CCA Compliance & Reporting 3 — Questions and Answers
Question 1: In CMMC assessments, what does the term 'inherited controls' refer to in the context of compliance reporting?
- Security practices passed down from parent company policies
- Controls implemented by a cloud service provider that the OSC relies upon (Correct answer)
- Requirements carried forward from a previous assessment cycle
- Legacy system controls documented but not actively enforced
Correct answer: Controls implemented by a cloud service provider that the OSC relies upon
Inherited controls are security capabilities provided by an external entity (such as a CSP) that the OSC leverages rather than implementing independently.
Question 2: Which NIST publication provides the 110 security requirements that form the basis of CMMC Level 2 compliance?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- NIST SP 800-37
- NIST CSF v2.0
Correct answer: NIST SP 800-171
NIST SP 800-171 'Protecting CUI in Nonfederal Systems and Organizations' provides the 110 requirements mapped to CMMC Level 2.
Question 3: When an OSC uses an external managed service provider (MSP) that handles CUI, what compliance obligation applies to that MSP?
- The MSP must obtain its own CMMC certification at the same or higher level (Correct answer)
- The OSC assumes full responsibility and the MSP has no direct obligations
- The MSP only needs SOC 2 Type II certification
- MSPs are explicitly excluded from CMMC scope
Correct answer: The MSP must obtain its own CMMC certification at the same or higher level
When an MSP processes or handles CUI on behalf of an OSC, that MSP must also meet the applicable CMMC level requirements.
Question 4: What is the purpose of the CMMC Assessment Scope categorization of 'Contractor Risk Managed Assets' (CRMAs)?
- Assets that require full CMMC assessment regardless of CUI contact
- Assets that could impact CUI but are managed by the contractor under documented risk controls (Correct answer)
- Assets outside the assessment boundary entirely
- Assets owned by DoD that contractors must protect
Correct answer: Assets that could impact CUI but are managed by the contractor under documented risk controls
CRMAs are assets that can affect CUI security but are managed through contractor-defined risk controls rather than full CMMC practice application.
Question 5: A CCA is reviewing an OSC's compliance documentation and finds that audit logs are retained for only 30 days. Which NIST SP 800-171 domain does this deficiency fall under?
- Access Control (AC)
- Audit and Accountability (AU) (Correct answer)
- Configuration Management (CM)
- Incident Response (IR)
Correct answer: Audit and Accountability (AU)
Audit log retention requirements fall under the Audit and Accountability domain, specifically AU.3.045 which addresses log protection and retention.
Question 6: Which role within the CMMC ecosystem is responsible for publishing and maintaining the CMMC standard, assessment guides, and rulemaking?
- Cyber AB (Accreditation Body)
- DoD (Department of Defense) (Correct answer)
- C3PAO (Certified Third-Party Assessor Organization)
- NIST (National Institute of Standards and Technology)
Correct answer: DoD (Department of Defense)
The DoD owns and publishes the CMMC model, issues the final rule through 32 CFR Part 170, and sets all programmatic policy.
Question 7: In a CMMC compliance report, what does a practice scored as 'MET' indicate?
- The practice is partially implemented with compensating controls
- All objectives for the practice are fully implemented and verified (Correct answer)
- The practice is waived due to business justification
- The practice is inherited from a parent organization
Correct answer: All objectives for the practice are fully implemented and verified
A 'MET' score means all assessment objectives for that practice have been verified as fully and consistently implemented.
In CMMC assessments, what does the term 'inherited controls' refer to in the context of compliance reporting?