CCA Cybersecurity Practices & Controls 3 β Questions and Answers
Question 1: Which CMMC practice specifically requires organizations to separate user functionality from system management functionality?
- AC.L2-3.1.6
- SC.L2-3.13.3 (Correct answer)
- CM.L2-3.4.5
- IA.L2-3.5.6
Correct answer: SC.L2-3.13.3
SC.L2-3.13.3 requires separation of user functionality from system management functionality to reduce risk.
Question 2: A CCA assessor reviews an organization's incident response plan and finds no defined roles for handling a CUI breach. Which practice gap does this represent?
- IR.L2-3.6.2 β Track, document, and report incidents
- IR.L2-3.6.1 β Establish an operational incident-handling capability (Correct answer)
- CA.L2-3.12.4 β Develop, document, and periodically update SSPs
- AU.L2-3.3.1 β Create and retain system audit logs
Correct answer: IR.L2-3.6.1 β Establish an operational incident-handling capability
IR.L2-3.6.1 requires establishing an incident-handling capability that includes defined roles and responsibilities.
Question 3: What does the CMMC practice PE.L1-3.10.1 require?
- Protect CUI systems from electromagnetic interference
- Limit physical access to organizational systems to authorized individuals (Correct answer)
- Maintain audit logs of all physical access events
- Require two-person integrity for access to server rooms
Correct answer: Limit physical access to organizational systems to authorized individuals
PE.L1-3.10.1 (Physical Protection) requires limiting physical access to systems, equipment, and the respective operating environments to authorized individuals.
Question 4: Which NIST SP 800-171 control family maps to the CMMC Audit and Accountability (AU) domain?
- Control Family 3.3 β Audit and Accountability (Correct answer)
- Control Family 3.5 β Identification and Authentication
- Control Family 3.1 β Access Control
- Control Family 3.12 β Security Assessment
Correct answer: Control Family 3.3 β Audit and Accountability
CMMC's AU domain maps directly to NIST SP 800-171 Control Family 3.3, Audit and Accountability.
Question 5: An organization uses a SIEM tool to aggregate and review security logs. Which CMMC practice is best supported by this control?
- SI.L2-3.14.7 β Identify unauthorized use of organizational systems
- AU.L2-3.3.2 β Ensure the actions of individual users can be traced (Correct answer)
- RA.L2-3.11.3 β Remediate vulnerabilities in accordance with risk assessments
- SC.L2-3.13.1 β Monitor, control, and protect communications at external boundaries
Correct answer: AU.L2-3.3.2 β Ensure the actions of individual users can be traced
AU.L2-3.3.2 requires that individual user actions be traceable through logs, which a SIEM directly supports by aggregating and analyzing audit data.
Question 6: Under CMMC, which practice requires that system components be protected from known vulnerabilities by applying patches and updates?
- CM.L2-3.4.9
- SI.L2-3.14.1 (Correct answer)
- RA.L2-3.11.3
- CA.L2-3.12.2
Correct answer: SI.L2-3.14.1
SI.L2-3.14.1 requires identifying, reporting, and correcting information and information system flaws in a timely manner, including applying security patches.
Question 7: When assessing a subcontractor's compliance with CUI handling requirements, a CCA assessor notices that the subcontractor shares CUI with a vendor via unencrypted email. Which CMMC practice does this violate?
- AC.L2-3.1.3 β Control the flow of CUI
- SC.L2-3.13.8 β Implement cryptographic mechanisms to protect CUI during transmission (Correct answer)
- MP.L2-3.8.5 β Control access to media containing CUI
- IA.L2-3.5.2 β Authenticate the identity of users before allowing access
Correct answer: SC.L2-3.13.8 β Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic protection of CUI during transmission; unencrypted email fails this requirement.
Which CMMC practice specifically requires organizations to separate user functionality from system management functionality?