CCA Evaluation Methodology 3 — Questions and Answers
Question 1: Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology?
- NIST SP 800-171
- NIST SP 800-53
- NIST SP 800-171A (Correct answer)
- NIST SP 800-37
Correct answer: NIST SP 800-171A
NIST SP 800-171A provides the assessment procedures for verifying the security requirements in NIST SP 800-171, which form the basis for CMMC Level 2 assessments.
Question 2: During the planning phase, an assessor develops the Assessment Plan (AP). Which element is MOST important to establish in the AP to ensure a focused, efficient assessment?
- The billing schedule for the assessment
- The assessment scope including the OSC's CUI boundary and in-scope systems (Correct answer)
- The names of all OSC employees who will be interviewed
- The remediation timeline for identified gaps
Correct answer: The assessment scope including the OSC's CUI boundary and in-scope systems
Establishing the assessment scope — particularly the CUI boundary and in-scope assets — is foundational to ensuring the assessment is focused and all relevant systems are evaluated.
Question 3: An assessor finds that an OSC has implemented a compensating control in place of a standard CMMC practice. Under CMMC methodology, how should this be handled?
- Compensating controls are automatically accepted as MET
- Compensating controls are not recognized in CMMC; the practice is marked NOT MET (Correct answer)
- The assessor documents the compensating control and elevates the decision to the C3PAO for approval
- The assessor can accept compensating controls only if approved by the DoD
Correct answer: Compensating controls are not recognized in CMMC; the practice is marked NOT MET
CMMC Level 2 does not have a formal compensating controls framework; practices must be met as defined, so a deviation results in a NOT MET finding.
Question 4: What is the purpose of the 'examine' method in CMMC assessment methodology?
- Conducting interviews with technical staff
- Reviewing specifications, mechanisms, and documentation to understand or confirm security control implementation (Correct answer)
- Running automated vulnerability scans
- Observing personnel performing security-related tasks
Correct answer: Reviewing specifications, mechanisms, and documentation to understand or confirm security control implementation
The 'examine' method involves reviewing documents, specifications, policies, and configurations to gain understanding or confirm that security controls are implemented.
Question 5: An OSC operates two geographically separated facilities, both processing CUI. How should the assessor treat each facility's controls during the assessment?
- Assess only the headquarters facility as representative of the enterprise
- Assess each facility independently since they may have different control implementations (Correct answer)
- Accept a single SSP covering both facilities without site-specific review
- Assess only the facility with more employees
Correct answer: Assess each facility independently since they may have different control implementations
Each facility must be assessed independently because control implementations may differ by location, and all in-scope environments must meet CMMC requirements.
Question 6: Which of the following scenarios would most likely result in a finding being escalated to the Cyber AB during a CMMC assessment?
- The OSC has a single missing patch on a non-critical system
- An assessor disagrees with the Lead Assessor's scoring of a practice
- Evidence of fraudulent representation of controls by the OSC (Correct answer)
- The OSC requests a scope reduction after assessment begins
Correct answer: Evidence of fraudulent representation of controls by the OSC
Fraudulent misrepresentation of controls is a serious integrity issue that must be escalated to the Cyber AB, as it violates the assessment's foundational trust requirements.
Question 7: When assessing the 'implement' objective of a CMMC practice, what type of evidence is MOST appropriate?
- Policy documents stating intent to implement the control
- Operational artifacts such as configuration screenshots, logs, and system outputs demonstrating the control is active (Correct answer)
- Employee acknowledgment forms
- Vendor documentation for a purchased security tool
Correct answer: Operational artifacts such as configuration screenshots, logs, and system outputs demonstrating the control is active
The 'implement' objective requires evidence that the control is actually operational, such as configuration settings, logs, or system outputs — not just policies or intentions.
Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology?