Compliance & Reporting Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance & Reporting flashcards as text
Which federal register rule codifies CMMC 2.0 requirements and makes CMMC contractually enforceable through the DFARS?
Answer: 32 CFR Part 170
32 CFR Part 170 is the DoD's final CMMC rule that establishes requirements, assessment procedures, and the framework structure.
An OSC's self-assessment SPRS score of -203 indicates what about their current compliance posture?
Answer: No practices are implemented; maximum negative score reflecting all requirements unmet
A score of -203 is the maximum negative SPRS score, indicating that zero of the 110 NIST SP 800-171 practices have been implemented.
What is the primary purpose of the CMMC Assessment Process (CAP) document published by the Cyber AB?
Answer: To standardize how C3PAOs conduct, document, and report CMMC assessments
The CAP establishes uniform procedures for C3PAOs to ensure consistent, repeatable, and trustworthy CMMC assessment execution and reporting.
During a CMMC Level 2 assessment, the CCA identifies that an OSC's cloud environment is not FedRAMP authorized. What is the compliance implication?
Answer: The cloud service must meet CMMC Level 2 equivalent requirements and be documented in the SSP
Non-FedRAMP cloud services can be used if they meet CMMC Level 2 equivalent security requirements, which must be documented and verified during assessment.
Which of the following evidence types would a CCA accept as proof that an OSC has implemented multi-factor authentication (MFA) for CUI system access?
Answer: Active Directory group policy screenshots showing MFA enforcement combined with a live system demonstration
CCAs require documentary and demonstrable evidence of implementation; policy alone or purchase records do not prove active enforcement.
Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required?
Answer: 3 years
CMMC Level 2 certifications obtained through C3PAO assessments are valid for three years, after which a new assessment must be completed.
A CCA finds that an OSC tracks and reports CUI incidents to their FSO but has no documented process for reporting to US-CERT within the required timeframe. Which practice is NOT MET?
Answer: IR.L2-3.6.2 - Incident Reporting to Authorities
IR.L2-3.6.2 requires reporting cybersecurity incidents to appropriate authorities including US-CERT within the required 72-hour timeframe per DFARS.