Cybersecurity Practices & Controls Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Practices & Controls flashcards as text
Which CMMC practice requires organizations to protect CUI during transmission using FIPS-validated cryptography?
Answer: SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic mechanisms—which for federal systems implies FIPS-validated algorithms—to protect CUI during transmission.
An organization's network diagram shows that CUI systems and general IT systems share the same network segment. Which CMMC practice is most relevant?
Answer: AC.L2-3.1.3 — Control the flow of CUI in accordance with approved authorizations
AC.L2-3.1.3 requires controlling the flow of CUI using approved authorizations, which includes network segmentation to separate CUI from non-CUI systems.
What is the role of a Third-Party Assessment Organization (C3PAO) in the CMMC ecosystem?
Answer: To independently assess and certify organizations seeking CMMC Level 2 or Level 3 certification
C3PAOs are authorized third-party organizations that conduct official CMMC assessments and issue certifications for Level 2 and Level 3.
Which CMMC practice requires that remote access sessions be controlled and monitored?
Answer: AC.L2-3.1.12 — Monitor and control remote access sessions
AC.L2-3.1.12 specifically requires that remote access sessions be monitored and controlled to reduce the risk of unauthorized access.
A CCA assessor is reviewing an organization's personnel security practices. Which practice requires screening individuals prior to granting access to CUI systems?
Answer: PS.L2-3.9.1 — Screen individuals prior to authorizing access to organizational systems
PS.L2-3.9.1 (Personnel Security) requires screening individuals before authorizing access to organizational systems containing CUI.
Which CMMC practice requires organizations to conduct risk assessments and use the results to inform security control selection?
Answer: RA.L2-3.11.1 — Periodically assess the risk to organizational operations, assets, and individuals
RA.L2-3.11.1 requires periodic risk assessments to evaluate risk to operations, assets, and individuals, providing the basis for security control decisions.
Under CMMC Level 2, which practice specifically addresses the protection of CUI on mobile devices and mobile computing platforms?
Answer: AC.L2-3.1.19 — Encrypt CUI on mobile devices and mobile computing platforms
AC.L2-3.1.19 specifically requires encrypting CUI on mobile devices and mobile computing platforms to protect against loss or theft.