Updated Mar 11, 2026 Certification Exam CMMC-CCA Dumps - Practice Test Questions [Q76-Q96]

Share

Updated Mar 11, 2026  Certification Exam CMMC-CCA Dumps - Practice Test Questions

Updated Verified CMMC-CCA dumps Q&As - Pass Guarantee or Full Refund


Cyber AB CMMC-CCA Exam Syllabus Topics:

TopicDetails
Topic 1
  • CMMC Assessment Process (CAP): This section of the exam measures skills of compliance professionals and tests knowledge of the full assessment lifecycle. It covers the steps needed to plan, prepare, conduct, and report on a CMMC Level 2 assessment, including the phases of execution and how to document and follow up on findings in alignment with DoD and CMMC-AB expectations.
Topic 2
  • Assessing CMMC Level 2 Practices: This section of the exam measures skills of cybersecurity assessors in evaluating whether organizations meet the required practices of CMMC Level 2. It emphasizes applying CMMC model constructs, understanding model levels, domains, and implementation, and using evidence to determine compliance with established cybersecurity practices.
Topic 3
  • CMMC Level 2 Assessment Scoping: This section of the exam measures skills of cybersecurity assessors and revolves around determining the proper scope of a CMMC assessment. It involves analyzing and categorizing Controlled Unclassified Information (CUI) assets, interpreting the Level 2 scoping guidelines, and making accurate judgments in scenario-based exercises to define what assets and systems fall within assessment boundaries.
Topic 4
  • Evaluating Organizations Seeking Certification (OSC) against CMMC Level 2 Requirements: This section of the exam measures skills of cybersecurity assessors and focuses on evaluating the environments of organizations seeking certification at CMMC Level 2. It covers understanding differences between logical and physical settings, recognizing constraints in cloud, hybrid, on-premises, single, and multi-site environments, and knowing what environmental exclusions apply for Level 2 assessments.

 

NEW QUESTION # 76
An OSC seeking Level 2 certification is migrating to a fully cloud-based environment. The organization wants to select a Cloud Service Provider (CSP) that can share responsibilities for CMMC Level 2 requirements. Assume both CSPs can equally provide the technical capabilities and business value required.
* CSP A has SOC 2 certification and is California Consumer Privacy Act (CCPA) and Health Insurance Portability and Accountability Act (HIPAA) compliant.
* CSP B has SOC 2 and FedRAMP Moderate certifications.
Based on this information, which CSP is MOST LIKELY to be acceptable?

  • A. CSP B
  • B. Both CSP A and B
  • C. Neither CSP A nor B
  • D. CSP A

Answer: A

Explanation:
When an OSC leverages cloud providers in a CMMC Level 2 assessment, the provider should have FedRAMP Moderate or higher authorization to align with NIST SP 800-171 requirements. SOC 2, HIPAA, or CCPA compliance do not demonstrate federal-level assurance for protecting CUI. Thus, CSP B is the most appropriate choice.
Exact extracts:
* "Cloud service providers that process, store, or transmit CUI should be FedRAMP Moderate Authorized or equivalent."
* "Assessors must verify evidence of FedRAMP authorization or comparable assurance before determining that OSC reliance on the provider is acceptable." Why the other options are incorrect:
* A: SOC 2, HIPAA, and CCPA compliance do not equate to CMMC-required federal assurance.
* C: Only FedRAMP-authorized providers meet the requirement, so both are not acceptable.
* D: CSP B does meet the criteria.
References:
CMMC Level 2 Scoping Guide - External Service Providers.
CMMC Assessment Guide - Treatment of Cloud Service Providers.


NEW QUESTION # 77
You are assessing Conedge Ltd, a contractor that develops cryptographic algorithms for classified government networks. In reviewing their network architecture documents, you see they have implemented role-based access controls on their workstations using Active Directory group policies. Software developers are assigned to the "Dev_Roles" group which grants access to compile and test code modules. The "Admin_Roles" group with elevated privileges for system administration activities is restricted to the IT staff. However, when you examine the event logs on a developer workstation, you find evidence that a developer was able to enable debugging permissions to access protected kernel memory - a privileged function. How should execution of the debugging permission be handled to align with AC.L2-3.1.7 - Privileged Functions?

