Certified CMMC Assessor (CCA) β Questions and Answers
Question 1: Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology?
- NIST SP 800-171
- NIST SP 800-37
- NIST SP 800-171A (Correct answer)
- NIST SP 800-53
Correct answer: NIST SP 800-171A
NIST SP 800-171A provides the assessment procedures for verifying the security requirements in NIST SP 800-171, which form the basis for CMMC Level 2 assessments.
Question 2: How does CMMC 2.0 differ from CMMC 1.0 in terms of maturity levels?
- Both versions use the same 3 levels
- CMMC 2.0 eliminated all maturity levels
- CMMC 2.0 reduced from 5 levels to 3 levels (Correct answer)
- CMMC 2.0 increased from 3 levels to 5 levels
Correct answer: CMMC 2.0 reduced from 5 levels to 3 levels
CMMC 2.0 streamlined the framework from 5 maturity levels in CMMC 1.0 to 3 levels.
Question 3: What action should a CCA take if they believe the lead assessor on their team is making inaccurate or biased findings?
- Silently note the disagreement in their personal assessment notes
- Agree with the lead assessor to maintain team cohesion
- Raise the concern through the C3PAO's quality assurance process and escalate if unresolved (Correct answer)
- Contact the OSC directly to alert them of the discrepancy
Correct answer: Raise the concern through the C3PAO's quality assurance process and escalate if unresolved
CCAs have a professional obligation to raise concerns about inaccurate findings through their organization's quality assurance process, as the integrity of the CMMC program depends on accurate determinations.
Question 4: Which CMMC domain is most directly concerned with ensuring that CUI is only accessible on a need-to-know basis?
- System and Communications Protection (SC)
- Identification and Authentication (IA)
- Access Control (AC) (Correct answer)
- Personnel Security (PS)
Correct answer: Access Control (AC)
The Access Control (AC) domain includes practices that enforce need-to-know access, such as AC.L1-3.1.3 (controlling the flow of CUI).
Question 5: Which document serves as the primary planning artifact for a CMMC assessment?
- Assessment Plan (AP) (Correct answer)
- Plan of Action & Milestones (POA&M)
- Incident Response Plan (IRP)
- System Security Plan (SSP)
Correct answer: Assessment Plan (AP)
The Assessment Plan (AP) is the primary planning artifact that outlines the scope, objectives, schedule, and methodology for a CMMC assessment.
Question 6: A defense subcontractor receives CUI from a prime contractor. Under CMMC 2.0, the subcontractor is required to:
- Obtain the same CMMC level certification as required by the prime contractor's contract (Correct answer)
- Only follow the prime contractor's internal security policies
- Self-attest at Level 1 regardless of what information is handled
- Register with the DoD but is not required to obtain certification
Correct answer: Obtain the same CMMC level certification as required by the prime contractor's contract
CMMC requirements flow down the supply chain; subcontractors handling CUI must obtain the same level of CMMC certification required by the prime contractor.
Question 7: What is the consequence for a CCA who knowingly certifies an OSC that does not meet CMMC requirements?
- Potential decertification, civil liability under the False Claims Act, and possible criminal charges (Correct answer)
- Required additional training on CMMC requirements
- Temporary suspension of assessment privileges for 30 days
- A formal warning from the Cyber AB
Correct answer: Potential decertification, civil liability under the False Claims Act, and possible criminal charges
A CCA who fraudulently certifies non-compliant organizations faces decertification by the Cyber AB, civil liability under the False Claims Act, and potentially criminal prosecution for fraud against the government.
Question 8: How should a CCA respond if an OSC representative attempts to coach or influence the assessor's findings during the assessment?
- Accept the guidance if it comes from a senior executive
- Politely decline and document the attempt, maintaining independent judgment based on evidence (Correct answer)
- Incorporate the feedback as additional context in the findings
- Terminate the assessment immediately and report to DoD IG
Correct answer: Politely decline and document the attempt, maintaining independent judgment based on evidence
Assessors must maintain independence; any attempt to influence findings should be declined and documented, as it represents a potential integrity issue that must be recorded.
Question 9: What happens if a company is found non-compliant during a CMMC assessment?
- They receive provisional approval
- They are given lifetime certification
- They are disqualified until remediation is complete (Correct answer)
- They can skip further assessments
Correct answer: They are disqualified until remediation is complete
If a company is non-compliant, it may be required to address deficiencies before receiving certification.
Question 10: Why is maintaining a complete evidence package critical for a CCA assessor?
- To comply with HIPAA documentation requirements
- To enable marketing of assessment services
- To support the assessment findings, enable quality reviews, and provide a defensible record of the assessment (Correct answer)
- To generate metrics for the CMMC-AB annual report
Correct answer: To support the assessment findings, enable quality reviews, and provide a defensible record of the assessment
A complete evidence package documents the basis for every finding, enabling quality assurance reviews and providing a defensible record if findings are challenged.
Question 11: What is the relationship between vulnerability management and CMMC compliance?
- CMMC delegates vulnerability management entirely to the DoD CSOC
- Vulnerability management only applies to CMMC Level 3
- CMMC requires organizations to identify, report, and remediate vulnerabilities in organizational systems (Correct answer)
- Vulnerability management is optional for CMMC Level 2
Correct answer: CMMC requires organizations to identify, report, and remediate vulnerabilities in organizational systems
CMMC Level 2 includes practices requiring organizations to identify, report, and remediate vulnerabilities as part of system and information integrity requirements.
Question 12: Under CMMC 2.0, which federal regulation mandates that defense contractors protect Controlled Unclassified Information (CUI)?
- FISMA
- DFARS 252.204-7012 (Correct answer)
- FAR 52.204-21
- ITAR Part 120
Correct answer: DFARS 252.204-7012
DFARS 252.204-7012 is the key clause requiring defense contractors to safeguard covered defense information including CUI.
Question 13: What are the three primary methods of evidence collection used in CMMC assessments?
- Inspect, analyze, and document
- Review, validate, and certify
- Scanning, testing, and reporting
- Examine, interview, and test (Correct answer)
Correct answer: Examine, interview, and test
CMMC assessors use three methods β examine (review documents/artifacts), interview (talk to personnel), and test (observe or exercise controls) β to gather evidence for each practice.
Question 14: When an assessor is evaluating the 'identify' objective of a CMMC practice, what is the primary focus?
- Verifying that technical controls are functioning correctly
- Determining whether the OSC can recognize and enumerate the relevant assets, systems, or actions (Correct answer)
- Checking whether personnel have completed required training
- Confirming that policies exist and are approved
Correct answer: Determining whether the OSC can recognize and enumerate the relevant assets, systems, or actions
The 'identify' objective tests whether the organization can correctly recognize and enumerate what is required by the practice, such as identifying CUI or relevant system components.
Question 15: Which practice requires OSCs to monitor system security alerts and advisories under CMMC Level 2?
- AU.2.041
- AC.2.006
- SI.2.214 (Correct answer)
- CM.2.061
Correct answer: SI.2.214
SI.2.214 requires organizations to monitor system security alerts and advisories and take appropriate actions in response, supporting proactive vulnerability awareness.
Question 16: Which of the following is NOT one of the CMMC 2.0 domains?
- Recovery (RE)
- Supply Chain Risk Management (SR)
- Privacy Engineering (PR) (Correct answer)
- Physical Protection (PE)
Correct answer: Privacy Engineering (PR)
Privacy Engineering is not a CMMC 2.0 domain; the 14 domains are inherited from NIST SP 800-171 and related standards.
Question 17: How many cybersecurity practices are required for CMMC Level 1 (Foundational)?
- 110
- 130
- 17 (Correct answer)
- 55
Correct answer: 17
CMMC Level 1 requires 17 practices across 6 domains that align with FAR clause 52.204-21, covering basic cyber hygiene to protect Federal Contract Information (FCI).
Question 18: Which CMMC assessment guide provides the authoritative criteria used by C3PAOs and CCAs during assessments?
- NIST SP 800-171
- DFARS 252.204-7012
- CMMC Assessment Guide Level 2 (Correct answer)
- DoD CUI Registry
Correct answer: CMMC Assessment Guide Level 2
The CMMC Assessment Guide Level 2 provides the specific assessment objectives and methods that CCAs must use when evaluating OSC implementations.
Question 19: When a CCA assessor 'examines' evidence during a CMMC assessment, what activities does this include?
- Reviewing documentation, policies, procedures, system configurations, and other artifacts (Correct answer)
- Interviewing personnel about security practices
- Running automated vulnerability scans
- Conducting hands-on penetration testing of systems
Correct answer: Reviewing documentation, policies, procedures, system configurations, and other artifacts
Examining involves reviewing written artifacts such as policies, procedures, system configurations, logs, and other documentation to assess whether required practices are implemented.
Question 20: What is the DoD's primary objective in implementing CMMC across the Defense Industrial Base (DIB)?
- To reduce the number of small businesses eligible for DoD contracts
- To generate revenue from contractor assessment fees
- To align defense contractor cybersecurity with commercial sector practices
- To protect CUI and FCI from adversaries by verifying that DIB companies have implemented required cybersecurity practices (Correct answer)
Correct answer: To protect CUI and FCI from adversaries by verifying that DIB companies have implemented required cybersecurity practices
CMMC's primary objective is to protect sensitive defense information by verifying that DIB companies have actually implemented required cybersecurity practices, moving beyond self-attestation to third-party verification.
Question 21: The Cyber AB Code of Professional Conduct requires CCAs to protect the confidentiality of what type of information?
