CCA CCA Risk Management & Vulnerabilities 1 — Questions and Answers
Question 1: In the context of CMMC, what is the primary goal of risk management for defense contractors?
- To maximize profit margins on defense contracts
- To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment (Correct answer)
- To eliminate all cybersecurity tools to reduce attack surface
- To transfer all cybersecurity risk to the DoD
Correct answer: To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment
The primary goal is to protect CUI and FCI by systematically identifying, assessing, and mitigating risks that could compromise the confidentiality, integrity, or availability of that data.
Question 2: Which NIST framework provides the foundational risk management guidance that underpins CMMC requirements?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- NIST Cybersecurity Framework (CSF)
- NIST SP 800-37
Correct answer: NIST SP 800-171
NIST SP 800-171 provides the specific security requirements for protecting CUI that form the technical basis of CMMC Level 2 requirements.
Question 3: What does a Plan of Action & Milestones (POA&M) represent in a CMMC assessment context?
- A roadmap for implementing new DoD contracts
- A documented plan to remediate identified security weaknesses with target completion dates (Correct answer)
- A report submitted to CMMC-AB after certification
- A list of approved third-party vendors
Correct answer: A documented plan to remediate identified security weaknesses with target completion dates
A POA&M documents known security deficiencies and outlines the remediation steps and timelines the OSC plans to follow to address those gaps.
Question 4: Which CMMC domain specifically addresses the requirement for organizations to identify and manage risk to operations?
- Access Control (AC)
- Risk Management (RM) (Correct answer)
- Incident Response (IR)
- Configuration Management (CM)
Correct answer: Risk Management (RM)
The Risk Management domain includes practices that require organizations to identify, assess, and respond to organizational and system risks.
Question 5: A CCA assessor finds that an OSC has not conducted a periodic risk assessment. Which CMMC practice is most likely 'Not Met'?
- AC.2.005
- RM.2.141 (Correct answer)
- IR.2.092
- SI.1.210
Correct answer: RM.2.141
RM.2.141 requires organizations to periodically assess the risk to organizational operations and assets, making it the practice most directly related to conducting risk assessments.
Question 6: What is the relationship between vulnerability management and CMMC compliance?
- Vulnerability management is optional for CMMC Level 2
- CMMC requires organizations to identify, report, and remediate vulnerabilities in organizational systems (Correct answer)
- Vulnerability management only applies to CMMC Level 3
- CMMC delegates vulnerability management entirely to the DoD CSOC
Correct answer: CMMC requires organizations to identify, report, and remediate vulnerabilities in organizational systems
CMMC Level 2 includes practices requiring organizations to identify, report, and remediate vulnerabilities as part of system and information integrity requirements.
In the context of CMMC, what is the primary goal of risk management for defense contractors?