  • A. Require it to generate an email alert
  • B. Ensure it is logged to the central SIEM system
  • C. Implement geo-IP blocking on the workstation
  • D. Perform automatic termination of the action

Answer: B

Explanation:
Comprehensive and Detailed In-Depth Explanation:
AC.L2-3.1.7 requires "preventing non-privileged users from executing privileged functions and logging such attempts." The developer's access to kernel memory (a privileged function) violates least privilege, and logging to a SIEM (D) ensures visibility and auditability, aligning with the practice. Alerts (A) are supplementary, termination (B) isn't required, and geo-IP blocking (C) is unrelated. The CMMC guide emphasizes logging for accountability.
Extract from Official CMMC Documentation:
* CMMC Assessment Guide Level 2 (v2.0), AC.L2-3.1.7: "Log attempts by non-privileged users to execute privileged functions."
* NIST SP 800-171A, 3.1.7: "Examine logs for privileged function attempts." Resources:
* https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.
0_FINAL_202112016_508.pdf


NEW QUESTION # 78
CMMC MA.L2-3.7.6 - Maintenance Personnel requires that maintenance personnel without required access authorization be supervised during maintenance activities. One of the ways organizations can achieve this is to develop a documented procedure for supervised maintenance activities. Which of the following elements should be excluded from the documented procedure?

  • A. The method used to authenticate and monitor the supervisor's activity during the maintenance session
  • B. A detailed list of all CUI assets that the maintenance activity might impact
  • C. Contact information for the organization's IT security team in case of emergencies or unexpected issues
  • D. The specific steps authorized for the visiting maintenance personnel with limited access

Answer: B

Explanation:
Comprehensive and Detailed In-Depth Explanation:
MA.L2-3.7.6 requires "supervising maintenance personnel without access authorization." Procedures should focus on supervision logistics: steps for personnel (B), IT contact (C), and supervisor monitoring (D). A list of CUI assets (A) is unnecessary and impractical, as it may vary per task and isn't required for supervision, per the CMMC guide.
Extract from Official CMMC Documentation:
* CMMC Assessment Guide Level 2 (v2.0), MA.L2-3.7.6: "Include supervision steps, not asset lists."
* NIST SP 800-171A, 3.7.6: "Examine supervision procedures."
Resources:
* https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.
0_FINAL_202112016_508.pdf


NEW QUESTION # 79
The Assessment Team is meeting with the OSC team and experiences a situation where some members of the OSC team describe the IT infrastructure differently from others. In some discussions, one person identifies a series of ESPs, while another describes the infrastructure as on-premises. What should the Lead Assessor do to clarify the actual operational environment?

  • A. Review the network diagrams
  • B. Ask for the contact information of the identified ESPs
  • C. Interview an authoritative OSC representative
  • D. Review the system interconnection agreements

Answer: A

Explanation:
* Applicable Requirement (CAP - Scoping and Evidence Validation): When inconsistencies arise about the environment, assessors are required to examine objective artifacts that define boundaries, such as network diagrams and system architecture documentation.
* Why A is Correct: Network diagrams objectively show whether systems are hosted on-premises or involve ESPs (cloud, MSSPs, hosting providers). Reviewing them avoids ambiguity from inconsistent verbal descriptions.
* Why Other Options Are Insufficient:
* B: Interviewing another OSC representative may add to confusion rather than resolve it.
* C: Interconnection agreements confirm ESP relationships but do not resolve whether the OSC has on-prem or hybrid environments.
* D: Contacting ESPs directly is not part of the assessment process; OSC must provide evidence.
References (CCA Official Sources):
* CMMC Assessment Process (CAP) v1.0 - Clarifying System Boundaries
* CMMC Assessment Guide - Level 2 - Evidence Types (network diagrams, architecture documentation)


