CCA CMMC Framework & Domains 3 — Questions and Answers
Question 1: Which CMMC domain addresses the protection of audit logs and monitoring of system activity?
- Audit and Accountability (AU) (Correct answer)
- Incident Response (IR)
- System and Communications Protection (SC)
- Risk Assessment (RA)
Correct answer: Audit and Accountability (AU)
The Audit and Accountability domain covers requirements for creating, protecting, and reviewing audit logs of system events.
Question 2: A defense contractor stores CUI and processes it on cloud systems. Under CMMC 2.0, the cloud service provider must meet which standard?
- FedRAMP Moderate or equivalent (Correct answer)
- ISO 27001
- SOC 2 Type II
- PCI DSS Level 1
Correct answer: FedRAMP Moderate or equivalent
Cloud service providers used by CMMC Level 2 contractors must meet FedRAMP Moderate or equivalent requirements.
Question 3: How does CMMC 2.0 differ from CMMC 1.0 in terms of maturity levels?
- CMMC 2.0 reduced from 5 levels to 3 levels (Correct answer)
- CMMC 2.0 increased from 3 levels to 5 levels
- Both versions use the same 3 levels
- CMMC 2.0 eliminated all maturity levels
Correct answer: CMMC 2.0 reduced from 5 levels to 3 levels
CMMC 2.0 streamlined the framework from 5 maturity levels in CMMC 1.0 to 3 levels.
Question 4: Which CMMC practice, if not implemented, would most directly violate the 'Identification and Authentication (IA)' domain requirements?
- Encrypting FCI during transmission
- Allowing shared user accounts for system administrators (Correct answer)
- Failing to patch known vulnerabilities within 30 days
- Not maintaining a system security plan
Correct answer: Allowing shared user accounts for system administrators
Shared accounts undermine the ability to uniquely identify users, which is a core requirement of the IA domain.
Question 5: In the CMMC framework, 'Federal Contract Information' (FCI) is BEST described as:
- Information provided by the government under a contract that is not intended for public release (Correct answer)
- Classified national security information requiring Top Secret clearance
- Information about federal employee personally identifiable details
- Any data stored on government-owned systems
Correct answer: Information provided by the government under a contract that is not intended for public release
FCI is information provided by or generated for the government under a contract, not intended for public release.
Question 6: The 'Media Protection (MP)' domain in CMMC primarily governs:
- Social media usage policies for employees
- Protection, control, sanitization, and disposal of digital and physical media containing CUI (Correct answer)
- Monitoring broadcast media for cybersecurity threats
- Encryption of multimedia files sent via email
Correct answer: Protection, control, sanitization, and disposal of digital and physical media containing CUI
The MP domain covers the handling, marking, storage, transport, and destruction of media that contains sensitive information.
Question 7: Which CMMC 2.0 domain requires organizations to periodically assess security controls and develop plans of action?
- Risk Assessment (RA)
- Security Assessment (CA) (Correct answer)
- Audit and Accountability (AU)
- System and Information Integrity (SI)
Correct answer: Security Assessment (CA)
The Security Assessment (CA) domain requires periodic assessment of security controls and creation of plans of action and milestones (POA&Ms).
Which CMMC domain addresses the protection of audit logs and monitoring of system activity?