- Information the OSC designates as confidential in writing
- Only information explicitly marked 'CUI' during the assessment
- Only information shared during formal interviews
- All sensitive information about the OSC's systems, security posture, and assessment findings (Correct answer)
Correct answer: All sensitive information about the OSC's systems, security posture, and assessment findings
CCAs must protect the confidentiality of all sensitive OSC information encountered during the assessment, not just formally marked CUI, as disclosure could harm the OSC or compromise national security.
Question 22: What does CMMC require regarding the protection of CUI in transit across external networks?
- CUI must be encrypted using FIPS 140-2 validated cryptography when transmitted over external networks (Correct answer)
- CUI may be transmitted via standard email without encryption
- CUI transmission over external networks is prohibited entirely
- Encryption is only required for CUI classified above the Controlled level
Correct answer: CUI must be encrypted using FIPS 140-2 validated cryptography when transmitted over external networks
CMMC requires that CUI transmitted over external networks be protected using FIPS 140-2 validated cryptographic mechanisms to prevent unauthorized interception or disclosure.
Question 23: How is a practice marked during a CMMC assessment?
- MET/NOT MET/NOT APPLICABLE (Correct answer)
- Complete/Incomplete
- Pass/Fail
- Green/Red/Yellow
Correct answer: MET/NOT MET/NOT APPLICABLE
Each practice is evaluated and marked as MET, NOT MET, or NOT APPLICABLE based on collected evidence.
Question 24: Why is it important for a CCA to thoroughly document the rationale for 'Met' findings, not just 'Not Met' findings?
- 'Met' findings do not require documentation beyond a checkbox
- Documenting 'Met' rationale supports quality reviews, defends against appeals, and demonstrates that the assessor actually collected and evaluated evidence (Correct answer)
- Only 'Not Met' findings are subject to Cyber AB review
- Documentation of 'Met' findings is optional based on the C3PAO's QMS preferences
Correct answer: Documenting 'Met' rationale supports quality reviews, defends against appeals, and demonstrates that the assessor actually collected and evaluated evidence
Documenting the evidence and rationale for 'Met' findings is essential for quality assurance, appeals defense, and demonstrating that each determination was based on actual evidence review rather than assumption.
Question 25: Which CMMC practice requires that system security plans (SSPs) be developed, documented, and periodically updated?
- CA.L2-3.12.3
- CA.L2-3.12.2
- CA.L2-3.12.1
- CA.L2-3.12.4 (Correct answer)
Correct answer: CA.L2-3.12.4
CA.L2-3.12.4 specifically requires development, documentation, and periodic updating of system security plans for organizational systems.
Question 26: Which term describes the boundary within which CMMC requirements must be assessed?
- Security enclave
- Assessment boundary (Correct answer)
- Certification zone
- Compliance perimeter
Correct answer: Assessment boundary
The assessment boundary defines the people, technology, facilities, and external service providers that process, store, or transmit CUI/FCI within scope.
Question 27: Which CMMC practice requires organizations to develop and implement a risk management strategy?
- RM.3.144 (Correct answer)
- SI.3.218
- IR.2.093
- AC.1.001
Correct answer: RM.3.144
RM.3.144 requires organizations to periodically assess the risk to organizational operations, assets, and individuals, and to develop risk management strategies to address identified risks.
Question 28: Which statement BEST describes a Plan of Action and Milestones (POA&M) in the CMMC context?
- A document authorizing a system to operate with known risks
- A formal plan for responding to cybersecurity incidents
- A checklist used by C3PAOs during assessments
- A roadmap identifying deficiencies and scheduled remediation actions (Correct answer)
Correct answer: A roadmap identifying deficiencies and scheduled remediation actions
A POA&M documents security deficiencies and the planned corrective actions with target completion dates.
Question 29: In a CMMC compliance report, what does a practice scored as 'MET' indicate?
- The practice is inherited from a parent organization
- The practice is partially implemented with compensating controls
- The practice is waived due to business justification
- All objectives for the practice are fully implemented and verified (Correct answer)
Correct answer: All objectives for the practice are fully implemented and verified
A 'MET' score means all assessment objectives for that practice have been verified as fully and consistently implemented.
Question 30: Which of the following would NOT be appropriate as evidence for assessing whether multi-factor authentication (MFA) is implemented?
- A policy document stating MFA is required
- A signed attestation from the CISO that MFA is in place (Correct answer)
- System configuration screenshots showing MFA settings enabled
- A live demonstration of an MFA login
Correct answer: A signed attestation from the CISO that MFA is in place
A signed attestation is a self-assertion without objective technical evidence, making it the weakest and least appropriate evidence type for verifying a technical control like MFA.
Question 31: When a contractor uses a cloud service provider (CSP) to store CUI, which federal authorization standard must the CSP meet?
- ISO 27001 certification
- FedRAMP authorization at the appropriate impact level (Correct answer)
- SOC 2 Type II certification
- CMMC Level 2 certification for the CSP itself
Correct answer: FedRAMP authorization at the appropriate impact level
CSPs that store, process, or transmit CUI for defense contractors must meet FedRAMP authorization requirements at the appropriate impact level (typically Moderate or High for CUI).
Question 32: What is the minimum number of assessors required for a CMMC Level 2 certification assessment conducted by a C3PAO?
- A team of at least two CCAs (Correct answer)
- Three CCAs plus a Certified CMMC Professional
- One CCA acting independently
- One CCA and one CMMC Registered Practitioner
Correct answer: A team of at least two CCAs
CMMC Level 2 certification assessments require a team of at least two CCAs to ensure objectivity and thoroughness.
Question 33: Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?
- DFARS 252.204-7012 (Correct answer)
- DFARS 252.204-7000
- DFARS 252.239-7010
- DFARS 252.204-7020
Correct answer: DFARS 252.204-7012
DFARS 252.204-7012 requires defense contractors to implement NIST SP 800-171 security requirements and report cyber incidents involving covered contractor information systems within 72 hours.
Question 34: What is the consequence for a defense contractor that falsely self-attests to CMMC compliance?
- Automatic downgrade to CMMC Level 1
- A warning letter from the contracting officer
- Potential liability under the False Claims Act, including significant financial penalties and exclusion from federal contracts (Correct answer)
- Mandatory enrollment in a CMMC remediation program
Correct answer: Potential liability under the False Claims Act, including significant financial penalties and exclusion from federal contracts
False CMMC self-attestations can constitute False Claims Act violations, exposing contractors to treble damages, civil penalties, and potential debarment from government contracting.
Question 35: When scoping a CMMC assessment, which type of data determines what systems fall within scope?
- Export Controlled Technical Data (ECTD)
- Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) (Correct answer)
- Personally Identifiable Information (PII)
- Classified National Security Information (CNSI)
Correct answer: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
FCI and CUI are the data types that determine which systems, personnel, and processes fall within the CMMC assessment scope.
Question 36: What is the first step a CCA assessor must complete before beginning a CMMC Level 2 assessment?
- Define the assessment scope and boundary (Correct answer)
- Install monitoring software on contractor systems
- Review contractor invoices
- Submit the final assessment report
Correct answer: Define the assessment scope and boundary
Defining the assessment scope and boundary is the mandatory first step to ensure all relevant systems and data are properly evaluated.
Question 37: A CCA assessor is reviewing an organization's personnel security practices. Which practice requires screening individuals prior to granting access to CUI systems?
- PS.L2-3.9.1 β Screen individuals prior to authorizing access to organizational systems (Correct answer)
- IA.L2-3.5.5 β Employ identifier management
- PE.L1-3.10.3 β Escort visitors and monitor visitor activity
- AC.L2-3.1.1 β Limit system access to authorized users
Correct answer: PS.L2-3.9.1 β Screen individuals prior to authorizing access to organizational systems
PS.L2-3.9.1 (Personnel Security) requires screening individuals before authorizing access to organizational systems containing CUI.
Question 38: Which NIST publication provides the 110 security requirements that form the basis of CMMC Level 2 compliance?
- NIST SP 800-37
- NIST SP 800-171 (Correct answer)
- NIST CSF v2.0
- NIST SP 800-53
Correct answer: NIST SP 800-171
NIST SP 800-171 'Protecting CUI in Nonfederal Systems and Organizations' provides the 110 requirements mapped to CMMC Level 2.
Question 39: How many domains are defined in CMMC 2.0?
- 14 (Correct answer)
- 12
- 17
- 10
Correct answer: 14
CMMC 2.0 organizes cybersecurity requirements into 14 domains inherited from NIST SP 800-171.
Question 40: Which domain focuses on managing physical access to systems and facilities?
- Access Control (AC)
- System Integrity (SI)
- Physical Protection (PE) (Correct answer)
- Configuration Management (CM)
Correct answer: Physical Protection (PE)
The Physical Protection (PE) domain involves measures to restrict access to sensitive physical areas and systems.
Question 41: An OSC receives a CMMC Level 2 final assessment report. Where is this report ultimately submitted for DoD contract award decisions?
- The System for Award Management (SAM.gov)
- The DoD Contract Management Activity (CMA)
- The Supplier Performance Risk System (SPRS) (Correct answer)
- Directly to the contracting officer via email
Correct answer: The Supplier Performance Risk System (SPRS)
CMMC assessment results and the resulting SPRS score are reported to the Supplier Performance Risk System, which contracting officers review.
Question 42: What is the significance of the CMMC Ecosystem in contractor compliance?