NEW QUESTION # 80
The OSC POC has prepared evidence from an internal pre-assessment for the C3PAO in preparation for a third-party assessment. The OSC POC has identified that there are several ESPs (External Service Providers) involved in protecting the security of the infrastructure. While reviewing the pre-assessment documentation regarding ESPs, the Lead Assessor will be looking for items that are:

  • A. Marked as NOT APPLICABLE
  • B. Marked as requiring a waiver
  • C. Noted as partially implemented
  • D. Noted as inherited

Answer: D

Explanation:
When External Service Providers are used, the OSC can inherit practices from the ESP if sufficient evidence is provided (such as FedRAMP authorization or equivalent). The Lead Assessor must verify which controls are noted as inherited, as these are assessed differently from controls implemented directly by the OSC.
Exact Extracts:
* CMMC Assessment Guide: "An OSC may inherit practices from External Service Providers when those providers demonstrate equivalent compliance (e.g., FedRAMP Moderate for CUI)."
* "Assessors must review documentation that identifies which practices are inherited, partially implemented, or implemented internally."
* CMMC Scoping Guide: "Inherited controls must be clearly documented by the OSC in the SSP." Why the other options are not correct:
* B: Waivers are not part of CMMC assessments.
* C: "Not Applicable" does not apply to ESP involvement; they either provide inherited practices or not.
* D: "Partially implemented" indicates deficiencies, not proper inheritance.
References:
CMMC Assessment Guide - Level 2, Version 2.13: External Service Providers and inheritance (pp. 10-13).
CMMC Scoping Guide - Level 2: Inherited practices documentation requirements.


NEW QUESTION # 81
A software development company wins a DoD contract requiring CMMC Level 2. The company is small and has one main office. However, it outsources some data storage requirements to a cloud service provider (CSP). What type of organization would the cloud service provider be considered in the CMMC assessment scope?

  • A. A Supporting Unit
  • B. The HQ Organization
  • C. The Host Unit
  • D. An Enclave

Answer: A

Explanation:
Comprehensive and Detailed Explanation:
The CMMC Assessment Scope - Level 2 defines the Host Unit as the entity (OSC) directly performing the DoD contract work-here, the software development company. A Supporting Unit includes external entities, such as a cloud service provider (CSP), that provide services supporting the Host Unit but are not the primary contractor. The CSP, by handling data storage, supports the OSC's operations without being the Host Unit (Option C) or HQ Organization (Option D, the parent entity). An Enclave (Option B) is a technical boundary, not an organization. A is correct per the scoping guide.
Reference:
CMMC Assessment Scope - Level 2, Section 2.1 (Host Unit and Supporting Organizations), p. 3: "Supporting Units are external entities providing services to the Host Unit."


NEW QUESTION # 82
During a CMMC assessment, a CCA took home some documents from the OSC's facility without their knowledge. The documents contained confidential, proprietary information (jet engine designs). After a few days, the OSC realized the documents were missing. Upon realizing the mistake, the CCA returned the document and informed the Lead Assessor. One year later, the information appeared online. The OSC believes the CCA duplicated the information and kept a copy for themselves. Angered by the situation, the OSC sues the CCA for IP theft. Under the CoPC, what action should the CCA take?

  • A. None; they should only defend themselves in court.
  • B. Plead guilty to receive a reduced fine.
  • C. Ask their C3PAO for legal assistance.
  • D. Inform the Cyber AB within 30 days.

Answer: D

Explanation:
Comprehensive and Detailed in Depth Explanation:
The CoPC requires CCAs to report legal actions like lawsuits related to their CMMC role to the Cyber AB within 30 days, ensuring transparency and accountability. Option A (pleading guilty) is a legal strategy, not a CoPC requirement. Option B (doing nothing) ignores reporting obligations. Option D (asking C3PAO) is not mandated by CoPC. Option C is the required action.
Extract from Official Document (CoPC):
* Paragraph 3.6(4) - Lawful and Ethical Practices (pg. 8):"Report to the Cyber AB within 30 days any legal actions, such as being sued for larceny, related to your role in the CMMC ecosystem." References:
CMMC Code of Professional Conduct, Paragraph 3.6(4).


