CCA Cheat Sheet 2026

The 30 highest-yield CCA facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

150 questions
240 min time limit
70.00% to pass
  1. Which CMMC domain deals with identifying and responding to cybersecurity threats? Incident Response (IR)
  2. What does the CMMC practice PE.L1-3.10.1 require? Limit physical access to organizational systems to authorized individuals
  3. What evidence types are used in CMMC assessments? Objective evidence from multiple sources
  4. What is required of assessors before performing evaluations? Hold certification and adhere to standards
  5. What standard governs the professional competency expected of CCA assessors in performing their assessments? The CMMC Assessment Guide, Cyber AB standards, and applicable NIST guidance
  6. What does the term 'OSC' refer to in the context of CMMC assessments? Organization Seeking Certification
  7. Under CMMC 2.0, Level 3 is based primarily on requirements from which source beyond NIST SP 800-171? NIST SP 800-172
  8. An OSC's self-assessment SPRS score of -203 indicates what about their current compliance posture? No practices are implemented; maximum negative score reflecting all requirements unmet
  9. Which CMMC compliance artifact describes how security requirements are implemented across an organization's system boundary? System Security Plan (SSP)
  10. Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology? NIST SP 800-171A
  11. The 'Risk Assessment (RA)' domain under CMMC requires organizations to: Periodically assess risk to operations, assets, and individuals from system operations
  12. What is the standard CMMC term for a contractor or subcontractor that undergoes a CMMC assessment to achieve certification? Organization Seeking Certification (OSC)
  13. What is the purpose of CMMC compliance? To protect sensitive government information
  14. What is the primary purpose of the Media Protection (MP) domain in CMMC? To protect system media containing CUI, both paper and digital
  15. Under CMMC, which practice area is concerned with limiting system access to authorized users and the minimum necessary permissions? Least privilege and need-to-know, under Access Control (AC)
  16. Which DoD contract clause requires contractors to implement basic safeguarding requirements specifically for Federal Contract Information (FCI)? FAR 52.204-21
  17. Which of the following would constitute a finding of 'NOT MET' for the CMMC practice requiring media sanitization (MP.L2-3.8.3)? Reformatting a drive and returning it to service without verification of data removal
  18. How many cybersecurity practices are required for CMMC Level 1 (Foundational)? 17
  19. What type of sensitive information does CMMC Level 2 specifically aim to protect? Controlled Unclassified Information (CUI)
  20. Which CMMC domain addresses the protection of audit logs and monitoring of system activity? Audit and Accountability (AU)
  21. What type of assessment is required for a CMMC Level 1 certification? Annual self-assessment affirmed by a senior official
  22. Which CMMC domain addresses the need to establish and maintain baseline configurations for information technology systems? Configuration Management (CM)
  23. Which statement BEST describes a Plan of Action and Milestones (POA&M) in the CMMC context? A roadmap identifying deficiencies and scheduled remediation actions
  24. How is a practice marked during a CMMC assessment? MET/NOT MET/NOT APPLICABLE
  25. Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required? 3 years
  26. Which CMMC level specifically addresses protecting CUI against Advanced Persistent Threats (APTs)? Level 3
  27. Which factor is most important when determining if a cloud service provider falls within an OSC's CMMC assessment scope? Whether CUI is stored, processed, or transmitted within the CSP environment
  28. A defense subcontractor receives CUI from a prime contractor. Under CMMC 2.0, the subcontractor is required to: Obtain the same CMMC level certification as required by the prime contractor's contract
  29. Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents? DFARS 252.204-7012
  30. What is the first step a CCA assessor must complete before beginning a CMMC Level 2 assessment? Define the assessment scope and boundary
Turn these facts into recall:
Was this helpful?