โ† All CCA Flashcard Decks

CMMC Framework & Domains Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CMMC Framework & Domains flashcards as text
  1. Which CMMC domain addresses the protection of audit logs and monitoring of system activity?

    Answer: Audit and Accountability (AU)

    The Audit and Accountability domain covers requirements for creating, protecting, and reviewing audit logs of system events.

  2. A defense contractor stores CUI and processes it on cloud systems. Under CMMC 2.0, the cloud service provider must meet which standard?

    Answer: FedRAMP Moderate or equivalent

    Cloud service providers used by CMMC Level 2 contractors must meet FedRAMP Moderate or equivalent requirements.

  3. How does CMMC 2.0 differ from CMMC 1.0 in terms of maturity levels?

    Answer: CMMC 2.0 reduced from 5 levels to 3 levels

    CMMC 2.0 streamlined the framework from 5 maturity levels in CMMC 1.0 to 3 levels.

  4. Which CMMC practice, if not implemented, would most directly violate the 'Identification and Authentication (IA)' domain requirements?

    Answer: Allowing shared user accounts for system administrators

    Shared accounts undermine the ability to uniquely identify users, which is a core requirement of the IA domain.

  5. In the CMMC framework, 'Federal Contract Information' (FCI) is BEST described as:

    Answer: Information provided by the government under a contract that is not intended for public release

    FCI is information provided by or generated for the government under a contract, not intended for public release.

  6. The 'Media Protection (MP)' domain in CMMC primarily governs:

    Answer: Protection, control, sanitization, and disposal of digital and physical media containing CUI

    The MP domain covers the handling, marking, storage, transport, and destruction of media that contains sensitive information.

  7. Which CMMC 2.0 domain requires organizations to periodically assess security controls and develop plans of action?

    Answer: Security Assessment (CA)

    The Security Assessment (CA) domain requires periodic assessment of security controls and creation of plans of action and milestones (POA&Ms).