CCA Cheat Sheet 2026

The 30 highest-yield CCA facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
240 min time limit
70.00% to pass
  1. Which CMMC domain deals with identifying and responding to cybersecurity threats? → Incident Response (IR)
  2. What does the CMMC practice PE.L1-3.10.1 require? → Limit physical access to organizational systems to authorized individuals
  3. What evidence types are used in CMMC assessments? → Objective evidence from multiple sources
  4. What is required of assessors before performing evaluations? → Hold certification and adhere to standards
  5. What standard governs the professional competency expected of CCA assessors in performing their assessments? → The CMMC Assessment Guide, Cyber AB standards, and applicable NIST guidance
  6. What does the term 'OSC' refer to in the context of CMMC assessments? → Organization Seeking Certification
  7. Under CMMC 2.0, Level 3 is based primarily on requirements from which source beyond NIST SP 800-171? → NIST SP 800-172
  8. An OSC's self-assessment SPRS score of -203 indicates what about their current compliance posture? → No practices are implemented; maximum negative score reflecting all requirements unmet
  9. Which CMMC compliance artifact describes how security requirements are implemented across an organization's system boundary? → System Security Plan (SSP)
  10. Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology? → NIST SP 800-171A
  11. The 'Risk Assessment (RA)' domain under CMMC requires organizations to: → Periodically assess risk to operations, assets, and individuals from system operations
  12. What is the standard CMMC term for a contractor or subcontractor that undergoes a CMMC assessment to achieve certification? → Organization Seeking Certification (OSC)
  13. What is the purpose of CMMC compliance? → To protect sensitive government information
  14. What is the primary purpose of the Media Protection (MP) domain in CMMC? → To protect system media containing CUI, both paper and digital
  15. Under CMMC, which practice area is concerned with limiting system access to authorized users and the minimum necessary permissions? → Least privilege and need-to-know, under Access Control (AC)
  16. Which DoD contract clause requires contractors to implement basic safeguarding requirements specifically for Federal Contract Information (FCI)? → FAR 52.204-21
  17. Which of the following would constitute a finding of 'NOT MET' for the CMMC practice requiring media sanitization (MP.L2-3.8.3)? → Reformatting a drive and returning it to service without verification of data removal
  18. How many cybersecurity practices are required for CMMC Level 1 (Foundational)? → 17
  19. What type of sensitive information does CMMC Level 2 specifically aim to protect? → Controlled Unclassified Information (CUI)
  20. Which CMMC domain addresses the protection of audit logs and monitoring of system activity? → Audit and Accountability (AU)
  21. What type of assessment is required for a CMMC Level 1 certification? → Annual self-assessment affirmed by a senior official
  22. Which CMMC domain addresses the need to establish and maintain baseline configurations for information technology systems? → Configuration Management (CM)
  23. Which statement BEST describes a Plan of Action and Milestones (POA&M) in the CMMC context? → A roadmap identifying deficiencies and scheduled remediation actions
  24. How is a practice marked during a CMMC assessment? → MET/NOT MET/NOT APPLICABLE
  25. Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required? → 3 years
  26. Which CMMC level specifically addresses protecting CUI against Advanced Persistent Threats (APTs)? → Level 3
  27. Which factor is most important when determining if a cloud service provider falls within an OSC's CMMC assessment scope? → Whether CUI is stored, processed, or transmitted within the CSP environment
  28. A defense subcontractor receives CUI from a prime contractor. Under CMMC 2.0, the subcontractor is required to: → Obtain the same CMMC level certification as required by the prime contractor's contract
  29. Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents? → DFARS 252.204-7012
  30. What is the first step a CCA assessor must complete before beginning a CMMC Level 2 assessment? → Define the assessment scope and boundary
Turn these facts into recall:
Was this helpful?