CCA CCA Assessment Planning & Scoping 2 — Questions and Answers
Question 1: Which CMMC assessment guide provides the authoritative criteria used by C3PAOs and CCAs during assessments?
- NIST SP 800-171
- CMMC Assessment Guide Level 2 (Correct answer)
- DFARS 252.204-7012
- DoD CUI Registry
Correct answer: CMMC Assessment Guide Level 2
The CMMC Assessment Guide Level 2 provides the specific assessment objectives and methods that CCAs must use when evaluating OSC implementations.
Question 2: What does the term 'OSC' refer to in the context of CMMC assessments?
- Operations Security Coordinator
- Organization Seeking Certification (Correct answer)
- Oversight and Surveillance Committee
- Official Security Counsel
Correct answer: Organization Seeking Certification
OSC stands for Organization Seeking Certification, referring to the defense contractor undergoing the CMMC assessment.
Question 3: During assessment scoping, what role does the System Security Plan (SSP) play?
- It replaces the need for an assessment plan
- It provides a description of the system boundary, components, and implemented security controls (Correct answer)
- It serves as the final assessment report
- It is submitted to CMMC-AB for review before the assessment
Correct answer: It provides a description of the system boundary, components, and implemented security controls
The SSP describes the system boundary and how security controls are implemented, serving as a critical reference document for scoping and evaluating the assessment.
Question 4: What is the minimum number of assessors required for a CMMC Level 2 certification assessment conducted by a C3PAO?
- One CCA acting independently
- A team of at least two CCAs (Correct answer)
- Three CCAs plus a Certified CMMC Professional
- One CCA and one CMMC Registered Practitioner
Correct answer: A team of at least two CCAs
CMMC Level 2 certification assessments require a team of at least two CCAs to ensure objectivity and thoroughness.
Question 5: What is a 'gap analysis' in the context of CMMC assessment planning?
- A final compliance determination issued by the CMMC-AB
- A pre-assessment review identifying where an OSC does not yet meet CMMC requirements (Correct answer)
- A network vulnerability scan performed during fieldwork
- A review of contractor invoices for missing line items
Correct answer: A pre-assessment review identifying where an OSC does not yet meet CMMC requirements
A gap analysis is a pre-assessment activity that identifies where the OSC's current security posture falls short of CMMC requirements, allowing remediation before the formal assessment.
Question 6: Which factor is most important when determining if a cloud service provider falls within an OSC's CMMC assessment scope?
- Whether the CSP is FedRAMP authorized
- Whether CUI is stored, processed, or transmitted within the CSP environment (Correct answer)
- Whether the CSP has a signed NDA with the OSC
- Whether the CSP is a US-based company
Correct answer: Whether CUI is stored, processed, or transmitted within the CSP environment
A cloud service provider is in scope if CUI is stored, processed, or transmitted within its environment, regardless of FedRAMP status.
Which CMMC assessment guide provides the authoritative criteria used by C3PAOs and CCAs during assessments?