A C3PAO and OSC have agreed to proceed with CMMC assessment planning. The OSC assessment official and the C3PAO are working to determine the planning details and purview of the Assessment, which includes scoping. When should the C3PAO and OSC conduct the high-level contract framing?
-
A
After the C3PAO has assigned the Lead Assessor and Assessment Team.
-
B
At the beginning of their engagement for the CMMC assessment.
-
C
During Phase 2 of the CMMC assessment process.
-
D
After the OSC has determined the CMMC Assessment Scope.
Reveal answer details
Close answer details
After completing a CMMC assessment, the OSC should hash all the evidence artifacts in accordance with the CMMC Artifact Hashing Tool User Guide. However, you have just realized that this requirement was not fulfilled, and the OSC Assessment Official cannot be reached to confirm it was done. To avoid any issues, you quickly complete this step and later inform the OSC Assessment Official. Which CoPC principle have you just violated by hashing the evidence artifacts in place of the OSC?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
To verify the scope accuracy and integrity, a Lead Assessor asks for documents supporting some elements of the scope. However, the OSC states that the information is proprietary and requires that the Lead Assessor sign a Non-Disclosure Agreement (NDA) before granting access. What should the Lead Assessor do?
-
A
File a complaint with the CMMC Accreditation Body (the Cyber AB).
-
B
File a complaint with the CMMC Accreditation Body (the Cyber AB).
-
C
Sign the NDA and handle the proprietary information with utmost care.
-
D
Inform the OSC that they have a legitimate right to access that information without signing the NDA.
Reveal answer details
Close answer details
To meet AC.L2-3.1.5: Least Privilege, the following procedure is established: 1. All employees are given a basic, non-privileged user account. 2. System Administrators are given a separate System Administrator account. 3. Database Administrators are given a separate Database Administrator account. Which steps should be added to BEST meet all of the standards for least privilege?
-
A
4. Database Administrators use their Database Administrator accounts to perform privileged functions. 5. All users use their basic accounts for non-privileged functions.
-
B
4. Database Administrators use their Database Administrator accounts to perform privileged functions. 5. Non-privileged users use their basic accounts for non-privileged functions.
-
C
4. Database Administrators use the System Administrator accounts to perform privileged functions. 5. All other users use their basic accounts for all authorized functions.
-
D
4. Database Administrators use the System Administrator accounts to perform privileged functions. 5. Non-privileged users use their basic accounts for all authorized functions.
Reveal answer details
Close answer details
Correct answerA
ExplanationLeast privilege requires users to perform privileged functions only with privileged accounts and to use their basic, non-privileged accounts for general activity. This prevents unnecessary exposure of elevated rights and limits attack surfaces. Database Administrators must use their Database Administrator accounts only for DBA tasks, and all users must use their basic accounts for non-privileged tasks. Exact Extracts: AC.L2-3.1.5: "Employ the principle of least privilege, including for specific security functions and privileged accounts." Assessment Objectives: Require separate accounts for privileged and non-privileged activities. Assessment Guide Clarification: "Privileged accounts should be used only for privileged functions; standard accounts must be used for all other activities." Why the other options are not correct: Option B: States that "non-privileged users use their basic account," but does not explicitly require all users, including administrators, to use their basic accounts for non-privileged tasks. Option C/D: Incorrectly assign System Administrator accounts to Database Administrators, which violates least privilege. Administrators must only have the access needed for their role. References: CMMC Assessment Guide ?Level 2, Version 2.13: AC.L2-3.1.5, pp. 17?9. NIST SP 800-171A: Assessment procedures for least privilege and account management.
As a Lead Assessor working with an OSC in preparation for an upcoming assessment, you request they appoint an Assessment Official. This is the individual you will collaborate with and who has the OSC's decision-making authority regarding the CMMC assessment. The OSC Assessment Official will lead and manage the OSC's engagement in the assessment. As the Lead Assessor, you expect the OSC Assessment Official to have the following responsibilities, EXCEPT?
-
A
Identify assessment funding and authorize payment.
-
B
Sign off on the assessment scope and boundaries.
-
C
Approve the assessment plan and review assessment results with the Lead Assessor.
-
D
Handle facility access and daily visitor escort.
Reveal answer details
Close answer details
During a CMMC assessment, the OSC's IT manager asks the CCA if they can "fix" a non-compliant practice during the assessment to improve their score. The CCA declines and continues the assessment. What CoPC principle does the CCA uphold by refusing to assist?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
The Certification Assessment Readiness Review (CA-RR) aims to determine whether the OSC and the Assessment Team are ready to conduct the assessment as planned and within the allocated time. It addresses all of the following aspects of readiness to conduct the assessment except which one?
-
A
OSC cybersecurity posture.
-
B
-
C
-
D
Reveal answer details
Close answer details
You are the Lead Assessor of the Assessment Team conducting a CMMC Level 2 assessment for an OSC. You have completed the first phase of the assessment process, which included the assessment kickoff meeting. Now, you are moving into the second phase, which involves collecting and examining evidence to determine the OSC's compliance with the CMMC practices. During the assessment, you find that the OSC has failed to meet the requirements for CMMC practice AU.L2-3.3.4 - Audit Failure Alerting. According to the CMMC Assessment Process (CAP), which of the following should be your next step?
-
A
Immediately stop the assessment and report the failure to the C3PAO.
-
B
Mark the practice as "NOT MET" in the final assessment report without further action.
-
C
Provide the OSC with a specific timeframe to remediate the failed practice.
-
D
Evaluate the failed practice against the DoD Assessment Methodology and CMMC 2.0 POA&M scoring criteria.
Reveal answer details
Close answer details
You are a CCA who is part of an Assessment Team conducting a CMMC assessment on an aerospace company. While analyzing their network architecture, you realize that it includes a Demilitarized Zone (DMZ) to host their public-facing web servers. What is the primary purpose of a DMZ in a network architecture?
-
A
To physically isolate the organization's internal network from the internet
-
B
To provide physical security for the organization's public-facing web servers
-
C
To allow unrestricted access between the internal network and the internet
-
D
To logically isolate the organization's public-facing web servers from the internal network
Reveal answer details
Close answer details
Question 10
Single choice
The SSP for an OSC undergoing an assessment categorizes a device in the inventory that wirelessly connects to the network. In order to secure the connection of wireless devices that access a system that transmits, stores, or processes CUI, what are the requirements?
-
A
Wireless access must be configured to use FIPS 140 validated cryptography.
-
B
Wireless users must be vetted, and an Access Control List maintained for access to CUI.
-
C
Wireless access must be configured to use FIPS 140 validated cryptography and limited to authenticated users.
-
D
Wireless users must be specifically identified in network diagrams and configured to use FIPS 140 validated cryptography.
