ISACA · IT-Audit-Fund
Validates foundational IT audit knowledge, covering audit performance, IT environment and components, specific audit subjects, newer technologies, controls and risk, and the audit function, including IT audit terminology, concepts, and general practices.
Practice Questions
627
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Jul 2026
The IT Audit Fundamentals Certificate is ISACA's entry point into IT audit, launched in 2022 for people with no prior audit experience. The exam weights six domains: Performing an Audit is by far the largest at 35 percent, followed by IT Environment and Components at 25 percent, Specific Audit Subjects at 15 percent, Overview of Newer Technologies (AI, blockchain, cloud, IoT) at 12 percent, Controls, Risk and Audit at 8 percent, and The Audit Function at 5 percent. This question bank mirrors those weights, so most of your practice time lands on planning, executing, and documenting audits and on the infrastructure components an auditor actually evaluates.
The exam itself costs $175 for ISACA members and $225 for non-members, runs 2 hours as a remotely proctored computer-based test, and requires 65 percent or higher to pass. It blends standard multiple-choice questions with interactive, performance-based ones that simulate audit tasks, and your registration gives you a six-month eligibility window with appointments available as soon as 48 hours after payment. There are no prerequisites, so career changers and recent graduates can register immediately.
Unlike CISA, which demands five years of experience and ongoing CPE renewal, this certificate is earned once and positions you for entry-level IT auditor, compliance analyst, and IT controls roles. It is the natural first step on the path to CISA. Benchmark yourself with the 30 free questions, then drill the full 627-question bank with detailed explanations until you hold steady above 65 percent across all six domains.
The ISACA IT Audit Fundamentals Certificate is a foundational-level credential that validates knowledge of core IT audit terminology, concepts, and general practices across six functional domains. It covers the full audit lifecycle—from understanding the audit function and organizational controls to performing audits and evaluating specific IT subjects such as networking, operating systems, and IT general controls. The certificate was introduced by ISACA in 2022 to address growing demand for entry-level IT audit professionals and provides a structured foundation for those entering the field.
The program blends knowledge-based and performance-based learning, reflecting real-world audit skills rather than pure theoretical recall. It specifically addresses newer technologies including artificial intelligence (AI), blockchain, and the Internet of Things (IoT), ensuring candidates are equipped to audit modern IT environments. Successful candidates earn a digital badge through ISACA's Credly platform and a recognized certificate, positioning them as credible candidates for IT audit roles.
This certificate is designed for early-career professionals seeking to enter the IT audit field, as well as IT practitioners—such as system administrators, network engineers, and security specialists—who want to transition into audit roles. It is equally relevant for internal and external auditors with limited IT audit exposure, compliance officers who need to understand IT audit processes, and risk management personnel who work alongside audit teams.
Because no prior IT audit experience is required, the certificate also suits recent graduates in information systems, accounting, or cybersecurity programs who want a recognized credential to support job applications. It serves as a clearly defined first step toward the CISA (Certified Information Systems Auditor) certification, ISACA's globally recognized advanced credential for IT auditors.
There are no formal prerequisites for the IT Audit Fundamentals Certificate. Candidates can register at any time without needing to demonstrate prior work experience or hold any other certification. This open eligibility makes it accessible to career changers, students, and early-career professionals alike.
While no prerequisites are required, candidates will benefit from a basic familiarity with IT concepts such as networks, operating systems, and databases, as the exam covers IT environment components at a foundational level. A general understanding of business processes and organizational risk management practices will also help candidates contextualize the audit concepts covered across the six exam domains.
The IT Audit Fundamentals exam is delivered online via remote proctoring and has a time limit of 120 minutes. It combines two question types: traditional multiple-choice (knowledge-based) questions and interactive performance-based questions that simulate real audit scenarios. The exact total number of scored questions is not publicly disclosed by ISACA.
Candidates must achieve a passing score of 65% or higher. Exam eligibility is valid for 12 months from the date of registration, and testing appointments can be scheduled as early as 48 hours after payment. There is no penalty for rescheduling as long as changes are made at least 48 hours before the scheduled appointment. Exam fees are $175 USD for ISACA members and $225 USD for non-members.
The IT Audit Fundamentals Certificate positions holders for entry-level IT audit roles at a time when demand for audit professionals is expanding alongside growth in cyberattacks, cloud adoption, and regulatory compliance requirements. Entry-level IT auditor salaries in the United States range from approximately $57,000 to $78,000 annually, with Glassdoor data placing average entry-level compensation around $74,658. Salaries increase substantially with experience, reaching roughly $88,932 for professionals with 4–6 years of experience and over $119,000 for senior practitioners. Common entry-level roles for certificate holders include IT Auditor, Junior Risk Analyst, Compliance Analyst, and IT Controls Analyst.
Beyond immediate job placement, the certificate serves as a recognized stepping stone to the CISA certification — the global gold standard for IT auditors — giving holders a structured credential pathway. ISACA's digital badge, issued via Credly, allows professionals to display the credential on LinkedIn and resumes for employer recognition. For organizations, the certificate validates that team members have a standardized, vendor-neutral foundation in IT audit practices, making it valuable for upskilling internal audit, risk, and compliance teams.
5 sample questions with answers and explanations. The full bank has 627 questions, enough for 4 full-length practice exams.
Preview — answers shown1. During a business continuity audit, the auditor reviews BC testing documentation and finds the organization conducts annual walk-through exercises where participants discuss recovery procedures without actual system failover. The organization's critical systems have 1-hour RTO requirements. What should the auditor recommend? (Select one!)
