CMMC-CCA Web TestEngine demo

Exit VCEDump CMMC-CCA Certified CMMC Assessor (CCA)
Question 70 of 80
0% complete
Q70 Single choice

In assessing an OSC's CUI handling practices, you learn they use an approved algorithm (AES-256) to encrypt the data to ensure its confidentiality. However, the encryption module they are using has not been validated under the FIPS 140 standard. The OSC believes that using an approved algorithm is sufficient to comply with the CMMC practice for CUI encryption requirements.

Which of the following would be the most appropriate next step for the assessor?

Sign in to mark questions

Sign in to save marked questions and return to this demo.

Sign in