CCA Evidence Collection & Documentation Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 CCA Evidence Collection & Documentation flashcards as text
What are the three primary methods of evidence collection used in CMMC assessments?
Answer: Examine, interview, and test
CMMC assessors use three methods — examine (review documents/artifacts), interview (talk to personnel), and test (observe or exercise controls) — to gather evidence for each practice.
When a CCA assessor 'examines' evidence during a CMMC assessment, what activities does this include?
Answer: Reviewing documentation, policies, procedures, system configurations, and other artifacts
Examining involves reviewing written artifacts such as policies, procedures, system configurations, logs, and other documentation to assess whether required practices are implemented.
What type of evidence is considered most reliable when assessing the implementation of a technical control?
Answer: System-generated logs and configuration screenshots observed directly by the assessor
Direct observation of system-generated evidence (logs, configurations) is most reliable because it provides objective, system-level proof of control implementation rather than relying on assertions.
What is a 'finding' in the context of a CMMC assessment?
Answer: A documented determination of whether a specific practice is 'Met' or 'Not Met' based on collected evidence
A finding is the assessor's documented determination of whether an assessed practice is 'Met' or 'Not Met,' supported by the evidence collected during the assessment.
Why is maintaining a complete evidence package critical for a CCA assessor?
Answer: To support the assessment findings, enable quality reviews, and provide a defensible record of the assessment
A complete evidence package documents the basis for every finding, enabling quality assurance reviews and providing a defensible record if findings are challenged.
Which of the following would NOT be appropriate as evidence for assessing whether multi-factor authentication (MFA) is implemented?
Answer: A signed attestation from the CISO that MFA is in place
A signed attestation is a self-assertion without objective technical evidence, making it the weakest and least appropriate evidence type for verifying a technical control like MFA.