Reveal answer details
Close answer details
Correct answerC
ExplanationWireless access to systems transmitting, processing, or storing CUI must be protected with FIPS 140- validated cryptography and access must be limited to authenticated users. This ensures confidentiality and integrity of CUI while preventing unauthorized wireless access. Exact Extracts (official CMMC Assessor/Study documents): SC.L2-3.13.13: "Employ FIPS-validated cryptography when used to protect the confidentiality of CUI." AC.L2-3.1.1 / 3.1.2: "Limit system access to authorized users... and authenticate the identities of those users." SC.L2-3.13.17: "Protect wireless access to the system using authentication and encryption." Assessment Guide clarifies: "Wireless access must use FIPS 140 validated cryptographic modules and must be restricted to authenticated users." Why other options are not correct: Option A: Only requires encryption; does not address authenticated access, which is mandatory. Option B: Vetting and access lists may be useful, but they are not sufficient substitutes for cryptographic and authentication requirements. Option D: Identifying users in diagrams is good documentation practice but not a CMMC requirement for wireless protection. References (official CCA/CMMC documents): CMMC Assessment Guide - Level 2, Version 2.13: Practices SC.L2-3.13.13 and SC.L2-3.13.17 (pp.134- 136). NIST SP 800-171A, Assessment Objectives for wireless access and cryptographic requirements.
Question 11
Single choice
While completing the Level 2 Assessment, the Lead Assessor found that the OSC was deficient on a number of CMMC practices. Forty practices were scored as NOT MET, all on the Authorized Deficiency Corrections list. The OSC remediated 17 of those during closeout, leaving 23 practices still NOT MET. What should the Lead Assessor recommend?
-
A
Pass the OSC but put the 23 remaining on a POA&M
-
B
Fail the OSC and require them to remediate and reapply for Level 2 certification
-
C
Recommend an interim certification and put the 23 remaining practices on a POA&M
-
D
Recommend an interim certification and revisit the failed practices upon certification renewal
Reveal answer details
Close answer details
Correct answerB
ExplanationUnder CMMC 2.0 Level 2, POA&Ms are permitted only for a limited subset of practices and only if the organization achieves at least 80% compliance, with no high-weight practices failed. With 23 practices NOT MET, the OSC falls below this threshold. Therefore, the Lead Assessor must recommend a Fail, requiring remediation and reassessment. Exact extracts: "For Level 2, OSCs must achieve a score of at least 80% and cannot fail any high-weighted practices." "POA&Ms may be allowed for a small number of selected practices but must be closed within 180 days." "If the OSC does not meet minimum requirements, the assessment result is Fail and the OSC must remediate before reapplying." Why the other options are incorrect: Option A: POA&Ms cannot cover such a large number of deficiencies. C/Option D: Interim certification does not exist in CMMC 2.0. References: CMMC Assessment Guide - Level 2, POA&M policy. DoD CMMC 2.0 Program guidance on minimum passing scores and fail conditions.
Question 12
Single choice
You are the Lead Assessor of the Assessment Team conducting a CMMC Level 2 assessment for an OSC. You have completed the first phase of the assessment process, which included the assessment kickoff meeting. Now, you are moving into the second phase, which involves collecting and examining evidence to determine the OSC's compliance with the CMMC practices. During the evidence collection phase, you need to examine the OSC's policies and procedures related to the CMMC practice AC.L2-3.1.5 - Least Privilege. Which of the following would be an appropriatesource of evidence for this practice?
-
A
Testing the OSC's Role-Based Access Control (RBAC) and Privilege Access Management (PAM) tools.
-
B
Observing the system administrators as they configure the systems.
-
C
Examining the organization's system configuration documentation.
-
D
Interviewing the system administrators about their daily activities.
Reveal answer details
Close answer details
Question 13
Single choice
John, a Certified CMMC Assessor, has been conducting CMMC assessments for several years. During a recent assessment at a defense contractor, he encountered several issues similar to challenges he had faced in previous assessments. Influenced by his past experiences, John's interpretation of the contractor's practices was shaped by his preconceptions. Which of the following is TRUE about John's interpretation?
-
A
John's bias has no impact on the integrity of the assessment
-
B
John's bias can affect the integrity of the CMMC assessment
-
C
John's experience ensures that all assessments will be unbiased and accurate
-
D
John's preconceptions help streamline the assessment process and ensure consistency
Reveal answer details
Close answer details
Question 14
Single choice
During the assessment process, a CCA encounters a situation in which the evidence provided by the OSC raises concerns about its adequacy and alignment with the CMMC practice being assessed. What priority factors must the CCA have considered to arrive at these concerns?
-
A
The format and presentation of the evidence
-
B
The completeness of the evidence across all systems and processes
-
C
The level of detail and granularity provided in the evidence
-
D
Whether the evidence is the right evidence and meets the intent of the CMMC practice
Reveal answer details
Close answer details
Question 15
Single choice
A CCA is prohibited from doing which of the following?
-
A
Verifying key internal system boundaries
-
B
Determining if physically separated assets contain CUI
-
C
Ensuring the external system boundary is fully defined
-
D
Examining whether communications are monitored at the external system boundary
Reveal answer details
Close answer details
Correct answerB
ExplanationThe OSC is responsible for identifying and declaring where CUI is processed, stored, or transmitted. A Certified CMMC Assessor (CCA) may verify boundaries, examine evidence, and confirm monitoring or control practices, but cannot independently determine if a physically separated asset contains CUI. That determination is the responsibility of the OSC, not the assessor. Exact extracts: "The OSC is responsible for identifying CUI assets." "Assessors verify and validate the OSC's identification, but do not independently declare or determine the presence of CUI." "Assessors are permitted to examine boundary protections, monitoring mechanisms, and internal boundary controls." Why the other options are allowed: Option A: Assessors are required to verify internal system boundaries. Option C: Assessors must confirm that external system boundaries are clearly defined. Option D: Assessors must examine evidence of communication monitoring. References (CCA documents / Study Guide): CMMC Assessment Guide - Level 2, Assessor Roles and Responsibilities. CMMC Code of Professional Conduct (OSC retains CUI ownership; assessors validate but cannot declare CUI).
Question 16
Single choice
During a CMMC assessment, an OSC employee asks the CCA if their current security measures are "good enough" to pass the assessment. The CCA responds by saying, "I can't tell you that, but here's what the CMMC requires for this practice." What principle of the CoPC does this response uphold?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 17
Single choice
Ron is the Lead Assessor for an OSC's CMMC assessment. His team has scheduled interviews and demonstrations with the OSC's system administrator, Olivia. However, on the first day, the CEO informs Ron that Olivia is very ill and is unavailable. The CEO offers to be interviewed about Olivia's responsibilities instead, even though he does not actually perform those tasks. What should Ron do in this scenario?
-
A
Have the CEO accompanied by another IT rep during the interview.
-
B
-
C
It depends on the specific details discussed during the interview with the CEO.
-
D
Reschedule the interviews with Olivia or continue with another person who understands and performs Olivia's duties while she is away.