- It refers only to the software tools used in CMMC assessments
- It is a DoD internal database of cleared contractors
- It encompasses the network of C3PAOs, CCAs, RPOs, RPs, and the Cyber AB that support contractor CMMC certification (Correct answer)
- It refers to the environmental controls required for CUI storage
Correct answer: It encompasses the network of C3PAOs, CCAs, RPOs, RPs, and the Cyber AB that support contractor CMMC certification
The CMMC Ecosystem includes all the accredited organizations and individuals (C3PAOs, CCAs, RPOs, RPs) that support contractors in achieving and maintaining CMMC compliance under the Cyber AB's oversight.
Question 43: What is a 'finding' in the context of a CMMC assessment?
- A report submitted to the contracting officer
- A documented determination of whether a specific practice is 'Met' or 'Not Met' based on collected evidence (Correct answer)
- A billing item on the assessment invoice
- A suggestion for improving cybersecurity beyond CMMC requirements
Correct answer: A documented determination of whether a specific practice is 'Met' or 'Not Met' based on collected evidence
A finding is the assessor's documented determination of whether an assessed practice is 'Met' or 'Not Met,' supported by the evidence collected during the assessment.
Question 44: Which of the following is a basic preventive security control?
- Backup restoration
- Audit logging
- Post-incident review
- Firewall implementation (Correct answer)
Correct answer: Firewall implementation
Firewalls act as a first line of defense by filtering incoming and outgoing network traffic.
Question 45: What continuing education requirement must CCAs fulfill to maintain their certification?
- CCAs must complete Cyber AB-required continuing professional education (CPE) credits each year (Correct answer)
- No continuing education is required once certified
- CCAs must retake the full CCA exam every two years
- CCAs must conduct a minimum of 10 assessments per year
Correct answer: CCAs must complete Cyber AB-required continuing professional education (CPE) credits each year
CCAs must complete continuing professional education credits as required by the Cyber AB to maintain current knowledge of CMMC requirements, assessment methodologies, and cybersecurity developments.
Question 46: An organization's network diagram shows that CUI systems and general IT systems share the same network segment. Which CMMC practice is most relevant?
- SC.L2-3.13.2 β Employ architectural designs, software development techniques, and systems engineering to provide effective information security
- RA.L2-3.11.1 β Periodically assess the risk to organizational operations
- SC.L2-3.13.1 β Monitor, control, and protect organizational communications at external boundaries
- AC.L2-3.1.3 β Control the flow of CUI in accordance with approved authorizations (Correct answer)
Correct answer: AC.L2-3.1.3 β Control the flow of CUI in accordance with approved authorizations
AC.L2-3.1.3 requires controlling the flow of CUI using approved authorizations, which includes network segmentation to separate CUI from non-CUI systems.
Question 47: What is the role of a Registered Practitioner Organization (RPO) in the CMMC ecosystem?
- To conduct official CMMC certification assessments
- To serve as the government liaison between DoD and contractors
- To accredit C3PAOs on behalf of the Cyber AB
- To provide CMMC consulting and implementation support to organizations seeking certification, but not to conduct assessments (Correct answer)
Correct answer: To provide CMMC consulting and implementation support to organizations seeking certification, but not to conduct assessments
RPOs provide consulting, advisory, and implementation support to help OSCs prepare for CMMC assessments but are not authorized to conduct official certification assessments.
Question 48: Which factor is most important when determining if a cloud service provider falls within an OSC's CMMC assessment scope?
- Whether the CSP has a signed NDA with the OSC
- Whether the CSP is a US-based company
- Whether CUI is stored, processed, or transmitted within the CSP environment (Correct answer)
- Whether the CSP is FedRAMP authorized
Correct answer: Whether CUI is stored, processed, or transmitted within the CSP environment
A cloud service provider is in scope if CUI is stored, processed, or transmitted within its environment, regardless of FedRAMP status.
Question 49: Under the Cyber AB Code of Professional Conduct, which activity is explicitly prohibited for CCAs?
- Accepting gifts, payments, or favors from an OSC in exchange for favorable assessment findings (Correct answer)
- Discussing assessment methodology with other CCAs
- Conducting assessments outside the assessor's primary geographic region
- Working for multiple C3PAOs simultaneously
Correct answer: Accepting gifts, payments, or favors from an OSC in exchange for favorable assessment findings
Accepting gifts or payments from OSCs in exchange for favorable findings is bribery and a direct violation of the Cyber AB Code of Professional Conduct, which could result in decertification.
Question 50: Under CMMC 2.0, which Level 2 contractors may be permitted to use self-assessment rather than a third-party C3PAO assessment?
- Only contractors with fewer than 50 employees
- All Level 2 contractors if they have a clean prior assessment record
- Contractors that have maintained CMMC Level 1 certification for at least three years
- Contractors on non-prioritized acquisition programs that do not involve CUI (Correct answer)
Correct answer: Contractors on non-prioritized acquisition programs that do not involve CUI
Some CMMC Level 2 contracts involving lower-risk programs may allow self-assessment; however, prioritized acquisition programs handling sensitive CUI require a C3PAO third-party assessment.
Question 51: What is the significance of the CCA oath or attestation taken at certification?
- It certifies the CCA as a licensed cybersecurity attorney
- It transfers liability for assessment findings to the Cyber AB
- It commits the CCA to uphold the Cyber AB Code of Professional Conduct and perform assessments with integrity and objectivity (Correct answer)
- It is a formality with no legal significance
Correct answer: It commits the CCA to uphold the Cyber AB Code of Professional Conduct and perform assessments with integrity and objectivity
The CCA attestation is a formal commitment to uphold professional standards, objectivity, and the Cyber AB's Code of Professional Conduct throughout the assessor's certification period.
Question 52: Which CMMC practice requires that remote access sessions be controlled and monitored?
- IA.L2-3.5.3 β Use multifactor authentication for network access
- AC.L2-3.1.14 β Route remote access via managed access control points
- SC.L2-3.13.5 β Implement subnetworks for publicly accessible system components
- AC.L2-3.1.12 β Monitor and control remote access sessions (Correct answer)
Correct answer: AC.L2-3.1.12 β Monitor and control remote access sessions
AC.L2-3.1.12 specifically requires that remote access sessions be monitored and controlled to reduce the risk of unauthorized access.
Question 53: What is the maximum timeframe an OSC has under CMMC 2.0 to resolve a POA&M item before it causes assessment failure at Level 2?
- 30 days
- 365 days
- 90 days
- 180 days (Correct answer)
Correct answer: 180 days
Under CMMC 2.0 rules, POA&M items must be closed within 180 days of a conditional certification being awarded.
Question 54: What is the key distinction between a Plan of Action and Milestones (POA&M) and a System Security Plan (SSP) in the context of CMMC?
- An SSP is reviewed by the DoD; a POA&M remains internal to the organization
- An SSP documents the current security posture while a POA&M documents gaps and remediation timelines (Correct answer)
- An SSP documents deficiencies while a POA&M documents all implemented controls
- A POA&M is required only at Level 3; an SSP is required at all levels
Correct answer: An SSP documents the current security posture while a POA&M documents gaps and remediation timelines
The SSP describes the current state of security controls, while the POA&M identifies gaps and establishes timelines to remediate them.
Question 55: What does the term 'OSC' refer to in the context of CMMC assessments?
- Organization Seeking Certification (Correct answer)
- Oversight and Surveillance Committee
- Official Security Counsel
- Operations Security Coordinator
Correct answer: Organization Seeking Certification
OSC stands for Organization Seeking Certification, referring to the defense contractor undergoing the CMMC assessment.
Question 56: Which of the following scenarios represents a conflict of interest for a CCA assessor?
- Assessing an OSC for which the assessor previously provided CMMC consulting or implementation support (Correct answer)
- Assessing an OSC in a different state than where the assessor is located
- Assessing an OSC that is a competitor of a former employer
- Assessing an OSC in an industry the assessor is unfamiliar with
Correct answer: Assessing an OSC for which the assessor previously provided CMMC consulting or implementation support
A CCA who previously provided consulting or implementation help to an OSC has a conflict of interest because they would effectively be assessing their own prior work, compromising objectivity.
Question 57: What is the significance of 'sampling' in CMMC evidence collection?
- It is prohibited β all systems must be individually assessed
- It only applies to personnel interviews, not technical controls
- It allows assessors to only review a subset of systems to draw conclusions about the entire population (Correct answer)
- It is used exclusively for CMMC Level 3 assessments
Correct answer: It allows assessors to only review a subset of systems to draw conclusions about the entire population
Sampling allows assessors to review a representative subset of systems, devices, or users to make reasonable inferences about the broader population without exhaustively testing every instance.
Question 58: Which entity is responsible for authorizing C3PAOs to conduct CMMC assessments?
- The Department of Defense directly
- The Cybersecurity and Infrastructure Security Agency (CISA)
- NIST
- The CMMC Accreditation Body (CMMC-AB), also known as The Cyber AB (Correct answer)
Correct answer: The CMMC Accreditation Body (CMMC-AB), also known as The Cyber AB
The Cyber AB (formerly CMMC-AB) is the accreditation body that authorizes C3PAOs to conduct official CMMC assessments and certifies CCA assessors.
Question 59: Which of the following best describes the Final Assessment Report in the CMMC assessment lifecycle?
- A marketing document describing the C3PAO's assessment methodology
- A preliminary document shared only with the OSC
- The authoritative record of all findings, determinations, and the overall CMMC Level achievement submitted to the CMMC-AB (Correct answer)
- An internal C3PAO quality assurance document
Correct answer: The authoritative record of all findings, determinations, and the overall CMMC Level achievement submitted to the CMMC-AB
The Final Assessment Report is the authoritative deliverable documenting all practice determinations, findings, and the overall CMMC Level achievement that is submitted to the CMMC-AB.
Question 60: Which organization oversees the CMMC assessment ecosystem?
- NIST
- CMMC-AB (Correct answer)
- ISO
- NSA
Correct answer: CMMC-AB
The CMMC Accreditation Body (CMMC-AB) manages the training, certification, and performance of assessors and C3PAOs.
Question 61: A CCA finds that an OSC tracks and reports CUI incidents to their FSO but has no documented process for reporting to US-CERT within the required timeframe. Which practice is NOT MET?
- SI.L2-3.14.6 - Security Alert Monitoring
- AU.L2-3.3.1 - System Audit Logging
- IR.L2-3.6.2 - Incident Reporting to Authorities (Correct answer)
- IR.L2-3.6.1 - Incident Response Capability
Correct answer: IR.L2-3.6.2 - Incident Reporting to Authorities
IR.L2-3.6.2 requires reporting cybersecurity incidents to appropriate authorities including US-CERT within the required 72-hour timeframe per DFARS.
Question 62: What is the role of the C3PAO's Quality Management System (QMS) in maintaining assessment integrity?
- It is an optional certification that C3PAOs may pursue voluntarily
- It tracks assessor travel expenses and scheduling
- It provides a framework for ensuring assessments are conducted consistently, accurately, and in compliance with CMMC requirements and Cyber AB standards (Correct answer)
- It manages the C3PAO's financial accounts and billing processes
Correct answer: It provides a framework for ensuring assessments are conducted consistently, accurately, and in compliance with CMMC requirements and Cyber AB standards
The QMS provides processes and procedures that ensure all assessments conducted by a C3PAO meet CMMC and Cyber AB quality standards, supporting consistency and accuracy across the assessment team.
Question 63: Which role within the CMMC ecosystem is responsible for publishing and maintaining the CMMC standard, assessment guides, and rulemaking?
- DoD (Department of Defense) (Correct answer)
- C3PAO (Certified Third-Party Assessor Organization)
- Cyber AB (Accreditation Body)
- NIST (National Institute of Standards and Technology)
Correct answer: DoD (Department of Defense)
The DoD owns and publishes the CMMC model, issues the final rule through 32 CFR Part 170, and sets all programmatic policy.
Question 64: What is a key feature of Level 2 in CMMC 2.0?
- No third-party assessments required
- Alignment with NIST SP 800-171 (Correct answer)
- Focus on informal controls
- Elimination of documentation
Correct answer: Alignment with NIST SP 800-171
Level 2 (Advanced) aligns with NIST SP 800-171 and is required for organizations handling CUI.
Question 65: The 'Risk Assessment (RA)' domain under CMMC requires organizations to:
- Only perform risk assessments when a new system is deployed
- Outsource all risk assessments to a certified third party
- Periodically assess risk to operations, assets, and individuals from system operations (Correct answer)
- Document risks but take no action unless directed by the DoD
Correct answer: Periodically assess risk to operations, assets, and individuals from system operations
The RA domain requires organizations to conduct periodic risk assessments and use findings to inform security decisions and remediation efforts.
Question 66: Which NIST SP 800-171 control family maps to the CMMC Audit and Accountability (AU) domain?
- Control Family 3.1 β Access Control
- Control Family 3.3 β Audit and Accountability (Correct answer)
- Control Family 3.5 β Identification and Authentication
- Control Family 3.12 β Security Assessment
Correct answer: Control Family 3.3 β Audit and Accountability
CMMC's AU domain maps directly to NIST SP 800-171 Control Family 3.3, Audit and Accountability.
Question 67: What is a 'covered contractor information system' under DFARS 252.204-7012?
- Only classified systems used by contractors with SECRET clearances
- An unclassified information system owned or operated by a contractor that processes, stores, or transmits covered defense information (Correct answer)
- Systems covered by contractor property insurance policies
- Any IT system owned by a defense contractor
Correct answer: An unclassified information system owned or operated by a contractor that processes, stores, or transmits covered defense information
A covered contractor information system is an unclassified system that processes, stores, or transmits covered defense information (CUI) as required or authorized by the DoD contract.
Question 68: Which domain ensures users are only granted necessary access?
- Access Control (AC) (Correct answer)
- System and Communications Protection (SC)
- Identification and Authentication (IA)
- Security Assessment (CA)
Correct answer: Access Control (AC)
The Access Control (AC) domain requires limiting system access to authorized users and processes based on the principle of least privilege.
Question 69: Under CMMC, what specific obligation does a contractor have if it discovers that a subcontractor handling CUI has suffered a cyber incident?
- The prime contractor must immediately terminate the subcontract
- The prime contractor must conduct its own assessment of the subcontractor's systems
- The prime contractor must ensure the subcontractor reports the incident to DoD and may need to report itself if its own covered systems are affected (Correct answer)
- The prime contractor has no obligation regarding subcontractor incidents
Correct answer: The prime contractor must ensure the subcontractor reports the incident to DoD and may need to report itself if its own covered systems are affected
Prime contractors are responsible for ensuring subcontractors comply with CMMC requirements, including incident reporting, and the prime may have its own reporting obligations if the incident affects covered information on its systems.
Question 70: When assessing Configuration Management controls, a CCA assessor finds that change requests are approved verbally with no documentation. Which practice gap does this represent?
- CM.L2-3.4.5 β Define, document, and implement a system component inventory
- CM.L2-3.4.1 β Establish and maintain baseline configurations
- CM.L2-3.4.9 β Control and monitor user-installed software
- CM.L2-3.4.3 β Track, review, approve, and log changes to organizational systems (Correct answer)
Correct answer: CM.L2-3.4.3 β Track, review, approve, and log changes to organizational systems
CM.L2-3.4.3 requires that changes be tracked, reviewed, approved, and logged; verbal-only approvals lack the required documentation.
Question 71: What is the appropriate response when a CCA's assessment finding is disputed by the OSC after the assessment is complete?
- Change the finding to avoid conflict with the client
- Follow the C3PAO's formal dispute resolution process, reviewing evidence with appropriate oversight (Correct answer)
- Close the dispute by issuing a revised finding that splits the difference
- Refer the dispute directly to DoD for resolution
Correct answer: Follow the C3PAO's formal dispute resolution process, reviewing evidence with appropriate oversight
Disputes must be handled through formal, documented processes with appropriate oversight to ensure that any revisions to findings are based on legitimate new evidence or valid technical disagreement, not client pressure.
Question 72: A CCA reviews an OSC's incident response documentation and finds no evidence of annual IR testing. Which compliance artifact would best close this gap?
- Updated System Security Plan narrative section
- Vendor attestation that IR capability exists
- Insurance policy covering cyber incidents
- Documented tabletop exercise or IR drill records with after-action report (Correct answer)
Correct answer: Documented tabletop exercise or IR drill records with after-action report
Documented evidence of conducted IR exercises (tabletop, walkthrough, or full drill) with after-action reports demonstrates practice implementation.
Question 73: A CMMC assessor is reviewing access control practices. An employee states they share credentials with a colleague when that colleague is out of the office. How should this be scored?
- MET, because the practice is still technically implemented on the system
- NOT MET, because shared credentials violate individual accountability requirements (Correct answer)
- DEFERRED, pending management review
- NOT APPLICABLE, because the colleague is absent
Correct answer: NOT MET, because shared credentials violate individual accountability requirements
Credential sharing violates the individual accountability principle required by access control practices, making the relevant practice NOT MET regardless of technical configurations.
Question 74: The 'Media Protection (MP)' domain in CMMC primarily governs:
- Protection, control, sanitization, and disposal of digital and physical media containing CUI (Correct answer)
- Encryption of multimedia files sent via email
- Social media usage policies for employees
- Monitoring broadcast media for cybersecurity threats
Correct answer: Protection, control, sanitization, and disposal of digital and physical media containing CUI
The MP domain covers the handling, marking, storage, transport, and destruction of media that contains sensitive information.
Question 75: Which practice requires contractors to limit the use of portable storage devices on organizational systems?
- MP.2.120 (Correct answer)
- SI.1.210
- AC.2.007
- CM.3.068
Correct answer: MP.2.120
MP.2.120 requires organizations to control and limit the use of removable media on system components to reduce the risk of data exfiltration or introduction of malicious code.
Question 76: Under CMMC, which practice area is concerned with limiting system access to authorized users and the minimum necessary permissions?
- Baseline configuration under Configuration Management (CM)
- Role separation under Personnel Security (PS)
- Authorized use under Awareness and Training (AT)
- Least privilege and need-to-know, under Access Control (AC) (Correct answer)
Correct answer: Least privilege and need-to-know, under Access Control (AC)
The Access Control domain enforces least privilege and need-to-know principles to restrict what users can access and do.
Question 77: What type of evidence is considered most reliable when assessing the implementation of a technical control?
- Verbal assertions from the CISO
- Policy documents attesting to the control's existence
- Employee training completion certificates
- System-generated logs and configuration screenshots observed directly by the assessor (Correct answer)
Correct answer: System-generated logs and configuration screenshots observed directly by the assessor
Direct observation of system-generated evidence (logs, configurations) is most reliable because it provides objective, system-level proof of control implementation rather than relying on assertions.
Question 78: In CMMC assessments, what is a 'Contractor Risk Managed Asset' (CRA)?
- An asset that processes CUI and is included in the assessment scope
- Any asset that has been formally decommissioned from the network
- An asset that can reach CUI but is managed with compensating controls outside the assessment scope (Correct answer)
- A third-party vendor system used to store CUI backups
Correct answer: An asset that can reach CUI but is managed with compensating controls outside the assessment scope
A CRA is an asset that can reach CUI-scoped assets but is separated and managed by the contractor with mitigating controls, placing it outside the full assessment scope.
