CCA CCA Contractor & Supplier Requirements 2 — Questions and Answers
Question 1: What is a 'covered contractor information system' under DFARS 252.204-7012?
- Any IT system owned by a defense contractor
- An unclassified information system owned or operated by a contractor that processes, stores, or transmits covered defense information (Correct answer)
- Only classified systems used by contractors with SECRET clearances
- Systems covered by contractor property insurance policies
Correct answer: An unclassified information system owned or operated by a contractor that processes, stores, or transmits covered defense information
A covered contractor information system is an unclassified system that processes, stores, or transmits covered defense information (CUI) as required or authorized by the DoD contract.
Question 2: Under CMMC, what is the contractor's obligation regarding media containing CUI that is sent off-site for maintenance?
- No special precautions are required if the vendor has signed an NDA
- CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented (Correct answer)
- Media can be sent to any certified repair vendor without restriction
- Only media containing classified information requires special handling during maintenance
Correct answer: CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented
CMMC media protection practices require that CUI be sanitized or appropriately encrypted when media is sent for maintenance, and the chain of custody must be maintained to protect against unauthorized disclosure.
Question 3: Which practice requires contractors to limit the use of portable storage devices on organizational systems?
- MP.2.120 (Correct answer)
- AC.2.007
- CM.3.068
- SI.1.210
Correct answer: MP.2.120
MP.2.120 requires organizations to control and limit the use of removable media on system components to reduce the risk of data exfiltration or introduction of malicious code.
Question 4: What is the significance of the CMMC Ecosystem in contractor compliance?
- It refers only to the software tools used in CMMC assessments
- It encompasses the network of C3PAOs, CCAs, RPOs, RPs, and the Cyber AB that support contractor CMMC certification (Correct answer)
- It is a DoD internal database of cleared contractors
- It refers to the environmental controls required for CUI storage
Correct answer: It encompasses the network of C3PAOs, CCAs, RPOs, RPs, and the Cyber AB that support contractor CMMC certification
The CMMC Ecosystem includes all the accredited organizations and individuals (C3PAOs, CCAs, RPOs, RPs) that support contractors in achieving and maintaining CMMC compliance under the Cyber AB's oversight.
Question 5: When a contractor uses a cloud service provider (CSP) to store CUI, which federal authorization standard must the CSP meet?
- ISO 27001 certification
- FedRAMP authorization at the appropriate impact level (Correct answer)
- SOC 2 Type II certification
- CMMC Level 2 certification for the CSP itself
Correct answer: FedRAMP authorization at the appropriate impact level
CSPs that store, process, or transmit CUI for defense contractors must meet FedRAMP authorization requirements at the appropriate impact level (typically Moderate or High for CUI).
Question 6: What does CMMC require regarding the protection of CUI in transit across external networks?
- CUI may be transmitted via standard email without encryption
- CUI must be encrypted using FIPS 140-2 validated cryptography when transmitted over external networks (Correct answer)
- CUI transmission over external networks is prohibited entirely
- Encryption is only required for CUI classified above the Controlled level
Correct answer: CUI must be encrypted using FIPS 140-2 validated cryptography when transmitted over external networks
CMMC requires that CUI transmitted over external networks be protected using FIPS 140-2 validated cryptographic mechanisms to prevent unauthorized interception or disclosure.
What is a 'covered contractor information system' under DFARS 252.204-7012?