Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the Cyber AB CMMC CMMC-CCA Questions and answers with ValidTests

Exam CMMC-CCA All Questions
Exam CMMC-CCA Premium Access

View all detail and faqs for the CMMC-CCA exam

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

You are the Lead Assessor for a CMMC Level 2 Assessment of an OSC. During Phase 1 planning, the OSC’s Assessment Official informs you that several key personnel who manage the in-scope IT systems will be unavailable during the scheduled assessment dates due to a company-wide training event. The Assessment Official asks if the assessment can proceed with substitute personnel who are less familiar with the systems. What should you do?

Options:

A.

Proceed with the assessment using the substitute personnel, as long as they can provide some information about the systems.

B.

Agree to proceed but request that the OSC provide written documentation to compensate for the unavailable personnel.

C.

Reschedule the assessment to a time when the key personnel are available, as their participation is critical for an accurate assessment.

D.

Conduct the assessment virtually to accommodate the unavailable personnel.

Expert Solution
Questions # 32:

You are part of an Assessment Team tasked with conducting a CMMC Assessment for an OSC. When assessing the contractor’s implementation of SC.L2-3.13.6 – Network Communication by Exception, objectives [a] and [b], the OSC’s system admin informs you that they use Fortinet Next-Generation Firewall (NGFW). Fortinet NGFWs are hardcoded to deny all traffic by default, and traffic is only allowed on an exception basis. While this is factual, the Lead Assessor asks you to test the NGFW to ascertain whether it meets the intent of Assessment Objectives in SC.L2-3.13.6 – Network Communication by Exception. What is the benefit of testing as an assessment method?

Options:

A.

Testing helps determine if CMMC practices are implemented and whether adequate resources were provided to the individuals performing the practices.

B.

Testing allows you to observe what has been done and what has not been done.

C.

Testing allows you to determine if the OSC has the intent to meet the Assessment Objectives.

D.

Testing provides insight into the OSC’s handling of CMMC practices.

Expert Solution
Questions # 33:

You are the Lead Assessor for a CMMC assessment of an OSC that has previously obtained ISO 27001 certification for its information security management system. During the initial discussions, the OSC requests that you consider their ISO 27001 certification and grant them credit toward their CMMC certification. They believe there is a significant overlap between CMMC and ISO 27001. What should your response to the OSC be?

Options:

A.

Defer the decision on non-duplication credit until the DoD publishes official non-duplication policies.

B.

Verify the validity and authenticity of the OSC’s ISO 27001 certification against the requirements outlined in the CMMC Assessment Process (CAP) before considering granting any non-duplication credit.

C.

Inform the OSC that alternative cybersecurity certifications like ISO 27001 do not automatically bestow any status or credit towards CMMC certification.

D.

Grant the OSC credit towards their CMMC certification based on their ISO 27001 certification, as both standards cover similar cybersecurity requirements.

Expert Solution
Questions # 34:

During the Planning phase, the C3PAO and Lead Assessor will collect information from the OSC to provide a Rough Order of Magnitude (ROM). This enables the Assessor to approximate the duration, schedule, and cost of the Assessment. To determine the Rough Order of Magnitude (ROM), the Lead Assessor can use the following inputs, EXCEPT?

Options:

A.

The OSC’s location and number of facilities.

B.

Education levels of the Assessment Team.

C.

The size and complexity of the OSC.

D.

The OSC’s readiness.

Expert Solution
Questions # 35:

An OSC has provided its System Security Plan (SSP) as evidence for several CMMC practices related to system security. During your examination of the SSP, you discover a section outlining procedures for user access controls. However, upon further review, you find no mention of procedures for managing privileged accounts, which is a critical aspect of secure system access. If the OSC provides a separate document outlining privileged account management procedures, and upon review, these procedures appear sufficient, how should the Lead Assessor proceed with the SSP as evidence?

Options:

A.

Request that the OSC formally incorporate the privileged account management procedures into the SSP for consistency.

B.

Accept both the SSP and the separate document as evidence and proceed with the assessment.

C.

Deduct points from the overall assessment score due to the initial oversight in the SSP.

D.

Mark the related user access control practice as "Not Met" due to the initial deficiency in the SSP.

Expert Solution
Questions # 36:

During a readiness assessment for CoolPlanes Inc., Liz, a CCA, discovers a folder of technical drawings and illustrations of the aircraft that CoolPlanes produces. Liz has a younger brother, J.D., who loves airplanes. She thinks a large printed copy of one of the illustrations would make an excellent gift for J.D.’s birthday next month. She copies the drawing and sends it to be printed on a large canvas when she gets home. Which of the following principles of the CMMC Code of Professional Conduct did Liz most likely violate?

Options:

A.

Objectivity

B.

Professionalism

C.

Ethical Practices

D.

Confidentiality

Expert Solution
Questions # 37:

You are a CCA working for a C3PAO that has entered into a contractual agreement to provide CMMC assessment services for an OSC. After validating the evidence, the C3PAO feels that thetask is beyond its capabilities and informs the OSC that it cannot continue with the assessment. The C3PAO cites “insufficient workforce” as the reason. What principle of the CMMC CoPC has the C3PAO broken?

Options:

A.

Adherence to Materials and Methods

B.

Information Integrity

C.

Professionalism

D.

Respect for Intellectual Property

Expert Solution
Questions # 38:

As a CCA, understanding the guiding principles of the CoPC can help you when you face situations in which you are asked to compromise your values and integrity. Which of the following is NOT a guiding principle of the CoPC?

Options:

A.

Confidentiality

B.

Professionalism

C.

Availability

D.

Proper Use of Methods

Expert Solution
Questions # 39:

You are a Lead Assessor tasked with conducting a CMMC Assessment for an OSC seeking to secure its CMMC Level 2 certification. The OSC has previously conducted a self-assessment and engaged a Registered Practitioner Organization (RPO) for a preliminary evaluation. As part of the CMMC Assessment process, you begin by determining the necessary evidence for each practice or process across the OSC’s organizational functional areas. You consider both the adequacy and sufficiency of the evidence in relation to the CMMC’s requirements. After initial preparations, you and the OSC’s POC schedule a joint review session to align on the scope and expectations for the upcoming assessment. What is the primary focus of the ‘Sufficiency’ criterion during the evidence verification process in a CMMC assessment?

Options:

A.

Confirming the evidence has been reviewed and approved by all stakeholders.

B.

Sufficiency verifies that there is enough evidence to comprehensively assess each practice against the CMMC Assessment scope.

C.

Checking if the evidence includes the latest cybersecurity trends and technologies.

D.

Ensuring the evidence covers a wide range of cybersecurity threats.

Expert Solution
Questions # 40:

You are the Lead Assessor for a CMMC Level 2 assessment. During the assessment, the OSC admits that a practice was implemented only a week before the assessment began due to a last-minute effort to prepare. The practice appears to meet the objectives based on the evidence provided. How should you evaluate this evidence?

Options:

A.

Accept the evidence and score the practice as "MET" since it meets the objectives at the time of assessment.

B.

Document the recent implementation as an evidence gap and assess based on its effectiveness and sustainability.

C.

Score the practice as "NOT MET" because it was not implemented prior to the assessment preparation.

D.

Request the OSC to provide evidence of longer-term implementation before proceeding.

Expert Solution
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions