All Practice Exams

100+ Free NIST Cybersecurity Foundation Practice Questions

Prepare for the PECB NIST Cybersecurity Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: NIST Cybersecurity Foundation Exam

40 MCQ, 1h

Exam Format

PECB

Closed-book

Exam Type

PECB

70%

Passing Score

PECB

USD 500

Exam-Only Fee (Foundation level)

PECB

6 Functions

NIST CSF 2.0 (Govern added in 2024)

NIST

2 domains

PECB Competency Domains

PECB

PECB NIST Cybersecurity Foundation is a closed-book, 40-question, 1-hour MCQ exam (passing score 70%) with no prerequisites. It targets professionals starting in cybersecurity or supporting security initiatives, covering two competency domains: fundamental principles and concepts of cybersecurity, and risk management and cybersecurity controls.

Sample NIST Cybersecurity Foundation Practice Questions

Try these sample questions to test your NIST Cybersecurity Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which three security objectives form the CIA triad that underpins information security?
A.Control, Identification, Authentication
B.Confidentiality, Integrity, Availability
C.Compliance, Investigation, Assessment
D.Containment, Eradication, Recovery
Explanation: The CIA triad — confidentiality, integrity, and availability — is the foundational model of information security described in NIST SP 800-12 and anchored in U.S. federal law (FISMA). Every security control ultimately exists to preserve one or more of these three properties for information and systems.
2What does confidentiality mean in the context of information security?
A.Ensuring information is accessible only to those authorized to have access
B.Ensuring information is accurate and protected against unauthorized modification
C.Ensuring information and systems are usable when required by authorized users
D.Ensuring every action on a system can be traced to the individual who performed it
Explanation: Confidentiality is about preserving authorized restrictions on access and disclosure, protecting both personal privacy and proprietary information. Controls such as encryption, access control lists, and data classification exist primarily to uphold this objective.
3Which NIST Special Publication provides an introduction to information security fundamentals?
A.NIST SP 800-53
B.NIST SP 800-37
C.NIST SP 800-12
D.NIST SP 800-171
Explanation: NIST SP 800-12, 'An Introduction to Information Security,' explains core security concepts, principles, and common controls for a broad audience. It is one of the foundational NIST publications referenced in the PECB NIST Cybersecurity Foundation course.
4What is the primary purpose of the NIST Cybersecurity Framework (CSF)?
A.Mandating binding cybersecurity requirements for all private companies
B.Replacing an organization's risk management process with a fixed checklist
C.Testing and certifying commercial security products for federal use
D.Providing voluntary guidance that helps organizations understand, manage, and reduce cybersecurity risk
Explanation: The NIST CSF is voluntary guidance that gives organizations a common language and structure for understanding, managing, and communicating cybersecurity risk. It does not impose legal obligations, and it complements rather than replaces an organization's risk management process.
5Which statement best describes integrity as a security objective?
A.Information remains available to authorized users whenever it is needed
B.Information is disclosed only to people who are authorized to see it
C.Information is protected against improper modification or destruction, ensuring accuracy and completeness
D.Senders of a message cannot later deny that they sent it
Explanation: Integrity means guarding against improper information modification or destruction, including ensuring non-repudiation and authenticity of information. Hashing, digital signatures, checksums, and version control are typical integrity controls.
6A hospital's patient records system must be accessible to clinicians at all times, including during emergencies. Which security objective is most directly at stake?
A.Availability
B.Confidentiality
C.Non-repudiation
D.Accountability
Explanation: Availability means ensuring timely and reliable access to and use of information and systems. Denial-of-service attacks, ransomware, hardware failures, and natural disasters are classic threats to availability, which is why redundancy, backups, and contingency planning matter.
7Which list contains the six Functions of the NIST Cybersecurity Framework 2.0?
A.Identify, Protect, Detect, Respond, Recover
B.Govern, Identify, Protect, Detect, Respond, Recover
C.Plan, Identify, Defend, Detect, Respond, Restore
D.Prepare, Categorize, Select, Implement, Assess, Authorize
Explanation: CSF 2.0 organizes cybersecurity outcomes into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. The Govern function was added in version 2.0 and informs how an organization implements the other five.
8Which Function was newly introduced in NIST CSF 2.0 compared with earlier versions of the framework?
A.Identify
B.Protect
C.Detect
D.Govern
Explanation: CSF 2.0, published in 2024, added the Govern function, which addresses organizational context, risk management strategy, roles and responsibilities, policies, and oversight. Govern is cross-cutting: it informs how the organization carries out the other five Functions.
9What is the difference between a threat and a vulnerability?
A.A threat is a potential cause of harm; a vulnerability is a weakness that a threat can exploit
B.A threat is a weakness in a system; a vulnerability is the actor that attacks it
C.A threat applies only to natural disasters; a vulnerability applies only to software
D.The two terms are synonyms and can be used interchangeably
Explanation: A threat is any circumstance or event with the potential to adversely impact organizational operations, assets, or individuals. A vulnerability is a weakness in a system, process, or control that could be exploited by a threat source. Risk arises where threats and vulnerabilities intersect.
10How is cybersecurity risk commonly expressed?
A.The total cost of all security controls an organization has deployed
B.The number of vulnerabilities found in the most recent penetration test
C.A function of the likelihood of a threat exploiting a vulnerability and the resulting impact
D.The percentage of employees who completed security awareness training
Explanation: Risk is typically expressed as a function of the likelihood of a threat event and the potential adverse impact if that event occurs. This likelihood-and-impact view underpins NIST risk assessment guidance and drives prioritization of risk treatment.

