Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Exam CMMC-CCA All Questions
Exam CMMC-CCA All Questions

View all questions & answers for the CMMC-CCA exam

Cyber AB CMMC CMMC-CCA Question # 5 Topic 1 Discussion

CMMC-CCA Exam Topic 1 Question 5 Discussion:
Question #: 5
Topic #: 1

During a CMMC assessment, as the Lead Assessor, you realize that the OSC relies on a Managed Service Provider (MSP) to oversee some of their IT infrastructure, including a cloud-based storage solution. Employees access the cloud storage remotely through a web browser. The OSC has a Service Level Agreement (SLA) with the MSP outlining security protocols. However, you have limited access to the internal configuration and security controls of the MSP’s cloud environment. What challenges might you encounter when assessing the OSC’s compliance with CMMC’s external connection controls?


A.

The use of a web browser for remote access eliminates the need to evaluate external connection security


B.

Limited visibility of the MSP’s cloud environment could hinder assessment of how the OSC manages secure external connections to their cloud storage (AC.L1-3.1.20). The SLA might not provide sufficient detail about the specific controls implemented


C.

CMMC focuses only on the security of the OSC’s on-premises network, not that of external cloud services


D.

Verifying the effectiveness of the OSC’s employee training programs may be difficult


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.