Compliance & Reporting Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance & Reporting flashcards as text
Under CMMC 2.0 rules, which type of information does Level 1 protect, as distinct from what Level 2 protects?
Answer: Federal Contract Information (FCI) only
CMMC Level 1 focuses on protecting Federal Contract Information (FCI), while Level 2 adds the broader requirement to protect CUI.
An OSC receives a CMMC Level 2 final assessment report. Where is this report ultimately submitted for DoD contract award decisions?
Answer: The Supplier Performance Risk System (SPRS)
CMMC assessment results and the resulting SPRS score are reported to the Supplier Performance Risk System, which contracting officers review.
What is the maximum number of practices that can be placed on a POA&M for a CMMC Level 2 conditional certification to be granted?
Answer: A specific limited number as defined by DoD policy, currently set at no more than a specified maximum value-weighted threshold
DoD policy specifies a maximum point-weighted threshold for POA&M items; high-value practices cannot be deferred regardless of total count.
A CCA reviews an OSC's incident response documentation and finds no evidence of annual IR testing. Which compliance artifact would best close this gap?
Answer: Documented tabletop exercise or IR drill records with after-action report
Documented evidence of conducted IR exercises (tabletop, walkthrough, or full drill) with after-action reports demonstrates practice implementation.
When assessing multi-site organizations, how must a CCA determine whether each location requires separate CMMC assessment?
Answer: Each site handling CUI within its own network boundary requires separate scoping analysis
Each organizational location with its own network boundary that handles CUI must be individually scoped and may require separate assessment.
Which of the following would constitute a finding of 'NOT MET' for the CMMC practice requiring media sanitization (MP.L2-3.8.3)?
Answer: Reformatting a drive and returning it to service without verification of data removal
Simply reformatting without applying NIST SP 800-88 sanitization methods or verifying data removal does not meet the media sanitization requirement.
In CMMC compliance reporting, what distinguishes a 'deficiency' from a 'weakness' in assessment terminology?
Answer: A deficiency is a practice scored NOT MET; a weakness is a partially implemented practice noted for improvement
In CMMC context, deficiencies are practices that fully fail assessment (NOT MET), while weaknesses may indicate partial implementation or risk areas noted for monitoring.