Question 79: Which CMMC practice requires organizations to conduct risk assessments and use the results to inform security control selection?
- SI.L2-3.14.1 β Identify, report, and correct information system flaws
- RA.L2-3.11.1 β Periodically assess the risk to organizational operations, assets, and individuals (Correct answer)
- CA.L2-3.12.1 β Periodically assess the security controls in organizational systems
- CM.L2-3.4.1 β Establish and maintain baseline configurations
Correct answer: RA.L2-3.11.1 β Periodically assess the risk to organizational operations, assets, and individuals
RA.L2-3.11.1 requires periodic risk assessments to evaluate risk to operations, assets, and individuals, providing the basis for security control decisions.
Question 80: During a CMMC Level 2 assessment, the CCA identifies that an OSC's cloud environment is not FedRAMP authorized. What is the compliance implication?
- The cloud service must meet CMMC Level 2 equivalent requirements and be documented in the SSP (Correct answer)
- Non-FedRAMP cloud services are automatically disqualifying for any CMMC certification
- The OSC must immediately migrate all CUI to on-premises systems
- FedRAMP authorization is only required for Level 3 assessments
Correct answer: The cloud service must meet CMMC Level 2 equivalent requirements and be documented in the SSP
Non-FedRAMP cloud services can be used if they meet CMMC Level 2 equivalent security requirements, which must be documented and verified during assessment.
Question 81: How does CMMC handle a scenario where an OSC uses an external IT managed service provider (MSP) that accesses CUI-handling systems?
- The MSP must be included in the assessment scope or have its own CMMC certification, depending on the nature of its access (Correct answer)
- MSPs are regulated separately under FISMA, not CMMC
- MSPs only need to sign a CMMC compliance attestation form
- MSPs are automatically exempt from CMMC requirements
Correct answer: The MSP must be included in the assessment scope or have its own CMMC certification, depending on the nature of its access
MSPs with privileged access to CUI-handling systems must be scoped into the assessment or demonstrate their own CMMC compliance, as their access creates direct risk to the CUI environment.
Question 82: How many domains are included in the CMMC 2.0 model?
- 24
- 14 (Correct answer)
- 20
- 17
Correct answer: 14
CMMC 2.0 includes 14 domains (e.g., AC, AT, AU, CM, IA, IR, MA, MP, PE, PS, RA, CA, SC, SI) that map to the control families in NIST SP 800-171.
Question 83: Which of the following evidence types would a CCA accept as proof that an OSC has implemented multi-factor authentication (MFA) for CUI system access?
- An employee attestation form signed by all users confirming they use MFA
- Active Directory group policy screenshots showing MFA enforcement combined with a live system demonstration (Correct answer)
- A written policy stating MFA is required for all users
- A vendor invoice showing purchase of an MFA solution
Correct answer: Active Directory group policy screenshots showing MFA enforcement combined with a live system demonstration
CCAs require documentary and demonstrable evidence of implementation; policy alone or purchase records do not prove active enforcement.
Question 84: In CMMC 2.0, what is the primary role of an OSC (Organization Seeking Certification)?
- To implement required security practices and undergo assessment (Correct answer)
- To develop CMMC policy and update the framework
- To conduct assessments of other defense contractors
- To accredit C3PAOs on behalf of the DoD
Correct answer: To implement required security practices and undergo assessment
An OSC is the defense contractor or subcontractor that must implement CMMC requirements and be assessed to receive certification.
Question 85: A CCA assessor is evaluating an organization's use of mobile devices. Which practice requires the organization to sanitize or destroy media before disposal or reuse?
- CM.L2-3.4.2 β Establish and enforce security configuration settings
- MP.L2-3.8.3 β Sanitize or destroy system media before disposal or reuse (Correct answer)
- SI.L2-3.14.2 β Provide protection from malicious code
- AC.L2-3.1.18 β Control connection of mobile devices
Correct answer: MP.L2-3.8.3 β Sanitize or destroy system media before disposal or reuse
MP.L2-3.8.3 requires that system media be sanitized or destroyed before disposal or reuse to prevent unauthorized disclosure of CUI.
Question 86: Which CMMC practice specifically requires organizations to separate user functionality from system management functionality?
- CM.L2-3.4.5
- IA.L2-3.5.6
- SC.L2-3.13.3 (Correct answer)
- AC.L2-3.1.6
Correct answer: SC.L2-3.13.3
SC.L2-3.13.3 requires separation of user functionality from system management functionality to reduce risk.
Question 87: How long must C3PAOs retain CMMC assessment records?
- The duration of the DoD contract only
- 6 years from the date of assessment completion (Correct answer)
- 1 year from the date of assessment completion
- Indefinitely with no retention limit
Correct answer: 6 years from the date of assessment completion
CMMC requirements specify that C3PAOs must retain assessment records for a minimum of 6 years from the assessment completion date to support audits and reviews.
Question 88: What is the primary purpose of the CMMC Assessment Process (CAP) document published by the Cyber AB?
- To establish pricing guidelines for C3PAO assessment contracts
- To replace the NIST SP 800-171A assessment objectives
- To provide OSCs with a self-assessment checklist
- To standardize how C3PAOs conduct, document, and report CMMC assessments (Correct answer)
Correct answer: To standardize how C3PAOs conduct, document, and report CMMC assessments
The CAP establishes uniform procedures for C3PAOs to ensure consistent, repeatable, and trustworthy CMMC assessment execution and reporting.
Question 89: Under CMMC 2.0, Level 3 is based primarily on requirements from which source beyond NIST SP 800-171?
- CIS Controls v8
- NIST SP 800-172 (Correct answer)
- NIST SP 800-53 Moderate Baseline
- ISO/IEC 27002
Correct answer: NIST SP 800-172
CMMC Level 3 incorporates requirements from NIST SP 800-172, which provides enhanced security requirements for protecting CUI.
Question 90: Under what circumstances may a CCA share OSC assessment findings with parties outside the C3PAO and OSC?
- Only when required by law, court order, or explicitly authorized by the OSC (Correct answer)
- Whenever requested by other government contractors
- When the information is more than 90 days old
- When sharing would benefit the broader cybersecurity community
Correct answer: Only when required by law, court order, or explicitly authorized by the OSC
CCA confidentiality obligations restrict sharing of assessment findings to situations required by law, compelled by court order, or explicitly authorized by the OSC, protecting the OSC's sensitive security information.
Question 91: What is the purpose of CMMC compliance?
- To protect sensitive government information (Correct answer)
- To simplify billing processes
- To lower taxes
- To reduce software licenses
Correct answer: To protect sensitive government information
CMMC compliance ensures that contractors handling federal contract information and controlled unclassified information implement required cybersecurity practices.
Question 92: What must a CCA assessor do if an OSC provides documentation that appears to have been created specifically for the assessment rather than representing actual operations?
- Accept the documentation without question
- Request the OSC to backdate the documentation
- Immediately terminate the assessment and report fraud to DoD IG
- Flag the concern, seek corroborating evidence through interviews and system observations, and document the discrepancy (Correct answer)
Correct answer: Flag the concern, seek corroborating evidence through interviews and system observations, and document the discrepancy
Assessors must seek corroborating evidence to determine if controls are genuinely implemented; documentation that appears created solely for the assessment requires additional verification through technical testing and interviews.
Question 93: What is the assessor's responsibility when reviewing an OSC's incident response documentation during a CMMC assessment?
- To test whether the plan can withstand a DoD red team exercise
- To confirm the plan was approved by the contracting officer
- To assess whether the documentation addresses CMMC incident response practice requirements and that personnel know how to execute the plan (Correct answer)
- To verify the plan was created by a qualified cybersecurity professional
Correct answer: To assess whether the documentation addresses CMMC incident response practice requirements and that personnel know how to execute the plan
Assessors must verify that incident response documentation satisfies CMMC practice requirements and that staff are trained to execute the plan, combining examination of documents with interviews of personnel.
Question 94: Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required?
- 2 years
- 5 years
- 3 years (Correct answer)
- 1 year
Correct answer: 3 years
CMMC Level 2 certifications obtained through C3PAO assessments are valid for three years, after which a new assessment must be completed.
Question 95: During the planning phase, an assessor develops the Assessment Plan (AP). Which element is MOST important to establish in the AP to ensure a focused, efficient assessment?
- The remediation timeline for identified gaps
- The names of all OSC employees who will be interviewed
- The billing schedule for the assessment
- The assessment scope including the OSC's CUI boundary and in-scope systems (Correct answer)
Correct answer: The assessment scope including the OSC's CUI boundary and in-scope systems
Establishing the assessment scope β particularly the CUI boundary and in-scope assets β is foundational to ensuring the assessment is focused and all relevant systems are evaluated.
Question 96: What is the purpose of interviewing personnel during a CMMC assessment?
- To collect employee contact information for future outreach
- To assess employee satisfaction with cybersecurity policies
- To determine if employees have signed NDAs
- To gather information about security practice implementation that may not be fully captured in documentation (Correct answer)
Correct answer: To gather information about security practice implementation that may not be fully captured in documentation
Interviews with knowledgeable personnel provide context, clarify how practices are actually implemented day-to-day, and can surface discrepancies between documented procedures and actual practice.
Question 97: What is the primary purpose of the 'Configuration Management (CM)' domain in CMMC?
- Managing user access privileges
- Encrypting data at rest and in transit
- Monitoring network traffic for anomalies
- Establishing and maintaining baseline configurations of systems (Correct answer)
Correct answer: Establishing and maintaining baseline configurations of systems
The CM domain focuses on establishing, documenting, and enforcing baseline security configurations for organizational systems.
