fundamentals Certificate program on 1 June 2027, and the last day to purchase the exam or exam prep is 1 December 2026. ISACA points new candidates to its Certified Cybersecurity Specialist (CCS) as the successor.
ISACA's Certified Cybersecurity Specialist (CCS), a vendor-neutral certification for early-career professionals and IT staff moving into cybersecurity. It covers three domains (Cybersecurity Principles and Techniques, Security Operations, Secure By Design) and launched in beta at $199.
48 questions worth 60 points: 36 multiple-choice questions at 1 point each plus 12 performance-based lab questions at 2 points each, with a 2-hour time limit.
65 percent, which works out to roughly 39 of the 60 available points. It is a straight percentage threshold, not a scaled score.
$120 for ISACA members. ISACA's certificate page lists $144 for non-members, while its April 2025 exam guide lists $150, so confirm the current non-member price at checkout.
Four domains: Securing Assets (35%), Information Security Fundamentals (27%), Security Operations and Response (20%), and Threat Landscape (18%).
ISACA allows 4 attempts within a rolling 12-month period, paying the full exam fee each time. You must wait 30 days before your second attempt and 90 days before each of the third and fourth attempts.
Cybersecurity Fundamentals Certificate
CyberSec-Fund · 596 questions
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
$17.99
One-time access to this exam