CCA Study Guide 2026
Everything you need to pass the CCA exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.
📋 CCA Exam Format at a Glance
📚 CCA Topics to Study (38)
✍️ Sample CCA Questions & Answers
1. What type of sensitive information does CMMC Level 2 specifically aim to protect?
CMMC Level 2 is designed to protect Controlled Unclassified Information (CUI) in the defense supply chain, requiring the full 110 NIST SP 800-171 practices.
2. Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?
DFARS 252.204-7012 requires defense contractors to implement NIST SP 800-171 security requirements and report cyber incidents involving covered contractor information systems within 72 hours.
3. What is the primary function of multi-factor authentication (MFA)?
MFA adds an additional layer of security by requiring two or more verification factors to access systems.
4. An OSC receives a CMMC Level 2 final assessment report. Where is this report ultimately submitted for DoD contract award decisions?
CMMC assessment results and the resulting SPRS score are reported to the Supplier Performance Risk System, which contracting officers review.
5. Which CMMC practice requires organizations to protect CUI during transmission using FIPS-validated cryptography?
SC.L2-3.13.8 requires cryptographic mechanisms—which for federal systems implies FIPS-validated algorithms—to protect CUI during transmission.
6. Under CMMC 2.0 rules, which type of information does Level 1 protect, as distinct from what Level 2 protects?
CMMC Level 1 focuses on protecting Federal Contract Information (FCI), while Level 2 adds the broader requirement to protect CUI.