ISACA · IT-Audit-Fund
Validates foundational IT audit knowledge, covering audit performance, IT environment and components, specific audit subjects, newer technologies, controls and risk, and the audit function, including IT audit terminology, concepts, and general practices.
Practice Questions
627
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Jul 2026
The IT Audit Fundamentals Certificate is ISACA's entry point into IT audit, launched in 2022 for people with no prior audit experience. The exam weights six domains: Performing an Audit is by far the largest at 35 percent, followed by IT Environment and Components at 25 percent, Specific Audit Subjects at 15 percent, Overview of Newer Technologies (AI, blockchain, cloud, IoT) at 12 percent, Controls, Risk and Audit at 8 percent, and The Audit Function at 5 percent. This question bank mirrors those weights, so most of your practice time lands on planning, executing, and documenting audits and on the infrastructure components an auditor actually evaluates.
The exam itself costs $175 for ISACA members and $225 for non-members, runs 2 hours as a remotely proctored computer-based test, and requires 65 percent or higher to pass. It blends standard multiple-choice questions with interactive, performance-based ones that simulate audit tasks, and your registration gives you a six-month eligibility window with appointments available as soon as 48 hours after payment. There are no prerequisites, so career changers and recent graduates can register immediately.
Unlike CISA, which demands five years of experience and ongoing CPE renewal, this certificate is earned once and positions you for entry-level IT auditor, compliance analyst, and IT controls roles. It is the natural first step on the path to CISA. Benchmark yourself with the 30 free questions, then drill the full 627-question bank with detailed explanations until you hold steady above 65 percent across all six domains.
The ISACA IT Audit Fundamentals Certificate is a foundational-level credential that validates knowledge of core IT audit terminology, concepts, and general practices across six functional domains. It covers the full audit lifecycle—from understanding the audit function and organizational controls to performing audits and evaluating specific IT subjects such as networking, operating systems, and IT general controls. The certificate was introduced by ISACA in 2022 to address growing demand for entry-level IT audit professionals and provides a structured foundation for those entering the field.
The program blends knowledge-based and performance-based learning, reflecting real-world audit skills rather than pure theoretical recall. It specifically addresses newer technologies including artificial intelligence (AI), blockchain, and the Internet of Things (IoT), ensuring candidates are equipped to audit modern IT environments. Successful candidates earn a digital badge through ISACA's Credly platform and a recognized certificate, positioning them as credible candidates for IT audit roles.
This certificate is designed for early-career professionals seeking to enter the IT audit field, as well as IT practitioners—such as system administrators, network engineers, and security specialists—who want to transition into audit roles. It is equally relevant for internal and external auditors with limited IT audit exposure, compliance officers who need to understand IT audit processes, and risk management personnel who work alongside audit teams.
Because no prior IT audit experience is required, the certificate also suits recent graduates in information systems, accounting, or cybersecurity programs who want a recognized credential to support job applications. It serves as a clearly defined first step toward the CISA (Certified Information Systems Auditor) certification, ISACA's globally recognized advanced credential for IT auditors.
There are no formal prerequisites for the IT Audit Fundamentals Certificate. Candidates can register at any time without needing to demonstrate prior work experience or hold any other certification. This open eligibility makes it accessible to career changers, students, and early-career professionals alike.
While no prerequisites are required, candidates will benefit from a basic familiarity with IT concepts such as networks, operating systems, and databases, as the exam covers IT environment components at a foundational level. A general understanding of business processes and organizational risk management practices will also help candidates contextualize the audit concepts covered across the six exam domains.
The IT Audit Fundamentals exam is delivered online via remote proctoring and has a time limit of 120 minutes. It combines two question types: traditional multiple-choice (knowledge-based) questions and interactive performance-based questions that simulate real audit scenarios. The exact total number of scored questions is not publicly disclosed by ISACA.
Candidates must achieve a passing score of 65% or higher. Exam eligibility is valid for 12 months from the date of registration, and testing appointments can be scheduled as early as 48 hours after payment. There is no penalty for rescheduling as long as changes are made at least 48 hours before the scheduled appointment. Exam fees are $175 USD for ISACA members and $225 USD for non-members.
The IT Audit Fundamentals Certificate positions holders for entry-level IT audit roles at a time when demand for audit professionals is expanding alongside growth in cyberattacks, cloud adoption, and regulatory compliance requirements. Entry-level IT auditor salaries in the United States range from approximately $57,000 to $78,000 annually, with Glassdoor data placing average entry-level compensation around $74,658. Salaries increase substantially with experience, reaching roughly $88,932 for professionals with 4–6 years of experience and over $119,000 for senior practitioners. Common entry-level roles for certificate holders include IT Auditor, Junior Risk Analyst, Compliance Analyst, and IT Controls Analyst.
Beyond immediate job placement, the certificate serves as a recognized stepping stone to the CISA certification — the global gold standard for IT auditors — giving holders a structured credential pathway. ISACA's digital badge, issued via Credly, allows professionals to display the credential on LinkedIn and resumes for employer recognition. For organizations, the certificate validates that team members have a standardized, vendor-neutral foundation in IT audit practices, making it valuable for upskilling internal audit, risk, and compliance teams.
5 sample questions with answers and explanations. The full bank has 627 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An audit manager is developing the annual audit plan using a risk-based approach. Which two activities should be performed first when creating the audit universe? (Select two!)
Multiple correct answersExplanation
Risk-based audit planning follows a structured sequence. The first step is identifying all auditable entities to create a comprehensive audit universe including governance, data center operations, business applications, and external service providers. The second step is assessing risks by evaluating likelihood and impact for each entity. Only after identifying entities and assessing risks can auditors rank priorities, allocate resources, and schedule engagements. Scheduling specific engagements comes later in the planning process after risk ranking is complete. Resource allocation occurs after risk assessment determines priorities. Audit committee approval is the final step after the complete plan is developed.
