CCA CMMC Framework & Domains 1 — Questions and Answers
Question 1: What is the main goal of the CMMC framework?
- Reduce hardware costs
- Replace NIST guidance
- Protect CUI in the DIB (Correct answer)
- Improve software usability
Correct answer: Protect CUI in the DIB
The CMMC framework is designed to enhance the protection of controlled unclassified information (CUI) across the defense industrial base (DIB).
Question 2: How many levels are in the CMMC 2.0 model?
- 5
- 4
- 3 (Correct answer)
- 6
Correct answer: 3
CMMC 2.0 features three levels of cybersecurity maturity, ranging from Foundational to Expert.
Question 3: Which domain focuses on managing physical access to systems and facilities?
- Access Control (AC)
- System Integrity (SI)
- Physical Protection (PE) (Correct answer)
- Configuration Management (CM)
Correct answer: Physical Protection (PE)
The Physical Protection (PE) domain involves measures to restrict access to sensitive physical areas and systems.
Question 4: Which CMMC domain deals with identifying and responding to cybersecurity threats?
- Audit and Accountability (AU)
- Incident Response (IR) (Correct answer)
- Media Protection (MP)
- Personnel Security (PS)
Correct answer: Incident Response (IR)
The Incident Response (IR) domain requires organizations to have procedures for detecting, reporting, and mitigating cybersecurity events.
Question 5: What is a key feature of Level 2 in CMMC 2.0?
- Focus on informal controls
- Elimination of documentation
- Alignment with NIST SP 800-171 (Correct answer)
- No third-party assessments required
Correct answer: Alignment with NIST SP 800-171
Level 2 (Advanced) aligns with NIST SP 800-171 and is required for organizations handling CUI.
Question 6: Which domain ensures users are only granted necessary access?
- System and Communications Protection (SC)
- Access Control (AC) (Correct answer)
- Identification and Authentication (IA)
- Security Assessment (CA)
Correct answer: Access Control (AC)
The Access Control (AC) domain requires limiting system access to authorized users and processes based on the principle of least privilege.
What is the main goal of the CMMC framework?