Question 98: In CMMC assessment planning, what is a 'Letter of Assessment'?
- A letter sent to DIBCAC after assessment completion
- A preliminary compliance finding issued mid-assessment
- A formal contract between the C3PAO and the OSC authorizing the assessment (Correct answer)
- A notification sent to subcontractors about their CMMC obligations
Correct answer: A formal contract between the C3PAO and the OSC authorizing the assessment
The Letter of Assessment is the formal agreement between the C3PAO and the OSC that authorizes and defines the scope of the assessment engagement.
Question 99: What is the purpose of a pre-assessment kickoff meeting in CMMC assessment planning?
- To submit findings to the CMMC-AB
- To establish ground rules, confirm scope, and align expectations between assessors and the OSC (Correct answer)
- To sign the final assessment report
- To conduct penetration testing
Correct answer: To establish ground rules, confirm scope, and align expectations between assessors and the OSC
The kickoff meeting aligns the assessment team and the Organization Seeking Certification (OSC) on scope, logistics, and expectations before fieldwork begins.
Question 100: Which CMMC domain covers the vetting of personnel before granting access to systems containing CUI?
- Awareness and Training (AT)
- Access Control (AC)
- Identification and Authentication (IA)
- Personnel Security (PS) (Correct answer)
Correct answer: Personnel Security (PS)
The Personnel Security domain addresses screening individuals prior to granting access and managing termination or transfer processes.
Question 101: Which practice requires that CMMC Level 2 organizations scan for vulnerabilities in organizational systems and applications periodically?
- RA.L2-3.11.2 (Correct answer)
- CM.L2-3.4.7
- CA.L2-3.12.1
- SI.L2-3.14.1
Correct answer: RA.L2-3.11.2
RA.L2-3.11.2 requires periodic vulnerability scanning of organizational systems and hosted applications.
Question 102: During an assessment, the 'test' method is most appropriate for evaluating which type of control?
- A written policy describing acceptable use
- A technical control such as an access control mechanism or audit logging function that can be exercised to verify operation (Correct answer)
- Management's commitment to cybersecurity
- The completeness of an incident response plan document
Correct answer: A technical control such as an access control mechanism or audit logging function that can be exercised to verify operation
The 'test' method involves exercising or operating a mechanism to verify it functions as intended, making it most appropriate for technical controls that can be activated or triggered.
Question 103: Which of the following best describes 'assessment scope creep' in CMMC assessments?
- Updating the assessment plan after the kickoff meeting
- Requesting additional evidence from the OSC
- Adding additional assessors mid-assessment
- Expanding the assessment boundary beyond what was originally agreed upon without formal change control (Correct answer)
Correct answer: Expanding the assessment boundary beyond what was originally agreed upon without formal change control
Scope creep occurs when the assessment boundary expands informally beyond its agreed limits, potentially causing delays and resource issues without proper change management.
Question 104: What is the primary ethical obligation of a CCA during a CMMC assessment?
- To recommend specific security products that the assessor is familiar with
- To help the OSC achieve the highest possible CMMC score
- To complete the assessment as quickly as possible to minimize disruption to the OSC
- To provide an objective, impartial, and accurate assessment of the OSC's cybersecurity practices (Correct answer)
Correct answer: To provide an objective, impartial, and accurate assessment of the OSC's cybersecurity practices
A CCA's primary ethical obligation is objectivity and accuracy β assessments must reflect actual compliance status, not what the OSC or the C3PAO would prefer the outcome to be.
Question 105: Which CMMC practice addresses the requirement to control and monitor user-installed software?
- CM.L2-3.4.8 β Apply deny-by-exception policy to prevent use of unauthorized software (Correct answer)
- CM.L2-3.4.6 β Employ principle of least functionality
- AC.L2-3.1.5 β Employ principle of least privilege
- SI.L2-3.14.2 β Provide protection from malicious code
Correct answer: CM.L2-3.4.8 β Apply deny-by-exception policy to prevent use of unauthorized software
CM.L2-3.4.8 requires a deny-by-exception (blacklisting or whitelisting) policy to prevent or restrict installation of unauthorized software.
Question 106: Who is responsible for submitting CMMC assessment results?
- Contracting officer
- C3PAO (Correct answer)
- Any employee
- System administrator
Correct answer: C3PAO
Certified Third-Party Assessment Organizations (C3PAOs) are responsible for submitting results to the DoD for validation and certification.
Question 107: What is the purpose of the CMMC Assessment Scope categorization of 'Contractor Risk Managed Assets' (CRMAs)?
- Assets outside the assessment boundary entirely
- Assets that could impact CUI but are managed by the contractor under documented risk controls (Correct answer)
- Assets owned by DoD that contractors must protect
- Assets that require full CMMC assessment regardless of CUI contact
Correct answer: Assets that could impact CUI but are managed by the contractor under documented risk controls
CRMAs are assets that can affect CUI security but are managed through contractor-defined risk controls rather than full CMMC practice application.
Question 108: What is the significance of External Service Providers (ESPs) in CMMC scoping?
- They are only in scope for CMMC Level 3 assessments
- They only need to be scoped if they hold a DoD contract
- They are automatically excluded from scope
- They must be included in scope if they process, store, or transmit CUI (Correct answer)
Correct answer: They must be included in scope if they process, store, or transmit CUI
External Service Providers that handle CUI on behalf of the OSC must be included in the assessment scope to ensure comprehensive coverage.
Question 109: What standard governs the professional competency expected of CCA assessors in performing their assessments?
- The CMMC Assessment Guide, Cyber AB standards, and applicable NIST guidance (Correct answer)
- The assessor's personal judgment about what is reasonable
- The standards of the largest competing cybersecurity frameworks
- The contracting officer's specific directions for each assessment
Correct answer: The CMMC Assessment Guide, Cyber AB standards, and applicable NIST guidance
CCAs must follow the CMMC Assessment Guide, Cyber AB professional standards, and applicable NIST guidance to ensure assessments meet the technical and procedural standards required for valid CMMC determinations.
Question 110: How should a CCA assessor document a practice determination of 'Not Met'?
- By recommending a specific vendor solution to the OSC
- With specific evidence, the gap identified, and the practice objective that was not satisfied (Correct answer)
- By immediately halting the assessment
- With a brief note in the assessment summary only
Correct answer: With specific evidence, the gap identified, and the practice objective that was not satisfied
'Not Met' findings must be documented with the specific evidence reviewed, the identified gap, and which practice objective was not satisfied to ensure transparency and defensibility.
Question 111: How should a CCA assessor handle a situation where the OSC's scope definition appears to exclude systems that clearly handle CUI?
- Accept the OSC's scope as defined to avoid conflict
- Proceed with the assessment and note the exclusion in a footnote
- Report the OSC immediately to the DoD
- Flag the discrepancy and require the scope to be corrected before proceeding (Correct answer)
Correct answer: Flag the discrepancy and require the scope to be corrected before proceeding
An assessor must require accurate scope definition to ensure all CUI-handling systems are evaluated, as an incomplete scope would invalidate the assessment.
Question 112: Which CMMC domain covers regular system monitoring and scanning?
- System and Information Integrity (SI) (Correct answer)
- Access Control (AC)
- Configuration Management (CM)
- Incident Response (IR)
Correct answer: System and Information Integrity (SI)
System and Information Integrity (SI) includes controls for malware scanning, system alerts, and vulnerability monitoring.
Question 113: Which NIST publication serves as the primary framework for CMMC Level 2 (Advanced) requirements?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- NIST SP 800-172
- NIST SP 800-137
Correct answer: NIST SP 800-171
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171, which are designed to protect Controlled Unclassified Information (CUI) in non-federal systems.
Question 114: What is a 'gap analysis' in the context of CMMC assessment planning?
- A network vulnerability scan performed during fieldwork
- A review of contractor invoices for missing line items
- A pre-assessment review identifying where an OSC does not yet meet CMMC requirements (Correct answer)
- A final compliance determination issued by the CMMC-AB
Correct answer: A pre-assessment review identifying where an OSC does not yet meet CMMC requirements
A gap analysis is a pre-assessment activity that identifies where the OSC's current security posture falls short of CMMC requirements, allowing remediation before the formal assessment.
Question 115: Which CMMC domain governs how organizations perform maintenance on their IT systems and controls who can conduct that maintenance?
- System and Information Integrity (SI)
- Physical Protection (PE)
- Maintenance (MA) (Correct answer)
- Configuration Management (CM)
Correct answer: Maintenance (MA)
The Maintenance domain covers performing, controlling, monitoring, and documenting system maintenance activities and personnel.
Question 116: During a CMMC assessment, when an assessor encounters a practice that is partially implemented, which scoring outcome is most appropriate under the CMMC Level 2 methodology?
- NOT MET (Correct answer)
- NOT APPLICABLE
- DEFERRED
- MET
Correct answer: NOT MET
CMMC Level 2 uses a binary MET/NOT MET scoring β partial implementation results in NOT MET since all objectives for a practice must be satisfied.
Question 117: Which CMMC level specifically addresses protecting CUI against Advanced Persistent Threats (APTs)?
- Level 1
- Levels 2 and 3 equally
- Level 2
- Level 3 (Correct answer)
Correct answer: Level 3
CMMC Level 3 (Expert) is specifically designed to protect CUI against APTs by adding practices from NIST SP 800-172 on top of the Level 2 baseline.
Question 118: Which of the following is an example of objective evidence for assessing the practice of enforcing password complexity requirements?
- The organization's password policy document
- Employee acknowledgment forms for the password policy
- An email from the IT director confirming passwords are complex
- A screenshot of Active Directory Group Policy settings showing complexity requirements enabled (Correct answer)
Correct answer: A screenshot of Active Directory Group Policy settings showing complexity requirements enabled
A screenshot of Group Policy settings directly shows the technical enforcement of password complexity, providing objective evidence that the requirement is implemented at the system level.
Question 119: A CCA assessor is reviewing an OSC's vulnerability scanning program. Which finding would be most concerning from a CMMC compliance perspective?
- Scan reports are stored in PDF format instead of XML
- Scans are performed quarterly instead of monthly
- The scanning tool is not the same brand as DoD uses internally
- High-severity vulnerabilities on CUI systems have remained unpatched for over 180 days (Correct answer)
Correct answer: High-severity vulnerabilities on CUI systems have remained unpatched for over 180 days
Long-standing high-severity vulnerabilities on CUI-handling systems represent a critical compliance failure, as CMMC requires timely remediation of identified vulnerabilities.
Question 120: A CCA assessor reviews an organization's incident response plan and finds no defined roles for handling a CUI breach. Which practice gap does this represent?
- CA.L2-3.12.4 β Develop, document, and periodically update SSPs
- IR.L2-3.6.2 β Track, document, and report incidents
- AU.L2-3.3.1 β Create and retain system audit logs
- IR.L2-3.6.1 β Establish an operational incident-handling capability (Correct answer)
Correct answer: IR.L2-3.6.1 β Establish an operational incident-handling capability
IR.L2-3.6.1 requires establishing an incident-handling capability that includes defined roles and responsibilities.
Question 121: Which CMMC domain specifically addresses the ability to recover from a cybersecurity incident by restoring systems?
- Incident Response (IR)
- Recovery (RE) (Correct answer)
- System and Information Integrity (SI)
- Risk Assessment (RA)
Correct answer: Recovery (RE)
The Recovery domain focuses on maintaining data backups and restoring capabilities to ensure resilience after a cybersecurity event.
Question 122: Which NIST publication provides the enhanced security requirements that underpin CMMC Level 3 (Expert)?
- NIST SP 800-172 (Correct answer)
- NIST SP 800-53 Rev 5
- NIST SP 800-171 Rev 2
- NIST SP 800-161
Correct answer: NIST SP 800-172
CMMC Level 3 builds on Level 2 (NIST SP 800-171) by adding requirements from NIST SP 800-172, which addresses enhanced security measures to counter Advanced Persistent Threats (APTs).
Question 123: How does a CCA assessor determine which CMMC level to assess when the OSC's contract requirements are unclear?
- Consult the contract language, DFARS clauses, and the contracting officer for clarification (Correct answer)
- Use the OSC's self-assessment score to determine the level
- Always assess at Level 3 to ensure maximum coverage
- Default to Level 1 unless the OSC requests otherwise
Correct answer: Consult the contract language, DFARS clauses, and the contracting officer for clarification
The required CMMC level is determined by the contract requirements, relevant DFARS clauses, and if unclear, by seeking clarification from the contracting officer.
Question 124: What should a CCA do if an OSC refuses to provide access to required systems during the assessment?
- Request the CMMC-AB to intervene immediately
- Proceed with available evidence and assume compliance
- Document the lack of access, which may result in a 'Not Met' finding for affected practices (Correct answer)
- Extend the assessment deadline indefinitely
Correct answer: Document the lack of access, which may result in a 'Not Met' finding for affected practices
If an OSC withholds access to required systems, the assessor must document this and assign a 'Not Met' finding, as evidence cannot be gathered without access.
Question 125: What is the purpose of the CMMC Model and how does it relate to NIST SP 800-171?
- CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171, adding a third-party assessment mandate (Correct answer)
- CMMC is a voluntary framework while NIST SP 800-171 is mandatory
- CMMC only applies to large contractors while NIST SP 800-171 applies to small businesses
- CMMC replaces NIST SP 800-171 entirely with new requirements
Correct answer: CMMC Level 2 is based on the 110 security requirements in NIST SP 800-171, adding a third-party assessment mandate
CMMC Level 2 maps directly to the 110 security requirements of NIST SP 800-171 but adds the requirement for third-party assessment by a C3PAO rather than allowing self-attestation.
Question 126: What tool is commonly used to guide evaluators during CMMC assessments?
- NIST CSF Poster
- Incident Report Summary
- CMMC Assessment Guide (Correct answer)
- CMMC Compliance Ledger
Correct answer: CMMC Assessment Guide
The CMMC Assessment Guide outlines procedures, artifacts, and methods for each practice at every level.
Question 127: Under the CMMC evaluation methodology, what is the correct sequence of assessment phases?
- Initiate β Plan β Execute β Report (Correct answer)
- Kickoff β Discovery β Testing β Certification
- Scope β Assess β Remediate β Certify
- Plan β Execute β Report β Close
Correct answer: Initiate β Plan β Execute β Report
The CMMC assessment process follows four phases: Initiate, Plan, Execute, and Report, as defined in the CMMC Assessment Process (CAP).
Question 128: What is the role of a Third-Party Assessment Organization (C3PAO) in the CMMC ecosystem?
- To independently assess and certify organizations seeking CMMC Level 2 or Level 3 certification (Correct answer)
- To provide remediation services after a failed CMMC assessment
- To serve as the authorizing official for contractor system security plans
- To develop cybersecurity policy on behalf of the DoD
Correct answer: To independently assess and certify organizations seeking CMMC Level 2 or Level 3 certification
C3PAOs are authorized third-party organizations that conduct official CMMC assessments and issue certifications for Level 2 and Level 3.
Question 129: What does 'professional skepticism' mean for a CCA assessor?
- Maintaining a questioning mind and critically assessing evidence rather than accepting all representations at face value (Correct answer)
- Distrusting everything the OSC says during the assessment
- Requiring external legal counsel to verify all evidence
- Refusing to conduct assessments for OSCs with prior compliance issues
Correct answer: Maintaining a questioning mind and critically assessing evidence rather than accepting all representations at face value
Professional skepticism means critically evaluating evidence and not simply accepting OSC assertions as fact, seeking corroborating evidence to ensure findings are based on objective observation rather than trust.
Question 130: What is the maximum number of practices that can be placed on a POA&M for a CMMC Level 2 conditional certification to be granted?
- Up to 20% of all 110 practices (approximately 22 practices)
- A specific limited number as defined by DoD policy, currently set at no more than a specified maximum value-weighted threshold (Correct answer)
- No practices can be deferred; all must be met for any certification
- Unlimited, as long as all critical practices are implemented
Correct answer: A specific limited number as defined by DoD policy, currently set at no more than a specified maximum value-weighted threshold
DoD policy specifies a maximum point-weighted threshold for POA&M items; high-value practices cannot be deferred regardless of total count.
Question 131: Under CMMC rules, when must a prime contractor flow down CMMC requirements to its subcontractors?
- Never β CMMC only applies to prime contractors
- Only when the subcontract value exceeds $1 million
- Only for subcontractors with prior CMMC assessments
- When the subcontractor will process, store, or transmit CUI or FCI in support of the prime contract (Correct answer)
Correct answer: When the subcontractor will process, store, or transmit CUI or FCI in support of the prime contract
Prime contractors must flow down CMMC requirements to subcontractors that will handle CUI or FCI in performance of the contract, ensuring the full supply chain protects sensitive information.
Question 132: What is the primary purpose of DFARS clause 252.204-7012 in relation to cybersecurity?
- To authorize C3PAOs to conduct CMMC assessments
- To define CMMC certification levels and timelines
- To require annual self-assessments for all DoD contractors
- To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI (Correct answer)
Correct answer: To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI
DFARS 252.204-7012 requires contractors to implement adequate security to protect covered defense information (CUI) and mandates reporting of cyber incidents to DoD within 72 hours.
Question 133: During assessment scoping, what role does the System Security Plan (SSP) play?
- It is submitted to CMMC-AB for review before the assessment
- It replaces the need for an assessment plan
- It provides a description of the system boundary, components, and implemented security controls (Correct answer)
- It serves as the final assessment report
Correct answer: It provides a description of the system boundary, components, and implemented security controls
The SSP describes the system boundary and how security controls are implemented, serving as a critical reference document for scoping and evaluating the assessment.
Question 134: What does the CMMC Assessment Guide specify regarding the 'test' assessment method?
- Tests involve exercising or operating controls to observe how they function and verify their effectiveness (Correct answer)
- Tests are restricted to automated scanning tools only
- Tests may only be performed by DoD personnel
- Tests are optional and only used when other evidence is unavailable
Correct answer: Tests involve exercising or operating controls to observe how they function and verify their effectiveness
Testing involves exercising controls β such as simulating events or performing functional checks β to observe whether they operate as intended and produce expected results.
Question 135: In the context of CMMC, what is the primary goal of risk management for defense contractors?
- To maximize profit margins on defense contracts
- To eliminate all cybersecurity tools to reduce attack surface
- To transfer all cybersecurity risk to the DoD
- To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment (Correct answer)
Correct answer: To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment
The primary goal is to protect CUI and FCI by systematically identifying, assessing, and mitigating risks that could compromise the confidentiality, integrity, or availability of that data.
Question 136: When assessing multi-site organizations, how must a CCA determine whether each location requires separate CMMC assessment?
- All sites of an organization share a single certification automatically
- Sites are assessed together only if they share the same physical address
- Only the headquarters site is assessed; subsidiaries are excluded
- Each site handling CUI within its own network boundary requires separate scoping analysis (Correct answer)
Correct answer: Each site handling CUI within its own network boundary requires separate scoping analysis
Each organizational location with its own network boundary that handles CUI must be individually scoped and may require separate assessment.