Reveal answer details
Close answer details
Question 18
Single choice
During a CMMC Level 2 assessment, the OSC's Assessment Official asks the Lead Assessor if they can provide a list of recommended vendors to improve their security practices after the assessment. What should the Lead Assessor do?
-
A
Provide the list after the assessment is complete to assist the OSC.
-
B
Politely refuse, explaining that the C3PAO cannot offer consulting or vendor recommendations per the CoPC.
-
C
Offer to provide general guidance on vendor selection without specific recommendations.
-
D
Agree to provide the list but only after approval from the Cyber AB.
Reveal answer details
Close answer details
Question 19
Single choice
You are assessing an OSC that uses various collaborative computing devices, such as video conferencing systems, networked whiteboards, and webcams, for remote meetings and presentations. During your assessment, you examine the OSC's collaborative device inventory and find that they have identified and documented all collaborative computing devices. Most of the identified devices have indicators, such as LED lights, that notify users when the devices are in use. The OSC has also implemented a policy prohibiting the remote activation of collaborative computing devices without user consent. However, you find that the webcams can be activated remotely by authorized IT personnel for troubleshooting purposes. In addition to interviewing personnel, what other evidence would be helpful to assess the OSC's compliance with CMMC practice SC.L2-3.13.12 - Collaborative Device Control regarding the remote activation of webcams?
-
A
A documented risk assessment that identifies the potential risks associated with remote camera activation and outlines mitigation strategies
-
B
Network traffic logs showing no instances of remote activation attempts on the web cameras
-
C
User training records indicating that employees are aware of the policy and understand thepotential consequences of unauthorized remote camera activation
-
D
System configuration settings for the web cameras, verifying that remote activation is enabled
Reveal answer details
Close answer details
Question 20
Single choice
Video monitoring is used by an OSC to help meet PE.L2-3.10.2: Monitor Facility. The OSC's building has three external doors, each with badge access and a network-connected video camera above the door. The video cameras are connected to the same network as employee computers. The OSC contracted a local security company to provide surveillance services. The security company stores the recordings at its premises and requires access to the OSC's network to manage the video cameras. Which factor is a clear negative finding for the OSC's assessment?
-
A
Video surveillance needs to be of both private and public areas of the building
-
B
A non-certified third party accesses the OSC's network to manage the cameras
-
C
Video surveillance alone does not satisfy the facility monitoring requirement of PE.L2-3.10.2
-
D
A non-certified third party's data center may not store video recordings for a company authorized to process CUI
Reveal answer details
Close answer details
Correct answerB
ExplanationThe negative finding is that the OSC permits an uncertified external security provider to access the OSC's internal network. This introduces unmanaged risk to the CUI environment. CMMC requires the OSC to control and monitor external service provider access. The storage of recordings externally is not inherently noncompliant if properly controlled, and video monitoring is a valid method of meeting PE.L2-3.10.2. The key failure is giving unmanaged third-party access. Exact extracts: "Monitor physical facility to detect and respond to physical security incidents." (PE.L2-3.10.2) "Assessment Objectives... Determine if: monitoring is performed; unauthorized physical access is detected and responded to." "External service providers that connect into the OSC network are considered in-scope and must meet CMMC requirements or have equivalent authorization (e.g., FedRAMP)." Why other options are incorrect: Option A: Requirement does not mandate monitoring of both public and private areas. Option C: Video surveillance is an acceptable facility monitoring method when properly implemented. Option D: External storage can be acceptable if contractual safeguards and compliance are in place. References: CMMC Assessment Guide - Level 2, PE.L2-3.10.2. CMMC Scoping Guide - External Service Providers.
Question 21
Single choice
A company has a CUI enclave for handling all CUI processed, stored, and transmitted through the organization. While interviewing the IT manager, the CCA asks how assets that can, but are not intended to, handle CUI are identified. The IT manager refers to the CUI system's network diagram (which includes these assets) as well as the asset inventory (which lists these assets as Contractor Risk Managed Assets). Which other artifact MUST also mention these assets?
-
A
The identification and authentication policy should show how these assets are identified.
-
B
The physical protection policy should list these assets as being part of the physical environment of the organization.
-
C
The awareness and training program should include these assets so they are covered for all employees.
-
D
The SSP should show these assets are managed using the company's risk-based security policies, procedures, and practices.
Reveal answer details
Close answer details
Correct answerD
ExplanationContractor Risk Managed Assets (CRMA) are required to be identified in the System Security Plan (SSP) because the SSP must describe how each in-scope asset category is managed, including risk-based policies, procedures, and practices. Network diagrams and inventories alone are insufficient without documentation in the SSP. Exact Extracts: CMMC Scoping Guide: "Contractor Risk Managed Assets are part of the CMMC Assessment Scope and must be identified in the OSC's SSP and supporting documentation." "The SSP must describe how the contractor manages risk for Contractor Risk Managed Assets." "The asset categories (CUI assets, Security Protection Assets, Contractor Risk Managed Assets, Specialized Assets) must be included in the SSP with supporting evidence." Why the other options are not correct: Option A: Identification/authentication policy does not specifically require mention of CRMAs. Option B: Physical protection policies address facility controls, not risk-managed assets. Option C: Awareness training covers employees, not technical classification of assets. Option D: Correct, because the SSP must explicitly document how CRMAs are managed using risk-based approaches. References: CMMC Assessment Scope - Level 2, Version 2.13: Asset categories and documentation requirements for CRMAs (pp. 6-10). CMMC Assessment Guide - Level 2, Version 2.13: SSP documentation requirements (pp. 12-14).
Question 22
Single choice
You are assessing a contractor that develops software for air traffic control systems. In reviewing their documentation, you find that a single engineer is responsible for designing new ATC system features, coding the software updates, testing the changes on the development network, and deploying the updates to the production ATC system for customer delivery. How will proper separation of duties help the contractor meet the intent of AC.L2-3.1.4 - Separation of Duties?
-
A
It allows the engineers to specialize in specific areas
-
B
It reduces concentrated privileges and power and improves checks & balances. Errors and malicious actions are more likely to be caught. Risk is reduced without relying solely on one individual
-
C
It reduces the overall cost of software development
-
D
It simplifies the development process
Reveal answer details
Close answer details
Question 23
Single choice
During a CMMC Level 2 Assessment, a CCA interviewed a system administrator on the OSC's procedures around configuration management and endpoint security. The system administrator described how they build and deploy new systems, and noted that some users require specialized applications for their jobs. Users have been asked to email IT when they install and run an additional application so IT can add it to their list of allowed software. What must the CCA conclude?
-
A
The OSC has properly implemented application deny listing.
-
B
The OSC has not properly implemented application allow listing.
-
C
IT must deploy an application to report newly installed software.
-
D
IT does not have a policy that users notify IT when they install new applications.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe CMMC practice CM.L2-3.4.8 - Application Allow Listing requires that only specifically authorized software is permitted to execute, while all other software is automatically denied. Extract: "Application allow listing requires that only approved, explicitly identified applications are authorized to execute on a system. Reliance on users to notify IT after the fact does not meet the requirement." Because the OSC's process depends on users self-reporting rather than enforcing automated allow listing, it is not properly implemented. References: CMMC Assessment Guide - Level 2, CM.L2-3.4.8 (Configuration Management).
