โ† All CCA Flashcard Decks

Compliance & Reporting Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance & Reporting flashcards as text
  1. Under CMMC 2.0, which federal regulation mandates that defense contractors protect Controlled Unclassified Information (CUI)?

    Answer: DFARS 252.204-7012

    DFARS 252.204-7012 is the key clause requiring defense contractors to safeguard covered defense information including CUI.

  2. When a CMMC Level 2 assessment reveals a practice not fully implemented, what document must the OSC submit to capture remediation plans?

    Answer: Plan of Action and Milestones (POA&M)

    A POA&M documents identified weaknesses and the plan, resources, and timeline for correcting each deficiency.

  3. Which CMMC compliance artifact describes how security requirements are implemented across an organization's system boundary?

    Answer: System Security Plan (SSP)

    The SSP documents the system boundary, how each security requirement is met, and the roles responsible for implementation.

  4. A C3PAO discovers mid-assessment that an OSC intentionally misrepresented their implementation of access control practices. What is the C3PAO's required action?

    Answer: Suspend the assessment and report the misrepresentation to the Cyber AB

    C3PAOs must report intentional misrepresentation to the Cyber AB, as this constitutes a violation of assessment integrity.

  5. What is the maximum timeframe an OSC has under CMMC 2.0 to resolve a POA&M item before it causes assessment failure at Level 2?

    Answer: 180 days

    Under CMMC 2.0 rules, POA&M items must be closed within 180 days of a conditional certification being awarded.

  6. Which component of CMMC compliance reporting confirms the scope of the assessment, including all assets that store, process, or transmit CUI?

    Answer: System Security Plan scope section

    The SSP's scope section defines the assessment boundary including all in-scope assets, networks, and personnel handling CUI.

  7. Under CMMC 2.0, Level 1 compliance is demonstrated primarily through which mechanism?

    Answer: Annual self-attestation signed by a senior company official

    CMMC Level 1 requires annual self-attestation affirming implementation of all 17 basic safeguarding practices, signed by a senior official.