CCA CMMC Framework & Domains 2 — Questions and Answers
Question 1: How many domains are defined in CMMC 2.0?
- 14 (Correct answer)
- 17
- 10
- 12
Correct answer: 14
CMMC 2.0 organizes cybersecurity requirements into 14 domains inherited from NIST SP 800-171.
Question 2: Which CMMC 2.0 level requires a third-party assessment by a C3PAO?
- Level 1
- Level 2 (for prioritized acquisitions) (Correct answer)
- Level 3
- All levels
Correct answer: Level 2 (for prioritized acquisitions)
Level 2 prioritized acquisitions require a triennial assessment by a CMMC Third-Party Assessment Organization (C3PAO).
Question 3: The CMMC domain 'Incident Response' (IR) primarily maps to which NIST SP 800-171 family?
- IR — Incident Response (Correct answer)
- AU — Audit and Accountability
- CA — Security Assessment
- SI — System and Information Integrity
Correct answer: IR — Incident Response
The CMMC Incident Response domain directly maps to the IR family in NIST SP 800-171.
Question 4: In CMMC 2.0, which level specifically protects Controlled Unclassified Information (CUI) in non-critical programs?
- Level 1
- Level 2 (Correct answer)
- Level 3
- Level 4
Correct answer: Level 2
CMMC Level 2 is designed to protect CUI in non-critical national security programs.
Question 5: Which of the following is NOT one of the CMMC 2.0 domains?
- Physical Protection (PE)
- Supply Chain Risk Management (SR)
- Privacy Engineering (PR) (Correct answer)
- Recovery (RE)
Correct answer: Privacy Engineering (PR)
Privacy Engineering is not a CMMC 2.0 domain; the 14 domains are inherited from NIST SP 800-171 and related standards.
Question 6: What is the primary purpose of the 'Configuration Management (CM)' domain in CMMC?
- Managing user access privileges
- Establishing and maintaining baseline configurations of systems (Correct answer)
- Monitoring network traffic for anomalies
- Encrypting data at rest and in transit
Correct answer: Establishing and maintaining baseline configurations of systems
The CM domain focuses on establishing, documenting, and enforcing baseline security configurations for organizational systems.
Question 7: Under CMMC 2.0, which entity is responsible for authorizing C3PAOs to conduct assessments?
- Department of Defense (DoD)
- CMMC Accreditation Body (Cyber AB) (Correct answer)
- National Institute of Standards and Technology (NIST)
- Defense Contract Management Agency (DCMA)
Correct answer: CMMC Accreditation Body (Cyber AB)
The Cyber AB (formerly CMMC-AB) is the accreditation body responsible for authorizing C3PAOs.
How many domains are defined in CMMC 2.0?