Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cyber AB CMMC CMMC-CCA Questions and answers with ValidTests

Exam CMMC-CCA All Questions
Exam CMMC-CCA Premium Access

View all detail and faqs for the CMMC-CCA exam

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

As the Lead Assessor for an OSC, John admires their advanced security solutions during the assessment. However, his admiration distracts him from the assessment’s focus. Instead, he engages in conversation about the OSC’s robust security, becoming swayed by their capabilities. Consequently, John becomes hesitant to identify deficiencies or noncompliances, displaying a positive bias toward the OSC. What is the impact of this positive bias on the CMMC assessment of the OSC?

Options:

A.

It is not a concern in CMMC assessments

B.

It may lead to a more thorough and rigorous evaluation of the OSC

C.

It has no effect on the assessment process and outcomes

D.

It can result in a more lenient and inaccurate assessment of the OSC

Expert Solution
Questions # 22:

An OSC uses a web application for document management. Employees can access this application from any internet-connected device through a web browser. The application resides on servers in a secure data center managed by a third-party vendor. The OSC maintains separate servers within its network to store the documents. When employees use the web application to upload documents, what type of locations are they interacting with?

Options:

A.

A logical location for the web application and a physical location for the document storage servers

B.

A secure area within the OSC’s data center

C.

The physical location of their internet-connected devices

D.

The physical location of the vendor’s data center

Expert Solution
Questions # 23:

The use of removable storage media remains a source of data breaches. The CMMC requires control of the use of removable media on system components. As a CCA, you can use different assessment methods to determine whether an OSC has met this requirement. What is the best assessment method to ascertain that MP.L2-3.8.7[a] has been met?

Options:

A.

Examining System Media Protection Policy

B.

Interviewing personnel with responsibilities for system media use

C.

Testing mechanisms that restrict or prohibit the use of removable media on systems or system components

D.

Examining System Design documentation

Expert Solution
Questions # 24:

The DoD has awarded a defense contractor a contract to deliver next-gen jet engine parts. The order requires the contractor to submit the blueprints/CAD files within six months, and once they are validated, the contractor submits a production schedule. The contractor indicates that they should be able to deliver the components in three years. Which of the following is true about the dates and schedule of the engine components?

Options:

A.

They must be protected under NIST SP 800-171

B.

They must be properly marked and labeled

C.

They are part of the OSC’s CUI

D.

They must be protected in accordance with FAR 52.204-21

Expert Solution
Questions # 25:

AC.L1-3.1.2 requires OSCs to “limit information system access to the types of transactions and functions that authorized users are permitted to execute.” Assessment Objective [a] of AC.L1-3.1.2 requires the Assessor to determine whether “the types of transactions and functions that authorized users are permitted to execute are defined.” What assessment method would you use to determine whether the OSC has met this assessment objective?

Options:

A.

Interview system developers

B.

Test the system configuration settings

C.

Review the System Security Plan

D.

Examine the list of approved authorizations, including remote access authorizations

Expert Solution
Questions # 26:

You are working as a CCA on a Level 2 Assessment for a DoD prime contractor. The Organization Seeking Certification (OSC) seeks to keep assessment costs down, and the C3PAO and OSC have decided to conduct all possible work remotely. You are assigned to work primarily on the Media Protection (MP), Personnel Security (PS), and Physical Protection (PE) domains. In addition, the Lead Assessor has designated you as the one person from the Assessment Team to conduct all the on-premises work. Which of the following factors do you and the Assessment Team not need to consider as part of your on-site work?

Options:

A.

For the virtual aspects of the assessment, availability of a DoD-approved collaboration tool for virtual communication with the OSC

B.

Limitations of conducting on-premises assessments for the Media Protection (MP), Personnel Security (PS), and Physical Protection (PE) domains

C.

For the virtual aspects of the assessment, the mandatory Virtual Assessment Evidence Preparation Template must be used to ensure proper assessment methods

D.

Non-critical areas of the OSC facilities

Expert Solution
Questions # 27:

Prior to starting an assessment, an OSC must develop a data flow diagram. This diagram can then be used as a tool to help establish the context and boundaries of the CMMC assessment activities. What is critical to capture while developing the data flow diagram?

Options:

A.

The organization’s network topology and hardware configurations

B.

A list of all employees and their job functions

C.

The physical layout of the organization’s office spaces

D.

Business processes, subprocesses, and assets and systems used to support the process

Expert Solution
Questions # 28:

You are a CCA who is part of an Assessment Team conducting a CMMC assessment on an aerospace company. While analyzing their network architecture, you realize that it includes a Demilitarized Zone (DMZ) to host their public-facing web servers. What is the primary purpose of a DMZ in a network architecture?

Options:

A.

To physically isolate the organization’s internal network from the internet

B.

To provide physical security for the organization’s public-facing web servers

C.

To allow unrestricted access between the internal network and the internet

D.

To logically isolate the organization’s public-facing web servers from the internal network

Expert Solution
Questions # 29:

You are the CCA working with a client to deliver certified consulting services, and the OSC has asked how to ensure their scope is accurate. You mention the use of a data flow diagram, which intrigues the OSC. What would be the first step in constructing the data flow diagram for the OSC?

Options:

A.

Implement a Data Loss Prevention (DLP) tool to monitor data flows within the OSC

B.

Conduct interviews with key stakeholders to understand the organization’s business processes

C.

Identify how data flows through the OSC’s business, including systems, subprocesses, and data stores, identifying major inputs and outputs to the environment

D.

Gather information about the OSC’s network infrastructure and create a network diagram

Expert Solution
Questions # 30:

During a CMMC Level 2 assessment, an OSC receives a Conditional Certification with several practices placed on a Plan of Action and Milestones (POA&M). After implementing corrective actions, the OSC requests the Assessment Team to conduct a POA&M Close-Out Assessment. Which of the following is the correct action for the Team’s Lead Assessor during the POA&M Close-Out Assessment?

Options:

A.

Recommend the organization for CMMC Level 2 Final Certification if all POA&M items arefully implemented and do not limit the effectiveness of other practices scored as 'MET' during the initial assessment.

B.

Recommend the organization for CMMC Level 2 Final Certification if all POA&M items have been fully implemented and meet the required criteria.

C.

Recommend the organization for CMMC Level 2 Final Certification regardless of the POA&M items’ impact on other practices.

D.

Recommend the organization reapply for CMMC Level 2 Certification, even if all POA&M items are fully implemented.

Expert Solution
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions