โ† All CCA Flashcard Decks

Compliance & Reporting Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance & Reporting flashcards as text
  1. Which federal register rule codifies CMMC 2.0 requirements and makes CMMC contractually enforceable through the DFARS?

    Answer: 32 CFR Part 170

    32 CFR Part 170 is the DoD's final CMMC rule that establishes requirements, assessment procedures, and the framework structure.

  2. An OSC's self-assessment SPRS score of -203 indicates what about their current compliance posture?

    Answer: No practices are implemented; maximum negative score reflecting all requirements unmet

    A score of -203 is the maximum negative SPRS score, indicating that zero of the 110 NIST SP 800-171 practices have been implemented.

  3. What is the primary purpose of the CMMC Assessment Process (CAP) document published by the Cyber AB?

    Answer: To standardize how C3PAOs conduct, document, and report CMMC assessments

    The CAP establishes uniform procedures for C3PAOs to ensure consistent, repeatable, and trustworthy CMMC assessment execution and reporting.

  4. During a CMMC Level 2 assessment, the CCA identifies that an OSC's cloud environment is not FedRAMP authorized. What is the compliance implication?

    Answer: The cloud service must meet CMMC Level 2 equivalent requirements and be documented in the SSP

    Non-FedRAMP cloud services can be used if they meet CMMC Level 2 equivalent security requirements, which must be documented and verified during assessment.

  5. Which of the following evidence types would a CCA accept as proof that an OSC has implemented multi-factor authentication (MFA) for CUI system access?

    Answer: Active Directory group policy screenshots showing MFA enforcement combined with a live system demonstration

    CCAs require documentary and demonstrable evidence of implementation; policy alone or purchase records do not prove active enforcement.

  6. Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required?

    Answer: 3 years

    CMMC Level 2 certifications obtained through C3PAO assessments are valid for three years, after which a new assessment must be completed.

  7. A CCA finds that an OSC tracks and reports CUI incidents to their FSO but has no documented process for reporting to US-CERT within the required timeframe. Which practice is NOT MET?

    Answer: IR.L2-3.6.2 - Incident Reporting to Authorities

    IR.L2-3.6.2 requires reporting cybersecurity incidents to appropriate authorities including US-CERT within the required 72-hour timeframe per DFARS.