ISACA · IT-Audit-Fund
Validates foundational IT audit knowledge, covering audit performance, IT environment and components, specific audit subjects, newer technologies, controls and risk, and the audit function, including IT audit terminology, concepts, and general practices.
Practice Questions
627
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Sep 2026
The IT Audit Fundamentals Certificate is ISACA's entry point into IT audit, launched in August 2022 for people with no prior audit experience. Note the word certificate: ISACA classes it as a knowledge certificate, not a certification like CISA, which is why it carries no experience requirement and no CPE renewal. The exam weights six domains: Performing an Audit is by far the largest at 35 percent, followed by IT Environment and Components at 25 percent, Specific Audit Subjects at 15 percent, Overview of Newer Technologies (AI, blockchain, cloud, IoT) at 12 percent, Controls, Risk and Audit at 8 percent, and The Audit Function at 5 percent. This question bank mirrors those weights, so most of your practice time lands on planning, executing, and documenting audits and on the infrastructure components an auditor actually evaluates.
The exam costs $175 for ISACA members and $225 for non-members, runs 2 hours as an online, remotely proctored test, and requires 65 percent or higher to pass. It blends standard multiple-choice questions with interactive, performance-based ones that simulate audit tasks. Registration is continuous, your eligibility window runs six months from registration, appointments open as soon as 48 hours after payment, and you can reschedule without penalty up to 48 hours before your slot. There are no prerequisites, so career changers and recent graduates can register immediately.
Unlike CISA, which demands five years of experience and ongoing CPE renewal every three years, this certificate is earned once and positions you for entry-level IT auditor, compliance analyst, and IT controls roles. It is the natural first step on the path to CISA. Benchmark yourself with the 30 free questions, then drill the full 627-question bank with detailed explanations until you hold steady above 65 percent across all six domains, especially the two that decide 60 percent of your score.
The ISACA IT Audit Fundamentals Certificate is a foundational-level credential that validates knowledge of core IT audit terminology, concepts, and general practices across six functional domains. It covers the full audit lifecycle—from understanding the audit function and organizational controls to performing audits and evaluating specific IT subjects such as networking, operating systems, and IT general controls. The certificate was introduced by ISACA in 2022 to address growing demand for entry-level IT audit professionals and provides a structured foundation for those entering the field.
The program blends knowledge-based and performance-based learning, reflecting real-world audit skills rather than pure theoretical recall. It specifically addresses newer technologies including artificial intelligence (AI), blockchain, and the Internet of Things (IoT), ensuring candidates are equipped to audit modern IT environments. Successful candidates earn a digital badge through ISACA's Credly platform and a recognized certificate, positioning them as credible candidates for IT audit roles.
This certificate is designed for early-career professionals seeking to enter the IT audit field, as well as IT practitioners—such as system administrators, network engineers, and security specialists—who want to transition into audit roles. It is equally relevant for internal and external auditors with limited IT audit exposure, compliance officers who need to understand IT audit processes, and risk management personnel who work alongside audit teams.
Because no prior IT audit experience is required, the certificate also suits recent graduates in information systems, accounting, or cybersecurity programs who want a recognized credential to support job applications. It serves as a clearly defined first step toward the CISA (Certified Information Systems Auditor) certification, ISACA's globally recognized advanced credential for IT auditors.
There are no formal prerequisites for the IT Audit Fundamentals Certificate. Candidates can register at any time without needing to demonstrate prior work experience or hold any other certification. This open eligibility makes it accessible to career changers, students, and early-career professionals alike.
While no prerequisites are required, candidates will benefit from a basic familiarity with IT concepts such as networks, operating systems, and databases, as the exam covers IT environment components at a foundational level. A general understanding of business processes and organizational risk management practices will also help candidates contextualize the audit concepts covered across the six exam domains.
The IT Audit Fundamentals exam is delivered online via remote proctoring and has a time limit of 120 minutes. It combines two question types: traditional multiple-choice (knowledge-based) questions and interactive performance-based questions that simulate real audit scenarios. The exact total number of scored questions is not publicly disclosed by ISACA.