Explanation
Walk-through or tabletop exercises only validate that team members understand procedures on paper but do not test actual technical recovery capabilities, resource adequacy, or ability to meet RTO requirements. With critical 1-hour RTO requirements, the organization needs parallel testing (testing recovery without affecting production) or full interruption testing (actual failover) to validate they can actually recover systems within required timeframes. These higher-level tests reveal technical issues, resource gaps, and timing problems that walk-throughs cannot identify. Increasing walk-through frequency does not address the fundamental limitation that procedures are never actually executed. Checklist reviews provide even less assurance than walk-throughs. Only actual execution testing validates recovery capability to meet aggressive RTO requirements.
2. An audit committee reviews the annual audit plan and requests that the IT audit function provide absolute assurance that no material weaknesses exist in the organization's controls. How should the chief audit executive respond? (Select one!)
Explanation
Auditors can only provide reasonable assurance, not absolute assurance, due to inherent limitations in the audit process including the use of sampling, judgment in selecting procedures, reliance on representations, and the potential for collusion or management override. ITAF standards explicitly recognize these limitations. Even 100 percent testing cannot provide absolute assurance due to timing limitations, the potential for fraudulent concealment, and the need for professional judgment in evaluating evidence. External auditors face the same limitations and cannot provide absolute assurance. Limiting absolute assurance to critical systems only still misrepresents audit capabilities. The chief audit executive must educate the audit committee on the fundamental concept of reasonable assurance.
3. During a risk assessment, the security team calculates that a server with an asset value of $200,000 has an exposure factor of 60% for a flood risk that occurs once every 10 years. What is the Annualized Loss Expectancy? (Select one!)
Explanation
The Annualized Loss Expectancy formula is: ALE equals SLE times ARO. First calculate Single Loss Expectancy: SLE equals Asset Value times Exposure Factor, which is $200,000 times 0.60 equals $120,000. Then calculate ALE: $120,000 times Annualized Rate of Occurrence. Since the flood occurs once every 10 years, the ARO is 0.10. Therefore: $120,000 times 0.10 equals $12,000 annual expected loss. $20,000 would be incorrect ARO calculation. $120,000 is the SLE, not the ALE. $200,000 is the asset value without applying exposure factor or occurrence rate. Understanding these quantitative risk formulas is essential for IT auditors to evaluate risk assessment processes and determine cost-effectiveness of controls.
4. An organization stores customer data in a cloud-based SaaS application. During a compliance audit, the auditor requests documentation of data encryption methods, backup procedures, and security controls. The cloud provider's contract states that detailed security information is proprietary and cannot be disclosed. What should the auditor request as an alternative? (Select one!)
Explanation
A SOC 2 Type II report is the appropriate alternative when direct access to cloud provider controls and documentation is not available. SOC 2 reports are independent audits conducted by qualified external auditors that evaluate and opine on service organization controls related to security, availability, processing integrity, confidentiality, and privacy. Type II reports test control effectiveness over a period of time, typically 6-12 months. These standardized reports allow organizations to obtain assurance about third-party controls without requiring direct access to proprietary systems. Direct infrastructure access is unrealistic and unnecessary. Verbal assurances lack independence and verifiability. Switching providers is premature and impractical. SOC 2 reports are the industry-standard mechanism for auditing cloud service provider controls.
5. An auditor issues an audit opinion on financial system controls. The auditor found material control deficiencies but they only affect specific modules, not the entire system. Which opinion type is MOST appropriate? (Select one!)
Explanation
Qualified opinions are appropriate when material but not pervasive issues exist, using except for language to specify the matters. Unqualified opinions require no material exceptions. Adverse opinions are for material and pervasive issues affecting everything. Disclaimers are for insufficient evidence, not identified deficiencies. Since deficiencies are material but limited to specific modules, not pervasive across the entire system, a qualified opinion properly communicates the scope and limitation of the issues.
A foundational credential ISACA introduced in 2022 that validates core IT audit knowledge across six domains, from performing audits to evaluating IT infrastructure and newer technologies like AI and blockchain. It is designed for people entering IT audit with no prior experience.
USD $175 for ISACA members and $225 for non-members. Registration is open continuously, your eligibility window runs six months from registration, and you can schedule a testing appointment as early as 48 hours after payment.
ISACA does not publish an official count. The 2-hour exam blends standard multiple-choice questions with interactive, performance-based questions that simulate real audit tasks, and many candidates report seeing around 55 questions.
You need 65 percent or higher. The exam is computer-based and remotely proctored, so you can take it from home with a webcam and a stable connection.
No. Like ISACA's other fundamentals certificates, you earn it once and ISACA publishes no CPE or renewal requirement for it. That sets it apart from ISACA certifications such as CISA, which must be renewed every three years with continuing education credits.
None. No work experience, degree, or other certification is required, which makes it accessible to students, career changers, and IT professionals moving into audit. Basic familiarity with networks, operating systems, and databases helps.
For breaking into IT audit, yes. It maps to entry-level roles like IT auditor, compliance analyst, and IT controls analyst, where United States salaries typically start around $57,000 to $78,000, and it gives hiring managers a vendor-neutral signal that you know audit basics.
CISA is ISACA's professional certification for experienced auditors: it requires five years of IT audit experience and ongoing CPE renewal. IT Audit Fundamentals has no experience requirement and no renewal, making it the natural first step on the path to CISA.
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
Information Technology Certified Associate (ITCA)
ITCA · 596 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
$17.99
One-time access to this exam