โ† All CCA Flashcard Decks

CMMC Framework & Domains Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 CMMC Framework & Domains flashcards as text
  1. Which statement BEST describes a Plan of Action and Milestones (POA&M) in the CMMC context?

    Answer: A roadmap identifying deficiencies and scheduled remediation actions

    A POA&M documents security deficiencies and the planned corrective actions with target completion dates.

  2. Under CMMC 2.0, Level 3 is based primarily on requirements from which source beyond NIST SP 800-171?

    Answer: NIST SP 800-172

    CMMC Level 3 incorporates requirements from NIST SP 800-172, which provides enhanced security requirements for protecting CUI.

  3. An assessor finds that a contractor uses multi-factor authentication for privileged users but not for standard users accessing CUI systems. Which domain is most likely deficient?

    Answer: Identification and Authentication (IA)

    The IA domain requires multi-factor authentication for all users, not just privileged accounts, when accessing systems with CUI.

  4. Which CMMC domain covers the vetting of personnel before granting access to systems containing CUI?

    Answer: Personnel Security (PS)

    The Personnel Security domain addresses screening individuals prior to granting access and managing termination or transfer processes.

  5. What does the 'Awareness and Training (AT)' domain require of organizations under CMMC?

    Answer: All personnel must receive cybersecurity awareness training

    The AT domain mandates that all personnel receive role-appropriate security awareness training to recognize and respond to cybersecurity threats.

  6. A CMMC assessor reviews a contractor's system and finds CUI is transmitted between sites without encryption. This finding most directly violates which domain?

    Answer: System and Communications Protection (SC)

    The SC domain requires that CUI be encrypted when transmitted across networks to protect it from unauthorized disclosure.

  7. In CMMC 2.0, what is the primary role of an OSC (Organization Seeking Certification)?

    Answer: To implement required security practices and undergo assessment

    An OSC is the defense contractor or subcontractor that must implement CMMC requirements and be assessed to receive certification.