ISACA · IoT-Fund
Validates foundational knowledge of Internet of Things technology, covering IoT network components, sensors and actuators, middleware, physical security systems, data authentication and protection methods, and IoT architecture elements.
Practice Questions
630
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Feb 2026
Use this IoT-Fund practice exam to prepare for IoT Fundamentals Certificate with realistic questions, detailed explanations, and focused study modes. The practice bank includes 630 questions for ISACA IoT-Fund, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The ISACA IoT Fundamentals Certificate validates foundational knowledge of Internet of Things concepts and the technologies that enable IoT ecosystems. The exam assesses a candidate's understanding of IoT network architecture, the roles of sensors and actuators, middleware functionality, physical security systems, and data authentication and protection methods. It is part of ISACA's Certified in Emerging Technology (CET) Certification program, which encompasses four certificate exams — Cloud Computing Fundamentals, Blockchain Fundamentals, IoT Fundamentals, and AI Fundamentals — that together constitute the full CET credential.
The certification employs a hybrid assessment model, combining traditional knowledge-based multiple-choice questions with performance-based questions delivered in a live virtual lab environment. This approach ensures candidates can not only articulate IoT principles but also demonstrate practical skills in applying IoT technologies. The exam covers real-world IoT use cases across industries including healthcare, government, utilities, and enterprise operations, with particular emphasis on security risks and governance considerations.
The IoT Fundamentals Certificate is designed for individuals at the beginning of their IoT journey, including students, recent graduates, and career changers seeking to establish credibility in emerging technology domains. IT professionals looking to broaden their skills into IoT, as well as cybersecurity, risk, and audit professionals who need to evaluate IoT environments and their associated controls, are well-suited for this credential.
Technical and business analysts who bridge IoT technology with organizational strategy, consultants and solution architects advising on IoT implementations, and government or utility professionals working on smart infrastructure initiatives are also prime candidates. Because there are no prerequisites, the exam is accessible to anyone with a foundational interest in IoT, regardless of prior formal technology credentials.
ISACA imposes no formal prerequisites for the IoT Fundamentals Certificate. Candidates can register at any time without meeting prior educational or professional requirements, making it one of the most accessible entry points in ISACA's credentialing portfolio.
While no prior experience is required, candidates with a basic familiarity with networking concepts, general IT infrastructure, and cybersecurity principles will find the material more approachable. ISACA recommends using its official preparation resources — the self-guided online course, the lab package, and the study guide — to build the necessary foundational knowledge before attempting the exam.
The IoT Fundamentals exam consists of 60 questions delivered in a computer-based, remotely proctored format over a 2-hour time limit. Questions blend traditional knowledge-based multiple-choice items with performance-based questions set in a virtual lab environment, assessing both conceptual understanding and practical application. Candidates must achieve a passing score of 65% or higher.
The exam is administered online with continuous registration — there are no restricted testing windows. Exam eligibility is valid for 12 months from the date of registration, and appointments can be scheduled as early as 48 hours after payment. Candidates receive four total attempts within any rolling 12-month period. Rescheduling is permitted without penalty provided at least 48 hours' notice is given.
Earning the IoT Fundamentals Certificate signals to employers a verified, vendor-neutral understanding of IoT concepts validated by ISACA, a globally recognized IT governance and cybersecurity credentialing body. The certificate serves as a stepping stone toward ISACA's full Certified in Emerging Technology (CET) Certification, which requires passing all four CET-track exams (Cloud Computing, Blockchain, IoT, and AI Fundamentals) and submitting an application. Holding the CET designation positions professionals across roles such as IoT solution architect, cybersecurity analyst, IT risk consultant, technical analyst, and smart infrastructure engineer.
The IoT market continues to expand rapidly across sectors including industrial automation, healthcare, smart cities, and connected consumer devices, driving consistent enterprise demand for professionals who can evaluate IoT risk and governance. While salary data specific to this certificate is not published by ISACA, professionals who pair this credential with broader cybersecurity or cloud certifications — such as ISACA's CISM or CISA — report enhanced positioning for mid-to-senior roles in IT audit, risk management, and emerging technology advisory functions.
