CCA CCA Risk Management & Vulnerabilities 2 — Questions and Answers
Question 1: During a CMMC assessment, an assessor discovers an OSC has unpatched critical vulnerabilities on servers that store CUI. What is the appropriate assessor action?
- Recommend a patch management vendor to the OSC
- Document the finding as 'Not Met' for the relevant patching/vulnerability management practices (Correct answer)
- Ignore it if the server has perimeter firewall protection
- Defer the finding pending OSC remediation
Correct answer: Document the finding as 'Not Met' for the relevant patching/vulnerability management practices
Unpatched critical vulnerabilities on CUI-storing systems directly evidence failure of patch and vulnerability management practices, which must be documented as 'Not Met'.
Question 2: What is the primary purpose of threat intelligence in CMMC risk management?
- To generate marketing materials about cybersecurity threats
- To inform risk assessments and security decisions with current knowledge of threats facing defense contractors (Correct answer)
- To replace the need for vulnerability scanning
- To satisfy DoD reporting requirements only
Correct answer: To inform risk assessments and security decisions with current knowledge of threats facing defense contractors
Threat intelligence provides current information about adversarial tactics, techniques, and procedures relevant to defense contractors, helping organizations make informed risk management decisions.
Question 3: Which practice requires OSCs to monitor system security alerts and advisories under CMMC Level 2?
- AC.2.006
- SI.2.214 (Correct answer)
- CM.2.061
- AU.2.041
Correct answer: SI.2.214
SI.2.214 requires organizations to monitor system security alerts and advisories and take appropriate actions in response, supporting proactive vulnerability awareness.
Question 4: In CMMC risk management, what is meant by 'residual risk'?
- Risk that has been fully eliminated by security controls
- The remaining risk after security controls have been applied (Correct answer)
- Risk associated with terminated employees
- Risk that only applies to legacy systems
Correct answer: The remaining risk after security controls have been applied
Residual risk is the level of risk that remains after security controls have been implemented, which organizations must decide to accept, transfer, or further mitigate.
Question 5: How does CMMC address the risk posed by insider threats?
- CMMC does not address insider threats
- Through practices such as least privilege, separation of duties, and personnel screening (Correct answer)
- By requiring all contractor employees to hold security clearances
- By mandating continuous video surveillance of all workspaces
Correct answer: Through practices such as least privilege, separation of duties, and personnel screening
CMMC addresses insider threat risk through access control practices (least privilege), personnel security practices, and audit/accountability requirements that collectively reduce and detect insider threats.
Question 6: What is the significance of FIPS 140-2 validation in CMMC risk management?
- It is required for all contractor financial systems
- It ensures cryptographic modules meet federal standards, reducing risk of encryption failures protecting CUI (Correct answer)
- It applies only to CMMC Level 3 systems
- It is a voluntary standard with no compliance requirement
Correct answer: It ensures cryptographic modules meet federal standards, reducing risk of encryption failures protecting CUI
FIPS 140-2 validated cryptography is required by CMMC to ensure that encryption protecting CUI meets federal security standards and reduces the risk of cryptographic failure.
During a CMMC assessment, an assessor discovers an OSC has unpatched critical vulnerabilities on servers that store CUI.
What is the appropriate assessor action?