CCA CCA Evidence Collection & Documentation 1 — Questions and Answers
Question 1: What are the three primary methods of evidence collection used in CMMC assessments?
- Scanning, testing, and reporting
- Examine, interview, and test (Correct answer)
- Review, validate, and certify
- Inspect, analyze, and document
Correct answer: Examine, interview, and test
CMMC assessors use three methods — examine (review documents/artifacts), interview (talk to personnel), and test (observe or exercise controls) — to gather evidence for each practice.
Question 2: When a CCA assessor 'examines' evidence during a CMMC assessment, what activities does this include?
- Conducting hands-on penetration testing of systems
- Reviewing documentation, policies, procedures, system configurations, and other artifacts (Correct answer)
- Interviewing personnel about security practices
- Running automated vulnerability scans
Correct answer: Reviewing documentation, policies, procedures, system configurations, and other artifacts
Examining involves reviewing written artifacts such as policies, procedures, system configurations, logs, and other documentation to assess whether required practices are implemented.
Question 3: What type of evidence is considered most reliable when assessing the implementation of a technical control?
- Verbal assertions from the CISO
- System-generated logs and configuration screenshots observed directly by the assessor (Correct answer)
- Policy documents attesting to the control's existence
- Employee training completion certificates
Correct answer: System-generated logs and configuration screenshots observed directly by the assessor
Direct observation of system-generated evidence (logs, configurations) is most reliable because it provides objective, system-level proof of control implementation rather than relying on assertions.
Question 4: What is a 'finding' in the context of a CMMC assessment?
- A billing item on the assessment invoice
- A documented determination of whether a specific practice is 'Met' or 'Not Met' based on collected evidence (Correct answer)
- A suggestion for improving cybersecurity beyond CMMC requirements
- A report submitted to the contracting officer
Correct answer: A documented determination of whether a specific practice is 'Met' or 'Not Met' based on collected evidence
A finding is the assessor's documented determination of whether an assessed practice is 'Met' or 'Not Met,' supported by the evidence collected during the assessment.
Question 5: Why is maintaining a complete evidence package critical for a CCA assessor?
- To enable marketing of assessment services
- To support the assessment findings, enable quality reviews, and provide a defensible record of the assessment (Correct answer)
- To comply with HIPAA documentation requirements
- To generate metrics for the CMMC-AB annual report
Correct answer: To support the assessment findings, enable quality reviews, and provide a defensible record of the assessment
A complete evidence package documents the basis for every finding, enabling quality assurance reviews and providing a defensible record if findings are challenged.
Question 6: Which of the following would NOT be appropriate as evidence for assessing whether multi-factor authentication (MFA) is implemented?
- A live demonstration of an MFA login
- System configuration screenshots showing MFA settings enabled
- A policy document stating MFA is required
- A signed attestation from the CISO that MFA is in place (Correct answer)
Correct answer: A signed attestation from the CISO that MFA is in place
A signed attestation is a self-assertion without objective technical evidence, making it the weakest and least appropriate evidence type for verifying a technical control like MFA.
What are the three primary methods of evidence collection used in CMMC assessments?