Question 24
Single choice
As a Certified CMMC Assessor, you are part of a team assessing a small defense contractor. During the assessment, an employee being interviewed appears unsure about some security practices and asks for your advice on how to answer certain questions to make their compliance appear better. As a Certified CMMC Assessor, what should you do in this situation?
-
A
Suggest that they seek guidance from another Assessor.
-
B
Offer to create documentation to cover gaps in their compliance.
-
C
Politely refuse to provide any assistance and continue the assessment as planned.
-
D
Provide guidance on how to answer questions to maximize the appearance of compliance.
Reveal answer details
Close answer details
Question 25
Single choice
An OSC is undergoing a CMMC Level 2 assessment, and the C3PAO Assessment Team has identified several practices that the organization has not yet fully implemented. During the assessment, the CCA notes significant progress by the OSC towards implementing control MP.L2-3.8.4 - Media Markings, but acknowledges that not all required steps have been completed. The CCA explains to the OSC that this partially implemented practice will need to be tracked in theLimited Practice Deficiency Correction Program. How should CMMC practices tracked under the Limited Practice Deficiency Correction Program be scored?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 26
Single choice
An OSC is planning to have a C3PAO perform a CMMC Level 2 assessment. When validating the OSC's proposed assessment scope, you realize they use an ESP for various cybersecurity services. What action must you, as a CCA, take regarding the ESP?
-
A
Confirm the ESP has a CMMC Level 2 or Level 3 certification.
-
B
Accept the OSC's inclusion of the ESP in their assessment scope.
-
C
Advise the OSC to choose another ESP.
-
D
Request a self-assessment from the ESP.
Reveal answer details
Close answer details
Question 27
Single choice
An Assessor is evaluating whether an OSC has implemented adequate controls to meet AC.L2-3.1.7: Privileged Functions. The OSC has procedures that define privileged vs. non-privileged account provisioning and an access control policy that restricts execution of certain functions only to privileged. What might the Assessor do to further evaluate the implementation of this practice?
-
A
Examine system logs to verify automatic updates are being applied.
-
B
Test whether the application of a patch is captured in system logging.
-
C
Test whether a non-privileged user can log into a system where CUI is stored.
-
D
Examine a user access list for users that are authorized to access a key management system.
Reveal answer details
Close answer details
Correct answerD
ExplanationAC.L2-3.1.7 (Privileged Functions) requires that execution of privileged functions be restricted to authorized privileged accounts. The best evidence is an access list demonstrating who is allowed privileged access. Extract: "Limit the use of privileged functions to authorized users. Assessors should review access control lists or equivalent evidence to verify only privileged accounts have privileged permissions." Thus, the best next step is to examine a user access list for authorized privileged users. References: CMMC Assessment Guide - Level 2, AC.L2-3.1.7.
Question 28
Single choice
In ensuring it meets its mandates to protect CUI under CMMC, a contractor has implemented a robust, dynamic session lock with pattern-hiding displays to prevent access and viewing of data. After every 5 minutes of inactivity, the current session is locked and a blank, black screen with a battery life indicator is displayed. How is Session Lock typically initiated?
-
A
Automatically, after a predefined period of inactivity
-
B
By the system administrator manually
-
C
Through user authentication processes
-
D
Only when manually triggered by the user before leaving their workstation
Reveal answer details
Close answer details
Question 29
Single choice
A CCA has been selected to lead a team conducting a CMMC assessment for an OSC. However, it is later determined that the OSC's Point of Contact (POC) is the CCA's sister. Could this represent a Conflict of Interest (COI)? If yes, what CoPC guiding principle or practice may the CCA have violated?
-
A
Yes, conflict of interest.
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 30
Single choice
You are the Lead Assessor of the Assessment Team conducting a CMMC Level 2 assessment for an OSC. You have completed the first phase of the assessment process, which included the assessment kickoff meeting. Now, you are moving into the second phase, which involves collecting and examining evidence to determine the OSC's compliance with the CMMC practices. Which of the following is not one of the recommended methods for collecting evidence during a CMMC assessment?
-
A
-
B
Self-Assessment by the OSC
-
C
-
D
Reveal answer details
Close answer details
Question 31
Single choice
An OSC seeking Level 2 certification is reviewing the physical security of their building. Currently, the building manager unlocks and locks the doors for business operations. The OSC would like the ability to automatically unlock the door for authorized personnel, track access individually, and maintain access history for all personnel. The BEST approach is for the OSC to:
-
A
Maintain a list of authorized personnel and assign them a building key.
-
B
Maintain security cameras to continuously monitor access to the building.
-
C
Install a badge system and require each individual to use their badge to gain entry to the building.
-
D
Install a keypad system and require the entry code to be changed when an individual leaves the company.
Reveal answer details
Close answer details
Correct answerC
ExplanationCMMC Level 2 requires the ability to control and monitor physical access to systems and facilities containing CUI. The best practice is a badge-based access control system, which provides individual accountability, access tracking, and historical audit records. Keys and keypads do not provide individual traceability. Cameras alone do not prevent unauthorized entry. Exact Extracts (official CMMC Assessor/Study documents): PE.L2-3.10.1: "Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals." PE.L2-3.10.3: "Escort visitors and monitor visitor activity." PE.L2- 3.10.5: "Access records must be maintained." CMMC Assessment Guide clarifies that acceptable methods include badging systems with individual accountability for traceability. Why the other options are not correct: Option A (keys): Keys do not provide audit logs or individual accountability. Option B (cameras): Monitoring alone is insufficient; prevention and control are required. Option D (keypads): Shared codes do not provide unique traceability or access history per user. References: CMMC Assessment Guide - Level 2, Version 2.13: PE.L2 practices (pp. 153-159). NIST SP 800-171A, Physical and Environmental Protection (PE) assessment objectives.
Question 32
Single choice
In order to perform an interview, the Lead Assessor MUST ensure interview questions are:
-
A
-
B
Asked by any member of the OSC's team
-
C
Asked to those who implement, perform, or support the practices
-
D
Asked with multiple people simultaneously to limit the number of interviews needed
Reveal answer details
Close answer details
Correct answerC
ExplanationApplicable Requirement: CAP - Interview Guidance. Why Option C is Correct: Interviews must be directed to personnel responsible for implementing, performing, or supporting practices to ensure accurate and objective evidence is collected. Why Other Options Are Insufficient: Option A: Yes/no questions do not provide sufficient evidence detail. Option B: OSC personnel cannot ask themselves assessment questions; only assessors may conduct interviews. Option D: Group interviews may be used in some cases, but CAP stresses targeted interviews for evidence reliability. References (CCA Official Sources): CMMC Assessment Process (CAP) v1.0 - Interview Requirements NIST SP 800-171A - Use of Interview as an Assessment Method
Question 33
Single choice
During the planning and preparation discussions, a key member of the C3PAO Assessment Team falls ill and is unavailable for the originally scheduled assessment dates. The OSC is eager to proceed as planned and has expressed willingness to accommodate a smaller assessment team. If the OSC Assessment Official asks the C3PAO for advice on how to proceed, the Lead Assessor, on behalf of the C3PAO, should do which of the following?