5 sample questions with answers and explanations. The full bank has 630 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An IoT device development team selects an operating system specifically designed for networked, memory-constrained embedded systems with focus on low-power wireless communication protocols and IPv6 support. The OS must be open-source for academic and commercial IoT research. Which IoT operating system meets these requirements? (Select one!)
Explanation
Contiki is an open-source operating system specifically designed for networked, memory-constrained embedded systems in IoT applications. It provides IPv6 support, low-power wireless protocols, and runs on devices with minimal resources, making it ideal for IoT research and development. Ubuntu Server is a general-purpose Linux distribution too resource-intensive for memory-constrained embedded systems. Fedora Workstation with desktop environment requires significant resources unsuitable for embedded devices. Windows 10 IoT Enterprise, while designed for IoT, requires more resources than constrained embedded systems can provide and is not open-source.
2. A warehouse automation system architect must choose between Zigbee and Z-Wave for connecting 45,000 inventory tracking sensors across a 500,000 square foot facility. The sensors will form a mesh network with battery-powered end devices and mains-powered routers. Which protocol should be selected and why? (Select one!)
Explanation
Zigbee is correct because it supports 65,000+ nodes per network, which accommodates the 45,000 sensors required, and implements mesh topology allowing routers to extend range across the large facility. Zigbee uses IEEE 802.15.4 with coordinator, router, and end device roles suitable for the described architecture. Z-Wave is limited to 232 nodes per network, which is insufficient for 45,000 sensors even with multiple networks adding complexity. Z-Wave Long Range supports up to 4,000 nodes but uses star topology requiring all devices to communicate directly with the hub, impractical for a 500,000 square foot facility needing range extension. Zigbee operates primarily on 2.4 GHz globally, not sub-1 GHz, though regional variants exist at 868 MHz (EU) and 915 MHz (Americas).
3. An industrial facility implements IEC 62443 security standards for its SCADA system controlling critical infrastructure. The system must protect against intentional attacks using sophisticated means with moderate resources and skills. Which Security Level (SL) should be implemented? (Select one!)
Explanation
IEC 62443 Security Level 3 (SL-3) is designed to protect against intentional violations using sophisticated means with moderate resources and skills, which aligns with the requirements for critical infrastructure SCADA systems. SL-1 only protects against casual or accidental violations. SL-2 protects against simple intentional attacks with low resources. SL-4 provides the highest protection against nation-state level attacks with extended resources, which exceeds the stated requirements and would be more costly to implement.
4. A healthcare IoMT deployment must comply with HIPAA requiring FIPS 140-2 validated encryption for Protected Health Information. The system uses wearable devices transmitting biometric data to cloud storage. Which encryption implementation satisfies HIPAA technical safeguards? (Select one!)
Explanation
AES-256 with TLS 1.3 using FIPS 140-2 validated cryptographic modules is correct because HIPAA explicitly requires FIPS 140-2 validation for cryptographic implementations protecting PHI. AES-256 provides strong encryption and TLS 1.3 ensures secure data in transit. The FIPS validation ensures the cryptographic module meets federal standards required by HIPAA technical safeguards (45 CFR 164.312). ChaCha20-Poly1305 is a strong modern cipher but without FIPS 140-2 validation it does not meet HIPAA requirements. RSA 1024-bit is cryptographically weak by current standards and below the recommended 2048-bit minimum. Proprietary encryption algorithms lack peer review, FIPS validation, and are explicitly discouraged by security standards.
5. A food processing facility monitors temperature and humidity in refrigerated storage using wireless sensors. The deployment requires 500 sensors across multiple buildings with minimal infrastructure. Which Zigbee device role is responsible for forming the network, storing security keys, and assigning network addresses? (Select one!)
Explanation
Zigbee Coordinator is correct because this device role forms the network, stores security keys, assigns 16-bit network addresses to joining devices, and acts as the trust center. Each Zigbee network has exactly one coordinator that initiates network formation. Zigbee Routers extend range and relay data but cannot form networks or assign addresses. Zigbee End Devices are sensors or actuators that join the network but do not perform network management. Zigbee Gateway is not a standard Zigbee device role; gateways translate between Zigbee and other protocols but the coordinator manages the Zigbee network itself.
Data Science Fundamentals Certificate
DataSci-Fund · 591 questions
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
Information Technology Certified Associate (ITCA)
ITCA · 596 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
$17.99
One-time access to this exam