Compliance & Reporting Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance & Reporting flashcards as text
In CMMC assessments, what does the term 'inherited controls' refer to in the context of compliance reporting?
Answer: Controls implemented by a cloud service provider that the OSC relies upon
Inherited controls are security capabilities provided by an external entity (such as a CSP) that the OSC leverages rather than implementing independently.
Which NIST publication provides the 110 security requirements that form the basis of CMMC Level 2 compliance?
Answer: NIST SP 800-171
NIST SP 800-171 'Protecting CUI in Nonfederal Systems and Organizations' provides the 110 requirements mapped to CMMC Level 2.
When an OSC uses an external managed service provider (MSP) that handles CUI, what compliance obligation applies to that MSP?
Answer: The MSP must obtain its own CMMC certification at the same or higher level
When an MSP processes or handles CUI on behalf of an OSC, that MSP must also meet the applicable CMMC level requirements.
What is the purpose of the CMMC Assessment Scope categorization of 'Contractor Risk Managed Assets' (CRMAs)?
Answer: Assets that could impact CUI but are managed by the contractor under documented risk controls
CRMAs are assets that can affect CUI security but are managed through contractor-defined risk controls rather than full CMMC practice application.
A CCA is reviewing an OSC's compliance documentation and finds that audit logs are retained for only 30 days. Which NIST SP 800-171 domain does this deficiency fall under?
Answer: Audit and Accountability (AU)
Audit log retention requirements fall under the Audit and Accountability domain, specifically AU.3.045 which addresses log protection and retention.
Which role within the CMMC ecosystem is responsible for publishing and maintaining the CMMC standard, assessment guides, and rulemaking?
Answer: DoD (Department of Defense)
The DoD owns and publishes the CMMC model, issues the final rule through 32 CFR Part 170, and sets all programmatic policy.
In a CMMC compliance report, what does a practice scored as 'MET' indicate?
Answer: All objectives for the practice are fully implemented and verified
A 'MET' score means all assessment objectives for that practice have been verified as fully and consistently implemented.