CMMC-CCA Web TestEngine demo

Exit VCEDump CMMC-CCA Certified CMMC Assessor (CCA)
Question 41 of 80
0% complete
Q41 Single choice

During your review of an OSC's system security controls, you focus on CMMC practice SC.L2-3.13.9 -
Connection Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system uses default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work.

The scenario mentions that the server uses default settings for connection timeouts.

What additional approach, besides relying solely on user awareness, could be implemented to achieve connection termination based on inactivity and comply with CMMC practice SC.L2-3.13.9 - Connection Termination?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in