NEW QUESTION # 83
A Lead Assessor is preparing to conduct a Level 2 Assessment for an OSC. During the planning phase, the Lead Assessor and OSC have:
* Developed evidence collection approach;
* Identified the team members, resources, schedules, and logistics;
* Identified and managed conflicts of interest;
* Gained access to the OSC's relevant documentation.
Based on the information provided, which would be an additional element to be discussed during the planning phase of the assessment?

  • A. Identify and document evidence gaps
  • B. Describe the assessment appeals
  • C. Estimate a rough order-of-magnitude (ROM) cost for the assessment
  • D. Determine FedRAMP MODERATE equivalency for Cloud computing provider

Answer: A

Explanation:
During the planning phase, the Lead Assessor must ensure that evidence gaps are identified and documented before assessment execution. This ensures that the OSC is aware of missing or insufficient evidence and can address them prior to final scoring.
Exact Extracts:
* CMMC Assessment Guide: "During planning, assessors and OSC should confirm sufficiency of evidence and identify/document any evidence gaps."
* "The planning phase ensures readiness to proceed with the assessment, including identifying gaps and establishing how they will be addressed." Why the other options are not correct:
* B: Appeals are addressed post-assessment, not in planning.
* C: Assessment costs are agreed upon contractually, not part of the assessment planning phase.
* D: FedRAMP equivalency determination is part of scope validation, not general planning.
References:
CMMC Assessment Guide - Level 2, Version 2.13: Assessment planning activities (pp. 5-8).


NEW QUESTION # 84
Removable media can pose significant cybersecurity risks to an organization if not adequately controlled and secured. Understanding the dangers of this, an OSC has crafted a meticulous removable media policy. It defines removable media, types of removable media, examples of removable media, etc. The policy limits the use of removable media unless authorized; even then, the media must be scanned for malware. Organizational removable media has specific signatures unique to organizational systems and provided to a defined group of personnel. Any data stored on such media is encrypted, and the OSC has disabled autorun and closed some ports on their computer systems. The contractor also has deployed an endpoint protection solution for every employee searched while entering or leaving the facility. Users must also pass through a walk-in metal detector to ensure they do not sneak in thumb drives and SD cards. Based on the OSC's effort, how would you score their implementation of CMMC practice MP.L2-3.8.7 - Removable Media?

  • A. Met
  • B. Not Applicable
  • C. Not Met
  • D. Partially Met

Answer: A

Explanation:
Comprehensive and Detailed In-Depth Explanation:
MP.L2-3.8.7 requires "controlling removable media use on systems." The OSC's policy, restrictions, scanning, encryption, and technical/physical controls fully meet this, scoring Met (+1) for this 1-point practice. No gaps suggest Partial (C) or Not Met (D), and N/A (A) doesn't apply.
Extract from Official CMMC Documentation:
* CMMC Assessment Guide Level 2 (v2.0), MP.L2-3.8.7: "Control removable media with policy, scanning, and encryption."
* DoD Scoring Methodology: "1-point practice: Met = +1."
Resources:
* https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.
0_FINAL_202112016_508.pdf


NEW QUESTION # 85
During a CMMC Level 2 Assessment, a CCA interviewed a system administrator on the OSC's procedures around configuration management and endpoint security. The system administrator described how they build and deploy new systems, and noted that some users require specialized applications for their jobs. Users have been asked to email IT when they install and run an additional application so IT can add it to their list of allowed software.
What must the CCA conclude?

  • A. IT must deploy an application to report newly installed software.
  • B. The OSC has not properly implemented application allow listing.
  • C. The OSC has properly implemented application deny listing.
  • D. IT does not have a policy that users notify IT when they install new applications.