Candidates must achieve a passing score of 65% or higher. Exam eligibility is valid for 6 months from the date of registration, and testing appointments can be scheduled as early as 48 hours after payment. There is no penalty for rescheduling as long as changes are made at least 48 hours before the scheduled appointment. Exam fees are $175 USD for ISACA members and $225 USD for non-members.
The IT Audit Fundamentals Certificate positions holders for entry-level IT audit roles at a time when demand for audit professionals is expanding alongside growth in cyberattacks, cloud adoption, and regulatory compliance requirements. Entry-level IT auditor salaries in the United States range from approximately $57,000 to $78,000 annually, with Glassdoor data placing average entry-level compensation around $74,658. Salaries increase substantially with experience, reaching roughly $88,932 for professionals with 4–6 years of experience and over $119,000 for senior practitioners. Common entry-level roles for certificate holders include IT Auditor, Junior Risk Analyst, Compliance Analyst, and IT Controls Analyst.
Beyond immediate job placement, the certificate serves as a recognized stepping stone to the CISA certification — the global gold standard for IT auditors — giving holders a structured credential pathway. ISACA's digital badge, issued via Credly, allows professionals to display the credential on LinkedIn and resumes for employer recognition. For organizations, the certificate validates that team members have a standardized, vendor-neutral foundation in IT audit practices, making it valuable for upskilling internal audit, risk, and compliance teams.
5 sample questions with answers and explanations. The full bank has 627 questions, enough for 4 full-length practice exams.
Preview — answers shown1. During risk assessment planning, an auditor calculates that a server with an asset value of $150,000 faces a threat with an exposure factor of 40 percent occurring twice per year. What is the annualized loss expectancy? (Select one!)
Explanation
The annualized loss expectancy calculation uses the formula ALE equals SLE times ARO. First, calculate the single loss expectancy: SLE equals asset value times exposure factor, which is $150,000 times 0.40 equals $60,000. Then multiply by the annualized rate of occurrence: ALE equals $60,000 times 2 equals $120,000. This represents the expected annual financial impact from this threat. $60,000 represents only a single loss expectancy without considering frequency. $300,000 incorrectly multiplies the full asset value by the occurrence rate. $150,000 is simply the asset value without applying exposure factor or occurrence rate.
2. During a risk assessment, the security team calculates that a server with an asset value of $200,000 has an exposure factor of 60% for a flood risk that occurs once every 10 years. What is the Annualized Loss Expectancy? (Select one!)
Explanation
The Annualized Loss Expectancy formula is: ALE equals SLE times ARO. First calculate Single Loss Expectancy: SLE equals Asset Value times Exposure Factor, which is $200,000 times 0.60 equals $120,000. Then calculate ALE: $120,000 times Annualized Rate of Occurrence. Since the flood occurs once every 10 years, the ARO is 0.10. Therefore: $120,000 times 0.10 equals $12,000 annual expected loss. $20,000 would be incorrect ARO calculation. $120,000 is the SLE, not the ALE. $200,000 is the asset value without applying exposure factor or occurrence rate. Understanding these quantitative risk formulas is essential for IT auditors to evaluate risk assessment processes and determine cost-effectiveness of controls.
3. During risk assessment, an auditor calculates that a server valued at 200000 dollars has an exposure factor of 60 percent and an annualized rate of occurrence of 0.25. What is the annualized loss expectancy? (Select one!)
Explanation
The correct calculation is ALE equals SLE times ARO. First calculate Single Loss Expectancy: SLE equals Asset Value times Exposure Factor equals 200000 times 0.60 equals 120000 dollars. Then calculate Annualized Loss Expectancy: ALE equals 120000 times 0.25 equals 30000 dollars. This represents the expected annual financial impact from this risk. The 50000 dollar option may result from calculation errors. The 120000 dollar figure is the SLE, not the ALE. The 800000 dollar option has no basis in the correct formula.
