ISACA • IT-Audit-Fund
Validates foundational IT audit knowledge, covering audit performance, IT environment and components, specific audit subjects, newer technologies, controls and risk, and the audit function, including IT audit terminology, concepts, and general practices.
Questions
627
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Feb 2026
The ISACA IT Audit Fundamentals Certificate is a foundational-level credential that validates knowledge of core IT audit terminology, concepts, and general practices across six functional domains. It covers the full audit lifecycle—from understanding the audit function and organizational controls to performing audits and evaluating specific IT subjects such as networking, operating systems, and IT general controls. The certificate was introduced by ISACA in 2022 to address growing demand for entry-level IT audit professionals and provides a structured foundation for those entering the field.
The program blends knowledge-based and performance-based learning, reflecting real-world audit skills rather than pure theoretical recall. It specifically addresses newer technologies including artificial intelligence (AI), blockchain, and the Internet of Things (IoT), ensuring candidates are equipped to audit modern IT environments. Successful candidates earn a digital badge through ISACA's Credly platform and a recognized certificate, positioning them as credible candidates for IT audit roles.
This certificate is designed for early-career professionals seeking to enter the IT audit field, as well as IT practitioners—such as system administrators, network engineers, and security specialists—who want to transition into audit roles. It is equally relevant for internal and external auditors with limited IT audit exposure, compliance officers who need to understand IT audit processes, and risk management personnel who work alongside audit teams.
Because no prior IT audit experience is required, the certificate also suits recent graduates in information systems, accounting, or cybersecurity programs who want a recognized credential to support job applications. It serves as a clearly defined first step toward the CISA (Certified Information Systems Auditor) certification, ISACA's globally recognized advanced credential for IT auditors.
There are no formal prerequisites for the IT Audit Fundamentals Certificate. Candidates can register at any time without needing to demonstrate prior work experience or hold any other certification. This open eligibility makes it accessible to career changers, students, and early-career professionals alike.
While no prerequisites are required, candidates will benefit from a basic familiarity with IT concepts such as networks, operating systems, and databases, as the exam covers IT environment components at a foundational level. A general understanding of business processes and organizational risk management practices will also help candidates contextualize the audit concepts covered across the six exam domains.
The IT Audit Fundamentals exam is delivered online via remote proctoring and has a time limit of 120 minutes. It combines two question types: traditional multiple-choice (knowledge-based) questions and interactive performance-based questions that simulate real audit scenarios. The exact total number of scored questions is not publicly disclosed by ISACA.
Candidates must achieve a passing score of 65% or higher. Exam eligibility is valid for 12 months from the date of registration, and testing appointments can be scheduled as early as 48 hours after payment. There is no penalty for rescheduling as long as changes are made at least 48 hours before the scheduled appointment. Exam fees are $175 USD for ISACA members and $225 USD for non-members.
The IT Audit Fundamentals Certificate positions holders for entry-level IT audit roles at a time when demand for audit professionals is expanding alongside growth in cyberattacks, cloud adoption, and regulatory compliance requirements. Entry-level IT auditor salaries in the United States range from approximately $57,000 to $78,000 annually, with Glassdoor data placing average entry-level compensation around $74,658. Salaries increase substantially with experience, reaching roughly $88,932 for professionals with 4–6 years of experience and over $119,000 for senior practitioners. Common entry-level roles for certificate holders include IT Auditor, Junior Risk Analyst, Compliance Analyst, and IT Controls Analyst.
Beyond immediate job placement, the certificate serves as a recognized stepping stone to the CISA certification — the global gold standard for IT auditors — giving holders a structured credential pathway. ISACA's digital badge, issued via Credly, allows professionals to display the credential on LinkedIn and resumes for employer recognition. For organizations, the certificate validates that team members have a standardized, vendor-neutral foundation in IT audit practices, making it valuable for upskilling internal audit, risk, and compliance teams.
1. An auditor plans to use variable sampling to estimate the total value of inventory in a warehouse containing 50000 items worth approximately 10 million dollars. The auditor wants 95 percent confidence with a tolerable error of 200000 dollars. The population shows high variability in item values ranging from 5 dollars to 50000 dollars. How will the high population variation affect the required sample size? (Select one!)
2. An auditor discovers that the same person who develops SQL queries for a financial reporting system also has database administrator privileges and can modify audit logs. Which type of control deficiency does this represent? (Select one!)
3. During a privacy audit, the auditor finds that the organization retains customer data for seven years to support potential legal disputes, but the data retention policy states data will be deleted after three years. Customers consented to three-year retention. What principle is violated? (Select one!)
4. A manufacturing company deploys Industrial IoT sensors on production equipment. The auditor discovers that 150 IoT devices share a single administrative password that is hard-coded in the device firmware and cannot be changed. What is the MOST significant risk? (Select one!)
5. An auditor reviews the organization's cybersecurity incident response capability and examines the NIST SP 800-61 incident response lifecycle. The organization has strong detection and containment procedures but lacks a formal process for incorporating lessons learned. Which phase of the incident response lifecycle is deficient? (Select one!)
All exams included • Cancel anytime