Mixed Deck — All CCA Topics Flashcards
100 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCA Topics flashcards as text
What type of sensitive information does CMMC Level 2 specifically aim to protect?
Answer: Controlled Unclassified Information (CUI)
CMMC Level 2 is designed to protect Controlled Unclassified Information (CUI) in the defense supply chain, requiring the full 110 NIST SP 800-171 practices.
Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?
Answer: DFARS 252.204-7012
DFARS 252.204-7012 requires defense contractors to implement NIST SP 800-171 security requirements and report cyber incidents involving covered contractor information systems within 72 hours.
What is the primary function of multi-factor authentication (MFA)?
Answer: Require multiple forms of identity verification
MFA adds an additional layer of security by requiring two or more verification factors to access systems.
An OSC receives a CMMC Level 2 final assessment report. Where is this report ultimately submitted for DoD contract award decisions?
Answer: The Supplier Performance Risk System (SPRS)
CMMC assessment results and the resulting SPRS score are reported to the Supplier Performance Risk System, which contracting officers review.
Which CMMC practice requires organizations to protect CUI during transmission using FIPS-validated cryptography?
Answer: SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic mechanisms—which for federal systems implies FIPS-validated algorithms—to protect CUI during transmission.
Under CMMC 2.0 rules, which type of information does Level 1 protect, as distinct from what Level 2 protects?
Answer: Federal Contract Information (FCI) only
CMMC Level 1 focuses on protecting Federal Contract Information (FCI), while Level 2 adds the broader requirement to protect CUI.
What is the minimum number of assessors required for a CMMC Level 2 certification assessment conducted by a C3PAO?
Answer: A team of at least two CCAs
CMMC Level 2 certification assessments require a team of at least two CCAs to ensure objectivity and thoroughness.
What is the role of configuration baselines in CMMC vulnerability management?
Answer: They establish a known-good system state that enables detection of unauthorized changes that may introduce vulnerabilities
Configuration baselines establish the approved secure configuration state, enabling organizations to detect deviations that may introduce vulnerabilities or indicate compromise.
What is the purpose of interviewing personnel during a CMMC assessment?
Answer: To gather information about security practice implementation that may not be fully captured in documentation
Interviews with knowledgeable personnel provide context, clarify how practices are actually implemented day-to-day, and can surface discrepancies between documented procedures and actual practice.
Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required?
Answer: 3 years
CMMC Level 2 certifications obtained through C3PAO assessments are valid for three years, after which a new assessment must be completed.
An assessor is evaluating an OSC that recently migrated to a new system mid-year. Evidence for some practices only covers the new system, with gaps in coverage for the period when the old system was in use. How should this be handled?
Answer: Evaluate the completeness and continuity of evidence, noting any gaps, and score practices based on whether requirements were continuously met throughout the assessment period
Assessors evaluate whether practices were continuously implemented throughout the relevant period; evidence gaps during a migration may result in NOT MET if continuity cannot be demonstrated.
Under CMMC 2.0, how often must a CMMC Level 2 contractor that requires a third-party assessment renew their certification?
Answer: Every three years (triennially)
CMMC Level 2 third-party assessments must be renewed every three years (triennially), with annual senior official affirmations required in between assessment cycles.
Which part of the Defense Federal Acquisition Regulation Supplement introduced the requirement for CMMC in new DoD contracts?
Answer: DFARS 252.204-7021
DFARS 252.204-7021 is the clause that imposes CMMC requirements as a condition of contract award for DoD contracts requiring CMMC compliance.
Which CMMC 2.0 domain requires organizations to periodically assess security controls and develop plans of action?
Answer: Security Assessment (CA)
The Security Assessment (CA) domain requires periodic assessment of security controls and creation of plans of action and milestones (POA&Ms).
What must a CCA do when they identify a potential conflict of interest before beginning an assessment?
Answer: Disclose the conflict to the C3PAO and recuse themselves from the assessment if the conflict cannot be mitigated
CCAs must disclose conflicts of interest to their C3PAO and recuse themselves if the conflict cannot be appropriately mitigated, to preserve the objectivity required for a valid assessment.
How does a CCA assessor determine which CMMC level to assess when the OSC's contract requirements are unclear?
Answer: Consult the contract language, DFARS clauses, and the contracting officer for clarification
The required CMMC level is determined by the contract requirements, relevant DFARS clauses, and if unclear, by seeking clarification from the contracting officer.
Which role within the CMMC ecosystem is responsible for publishing and maintaining the CMMC standard, assessment guides, and rulemaking?
Answer: DoD (Department of Defense)
The DoD owns and publishes the CMMC model, issues the final rule through 32 CFR Part 170, and sets all programmatic policy.
How does CMMC affect a defense contractor that only handles Federal Contract Information (FCI) but not CUI?
Answer: FCI-only contractors must meet CMMC Level 1, which requires implementation of basic safeguarding requirements from FAR 52.204-21
Contractors handling only FCI must meet CMMC Level 1, which consists of 17 basic safeguarding practices aligned to FAR 52.204-21 and allows annual self-attestation.
Which CMMC domain deals with identifying and responding to cybersecurity threats?
Answer: Incident Response (IR)
The Incident Response (IR) domain requires organizations to have procedures for detecting, reporting, and mitigating cybersecurity events.
A CCA assessor is reviewing an organization's personnel security practices. Which practice requires screening individuals prior to granting access to CUI systems?
Answer: PS.L2-3.9.1 — Screen individuals prior to authorizing access to organizational systems
PS.L2-3.9.1 (Personnel Security) requires screening individuals before authorizing access to organizational systems containing CUI.