← All CCA Flashcard Decks

CMMC Framework & Domains Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 CMMC Framework & Domains flashcards as text
  1. How many domains are defined in CMMC 2.0?

    Answer: 14

    CMMC 2.0 organizes cybersecurity requirements into 14 domains inherited from NIST SP 800-171.

  2. Which CMMC 2.0 level requires a third-party assessment by a C3PAO?

    Answer: Level 2 (for prioritized acquisitions)

    Level 2 prioritized acquisitions require a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO).

  3. The CMMC domain 'Incident Response' (IR) primarily maps to which NIST SP 800-171 family?

    Answer: IR — Incident Response

    The CMMC Incident Response domain directly maps to the IR family in NIST SP 800-171.

  4. In CMMC 2.0, which level specifically protects Controlled Unclassified Information (CUI) in non-critical programs?

    Answer: Level 2

    CMMC Level 2 is designed to protect CUI in non-critical national security programs.

  5. Which of the following is NOT one of the CMMC 2.0 domains?

    Answer: Privacy Engineering (PR)

    Privacy Engineering is not a CMMC 2.0 domain; the 14 domains are inherited from NIST SP 800-171 and related standards.

  6. What is the primary purpose of the 'Configuration Management (CM)' domain in CMMC?

    Answer: Establishing and maintaining baseline configurations of systems

    The CM domain focuses on establishing, documenting, and enforcing baseline security configurations for organizational systems.

  7. Under CMMC 2.0, which entity is responsible for authorizing C3PAOs to conduct assessments?

    Answer: CMMC Accreditation Body (Cyber AB)

    The Cyber AB (formerly CMMC-AB) is the accreditation body responsible for authorizing C3PAOs.