ISACA · Risk-Fund
A knowledge-based ISACA certificate covering the foundations of information and technology risk governance, identification, analysis, response, monitoring, reporting, and communication.
Practice Questions
616
≈ 4 practice exams
Duration
120 minutes
Passing Score
65%
Difficulty
FoundationalLast Updated
Oct 2026
IT Risk Fundamentals is a knowledge-based ISACA certificate, not one of ISACA's experience-gated professional certifications. Its six-domain blueprint moves from a short introduction through governance, identification, assessment and analysis, response, and monitoring and communication. Risk Assessment and Analysis is the largest area at 25%.
The current candidate guide specifies 75 multiple-choice questions in 120 minutes and a 65% passing score. There are no prerequisites, the exam is delivered through PSI remote proctoring, and the purchase creates a six-month eligibility window. Current fees are $175 for ISACA members and $225 for non-members.
This 616-question practice bank lets you reinforce the vocabulary and decisions represented by each published domain without inventing objectives that ISACA does not publish freely. Start with 30 free questions, then give the 25% assessment domain and the two 20% domains proportionally more practice.
The ISACA IT Risk Fundamentals Certificate is a knowledge-based credential for people building a foundation in information and technology risk. It focuses on the language and core practices used to identify, assess, respond to, monitor, and communicate I&T-related risk.
ISACA's current Certificate Programs Exam Candidate Guide lists 75 multiple-choice questions, a 120-minute limit, and a 65% passing score. Risk Assessment and Analysis carries the largest share at 25%, followed by Risk Identification and Risk Monitoring, Reporting and Communication at 20% each.
ISACA positions the certificate for professionals new to risk, people who interact with risk professionals, risk specialists who want to verify foundational knowledge, and teams or individuals building I&T-related risk skills.
It is a certificate rather than one of ISACA's experience-based certifications. ISACA introduced it as groundwork for future CRISC study, but it is not a prerequisite for CRISC.
There is no education, work-experience, or prior-certification prerequisite. Registration is continuous, and exam eligibility lasts six months from purchase.
ISACA says candidates may schedule as early as 48 hours after payment, although available appointments are displayed only up to 90 days in advance. Purchases are non-refundable and non-transferable.
The current candidate guide specifies 75 multiple-choice questions in English, 120 minutes, and a 65% passing score. The exam is delivered online through PSI remote proctoring.
The current fee is $175 for ISACA members and $225 for non-members. ISACA's public materials reviewed do not specify a recurring maintenance requirement for this certificate; candidates should confirm current terms directly with ISACA rather than assuming that exam eligibility and credential validity are the same thing.
The certificate provides a current ISACA-issued way to demonstrate foundational I&T risk knowledge without an experience prerequisite. Its published scope is useful for people entering risk work and for professionals who need to collaborate with risk teams using a shared vocabulary.
ISACA's public materials reviewed do not publish salary outcomes, guarantee a job pathway, or specify an ongoing renewal cycle for this certificate, so this page does not make those claims.
5 sample questions with answers and explanations. The full bank has 616 questions, enough for 4 full-length practice exams.
Preview — answers shown1. An energy company uses a 5x5 risk matrix for qualitative risk assessment. A cybersecurity scenario involving ransomware is rated as Likely for probability (score 4) and Major for impact (score 4). What is the calculated risk score for this scenario? (Select one!)
Explanation
Risk score calculation follows the formula: Risk Score equals Likelihood Score multiplied by Impact Score. In this scenario, Likelihood score of 4 multiplied by Impact score of 4 equals 16. The score of 8 would incorrectly add the values instead of multiplying them. A score of 12 would result from a 4x3 or 3x4 combination. A score of 20 would result from a 5x4 or 4x5 combination, which represents higher likelihood or impact than stated.
2. A risk analyst calculates risk metrics for a database server. The asset value is 500,000 dollars, exposure factor is 40 percent, and the threat occurs twice annually. What is the Annualized Loss Expectancy? (Select one!)
Explanation
Annualized Loss Expectancy is calculated as SLE multiplied by ARO. First, calculate Single Loss Expectancy: SLE equals Asset Value multiplied by Exposure Factor, which equals 500,000 dollars multiplied by 0.40 equals 200,000 dollars. Then calculate ALE: ALE equals SLE multiplied by ARO, which equals 200,000 dollars multiplied by 2 equals 400,000 dollars. The 200,000 dollar value represents only the SLE, not the annualized expectancy. The 250,000 dollar calculation incorrectly uses the wrong formula. The 500,000 dollar value is the asset value, not the loss expectancy.
3. An organization implements a security awareness training program to reduce the likelihood of employees falling victim to phishing attacks. What type of control does this training program represent? (Select one!)
Explanation
Security awareness training is a directive control that provides guidance on expected behavior and appropriate actions. Directive controls include policies, procedures, guidelines, and training that tell people how to behave but do not technically prevent or detect incidents. Preventive controls would be technical measures that block phishing emails before they reach users. Detective controls would identify when phishing attempts occur or when users click suspicious links. Corrective controls would remediate issues after a phishing incident has occurred.
4. A technology startup implements the NIST Cybersecurity Framework 2.0 and must establish its cybersecurity risk management strategy, roles, and policies before implementing technical controls. Which CSF function addresses these foundational activities? (Select one!)
Explanation
Govern is the new function added in NIST CSF 2.0 that addresses establishing cybersecurity risk management strategy, roles, policies, and oversight. This function provides the foundation for the other five functions by setting organizational context and governance structures. Identify focuses on understanding cybersecurity risks to systems, assets, and capabilities. Protect involves implementing safeguards for critical services. Detect addresses identifying cybersecurity events. The Govern function must be established first to provide the strategic direction and governance framework that guides all other cybersecurity activities.
5. An organization implements the NIST Cybersecurity Framework version 2.0. The security team must explain which core function was newly added in version 2.0 to establish cybersecurity strategy and risk management context. Which function should be identified? (Select one!)
Explanation
GOVERN is the new core function added in NIST CSF 2.0 specifically to establish and monitor the organization's cybersecurity risk management strategy, expectations, and policy. This function provides the foundational governance context for the other functions. IDENTIFY, PROTECT, and RESPOND were all present in the original NIST CSF 1.0 framework and were not newly added in version 2.0.
ISACA’s current Certificate Programs Exam Candidate Guide lists 75 multiple-choice questions. Candidates receive 120 minutes.
ISACA sets the passing score at 65% or higher.
No. ISACA lists no education, experience, or prior-certification prerequisite for the certificate exam.
The current fee is $175 for ISACA members and $225 for non-members. ISACA states that purchases are non-refundable and non-transferable.
ISACA administers it online through PSI remote proctoring. Registration is continuous, and exam eligibility lasts six months from purchase.
Risk Assessment and Analysis is 25%; Risk Identification and Risk Monitoring, Reporting and Communication are 20% each; Risk Governance and Management and Risk Response are 15% each; and Risk Intro and Overview is 5%.
Information Technology Certified Associate (ITCA)
ITCA · 596 questions
IoT Fundamentals Certificate
IoT-Fund · 630 questions
IT Audit Fundamentals Certificate
IT-Audit-Fund · 627 questions
ISACA Advanced in AI Audit (AAIA)
AAIA · 600 questions
ISACA Advanced in AI Risk (AAIR)
AAIR · 598 questions
ISACA Advanced in AI Security Management (AAISM)
AAISM · 600 questions
$17.99
One-time access to this exam