Question 137: An assessor is evaluating an OSC that recently migrated to a new system mid-year. Evidence for some practices only covers the new system, with gaps in coverage for the period when the old system was in use. How should this be handled?
- Automatically grant a MET score since migration demonstrates proactive improvement
- Assess only the current configuration and ignore the migration period entirely
- Accept the new system's evidence as sufficient for the full assessment period
- Evaluate the completeness and continuity of evidence, noting any gaps, and score practices based on whether requirements were continuously met throughout the assessment period (Correct answer)
Correct answer: Evaluate the completeness and continuity of evidence, noting any gaps, and score practices based on whether requirements were continuously met throughout the assessment period
Assessors evaluate whether practices were continuously implemented throughout the relevant period; evidence gaps during a migration may result in NOT MET if continuity cannot be demonstrated.
Question 138: Which part of the Defense Federal Acquisition Regulation Supplement introduced the requirement for CMMC in new DoD contracts?
- DFARS 252.204-7012
- DFARS 252.239-7010
- DFARS 252.204-7021 (Correct answer)
- DFARS 252.204-7000
Correct answer: DFARS 252.204-7021
DFARS 252.204-7021 is the clause that imposes CMMC requirements as a condition of contract award for DoD contracts requiring CMMC compliance.
Question 139: Which of the following best describes the concept of 'assessor independence' in CMMC?
- Assessors must be free from financial, personal, or professional relationships that could bias their assessment findings (Correct answer)
- Assessors must work independently without collaborating with other team members
- Independence only applies to the lead assessor, not junior team members
- Independence requires assessors to be physically located outside the OSC's country
Correct answer: Assessors must be free from financial, personal, or professional relationships that could bias their assessment findings
Assessor independence means freedom from relationships or interests that could compromise objectivity, ensuring that findings reflect actual evidence rather than biased judgment influenced by personal, financial, or professional ties.
Question 140: What annual action is required of CMMC Level 2 contractors regardless of whether they undergo self-assessment or third-party assessment?
- Senior official affirmation confirming continued compliance with cybersecurity requirements (Correct answer)
- Contracting Officer's Representative (COR) verification of assessment results
- Third-party auditor sign-off on the current security posture
- Submission of an updated System Security Plan (SSP) to the Cyber AB
Correct answer: Senior official affirmation confirming continued compliance with cybersecurity requirements
CMMC 2.0 requires an annual affirmation by a senior company official attesting to compliance with required cybersecurity practices, creating executive-level accountability between triennial assessments.
Question 141: How does CMMC affect a defense contractor that only handles Federal Contract Information (FCI) but not CUI?
- FCI-only contractors must meet CMMC Level 2 with third-party assessment
- FCI-only contractors must meet CMMC Level 1, which requires implementation of basic safeguarding requirements from FAR 52.204-21 (Correct answer)
- FCI-only contractors are exempt from all CMMC requirements
- FCI is governed by a separate framework unrelated to CMMC
Correct answer: FCI-only contractors must meet CMMC Level 1, which requires implementation of basic safeguarding requirements from FAR 52.204-21
Contractors handling only FCI must meet CMMC Level 1, which consists of 17 basic safeguarding practices aligned to FAR 52.204-21 and allows annual self-attestation.
Question 142: Which CMMC practice requires organizations to protect CUI during transmission using FIPS-validated cryptography?
- SC.L2-3.13.8 β Implement cryptographic mechanisms to protect CUI during transmission (Correct answer)
- SC.L2-3.13.10 β Employ FIPS-validated cryptography when used to protect CUI
- MP.L2-3.8.6 β Implement cryptographic mechanisms to protect CUI on digital media
- IA.L2-3.5.10 β Store and transmit only cryptographically-protected passwords
Correct answer: SC.L2-3.13.8 β Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic mechanismsβwhich for federal systems implies FIPS-validated algorithmsβto protect CUI during transmission.
Question 143: A CCA discovers during an assessment that an OSC has experienced a significant cyber incident that was not reported to DoD as required. What is the CCA's obligation?
- Keep the information confidential as part of assessment findings
- Report the incident to DoD on behalf of the OSC
- Document the non-compliance finding and note the unreported incident in the assessment report (Correct answer)
- Advise the OSC verbally but not document it to avoid harming the relationship
Correct answer: Document the non-compliance finding and note the unreported incident in the assessment report
Failure to report a required cyber incident is a compliance deficiency that must be documented in the assessment findings, as it represents a violation of DFARS 252.204-7012 requirements.
Question 144: In CMMC assessment documentation, what is a 'corrective action plan'?
- A legal document filed against the OSC for non-compliance
- A documented plan for addressing 'Not Met' findings that may allow conditional progress toward certification (Correct answer)
- A military action plan for responding to cyber incidents
- A quality improvement plan for the C3PAO's assessment process
Correct answer: A documented plan for addressing 'Not Met' findings that may allow conditional progress toward certification
A corrective action plan outlines the specific steps and timeline an OSC will take to remediate 'Not Met' findings, which may be relevant to conditional certification pathways.
Question 145: What is the purpose of the CMMC Supplier Performance Risk System (SPRS) in the assessment lifecycle?
- It manages assessor credentials and certifications
- It stores contractor financial records for DoD procurement
- It tracks cybersecurity incident reports from defense contractors
- It is where OSCs submit their self-assessment scores and where C3PAOs upload final assessment results (Correct answer)
Correct answer: It is where OSCs submit their self-assessment scores and where C3PAOs upload final assessment results
SPRS is the DoD system where both OSC self-assessment scores and C3PAO assessment results are submitted and stored for DoD acquisition visibility.
Question 146: What obligation does a defense contractor have when it discovers a cyber incident affecting CUI under DFARS 252.204-7012?
- Report the incident to CISA within 24 hours
- Only report incidents that resulted in confirmed data exfiltration
- Document the incident internally with no reporting required
- Report the incident to the DoD within 72 hours of discovery (Correct answer)
Correct answer: Report the incident to the DoD within 72 hours of discovery
DFARS 252.204-7012 requires contractors to report cyber incidents involving covered contractor information systems to the DoD via the DIBNet portal within 72 hours of discovery.
Question 147: What is the primary reason CMMC assessors must maintain assessor independence from the OSC being assessed?
- To reduce travel costs for the C3PAO
- To allow the assessor to also serve as a consultant to the OSC post-assessment
- To comply with DoD contracting officer scheduling requirements
- To ensure findings are objective and unbiased, preserving the integrity and credibility of the certification outcome (Correct answer)
Correct answer: To ensure findings are objective and unbiased, preserving the integrity and credibility of the certification outcome
Assessor independence ensures that findings reflect actual control implementation rather than relationships or financial interests, which is essential to the trust and credibility of the CMMC program.
Question 148: What must a CCA do when they identify a potential conflict of interest before beginning an assessment?
- Proceed if the conflict is minor and disclose it only in the final report
- Document the conflict and continue, as disclosure satisfies the ethical obligation
- Disclose the conflict to the C3PAO and recuse themselves from the assessment if the conflict cannot be mitigated (Correct answer)
- Ask the OSC if they are comfortable proceeding despite the conflict
Correct answer: Disclose the conflict to the C3PAO and recuse themselves from the assessment if the conflict cannot be mitigated
CCAs must disclose conflicts of interest to their C3PAO and recuse themselves if the conflict cannot be appropriately mitigated, to preserve the objectivity required for a valid assessment.
Question 149: How should assessors handle conflicting evidence during a CMMC assessment?
- Automatically mark the practice as 'Not Met' when any conflict exists
- Always side with the OSC's preferred interpretation
- Document all conflicting evidence, gather additional evidence to resolve the conflict, and make a determination based on the weight of evidence (Correct answer)
- Defer the finding to the CMMC-AB for resolution
Correct answer: Document all conflicting evidence, gather additional evidence to resolve the conflict, and make a determination based on the weight of evidence
When evidence conflicts, assessors must document the conflict, seek additional evidence to clarify, and make a reasonable determination based on the totality of available evidence.
Question 150: What does it mean when a CMMC assessor assigns a practice determination of 'Not Applicable' (NA)?
- The practice only applies to CMMC Level 3
- The practice is not relevant to the OSC's assessed environment based on the scoped system boundary (Correct answer)
- The OSC has requested a waiver for the practice
- The assessor could not find evidence either way
Correct answer: The practice is not relevant to the OSC's assessed environment based on the scoped system boundary
A 'Not Applicable' determination means the practice's requirements genuinely do not apply to the OSC's environment as scoped (e.g., a mobile device practice when no mobile devices are in scope).
Question 151: Under CMMC, what is the contractor's obligation regarding media containing CUI that is sent off-site for maintenance?
- Media can be sent to any certified repair vendor without restriction
- No special precautions are required if the vendor has signed an NDA
- Only media containing classified information requires special handling during maintenance
- CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented (Correct answer)
Correct answer: CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented
CMMC media protection practices require that CUI be sanitized or appropriately encrypted when media is sent for maintenance, and the chain of custody must be maintained to protect against unauthorized disclosure.
Certified CMMC Assessor (CCA)
The CCA certification validates an assessor's ability to evaluate organizations seeking CMMC certification, covering assessment scoping, evidence collection, and evaluating Level 2 cybersecurity practices against NIST SP 800-171 controls. It is administered by Cyber AB and required for individuals conducting official CMMC assessments on behalf of C3PAOs.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds