All Practice Exams

100+ Free CMMC Foundation Practice Questions

Prepare for the PECB Certified CMMC Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: CMMC Foundation Exam

40 MCQ, 1h

Exam Format

PECB CMMC Foundation Candidate Handbook

70%

Passing Score

PECB CMMC Foundation Candidate Handbook

Open-book

Exam Type

PECB CMMC Foundation Candidate Handbook

USD 500

Exam Fee (Foundation)

PECB CMMC Foundation Candidate Handbook

2 domains

Competency Domains

PECB CMMC Foundation Candidate Handbook

15 days

Retake Waiting Period

PECB CMMC Foundation Candidate Handbook

PECB Certified CMMC Foundation is an open-book, 40-question, 1-hour multiple-choice exam designed for defense contractors, cybersecurity consultants, and auditors. It measures foundational comprehension of the CMMC framework, NIST SP 800-171 domains, assessment scoping, and professional ethics. Note: this practice bank is an English-language MCQ study resource with 100 questions for thorough exam preparation.

Sample CMMC Foundation Practice Questions

Try these sample questions to test your CMMC Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary purpose of the Cybersecurity Maturity Model Certification (CMMC) program?
A.To replace all DFARS clauses in Department of Defense contracts
B.To protect Federal Contract Information and Controlled Unclassified Information within the Defense Industrial Base against cyber threats
C.To certify the cybersecurity of commercial cloud services offered to the public
D.To audit the financial reporting systems of defense contractors
Explanation: CMMC is a Department of Defense initiative designed to safeguard Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) handled by the Defense Industrial Base (DIB). It verifies that contractors and subcontractors implement cybersecurity practices appropriate to the sensitivity of the information they handle.
2Which of the following correctly defines Federal Contract Information (FCI)?
A.Information intended for public release on government websites
B.Classified information handled under the National Industrial Security Program
C.Information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service
D.Personally identifiable information collected from federal employees
Explanation: FCI is defined in FAR 52.204-21 as information not intended for public release that is provided by or generated for the Government under a contract to develop or deliver a product or service. FCI is less sensitive than CUI and is protected at CMMC Level 1.
3What is Controlled Unclassified Information (CUI)?
A.Information that requires safeguarding or dissemination controls pursuant to law, regulation, or government-wide policy
B.Information that has been formally classified at the Confidential level
C.Information owned by a defense contractor that is exempt from any government oversight
D.Information published in the Federal Register for public comment
Explanation: CUI is unclassified information that nonetheless requires safeguarding or dissemination controls under laws, regulations, or government-wide policies, such as export-control or privacy requirements. Protecting CUI is the central objective of CMMC Levels 2 and 3.
4Which organization developed the CMMC model?
A.The National Institute of Standards and Technology (NIST)
B.The Cybersecurity and Infrastructure Security Agency (CISA)
C.The International Organization for Standardization (ISO)
D.The U.S. Department of Defense (DoD)
Explanation: CMMC was developed by the U.S. Department of Defense to strengthen the cybersecurity of the Defense Industrial Base supply chain. NIST standards such as SP 800-171 supply the technical practices, but the model and program belong to the DoD.
5What is the Defense Industrial Base (DIB)?
A.The network of government-owned laboratories that design military weapons
B.The worldwide industrial complex that enables research, development, production, delivery, and maintenance of military weapons systems, subsystems, and components for the DoD
C.A database used by the DoD to store classified contract information
D.A federal agency responsible for accrediting cybersecurity assessors
Explanation: The DIB is the global industrial complex of companies and organizations that research, develop, produce, deliver, and maintain military systems and services for the DoD. CMMC exists because adversaries increasingly target this supply chain to steal sensitive unclassified information.
6How many maturity levels does the CMMC 2.0 framework contain?
A.Two
B.Four
C.Three
D.Five
Explanation: CMMC 2.0 streamlined the model from the original five levels down to three: Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). This change simplified compliance and aligned the model directly with established NIST standards.
7What are the names of the three CMMC 2.0 levels, from lowest to highest?
A.Foundational, Advanced, and Expert
B.Basic, Intermediate, and Senior
C.Bronze, Silver, and Gold
D.Initial, Managed, and Optimizing
Explanation: CMMC 2.0 names its three levels Foundational (Level 1), Advanced (Level 2), and Expert (Level 3). Each level applies progressively more rigorous cybersecurity practices appropriate to the sensitivity of the information being protected.
8Which statement best describes the transition from CMMC 1.0 to CMMC 2.0?
A.It added two new maturity levels above the original five
B.It introduced CMMC-unique practices that go beyond NIST requirements
C.It reduced the model from five levels to three and removed CMMC-unique maturity process requirements
D.It converted the program into a purely voluntary self-attestation scheme for all contractors
Explanation: CMMC 2.0 was announced to streamline the program: it collapsed five levels into three, removed the CMMC-unique practices and maturity process requirements of version 1.0, and aligned the remaining practices directly with NIST SP 800-171 and selected NIST SP 800-172 practices.
9From which source are CMMC Level 1 practices derived?
A.NIST SP 800-53
B.The basic safeguarding requirements of FAR 52.204-21
C.ISO/IEC 27001 Annex A
D.The CIS Critical Security Controls
Explanation: CMMC Level 1 consists of practices corresponding to the basic safeguarding requirements in FAR 52.204-21, which has long required contractors to protect Federal Contract Information. These fundamental practices represent basic cyber hygiene.
10From which standard are CMMC Level 2 practices derived?
A.NIST SP 800-53
B.ISO/IEC 27001
C.The NIST Cybersecurity Framework
D.NIST SP 800-171
Explanation: CMMC Level 2 practices are drawn from NIST SP 800-171, the standard for protecting Controlled Unclassified Information in nonfederal systems. Level 2's 110 practices correspond to that standard's 110 security requirements.

