About the certification

A vulnerability is a weakness of software, hardware, or online service that can be exploited by a threat. An exploitation of vulnerabilities results in a disruption of the confidentiality, integrity, or availability of the ICT system or related information assets, which may cause a breach of data privacy, interruption of operation of mission critical systems, and so on. The main objective of a vulnerability management process is to reduce risks resulting from exploitation of published technical vulnerabilities.

The vulnerability management process should be implemented in an effective, systematic, and repeatable way with measurements taken to confirm its effectiveness. The Vulnerability Management Foundation is an entry-level certification intended for IT professionals seeking to validate their knowledge of Vulnerability Management. The exam tests the candidate knowledge in vulnerability management. The Vulnerability Management Foundation certification exam is based on ISO/IEC 27002:2013 Information technology - Security techniques - Code of practice for information security controls standard.

The Vulnerability Management Foundation certification exam is an online, closed-book, and remotely-proctored exam. It includes 20 multiple-choice questions and the passing score is 70%. You will have 30 minutes to complete the exam. Validate your knowledge of Vulnerability Management and advance your career. Register for your online exam now!

Exam details

Exam code


Launch date

March 30, 2017

Exam description

The Vulnerability Management Foudation exam tests the candidate's knowledge in Vulnerability Management.

Current version


Exam format

Multiple choice; computer-based; closed book

Number of questions

20 questions

Passing score

70% (14 out of 20)

Exam duration

30 minutes





Exam description

Vulnerability Management Process


16 hours

Recommended reading

• ISO/IEC 27002:2013 Information technology -- Security techniques -- Code of practice for information security controls standard.


There are no prerequisites for this certification

Recommended experience

Six months of work experience in Cybersecurity

Validity period



USD 150

How to get certified


Browse our certification programs and choose your certification.


Discover the exam objectives and prepare for your exam.


Register for your online proctored exam.


Take your online proctored exam in the comfort of your home or office.


Congratulations! You are certified!

Stackable Certifications

Earn 3 certifications and receive an integrator certification (designation).

InfoSec Foundation

Vulnerability Management Foundation

Information Security Policy Foundation

Information Security Analyst

Frequently Asked Questions

  • How much do Itcert's exams cost?

    All exams are available for USD 150 each. Prices may vary slightly by region and currency exchange rates.

  • Are there any prerequisites to take the exams?

    There are no prerequisites to take the exams. Itcerts recommends that candidates have at least six months of work experience in the area that the certification covers.

  • What is the exam retake policy?

    If a candidate does not achieve a passing score on the first attempt, there is no waiting period between the first and the second attempt. If a candidate does not achieve a passing score on the second attempt, the candidate must wait at least 7 days before retaking the exam for a third time. A candidate may not take a given exam any more than three times per year (12 months).

  • How do I register for an Online Proctored Exam?

    Visit the Online Proctored Exam registration page to find complete instructions.

  • Are there any mandatory training to take an exam?

    Training is recommended as part of your certification preparation, but it is not mandatory.

  • Which languages are the exams available in?

    Our exams are currently available in English, Spanish and Portuguese (Brazilian).

  • Where can I take the exams?

    Exams are delivered online (Online Proctored Exams) and can be taken from anywhere in the world.

  • Do the Itcerts certifications expire?

    Itcerts certifications are considered good-for-life and do not expire.

  • How can a potential employer verify my certifications?

    Your employer can verify your certification on our certification verification page. Your certification number will be needed in order to process the verification.



Subscribe to own newsletter