About the NIST Cybersecurity Foundation Exam

The PECB NIST Cybersecurity Foundation certification validates understanding of fundamental cybersecurity principles and NIST-based best practices. It covers core security concepts, key NIST publications (CSF 2.0, SP 800-12, SP 800-53, SP 800-37 RMF, SP 800-171), cybersecurity risk management, security controls, awareness and training, and incident management basics. Passing the exam and signing the PECB Code of Ethics earns the Certificate Holder in NIST Cybersecurity Foundation credential.

Questions

40 scored questions

Time Limit

1 hour

Passing Score

70%

Exam Fee

USD 500 exam-only (Foundation level); included when taken with PECB partner training (PECB (Professional Evaluation and Certification Board))

NIST Cybersecurity Foundation Exam Content Outline

~45% (weights not published by PECB)

Fundamental Principles and Concepts of Cybersecurity

CIA triad and supporting security properties; threats, vulnerabilities, attack vectors, and risk terminology; identification, authentication, and authorization; defense in depth and least privilege; the NIST Cybersecurity Framework 2.0 (six Functions, Core, Profiles, Tiers); and the purpose of NIST SP 800-12, SP 800-53, SP 800-37 (RMF), and SP 800-171

~55% (weights not published by PECB)

Risk Management and Cybersecurity Controls

Risk assessment (qualitative and quantitative) and the four risk treatment options; residual versus inherent risk; control types (preventive, detective, corrective) and classes (management, operational, technical); SP 800-53 baselines and FIPS 199 categorization; the SP 800-61 incident response life cycle and CSIRT roles; business continuity and disaster recovery basics (BCP/DRP, RTO/RPO, backups, recovery sites); and security awareness, training, and education

How to Pass the NIST Cybersecurity Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 1 hour
  • Exam fee: USD 500 exam-only (Foundation level); included when taken with PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

NIST Cybersecurity Foundation Study Tips from Top Performers

1Memorise which NIST publication does what: SP 800-12 (intro to security), SP 800-53 (control catalog), SP 800-37 (RMF), SP 800-61 (incident handling), SP 800-171 (CUI in nonfederal systems)
2Know the six CSF 2.0 Functions in order and that Govern was added in version 2.0 and informs the other five
3Learn the seven RMF steps in order: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor
4Drill control taxonomies: preventive/detective/corrective by effect, and management/operational/technical by class per SP 800-12
5Memorise the SP 800-61 incident response phases and what activities belong to each (preparation vs. containment vs. eradication vs. post-incident)
6The exam is closed-book — practice recalling frameworks from memory rather than looking them up, and train with 40-question timed sets

Frequently Asked Questions

What is the PECB NIST Cybersecurity Foundation exam format?

The exam consists of 40 multiple-choice questions with a 1-hour time limit. It is closed-book: no reference materials are permitted. The passing score is 70%. The exam can be taken online (proctored via the PECB Exams app) or in paper form at authorised PECB exam venues.

What does the NIST Cybersecurity Foundation certification cover?

The exam covers two PECB competency domains: (1) fundamental principles and concepts of cybersecurity, including the CIA triad, threats and vulnerabilities, and the roles of key NIST publications (CSF 2.0, SP 800-12, SP 800-53, SP 800-37 RMF, SP 800-171); and (2) risk management and cybersecurity controls, including risk treatment, control types and baselines, incident management, and security awareness.

Are there any prerequisites for the exam?

No. There are no prerequisites to attend the training course, and the credential requires no professional experience or project experience. After passing the exam you apply for the Certificate Holder in NIST Cybersecurity Foundation credential, which only requires signing the PECB Code of Ethics.

How much does the exam cost?

The exam-only fee for PECB Foundation-level exams is USD 500. When you take the course through a PECB authorised training partner, the training price includes the first exam attempt, one free retake, the certification application fee, and the first year of the Annual Maintenance Fee (within a 12-month cycle from course completion or purchase).

What happens if I fail the exam?

PECB requires a 15-day waiting period after a failed first attempt before you can retake the exam. Candidates who completed training through a PECB partner are entitled to one free retake within 12 months of the course completion date (or of the purchase date for self-study and eLearning formats).

How should I prepare for the exam?

Attend the 2-day PECB training course (Day 1: NIST standards and principles; Day 2: security controls and incident management), since the course quizzes mirror the exam structure. Because the exam is closed-book, memorise the purpose of each NIST publication, the six CSF 2.0 Functions, the RMF steps, control types, and the SP 800-61 incident response phases. Then complete timed 40-question practice sets within the 1-hour limit.