About the CMMC Foundation Exam

The PECB Certified CMMC Foundation credential validates foundational knowledge of the Cybersecurity Maturity Model Certification (CMMC) program. The exam evaluates understanding of CMMC objectives, Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) protection, the Cyber AB ecosystem (C3PAO, RPO, Assessor roles), the 14 security domains from NIST SP 800-171, assessment scoping rules, SPRS scoring, and the PECB Code of Ethics.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (Foundation level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

CMMC Foundation Exam Content Outline

42.5%

Fundamental Concepts of the CMMC Model, CMMC Ecosystem, and Code of Professional Conduct

Understand the origin, background, and rationale of CMMC; distinguish between FCI and CUI; analyze regulatory roots (FAR 52.204-21 and DFARS 252.204-7012); identify the roles within the Cyber AB ecosystem (C3PAO, RPO, CCA, CCP, DIBCAC); and apply the PECB Code of Professional Conduct.

57.5%

CMMC Domains, Practices, and Assessment Process

Examine the 14 CMMC domains and their underlying NIST SP 800-171 requirement families; evaluate practice requirements across Level 1 (17 practices) and Level 2 (110 practices); apply asset scoping rules (CUI, SPA, CRMA, Specialized, Out-of-Scope); navigate the 4 assessment phases; interpret SPRS scoring; and manage POA&M closeouts.

How to Pass the CMMC Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only (Foundation level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

CMMC Foundation Study Tips from Top Performers

1Review the two official competency domains in the PECB CMMC Foundation Candidate Handbook to understand domain weighting (42.5% vs 57.5%)
2Memorize the key distinctions between FCI (FAR 52.204-21 / Level 1 / 17 practices) and CUI (DFARS 252.204-7012 / NIST SP 800-171 / Level 2 / 110 practices)
3Master the five CMMC Level 2 asset categories: CUI Assets, Security Protection Assets (SPA), Contractor Risk Managed Assets (CRMA), Specialized Assets, and Out-of-Scope Assets
4Understand the 4 assessment phases (Plan & Prepare, Conduct Assessment, Report Results, POA&M Closeout) and the strict 180-day POA&M closeout window
5Organize and index your open-book course notes and reference manuals in advance so you can quickly lookup specific practice numbers and regulatory references during the 1-hour exam
6Practice timed question sets using this 100-question practice bank to build speed and accuracy under the 1-hour time constraint

Frequently Asked Questions

What is the PECB Certified CMMC Foundation exam format?

The official PECB CMMC Foundation exam contains 40 multiple-choice questions to be completed in 1 hour. It is an open-book exam: candidates may reference official PECB course materials, personal notes, and a hard-copy dictionary during the session.

How does this practice bank compare to the official PECB exam?

This independent practice bank provides 100 high-quality practice questions (expanded beyond the 40-question exam length) to help candidates thoroughly study all key concepts, domain practices, and assessment rules covered in the PECB CMMC Foundation candidate handbook.

What is the difference between PECB CMMC Foundation and the Cyber AB CCP credential?

PECB Certified CMMC Foundation is a PECB-issued foundational certification demonstrating understanding of the CMMC model and assessment process. The Certified CMMC Professional (CCP) is a separate, advanced credential issued through the Cyber AB for individuals who lead or participate in official C3PAO assessment teams.

What is the passing score and exam cost?

The passing score is 70% (28 correct out of 40). The standalone exam fee is USD 500 for Foundation level. When attending a training course with an authorized PECB partner, the exam fee and a free retake voucher are included in the course tuition.

Can I bring study materials into the exam?

Yes. As an open-book exam, candidates may refer to printed or digital PECB course manuals (accessed via the official PECB Exams application), personal study notes taken during training, and a hard-copy translation dictionary.

What is the retake policy if I do not pass on the first attempt?

Candidates who fail on their first attempt must wait 15 days before taking the exam again. Candidates who completed training with an authorized PECB partner are entitled to one free retake within 12 months of receiving their exam coupon.