4. An organization implements multi-factor authentication requiring users to provide a password, a hardware token, and a fingerprint scan. How many distinct authentication factor types are being used? (Select one!)
Explanation
Three distinct authentication factor types are being used. Authentication factors are categorized into three types: something you know (knowledge), something you have (possession), and something you are (inherence/biometric). The password represents something you know. The hardware token represents something you have. The fingerprint scan represents something you are. Even though three separate credentials are required, they map to three distinct factor types. True multi-factor authentication requires factors from at least two different categories. This implementation uses all three types, providing strong authentication. Using multiple factors of the same type, such as two passwords, would still be only one factor type and would not constitute true multi-factor authentication.
5. An auditor reviews role-based access controls and finds that the Finance Manager role has permissions to create vendor records, enter invoices, and approve payments. What control principle is violated? (Select one!)
Explanation
Segregation of duties requires that no single individual control all phases of a critical transaction. Creating vendors, entering invoices, and approving payments are incompatible functions that enable fraud—a user could create a fictitious vendor, enter fraudulent invoices, and approve payments to themselves. This represents a classic SoD violation. Least privilege relates to limiting access to the minimum necessary but doesn't specifically address transaction phase separation. Need to know is an information access principle. Defense in depth involves multiple layers of security controls. The ability to complete an entire financial transaction cycle from creation through approval without oversight or review violates fundamental control principles and creates fraud risk.
Even ISACA's foundational certificates fall under the same certification agreement as CISA and CISM. A flagged exam result means score nullification and possible permanent disqualification, regardless of whether the credential is an entry-level fundamentals certificate or a senior-level exam.
IT Audit Fundamentals is meant to be a low-friction way to prove baseline audit knowledge, not something worth risking an ISACA disqualification over. CertCompanion's bank has 627 practice questions, 30 free, built around the same audit fundamentals ISACA actually tests.
A foundational credential ISACA introduced in August 2022 that validates core IT audit knowledge across six domains, from performing audits to evaluating IT infrastructure and newer technologies like AI and blockchain. It is designed for people entering IT audit with no prior experience.
A certificate. ISACA draws a hard line between the two: certificates like IT Audit Fundamentals prove knowledge, have no experience requirement, and never need renewal, while certifications like CISA require five years of experience and continuing education to maintain. That is why this one is often the first ISACA credential people earn.
USD $175 for ISACA members and $225 for non-members. Registration is open continuously, your eligibility window runs six months from registration, and you can schedule a testing appointment as early as 48 hours after payment.
ISACA does not publish an official count. The 2-hour exam blends standard multiple-choice questions with interactive, performance-based questions that simulate real audit tasks, and many candidates report seeing around 55 questions.
You need 65 percent or higher. The exam is computer-based and remotely proctored, so you can take it from home with a webcam and a stable connection.
Yes, without penalty, as long as you reschedule at least 48 hours before your appointment and stay inside your six-month eligibility window. Appointments can be booked up to 90 days in advance through ISACA's testing partner PSI.
No. Like ISACA's other fundamentals certificates, you earn it once and ISACA publishes no CPE or renewal requirement for it. That sets it apart from ISACA certifications such as CISA, which must be renewed every three years with continuing education credits.
None. No work experience, degree, or other certification is required, which makes it accessible to students, career changers, and IT professionals moving into audit. Basic familiarity with networks, operating systems, and databases helps.
For breaking into IT audit, yes. It maps to entry-level roles like IT auditor, compliance analyst, and IT controls analyst, where United States salaries typically start around $57,000 to $78,000, and it gives hiring managers a vendor-neutral signal that you know audit basics before you have audit experience on your resume.
CISA is ISACA's professional certification for experienced auditors: it requires five years of IT audit experience and ongoing CPE renewal. IT Audit Fundamentals has no experience requirement and no renewal, making it the natural first step on the path to CISA.
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
Information Technology Certified Associate (ITCA)
ITCA · 596 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
$17.99
One-time access to this exam