CCA Compliance & Reporting 2 — Questions and Answers
Question 1: Under CMMC 2.0, which federal regulation mandates that defense contractors protect Controlled Unclassified Information (CUI)?
- FISMA
- DFARS 252.204-7012 (Correct answer)
- FAR 52.204-21
- ITAR Part 120
Correct answer: DFARS 252.204-7012
DFARS 252.204-7012 is the key clause requiring defense contractors to safeguard covered defense information including CUI.
Question 2: When a CMMC Level 2 assessment reveals a practice not fully implemented, what document must the OSC submit to capture remediation plans?
- Plan of Action and Milestones (POA&M) (Correct answer)
- System Security Plan (SSP)
- Incident Response Plan (IRP)
- Corrective Action Report (CAR)
Correct answer: Plan of Action and Milestones (POA&M)
A POA&M documents identified weaknesses and the plan, resources, and timeline for correcting each deficiency.
Question 3: Which CMMC compliance artifact describes how security requirements are implemented across an organization's system boundary?
- Risk Assessment Report
- System Security Plan (SSP) (Correct answer)
- Vulnerability Scan Report
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The SSP documents the system boundary, how each security requirement is met, and the roles responsible for implementation.
Question 4: A C3PAO discovers mid-assessment that an OSC intentionally misrepresented their implementation of access control practices. What is the C3PAO's required action?
- Complete the assessment and note discrepancies in the report
- Suspend the assessment and report the misrepresentation to the Cyber AB (Correct answer)
- Issue a conditional certification pending verification
- Require the OSC to self-attest to corrections
Correct answer: Suspend the assessment and report the misrepresentation to the Cyber AB
C3PAOs must report intentional misrepresentation to the Cyber AB, as this constitutes a violation of assessment integrity.
Question 5: What is the maximum timeframe an OSC has under CMMC 2.0 to resolve a POA&M item before it causes assessment failure at Level 2?
- 30 days
- 90 days
- 180 days (Correct answer)
- 365 days
Correct answer: 180 days
Under CMMC 2.0 rules, POA&M items must be closed within 180 days of a conditional certification being awarded.
Question 6: Which component of CMMC compliance reporting confirms the scope of the assessment, including all assets that store, process, or transmit CUI?
- Threat Model
- System Security Plan scope section (Correct answer)
- Business Impact Analysis
- Data Flow Diagram only
Correct answer: System Security Plan scope section
The SSP's scope section defines the assessment boundary including all in-scope assets, networks, and personnel handling CUI.
Question 7: Under CMMC 2.0, Level 1 compliance is demonstrated primarily through which mechanism?
- Third-party C3PAO assessment
- DoD-sponsored government assessment
- Annual self-attestation signed by a senior company official (Correct answer)
- ISO 27001 certification equivalency
Correct answer: Annual self-attestation signed by a senior company official
CMMC Level 1 requires annual self-attestation affirming implementation of all 17 basic safeguarding practices, signed by a senior official.
Under CMMC 2.0, which federal regulation mandates that defense contractors protect Controlled Unclassified Information (CUI)?