-
A
Provide sufficient advice and recommendations.
-
B
Politely refuse to provide any advice or recommendations.
-
C
Provide general advice but avoid specific recommendations that could be seen as implementation assistance.
-
D
Offer limited advice, but only if the OSC agrees to proceed with the assessment as originally scheduled.
Reveal answer details
Close answer details
Question 34
Single choice
A software development company uses a cloud-based source code repository and continuous integration/ continuous deployment (CI/CD) platform to manage its software development lifecycle. The cloud service provider hosts and manages the source code repository and CI/CD platform. Which of the following statements accurately describes how the OSC should handle the cloud service provider's assets in the CMMC Assessment Scope?
-
A
Exclude the cloud provider's assets from the Assessment Scope since they are not owned or managed by the company.
-
B
Include the cloud provider's assets in the Assessment Scope as they handle sensitive code.
-
C
Include the cloud service provider's assets in the certification boundary but exclude them from the assessment scope.
-
D
It depends on the contract between the company and the cloud provider.
Reveal answer details
Close answer details
Question 35
Single choice
You are the Lead Assessor for a C3PAO Assessment Team that has recently completed a CMMC Level 2 assessment for an OSC. You and your Assessment Team have finalized the assessment process and are now in Phase 3 - Report Recommended Assessment Results. You are preparing to deliver the final recommended findings to the OSC Assessment Official and OSC participants during the Final Findings Briefing. After you present the final recommended findings and practice scores, what is the next step in the CMMC Assessment Process?
-
A
The C3PAO CQAP conducts an internal quality review of the Assessment Results Package.
-
B
The OSC submits an appeal using the Assessment Appeals Process if it disagrees with the findings.
-
C
You submit the Assessment Results Package directly to CMMC eMASS.
-
D
You archive all assessment artifacts and dispose of them after three years.
Reveal answer details
Close answer details
Question 36
Single choice
An OSC is undergoing a CMMC Level 2 assessment. The assessment team is reviewing the evidence for configuration management procedures per CMMC Practice CM.L2-3.4.1 - System Baselining. The assessors discover that the OSC has a documented process for creating system baselines. However, upon reviewing a sample server, they find software installed that is not listed in the baseline documentation. The OSC acknowledges the discrepancy and explains that they recently deployed new security software but have not updated the baseline documentation yet. The following conditions hold true for CMMC practices ineligible for deficiency corrections EXCEPT?
-
A
Practices that could lead to significant exploitation of the network or exfiltration of CUI.
-
B
Practices that were not implemented by the OSC prior to the current CMMC Assessment.
-
C
Practices listed on the OSC's Self-Assessment Practice Deficiency Tracker.
-
D
Practices that involve minor updates to existing policies or procedures but have been in place for a period of time.
Reveal answer details
Close answer details
Question 37
Single choice
During an assessment, the IT security engineers responsible for password policy for the OSC provided documentation that all passwords are protected using a one-way hashing methodology. As a result, which statement is true?
-
A
Passwords are protected in storage and in transit.
-
B
Passwords are transmitted across the network as clear cipher-text.
-
C
The password protection allows access but not authorization to assets.
-
D
The transformation makes it impossible to re-convert the hashed password.
Reveal answer details
Close answer details
Correct answerD
ExplanationA one-way hash function is a cryptographic method used to store passwords securely. It is not reversible; hashed values cannot be converted back into the original password. Extract from SC.L2-3.13.10: "Store and transmit authentication information in a protected form by using one-way cryptographic transformations (e.g., hashing). One-way transformations cannot be reversed to reveal the original authentication secret." Thus, the correct statement is that the transformation makes it impossible to re-convert the hashed password.
Question 38
Single choice
During the planning and preparation discussions, a key member of the C3PAO Assessment Team falls ill and is unavailable for the originally scheduled assessment dates. The OSC is eager to proceed as planned and has expressed willingness to accommodate a smaller assessment team. Can the Lead Assessor proceed with the assessment using a reduced assessment team size?
-
A
Yes, as long as the remaining team members possess the necessary qualifications to cover all CMMC practices.
-
B
Yes, but only with the express written consent of the Cyber AB.
-
C
The decision is solely up to the OSC.
-
D
No, the assessment must be postponed until the full team is available.
Reveal answer details
Close answer details
Question 39
Single choice
An OSC outsources all of its security incident and event monitoring work to a third-party SOC. Additionally, the OSC utilizes a cloud-hosted antivirus (AV) system to fulfill the requirement of having virus protection without hosting additional servers on-site. During the scoping discussion, both the SOC and AV should be listed as what type of asset?
-
A
They are CUI Assets due to their operation within a CUI network.
-
B
They are Out-of-Scope Assets due to being fully hosted/operated by third parties.
-
C
They are Security Protection Assets due to their performance of security functions.
-
D
They are Contractor Risk Managed Assets because they are not physically or logically isolated from CUI assets.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe Scoping Guidance defines Security Protection Assets as systems, tools, or services that provide security functions protecting CUI assets, even if outsourced to third parties. Extract: "Security Protection Assets are tools, systems, or services that provide security functionality (e.g., SOC, antivirus, logging) to protect CUI assets. These must be included in scope." Therefore, SOC and AV must be categorized as Security Protection Assets. References: CMMC Scoping Guidance - Security Protection Assets.
Question 40
Single choice
You are assessing a contractor's implementation for CMMC practice MA.L2-3.7.4 - Media Inspection by examining their maintenance records. You realize the maintenance logs identify a repeating problem. A recently installed central server has been experiencing issues affecting the performance of the contractor's information systems. This is confirmed by your interview with the contractor's IT team. You requested to investigate the server, and the IT team agreed. On the server, there is a file named conf.zip that gets your attention. You decide to open the file in an isolated computer for further review. To your surprise, the file is a .exe used when testing the server for data exfiltration. How should this incident be handled?
-
A
By immediately reporting it to the FBI's Cyber Division
-
B
Decommissioning the server and installing a new one
-
C
In accordance with the incident response plan
-
D
By sandboxing the malicious code and continuing with business as usual
Reveal answer details
Close answer details
Question 41
Single choice
During your review of an OSC's system security controls, you focus on CMMC practice SC.L2-3.13.9 - Connection Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system uses default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work. The scenario mentions that the server uses default settings for connection timeouts. What additional approach, besides relying solely on user awareness, could be implemented to achieve connection termination based on inactivity and comply with CMMC practice SC.L2-3.13.9 - Connection Termination?