Answer: B

Explanation:
The CMMC practice CM.L2-3.4.8 - Application Allow Listing requires that only specifically authorized software is permitted to execute, while all other software is automatically denied.
Extract:
"Application allow listing requires that only approved, explicitly identified applications are authorized to execute on a system. Reliance on users to notify IT after the fact does not meet the requirement." Because the OSC's process depends on users self-reporting rather than enforcing automated allow listing, it is not properly implemented.
Reference: CMMC Assessment Guide - Level 2, CM.L2-3.4.8 (Configuration Management).


NEW QUESTION # 86
While completing the Level 2 Assessment, the Lead Assessor found that the OSC was deficient on a number of CMMC practices. Forty practices were scored as NOT MET, all on the Authorized Deficiency Corrections list. The OSC remediated 17 of those during closeout, leaving 23 practices still NOT MET. What should the Lead Assessor recommend?

  • A. Fail the OSC and require them to remediate and reapply for Level 2 certification
  • B. Recommend an interim certification and put the 23 remaining practices on a POA&M
  • C. Recommend an interim certification and revisit the failed practices upon certification renewal
  • D. Pass the OSC but put the 23 remaining on a POA&M

Answer: A

Explanation:
Under CMMC 2.0 Level 2, POA&Ms are permitted only for a limited subset of practices and only if the organization achieves at least 80% compliance, with no high-weight practices failed. With 23 practices NOT MET, the OSC falls below this threshold. Therefore, the Lead Assessor must recommend a Fail, requiring remediation and reassessment.
Exact extracts:
* "For Level 2, OSCs must achieve a score of at least 80% and cannot fail any high-weighted practices."
* "POA&Ms may be allowed for a small number of selected practices but must be closed within 180 days."
* "If the OSC does not meet minimum requirements, the assessment result is Fail and the OSC must remediate before reapplying." Why the other options are incorrect:
* A: POA&Ms cannot cover such a large number of deficiencies.
* C/D: Interim certification does not exist in CMMC 2.0.
References:
CMMC Assessment Guide - Level 2, POA&M policy.
DoD CMMC 2.0 Program guidance on minimum passing scores and fail conditions.


NEW QUESTION # 87
During a CMMC assessment, as the Lead Assessor, you realize that the OSC relies on a Managed Service Provider (MSP) to oversee some of their IT infrastructure, including a cloud-based storage solution.
Employees access the cloud storage remotely through a web browser. The OSC has a Service Level Agreement (SLA) with the MSP outlining security protocols. However, you have limited access to the internal configuration and security controls of the MSP's cloud environment. What challenges might you encounter when assessing the OSC's compliance with CMMC's external connection controls?

  • A. The use of a web browser for remote access eliminates the need to evaluate external connection security
  • B. CMMC focuses only on the security of the OSC's on-premises network, not that of external cloud services
  • C. Limited visibility of the MSP's cloud environment could hinder assessment of how the OSC manages secure external connections to their cloud storage (AC.L1-3.1.20). The SLA might not provide sufficient detail about the specific controls implemented
  • D. Verifying the effectiveness of the OSC's employee training programs may be difficult

Answer: C

Explanation:
Comprehensive and Detailed in Depth Explanation:
AC.L1-3.1.20 requires secure external connections, per NIST SP 800-171. Limited visibility into the MSP's cloud controls (Option B) hinders verifying compliance, as the SLA may lack specific control details, per CAP. Option A is false-web access requires evaluation. Option C misstates CMMC's scope, which includes cloud services. Option D (training) is unrelated. Option B is thecorrect answer.
Reference Extract:
* CMMC Assessment Process (CAP) v1.0, Section 4.3:"Limited MSP visibility challenges external connection assessments."Resources:https://cyberab.org/Portals/0/Documents/Process-Documents
/CMMC-Assessment-Process-CAP-v1.0.pdf


NEW QUESTION # 88
When validating an OSC's proposed CMMC assessment scope, the Assessment Team finds that the OSC has properly categorized its assets. The OSC has contracted an External Service Provider (ESP) for various cybersecurity functions. The ESP has deployed FortiSIEM and Splunk for real-time security monitoring, threat intelligence, application monitoring, log management, and reporting. They also deployed Microsoft Intune and configured app protection policies blocking proscribed apps and those suspected of data exfiltration. How should you handle the ESP during the CMMC assessment?

