CCA CCA Evidence Collection & Documentation 2 — Questions and Answers
Question 1: What does the CMMC Assessment Guide specify regarding the 'test' assessment method?
- Tests are optional and only used when other evidence is unavailable
- Tests involve exercising or operating controls to observe how they function and verify their effectiveness (Correct answer)
- Tests are restricted to automated scanning tools only
- Tests may only be performed by DoD personnel
Correct answer: Tests involve exercising or operating controls to observe how they function and verify their effectiveness
Testing involves exercising controls — such as simulating events or performing functional checks — to observe whether they operate as intended and produce expected results.
Question 2: How should a CCA assessor document a practice determination of 'Not Met'?
- With a brief note in the assessment summary only
- With specific evidence, the gap identified, and the practice objective that was not satisfied (Correct answer)
- By recommending a specific vendor solution to the OSC
- By immediately halting the assessment
Correct answer: With specific evidence, the gap identified, and the practice objective that was not satisfied
'Not Met' findings must be documented with the specific evidence reviewed, the identified gap, and which practice objective was not satisfied to ensure transparency and defensibility.
Question 3: What is the purpose of interviewing personnel during a CMMC assessment?
- To collect employee contact information for future outreach
- To gather information about security practice implementation that may not be fully captured in documentation (Correct answer)
- To determine if employees have signed NDAs
- To assess employee satisfaction with cybersecurity policies
Correct answer: To gather information about security practice implementation that may not be fully captured in documentation
Interviews with knowledgeable personnel provide context, clarify how practices are actually implemented day-to-day, and can surface discrepancies between documented procedures and actual practice.
Question 4: Which of the following is an example of objective evidence for assessing the practice of enforcing password complexity requirements?
- An email from the IT director confirming passwords are complex
- A screenshot of Active Directory Group Policy settings showing complexity requirements enabled (Correct answer)
- The organization's password policy document
- Employee acknowledgment forms for the password policy
Correct answer: A screenshot of Active Directory Group Policy settings showing complexity requirements enabled
A screenshot of Group Policy settings directly shows the technical enforcement of password complexity, providing objective evidence that the requirement is implemented at the system level.
Question 5: How should assessors handle conflicting evidence during a CMMC assessment?
- Always side with the OSC's preferred interpretation
- Document all conflicting evidence, gather additional evidence to resolve the conflict, and make a determination based on the weight of evidence (Correct answer)
- Automatically mark the practice as 'Not Met' when any conflict exists
- Defer the finding to the CMMC-AB for resolution
Correct answer: Document all conflicting evidence, gather additional evidence to resolve the conflict, and make a determination based on the weight of evidence
When evidence conflicts, assessors must document the conflict, seek additional evidence to clarify, and make a reasonable determination based on the totality of available evidence.
Question 6: What is the significance of 'sampling' in CMMC evidence collection?
- It allows assessors to only review a subset of systems to draw conclusions about the entire population (Correct answer)
- It is prohibited — all systems must be individually assessed
- It only applies to personnel interviews, not technical controls
- It is used exclusively for CMMC Level 3 assessments
Correct answer: It allows assessors to only review a subset of systems to draw conclusions about the entire population
Sampling allows assessors to review a representative subset of systems, devices, or users to make reasonable inferences about the broader population without exhaustively testing every instance.
What does the CMMC Assessment Guide specify regarding the 'test' assessment method?