2. During an incident response audit, the auditor reviews logs from a security breach that occurred 45 days ago. The organization cannot provide complete logs because the log retention period is 30 days. What is the PRIMARY issue? (Select one!)
Explanation
Log retention policies must balance storage costs with forensic investigation needs and regulatory compliance requirements. A 30-day retention period may be insufficient for investigating sophisticated attacks that remain undetected for extended periods. Many compliance frameworks require log retention from 90 days to several years depending on the data type and industry. Inadequate retention prevents complete root cause analysis, compromises legal and regulatory compliance, and may hinder prosecution. While early detection is important, the primary issue is the policy gap that prevents investigation regardless of detection timing. Storage capacity may be a factor but is secondary to the policy deficiency. Incident response timing is separate from the log retention issue.
3. An auditor tests automated controls in a payroll application and finds that input validation rules correctly reject invalid employee IDs. However, the auditor also discovers that IT general controls over program change management are ineffective, allowing developers to migrate code to production without proper approval. What is the MOST appropriate audit conclusion? (Select one!)
Explanation
Automated controls cannot be relied upon when IT general controls are ineffective. ITGCs provide the foundation for application controls, and if change management controls fail, there is no assurance that the validated application controls will continue operating correctly. Developers could modify the input validation code without authorization, rendering current testing results unrelevant for future periods. This represents a pervasive control failure where everything built upon weak foundations becomes unreliable. While substantive testing can provide some assurance about transaction accuracy, it cannot substitute for effective preventive controls. The auditor must conclude that automated application controls are unreliable when underlying ITGCs are weak, regardless of current testing results.
4. An organization implements blockchain technology to record supply chain transactions. The audit team is asked to review controls over the blockchain implementation. What should be the PRIMARY focus of the audit? (Select one!)
Explanation
Private key management controls and smart contract code quality should be the primary audit focus because these represent the critical control points in blockchain implementations. Private keys control access to blockchain assets and authorize transactions, similar to PKI infrastructure, requiring secure generation, storage, backup, and access controls. Compromised private keys cannot be revoked retroactively. Smart contracts execute automatically based on programmed logic, and code flaws are immutable once deployed, requiring rigorous testing and security review before deployment. These are high-risk areas where control failures have immediate severe consequences. Public blockchain may not be appropriate for enterprise supply chains due to confidentiality requirements and consortium or private blockchains are more common. Blockchain complements rather than replaces traditional controls, and both layers require audit coverage. Consensus algorithm performance is a technical architecture concern rather than a primary control audit objective.
5. An auditor is reviewing the audit universe for annual planning and notes that the organization migrated its email system to a cloud provider and implemented a new mobile device management system. What should the auditor do FIRST? (Select one!)
Explanation
The audit universe is a comprehensive inventory of all auditable entities and should be updated when significant IT environment changes occur. Per ITAF guidance, the audit universe should be reviewed annually and updated when changes affect IT systems or business objectives. Adding the cloud email system and MDM to the audit universe is the foundational step that enables proper risk-based planning. Only after updating the universe can the auditor perform risk assessment to prioritize these entities for audit scheduling. Immediately scheduling audits or requesting reports skips the essential planning step of updating the comprehensive inventory of auditable entities.
Even ISACA's foundational certificates fall under the same certification agreement as CISA and CISM. A flagged exam result means score nullification and possible permanent disqualification, regardless of whether the credential is an entry-level fundamentals certificate or a senior-level exam.
IT Audit Fundamentals is meant to be a low-friction way to prove baseline audit knowledge, not something worth risking an ISACA disqualification over. CertCompanion's bank has 627 practice questions, 30 free, built around the same audit fundamentals ISACA actually tests.
A foundational credential ISACA introduced in 2022 that validates core IT audit knowledge across six domains, from performing audits to evaluating IT infrastructure and newer technologies like AI and blockchain. It is designed for people entering IT audit with no prior experience.
USD $175 for ISACA members and $225 for non-members. Registration is open continuously, your eligibility window runs six months from registration, and you can schedule a testing appointment as early as 48 hours after payment.
ISACA does not publish an official count. The 2-hour exam blends standard multiple-choice questions with interactive, performance-based questions that simulate real audit tasks, and many candidates report seeing around 55 questions.
You need 65 percent or higher. The exam is computer-based and remotely proctored, so you can take it from home with a webcam and a stable connection.
No. Like ISACA's other fundamentals certificates, you earn it once and ISACA publishes no CPE or renewal requirement for it. That sets it apart from ISACA certifications such as CISA, which must be renewed every three years with continuing education credits.
None. No work experience, degree, or other certification is required, which makes it accessible to students, career changers, and IT professionals moving into audit. Basic familiarity with networks, operating systems, and databases helps.
For breaking into IT audit, yes. It maps to entry-level roles like IT auditor, compliance analyst, and IT controls analyst, where United States salaries typically start around $57,000 to $78,000, and it gives hiring managers a vendor-neutral signal that you know audit basics.
CISA is ISACA's professional certification for experienced auditors: it requires five years of IT audit experience and ongoing CPE renewal. IT Audit Fundamentals has no experience requirement and no renewal, making it the natural first step on the path to CISA.
Digital Trust Ecosystem Framework Foundation Certificate
Digital-Trust · 600 questions
Information Technology Certified Associate (ITCA)
ITCA · 596 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Risk Fundamentals Certificate
Risk-Fund · 616 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
$17.99
One-time access to this exam