  • A. Review the SSP per practice CA.L2-3.12.4 - System Security Plan.
  • B. Assess them against CA.L2-3.12.4 - System Security Plan only.
  • C. Assess against CMMC practices.
  • D. They are out of scope; there is no need to assess them against CMMC practices.

Answer: C

Explanation:
Comprehensive and Detailed Explanation:
External Service Providers (ESPs) that provide security functions, such as the ESP deploying FortiSIEM, Splunk, and Microsoft Intune, are classified as Security Protection Assets (SPAs) under the CMMC framework. The CMMC Assessment Scope - Level 2 mandates that SPAs be assessed against the relevant CMMC practices (up to 110 for Level 2) to ensure they adequately protect the CUI environment. These tools monitor and secure the OSC's network, directly impacting CUI security, and thus must be fully evaluated, not just reviewed in the SSP.
Option B limits the assessment to one practice, which is insufficient. Option C is incomplete, as reviewing the SSP is only part of the process. Option D is incorrect, as SPAs are explicitly in scope. Option A aligns with the scoping guidance.
Reference:
CMMC Assessment Scope - Level 2, Section 2.3.3 (Security Protection Assets), p. 6: "ESPs providing security functions are SPAs and must be assessed against applicable CMMC practices."


NEW QUESTION # 89
The Lead Assessor is reviewing the Assessment Plan to identify people for interviews regarding a specific Level 2 practice. Some OSC personnel previously interviewed provided only brief answers without meaningful verification. What can the Lead Assessor do to improve this situation going forward?

  • A. Ensure and verify the responses map to the documented artifacts
  • B. Ensure the people from the training matrix are made available
  • C. Ensure and verify confidentiality and non-attribution of responses
  • D. Ensure the respondents sign a non-disclosure agreement for the OSC

Answer: C

Explanation:
The CMMC Assessment Process emphasizes the importance of confidentiality and non-attribution in interviews to ensure OSC personnel provide candid, accurate information. Interviewees may give shallow or evasive answers if they fear attribution. Assuring confidentiality and non-attribution improves the quality and reliability of responses.
Exact extracts:
* "The assessment team must ensure confidentiality and non-attribution during interviews."
* "Responses should be validated against evidence, but the quality of input depends on establishing a safe environment for candor."
* "Non-attribution is critical to elicit detailed and honest responses." Why the other options are incorrect:
* A: Training matrices identify who is trained, not who should be interviewed.
* C: NDAs are not a CCA responsibility - they are contractual, not assessment requirements.
* D: Mapping to artifacts is part of correlation after interviews, but does not solve the problem of poor interview responses.
References:
CMMC Assessment Process (CAP), interview methodology.
CCA Exam Study Guide, section on interviews.


NEW QUESTION # 90
During a CMMC Level 2 assessment, a CCA is evaluating whether the organization meets the requirement to
"Employ FIPS-validated cryptography when used to protect the confidentiality of CUI." According to the CMMC requirement, the CCA must determine whether FIPS-validated cryptography is employed to protect the confidentiality of CUI. Which assessment procedure would the CCA most likely use to evaluate this requirement?

  • A. Observe the organization's use of cryptographic controls in practice
  • B. Interview personnel responsible for implementing cryptographic controls and review documentation of the organization's cryptographic policies and procedures
  • C. Examine the cryptographic modules
  • D. Examine validation certificates of the cryptographic modules used by the OSC

Answer: D

Explanation:
Comprehensive and Detailed in Depth Explanation:
SC.L2-3.13.11 requires FIPS-validated cryptography for CUI confidentiality, per NIST SP 800-171.
Examining validation certificates (Option D) directly confirms FIPS compliance, as mandated by NIST SP
800-171A's examine method, providing the most conclusive evidence. Option A(examining modules) is vague without certificates. Option B (interviews/documentation) supports but isn't definitive. Option C (observing use) doesn't verify FIPS validation. Option D is the correct answer.
Reference Extract:
* NIST SP 800-171A, SC-3.13.11:"Examine FIPS validation certificates to confirm cryptography meets standards."Resources:https://csrc.nist.gov/pubs/sp/800/171/a/final


NEW QUESTION # 91
A CMMC assessment involves testing, examining, and interviewing various assessment objects. The definition of an assessment object is provided in NIST SP 800-171A. Which of the following can an Assessment Object NOT be?