-
A
Modify the server-side application settings to automatically terminate inactive user sessions after a defined period
-
B
Implement a centralized inactivity monitoring tool to identify inactive connections across the network and notify administrators for manual termination
-
C
Upgrade the server operating system to the latest version, as newer versions may have stricter default timeouts for idle connections
-
D
Educate users about the importance of logging out and the risks associated with leaving sessions open
Reveal answer details
Close answer details
Question 42
Single choice
Examining an OSC password policy, you learn that a password should have a minimum of 15 characters. It also should have 3 uppercase, 2 special characters, and other alphanumeric characters. Passwords have to be changed every 45 days and cannot be easily tied to the account owner. Passwords cannot be reused until 30 cycles are complete. The OSC's systems send a temporary password to the user's email or authentication app, which is one of the events described in their password usage policy. However, a recent penetration test report shows that the generated temporary passwords did not have sufficient entropy, and an attacker may guess a temporary password through brute force attacks. Which CMMC practice has the contractor successfully implemented?
-
A
IA.L2-3.5.9 -Temporary Passwords
-
B
IA.L2-3.5.7 -Password Complexity and IA.L2-3.5.8 -Password Reuse
-
C
IA.L2-3.5.3 -Multifactor Authentication
-
D
IA.L2-3.5.6 -Identifier Handling
Reveal answer details
Close answer details
Question 43
Single choice
An OSC specializing in developing directed energy systems plans to bid on a DoD contract to produce a 250kW High Energy Laser Weapon System (HELWS). This system is to be deployed on military bases across the globe to protect U.S. servicemen against aerial threats, including mortars, rockets, and unmanned aerial vehicles (UAVs), as well as swarms of mini-UAVs. Because of the sensitivity of the information, the OSC has prohibited using emails to transmit information regarding the project, whether encrypted or otherwise. They also have instituted procedures to remove CUI from the email system. The documents containing project information from the DoD are likely to contain which banner marking?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 44
Single choice
An OSC has produced two assessment scopes. When the Lead Assessor questioned the OSC PoC why, they detailed that they process, store, or transmit FCI within one assessment scope and CUI in another. Which scope will the OSC obtain a CMMC Level 2 certification for?
-
A
The scope that processes, transmits, or stores FCI
-
B
The scope that transmits, processes, or stores CUI
-
C
For both assessment scopes
-
D
The OSC cannot be certified at Level 2 because they haven't met Level 1 requirements
Reveal answer details
Close answer details
Question 45
Single choice
While conducting a CMMC Level 2 Third-Party Assessment of a small defense contractor, an assessor discovers that the contractor's Information Security Policy has no documented change records demonstrating executive approval. The IT director states that they will add change records in the future, but that other evidence exists. Which documentation is MOST able to demonstrate persistent and habitual adherence to CMMC requirements?
-
A
Handwritten notes from executive committee meetings discussing implementation
-
B
Several years' worth of saved emails from the executive team approving policies and directing adherence
-
C
A notarized letter from the previous CEO stating that they approved information security policies annually
-
D
Transcribed interviews with new employees discussing their understanding of information security policies
Reveal answer details
Close answer details
Correct answerB
ExplanationApplicable Requirement: CA.L2-3.12.4 -"Develop, document, periodically review/update, and disseminate system security plans." Policies require executive approval and evidence of regular review. Why B is Correct: Multiple years of emails from executives approving policies provide a pattern of consistent executive involvement, demonstrating habitual compliance with review and approval requirements. This is stronger evidence than one-time or informal attestations. Why Other Options Are Insufficient: Option A: Handwritten notes are informal and lack authenticity controls. Option C: A notarized letter from a previous CEO is a one-time attestation, not evidence of recurring review. Option D: Employee interviews may demonstrate awareness but do not show executive approval. References (CCA Official Sources): NIST SP 800-171 Rev. 2 - CA.L2-3.12.4 NIST SP 800-171A - CA.L2-3.12.4 Assessment Objectives (evidence of policy review/approval) CMMC Assessment Guide - Level 2 - Policy and Approval Evidence Requirements
Question 46
Single choice
While assessing an OSC, you realize they have given identifiers to systems, users, and processes. Examining their documentation, you know they have assigned accounts uniquely to employees, contractors, and subcontractors. The OSC has an automated system that disables any identifiers that are left unused for 6 months. You also learn from interviewing IT security administrators that the OSC has defined a technical and documented policy where identifiers can only be reused after 12 months. How is the OSC likely to consider CMMC practice IA.L2-3.5.5 - Identifier Reuse if you find issues with its implementation?
-
A
-
B
Track it under limited deficiency correction
-
C
Hire another C3PAO to verify your assessment
-
D
Disregard it as it is not applicable
Reveal answer details
Close answer details
Question 47
Single choice
A C3PAO Assessment Team is conducting a CMMC Level 2 assessment for an OSC. During the assessment, the team finds that the OSC has not implemented a required practice due to a lack ofresources. The OSC requests a waiver from the CMMC requirements citing financial hardship. What should the Lead Assessor tell the OSC?
-
A
The CMMC process does not allow waivers; all practices must be implemented to achieve certification.
-
B
The Lead Assessor can grant a waiver if the OSC provides a detailed financial justification.
-
C
The OSC can appeal to the Cyber AB for a waiver based on financial hardship.
-
D
The practice can be deferred to a POA&M, allowing conditional certification.
Reveal answer details
Close answer details
Question 48
Single choice
During a CMMC Level 2 assessment, the OSC's Assessment Official asks the Lead Assessor if they can provide a preliminary score before the assessment is complete to help prioritize remediation efforts. What should the Lead Assessor do?
-
A
Provide a preliminary score based on the evidence reviewed so far.
-
B
Politely refuse, explaining that scores are only finalized after all evidence is assessed per the CMMC Assessment Process.
-
C
Offer to provide a general indication of compliance without specific scores.
-
D
Agree to provide the score but only after consulting with the C3PAO.
Reveal answer details
Close answer details
Question 49
Single choice
Jane is a CCA leading a CMMC assessment for an OSC. During the evaluation, Jane discovers that the OSC's Chief Information Security Officer (CISO) is a former colleague with whom she had a contentious relationship in the past. Unbeknownst to the OSC, Jane still harbors resentment toward the CISO due to their previous conflicts. As the assessment progresses, Jane becomes increasingly critical of the CISO's security practices, scrutinizing every detail and finding fault despite the OSC's best efforts to demonstrate compliance. Given this scenario, how can a Certified CMMC Assessor's personal bias impact the assessment of the OSC?
-
A
Assessor bias has no effect on the assessment process and outcomes
-
B
Assessor bias is not a concern in CMMC assessments
-
C
Personal bias may result in an unfairly harsh and critical assessment of the OSC
-
D
Assessor bias can lead to an overly lenient evaluation of the OSC
Reveal answer details
Close answer details
Question 50
Single choice
You are a CCA evaluating an OSC's proposed CMMC assessment scope when planning and preparing a CMMC assessment. The assessment scope is defined in CMMC Assessment Scope - Level 2. Which statement best defines the assessment scope according to CMMC guidelines?
