Compliance & Reporting Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance & Reporting flashcards as text
Under CMMC 2.0, which federal regulation mandates that defense contractors protect Controlled Unclassified Information (CUI)?
Answer: DFARS 252.204-7012
DFARS 252.204-7012 is the key clause requiring defense contractors to safeguard covered defense information including CUI.
When a CMMC Level 2 assessment reveals a practice not fully implemented, what document must the OSC submit to capture remediation plans?
Answer: Plan of Action and Milestones (POA&M)
A POA&M documents identified weaknesses and the plan, resources, and timeline for correcting each deficiency.
Which CMMC compliance artifact describes how security requirements are implemented across an organization's system boundary?
Answer: System Security Plan (SSP)
The SSP documents the system boundary, how each security requirement is met, and the roles responsible for implementation.
A C3PAO discovers mid-assessment that an OSC intentionally misrepresented their implementation of access control practices. What is the C3PAO's required action?
Answer: Suspend the assessment and report the misrepresentation to the Cyber AB
C3PAOs must report intentional misrepresentation to the Cyber AB, as this constitutes a violation of assessment integrity.
What is the maximum timeframe an OSC has under CMMC 2.0 to resolve a POA&M item before it causes assessment failure at Level 2?
Answer: 180 days
Under CMMC 2.0 rules, POA&M items must be closed within 180 days of a conditional certification being awarded.
Which component of CMMC compliance reporting confirms the scope of the assessment, including all assets that store, process, or transmit CUI?
Answer: System Security Plan scope section
The SSP's scope section defines the assessment boundary including all in-scope assets, networks, and personnel handling CUI.
Under CMMC 2.0, Level 1 compliance is demonstrated primarily through which mechanism?
Answer: Annual self-attestation signed by a senior company official
CMMC Level 1 requires annual self-attestation affirming implementation of all 17 basic safeguarding practices, signed by a senior official.