  • A. Specifications
  • B. Examine
  • C. Activities
  • D. Individuals

Answer: B

Explanation:
Comprehensive and Detailed in Depth Explanation:
NIST SP 800-171A defines Assessment Objects as items assessed (specifications, mechanisms, activities, individuals). "Examine" (Option D) is an assessment method, not an object, per NIST and CMMC guidelines.
Options A, B, and C are valid objects, making Option D the correct answer.
Reference Extract:
* NIST SP 800-171A, Introduction:"Assessment objects include specifications, mechanisms, activities, and individuals; methods are examine, interview, test."Resources:https://csrc.nist.gov/pubs/sp/800/171
/a/final


NEW QUESTION # 92
An OSC has provided its System Security Plan (SSP) as evidence for several CMMC practices related to system security. During your examination of the SSP, you discover a section outlining procedures for user access controls. However, upon further review, you find no mention of procedures for managing privileged accounts, which is a critical aspect of secure system access. According to the guidelines for examining evidence, what is the most appropriate course of action for the Lead Assessor in this scenario?

  • A. Accept the SSP as sufficient evidence and move on to the next practice.
  • B. Explain the discrepancy to the OSC but allow them to keep the existing SSP as evidence.
  • C. Recommend that the CMMC practice related to user access controls be marked "Not Met" due to the missing procedures.
  • D. Request additional evidence from the OSC that specifically addresses privileged account management.

Answer: D

Explanation:
Comprehensive and Detailed in Depth Explanation:
The CAP requires the Lead Assessor to ensure evidence fully demonstrates compliance with CMMC practices. The SSP's omission of privileged account management procedures indicates an evidence gap for practices like AC.L2-3.1.3 (Control Access). Option A (accepting) ignores this gap, risking an inaccurate assessment. Option B (explaining but accepting) is not actionable per CAP, as assessors cannot coach. Option C (marking "Not Met") is premature without seeking additional evidence. Option D aligns with CAP's guidance to request further evidence to address deficiencies.
Extract from Official Document (CAP v1.0):
* Section 2.2 - Conduct Assessment (pg. 25):"If evidence does not fully demonstrate compliance with a practice, the Lead Assessor shall request additional evidence from the OSC to address the gap." References:
CMMC Assessment Process (CAP) v1.0, Section 2.2.


NEW QUESTION # 93
An OSC creates standard user accounts with limited capabilities and administrator accounts with full system access. A standard user initiates the uninstall of the anti-virus software, which is organizationally defined as a privileged function. Which of the following would indicate AC.L2-3.1.7: Privileged Functions is properly implemented?

  • A. The antivirus software is successfully uninstalled.
  • B. The antivirus software is not uninstalled.
  • C. The antivirus software is successfully uninstalled, and the event is captured in an application audit log.
  • D. The antivirus software is not uninstalled, and the attempt is captured in an application audit log.