-
A
It focuses solely on the cybersecurity measures implemented within the organization.
-
B
It includes the boundaries within an organization's networked environment that contain all the assets that will be assessed.
-
C
It encompasses the entire organization's IT infrastructure.
-
D
It includes only the physical components of the information system.
Reveal answer details
Close answer details
Question 51
Single choice
While assessing an OSC, you realize they have given identifiers to systems, users, and processes. Examining their documentation, you know they have assigned accounts uniquely to employees, contractors, and subcontractors. The OSC has an automated system that disables any identifiers that are left unused for 6 months. You also learn from interviewing IT security administrators that the OSC has defined a technical and documented policy where identifiers can only be reused after 12 months. How is the OSC likely to consider CMMC practice IA.L2-3.5.5 - Identifier Reuse if you find issues with its implementation?
-
A
-
B
Track it under limited deficiency correction
-
C
Hire another C3PAO to verify your assessment
-
D
Disregard it as it is not applicable
Reveal answer details
Close answer details
Question 52
Single choice
Jane is a CCA for a leading C3PAO. She is selected to be part of a team of four, headed by James, to assess how Micron Inc., an OSC, has implemented the requirements for a CMMC Level 2 certification. However, she witnesses James striking a deal with Micron's CISO to manipulate some findings to ensure the OSC is certified. What should Jane do?
-
A
Assume nothing happened and continue with the assessment.
-
B
Privately request clarification from James.
-
C
Ask for a bribe from James to keep quiet.
-
D
Contact the DoD CIO and report James.
Reveal answer details
Close answer details
Question 53
Single choice
When assessing an environment, the CCA determines that CUI is contained within an IoT device. Which statement MUST be true?
-
A
The IoT device is a Contractor Risk Managed Asset.
-
B
The IoT device must be accurately documented within the SSP.
-
C
An IoT device may not be utilized to process, store, or transmit CUI.
-
D
Access provisioned to the IoT device must be done in accordance with AC.L2-3.1.1: Limit System Access.
Reveal answer details
Close answer details
Correct answerB
ExplanationWhen an IoT device processes, stores, or transmits CUI, it is categorized as a CUI Asset (not CRMA). All in-scope assets must be documented in the System Security Plan (SSP). The SSP must identify how the asset is managed, secured, and integrated into the OSC's environment. Exact Extracts: CMMC Scoping Guide: "All CUI Assets must be identified and described in the SSP." "Specialized Assets (including IoT) must be documented in the SSP if they process, store, or transmit CUI.""Contractor Risk Managed Assets do not include assets that process, store, or transmit CUI." Why other options are not correct: Option A: Incorrect, because an IoT device with CUI cannot be a CRMA. Option C: Incorrect, IoT can process CUI if properly secured and documented. Option D: While true in general (AC control applies), the mandatory requirement is accurate SSP documentation. References: CMMC Assessment Scope - Level 2, Version 2.13: Asset categories (pp. 5-10). CMMC Assessment Guide - Level 2: SSP documentation requirements.
Question 54
Single choice
During the assessment of a company, the CCA learns that 50% of employees work from home using remote access. After reviewing the Access Control policy and audit logs, the CCA is unsure how the system ensures only employees with correct privileges can access CUI. The CCA decides a Test of functionality is required. Which question is of the LEAST concern to the CCA?
-
A
Are remote access sessions necessary?
-
B
Are remote access sessions permitted?
-
C
Are remote access sessions monitored?
-
D
Are the types of permitted remote access identified?
Reveal answer details
Close answer details
Correct answerA
ExplanationUnder AC.L2-3.1.12: Remote Access, assessors must verify that all remote access sessions are identified, authorized, controlled, and monitored. Whether remote access is "necessary" is a business decision, not an assessment concern. The assessor is concerned with whether it is properly controlled and implemented, not with the business justification for its existence. Exact extracts: "Assessment Objectives... Determine if:- remote access methods are identified;- remote access is authorized prior to allowing such connections;- remote access sessions are controlled;- remote access sessions are monitored." "The requirement does not assess business necessity of remote access, only its security and authorization." Why the other options are important: Option B: Authorization (permitted) must be verified. Option C: Monitoring of remote sessions is mandatory. Option D: Permitted methods must be identified (e.g., VPN, VDI, etc.). References: CMMC Assessment Guide - Level 2, AC.L2-3.1.12. NIST SP 800-171 Rev. 2, 3.1.12.
Question 55
Single choice
As a Certified CMMC Assessor (CCA), you evaluate an OSC's implementation of the AC.L2-3.1.11 - Session Termination requirement during a CMMC Level 2 assessment. This requirement mandates the organization to automatically terminate a user session after defined conditions are met. During your assessment, you want to determine whether the OSC has properly defined theconditions that would trigger the automatic termination of a user session, as required by assessment objective [a]. Which of the following assessment objects would you most likely examine to make this determination?
-
A
The organization's system audit logs and records
-
B
Procedures addressing identification and authentication
-
C
Interviews with system administrators and personnel with information security responsibilities
-
D
The organization's Access Control Policy and system configuration settings
Reveal answer details
Close answer details
Question 56
Single choice
When assessing a contractor's implementation of CMMC requirements, you realize they have multiple data centers and regional offices, each having its access control mechanisms and security perimeter. The contractor uses a remote access solution to allow external partners and employees to collaborate on projects that involve CUI. The solution requires routing configuration to ensure the remote access to CUI is not compromised. Why should all traffic be routed through a managed Access Control point?
-
A
It simplifies network architecture and reduces complexity
-
B
Reduces the susceptibility to unauthorized access to organizational systems
-
C
It enables easier troubleshooting and monitoring of network traffic
-
D
It provides better performance and lower latency for remote users
Reveal answer details
Close answer details
Question 57
Single choice
As a CCA, understanding the guiding principles of the CoPC can help you when you face situations in which you are asked to compromise your values and integrity. Which of the following is NOT a guiding principle of the CoPC?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 58
Single choice
Assessing a DoD contractor, you observe they have implemented physical security measures to protect their facility housing organizational systems that process or store CUI. The facility has secure locks on all entrances, exits, and windows. Additionally, video surveillance cameras are installed at entry/exit points, and their feeds are monitored by security personnel. Feeds from areas where CUI is processed or stored and meeting rooms where executives meet to discuss things that have to do with CUI and other sensitive matters are segregated and stored on a designated server after monitoring. Walking around the facility, you notice network cables are hanging from the walls. To pass through a door, personnel must swipe their access cards. However, you observe an employee holding the door for others to enter. Although power cables are placed in wiring closets, they aren't locked, and the cabling conduits are damaged. Which of the following is NOT a concern regarding the contractor's implementation of CMMC practice PE.L2-3.10.2 - Monitor Facility?
