CCA Cybersecurity Practices & Controls 2 — Questions and Answers
Question 1: Under CMMC 2.0, which practice requires organizations to limit system access to authorized users, processes acting on behalf of authorized users, and devices?
- AC.L1-3.1.1 (Correct answer)
- IA.L2-3.5.3
- SC.L2-3.13.3
- AU.L2-3.3.1
Correct answer: AC.L1-3.1.1
AC.L1-3.1.1 (Authorized Access Control) is a Level 1 practice that limits system access to authorized users, processes, and devices.
Question 2: Which CMMC domain addresses the need to establish and maintain baseline configurations for information technology systems?
- Incident Response (IR)
- Configuration Management (CM) (Correct answer)
- Risk Assessment (RA)
- System and Communications Protection (SC)
Correct answer: Configuration Management (CM)
The Configuration Management (CM) domain includes practices for establishing and maintaining baseline configurations for IT systems.
Question 3: A CCA assessor finds that an organization uses shared accounts for multiple administrators. Which CMMC practice is most directly violated?
- AC.L2-3.1.6 — Use of non-privileged accounts
- IA.L2-3.5.4 — Employ replay-resistant authentication
- IA.L2-3.5.5 — Employ identifier management (Correct answer)
- AU.L2-3.3.9 — Protect audit information
Correct answer: IA.L2-3.5.5 — Employ identifier management
IA.L2-3.5.5 requires identifier management, including ensuring individual identifiability, which shared accounts violate.
Question 4: What is the primary purpose of the Media Protection (MP) domain in CMMC?
- To ensure backups are created and stored offsite
- To protect system media containing CUI, both paper and digital (Correct answer)
- To monitor network traffic for malicious content
- To manage software licenses and media keys
Correct answer: To protect system media containing CUI, both paper and digital
The Media Protection domain focuses on protecting system media containing CUI, whether in physical (paper) or digital form.
Question 5: Which practice requires that CMMC Level 2 organizations scan for vulnerabilities in organizational systems and applications periodically?
- CA.L2-3.12.1
- RA.L2-3.11.2 (Correct answer)
- SI.L2-3.14.1
- CM.L2-3.4.7
Correct answer: RA.L2-3.11.2
RA.L2-3.11.2 requires periodic vulnerability scanning of organizational systems and hosted applications.
Question 6: When assessing the Awareness and Training (AT) domain, what is the minimum evidence a CCA assessor should expect for CMMC Level 2?
- Annual cybersecurity training completion records for all users (Correct answer)
- A formal training plan with quarterly classroom sessions
- Penetration test results showing user awareness
- Evidence that only IT staff receive security training
Correct answer: Annual cybersecurity training completion records for all users
AT.L2-3.2.1 and AT.L2-3.2.2 require that users are made aware of security risks and trained; completion records demonstrate compliance.
Question 7: An organization encrypts CUI data at rest on laptops but transmits it in plaintext internally. Which CMMC practice is not being met?
- SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission (Correct answer)
- MP.L2-3.8.6 — Implement cryptographic mechanisms to protect CUI on digital media
- AC.L2-3.1.17 — Protect wireless access using authentication and encryption
- SI.L2-3.14.5 — Perform periodic scans of organizational systems
Correct answer: SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic protection of CUI during transmission, which is not satisfied by plaintext internal transfers.
Under CMMC 2.0, which practice requires organizations to limit system access to authorized users, processes acting on behalf of authorized users, and devices?