Answer: D

Explanation:
* Applicable Requirement: AC.L2-3.1.7 - "Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs."
* Correct Interpretation:
* A non-privileged (standard) user should be prevented from performing privileged functions (e.
g., uninstalling security software).
* The attempt must be logged to provide traceability and support accountability.
* Why C is Correct: It demonstrates both prevention (software not uninstalled) and auditing (attempt captured in a log), exactly matching the practice.
Why Other Options Are Insufficient:
* A: Prevention is shown, but there is no evidence of logging.
* B: Function was not prevented, so requirement not met.
* D: Logging exists, but privileged action was not prevented.
References (CCA Official Sources):
* NIST SP 800-171 Rev. 2 - AC.L2-3.1.7
* NIST SP 800-171A - AC.L2-3.1.7 Assessment Objectives
* CMMC Assessment Guide - Level 2, AC.L2-3.1.7


NEW QUESTION # 94
To transfer CUI between a government client and its internal systems, a defense contractor uses a Secure File- Sharing Application provided by the DoD. However, all data traversing this boundary must pass through a next-generation firewall (NGFW) managed by the contractor's Network Admin. All CUI is stored on a Solid State Drive (SSD) and accessed through a laptop. What type of asset is the Network Admin?

  • A. Security Protection Asset (SPA)
  • B. Contractor Risk Managed Asset (CRMA)
  • C. CUI Asset
  • D. Specialized Asset

Answer: A

Explanation:
Comprehensive and Detailed Explanation:
In the CMMC framework, asset types are categorized based on their role in handling or protecting CUI. The Network Admin manages the next-generation firewall (NGFW), which is a critical component in securing the data flow of CUI between the DoD's Secure File-Sharing Application and the contractor's internal systems.
Per the CMMC Assessment Scope - Level 2, Security Protection Assets (SPAs) are defined as assets that provide security functions or capabilities to the contractor's CMMC Assessment Scope, irrespective of whether they directly process, store, or transmit CUI. The Network Admin, by managing the NGFW, fulfills a security protection role, making them an SPA.
Option A (CRMA) applies to assets that can but are not intended to process, store, or transmit CUI due to risk management policies, which does not fit the Network Admin's active security role. Option C (Specialized Asset) includes items like OT or government-furnished equipment, not personnel. Option D (CUI Asset) applies to assets that directly handle CUI, like the SSD or laptop, not the admin managing security. Thus, B is correct.
Reference:
CMMC Assessment Scope - Level 2, Section 2.3.3 (Security Protection Assets), p. 6: "SPAs include people, technology, or facilities that provide security functions or capabilities."


NEW QUESTION # 95
During your review of an OSC's system security control, you focus on CMMC practice SC.L2-3.13.9 - Connections Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system utilizes default settings for connection timeouts.
Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work. Based on the scenario, what is the MOST concerning aspect from a CMMC compliance perspective regarding CMMC practice SC.L2-3.13.9 - Connections Termination?

  • A. The server operating system utilizes default settings for connection timeouts, which may be insufficient
  • B. The application is hosted on a dedicated server within the company's internal network
  • C. Users log in with usernames and passwords, potentially lacking multi-factor authentication
  • D. The lack of a documented policy or a defined period of inactivity for terminating remote access connections creates uncertainty and inconsistency

Answer: D

Explanation:
Comprehensive and Detailed In-Depth Explanation:
SC.L2-3.13.9 requires "terminating connections after a defined period of inactivity." The absence of a documented policy and defined inactivity period (C) is most concerning, as it fails the practice's core requirement, leaving termination inconsistent and user-dependent. Hosting location (A) is neutral, MFA (B) relates to AC.L2-3.1.3, and default timeouts (D) are a symptom of the policy gap. The CMMC guide prioritizes defined inactivity controls.
Extract from Official CMMC Documentation:
* CMMC Assessment Guide Level 2 (v2.0), SC.L2-3.13.9: "Define and document inactivity period for termination; lack thereof is non-compliant."
* NIST SP 800-171A, 3.13.9: "Examine policy for defined inactivity period." Resources:
* https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.
0_FINAL_202112016_508.pdf


NEW QUESTION # 96
......

Exam Engine for CMMC-CCA Exam Free Demo & 365 Day Updates: https://www.premiumvcedump.com/Cyber-AB/valid-CMMC-CCA-premium-vce-exam-dumps.html

CMMC-CCA PDF Questions and Testing Engine With 152 Questions: https://drive.google.com/open?id=1wLBQU_mMpDhhKknbZqnFW1YDfWl0Xdjn