Evaluation Methodology Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Evaluation Methodology flashcards as text
Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology?
Answer: NIST SP 800-171A
NIST SP 800-171A provides the assessment procedures for verifying the security requirements in NIST SP 800-171, which form the basis for CMMC Level 2 assessments.
During the planning phase, an assessor develops the Assessment Plan (AP). Which element is MOST important to establish in the AP to ensure a focused, efficient assessment?
Answer: The assessment scope including the OSC's CUI boundary and in-scope systems
Establishing the assessment scope — particularly the CUI boundary and in-scope assets — is foundational to ensuring the assessment is focused and all relevant systems are evaluated.
An assessor finds that an OSC has implemented a compensating control in place of a standard CMMC practice. Under CMMC methodology, how should this be handled?
Answer: Compensating controls are not recognized in CMMC; the practice is marked NOT MET
CMMC Level 2 does not have a formal compensating controls framework; practices must be met as defined, so a deviation results in a NOT MET finding.
What is the purpose of the 'examine' method in CMMC assessment methodology?
Answer: Reviewing specifications, mechanisms, and documentation to understand or confirm security control implementation
The 'examine' method involves reviewing documents, specifications, policies, and configurations to gain understanding or confirm that security controls are implemented.
An OSC operates two geographically separated facilities, both processing CUI. How should the assessor treat each facility's controls during the assessment?
Answer: Assess each facility independently since they may have different control implementations
Each facility must be assessed independently because control implementations may differ by location, and all in-scope environments must meet CMMC requirements.
Which of the following scenarios would most likely result in a finding being escalated to the Cyber AB during a CMMC assessment?
Answer: Evidence of fraudulent representation of controls by the OSC
Fraudulent misrepresentation of controls is a serious integrity issue that must be escalated to the Cyber AB, as it violates the assessment's foundational trust requirements.
When assessing the 'implement' objective of a CMMC practice, what type of evidence is MOST appropriate?
Answer: Operational artifacts such as configuration screenshots, logs, and system outputs demonstrating the control is active
The 'implement' objective requires evidence that the control is actually operational, such as configuration settings, logs, or system outputs — not just policies or intentions.