-
A
Video surveillance monitoring at entry/exit points
-
B
-
C
Network cables hanging from the walls
-
D
Reveal answer details
Close answer details
Question 59
Single choice
You are part of the Assessment Team assessing a small defense contractor. You learn that the contractor (ABC Manufacturing) outsources parts of its IT infrastructure and cybersecurity services to a reputable Managed Services Provider (MSP). During a CMMC assessment, the contractor's Assessment Official claims that several CMMC practices related to system security and monitoring are inherited from the MSP. Which of the following actions should the Lead Assessor take?
-
A
Automatically accept the contractor's claim and score the inherited practices as `MET' without further evaluation.
-
B
Recommend that the OSC implement the inherited practices internally, as inheriting from external providers is not allowed.
-
C
Score the inherited practices as `NOT MET' and require ABC Manufacturing to implement them internally.
-
D
Request evidence from the MSP to verify that their services meet the assessment objectives for the inherited practices and are applicable to ABC Manufacturing's in-scope assets.
Reveal answer details
Close answer details
Question 60
Single choice
During a CMMC assessment, the OSC's PoC asks the Lead Assessor if they can skip the daily checkpoint meetings to save time, promising to provide all evidence upfront. What should the Lead Assessor do?
-
A
Agree to skip the meetings if all evidence is provided upfront.
-
B
Explain that daily checkpoint meetings are a required part of the CMMC Assessment Process and cannot be skipped.
-
C
Allow skipping the meetings but require written updates instead.
-
D
Consult with the C3PAO to determine if the meetings can be waived.
Reveal answer details
Close answer details
Question 61
Single choice
A manufacturing company is seeking Level 2 certification. The loading docks are currently accessible directly from the company's main parking lot, which may lead to unauthorized access to facilities. Based on this information, how should this method be modified to BEST meet Level 2 requirements?
-
A
Implement physical perimeter controls, such as turnstiles, to limit access.
-
B
Require visitors to check in at the reception desk and maintain a visitor log.
-
C
Implement physical perimeter controls, such as cameras, to limit access to only authorized personnel.
-
D
Implement physical perimeter controls, such as a gate with a badge system, to limit access to only authorized personnel.
Reveal answer details
Close answer details
Correct answerD
ExplanationApplicable Requirement: PE.L2-3.10.3 -"Control physical access to organizational systems, equipment, and the respective operating environments." Why Option D is Correct: A gate with a badge system represents preventive perimeter control that ensures only authorized personnel can access sensitive areas (e.g., loading docks). This directly aligns with Level 2 physical protection requirements. Why Other Options Are Insufficient: Option A (Turnstiles): More relevant for internal building entry, not loading docks. Option B (Visitor log): Supports accountability, but does not prevent unauthorized entry. Option C (Cameras): Provides monitoring but not control - surveillance alone does not restrict access. References (CCA Official Sources): NIST SP 800-171 Rev. 2 - PE.L2-3.10.3 NIST SP 800-171A - PE.L2-3.10.3 Assessment Objectives CMMC Assessment Guide - Level 2, Physical Protection
Question 62
Single choice
While conducting a CMMC Level 2 self-assessment, an organization's Chief Information Security Officer asks the system administrator for evidence that remote access is routed through fully managed access control points. Which documentation would BEST demonstrate that all remote access is routed through managed access control points?
-
A
Network diagram and VPN logs
-
B
Access control policy and procedures
-
C
SSP and vendor management
-
D
Cloud service audit logs and hardware asset inventory
Reveal answer details
Close answer details
Correct answerA
ExplanationTo validate that remote access is routed through managed access control points, the assessor requires technical evidence, not just policy. The network diagram shows the design and routing of remote access through controlled points (e.g., VPN gateways), and VPN logs provide operational evidence that remote sessions are enforced through those points. Exact Extracts: AC.L2-3.1.14: "Route remote access through managed access control points." Assessment Objective (AC.L2-3.1.14[a]): "Remote access is routed through managed access control points." Assessment Method (Examine/Interview/Test): Requires network diagrams and remote access logs as evidence. CMMC Assessment Guide specifies: "Network diagrams and supporting logs are required to demonstrate implementation of remote access routing." Why the other options are not correct: Option B (policy/procedures): Policies describe intent, not proof of implementation. Option C (SSP/vendor mgmt): SSPs provide system description but not direct evidence of enforcement. Option D (cloud logs/hardware inventory): These do not specifically demonstrate remote access routing through managed points. References: CMMC Assessment Guide - Level 2, Version 2.13: AC.L2-3.1.14 (pp. 25-27). NIST SP 800-171A, Access Control assessment procedures.
Question 63
Single choice
A CCA is conducting a CMMC assessment and notices that the OSC's evidence includes a policy document that is outdated by two years. The OSC insists that the policy is still in effect, but staff interviews indicate that newer, undocumented procedures are being followed. How should the CCA handle this situation?
-
A
Accept the outdated policy as evidence since the OSC claims it is still in effect.
-
B
Document the discrepancy between the policy and actual procedures and assess based on all available evidence.
-
C
Reject the policy document outright and score the practice as "NOT MET."
-
D
Request the OSC to update the policy document before proceeding with the assessment.
Reveal answer details
Close answer details
Question 64
Single choice
During a CMMC assessment, you review the OSC's documented procedures for access control.These procedures detail a user access request and approval process for the organization's Human Resources (HR) information system. You then interview IT personnel responsible for access control, who confirm the documented procedures accurately reflect how access is managed for the HR system. However, the OSC's network diagram reveals the presence of other in-scope systems critical to their operations, such as their Engineering Design Database and Manufacturing Control System. Neither the documented procedures nor the interview addressed access control practices for these additional systems. Based on the CMMC Assessment Process guidelines on evidence sufficiency, how would you characterize the evidence collected so far regarding access control?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 65
Single choice
A CCA is conducting a CMMC assessment and notices that the OSC's evidence includes screenshots of system configurations that are not dated. The OSC claims the screenshots are current. How should the CCA proceed?
-
A
Accept the screenshots as evidence since the OSC claims they are current.
-
B
Document the lack of dates as an evidence gap and request additional verification of currency.
-
C
Reject the screenshots and score the related practice as "NOT MET."
-
D
Ask the OSC to recreate the screenshots with current dates during the assessment.
Reveal answer details
Close answer details
Question 66
Single choice
You have been hired to assess a contractor's implementation of remote access capabilities for information systems that handle CUI. While interviewing the network administrator, you realize they perform privileged activities remotely when at alternate worksites. Which of the following is the BEST action the contractor can take to address the network administrator's remote execution of privileged activities, as per CMMC practice AC.L2-3.1.15 - Privileged Remote Access?
-
A
Implement multifactor authentication before authorizing remote access sessions, regardless of privilege level
-
B
Prohibit the remote execution of privileged commands and remote access to security-relevant information entirely
-
C
Log and monitor all remote sessions
-
D
Limit remote access privileges to read-only activities and prohibit any remote execution of privileged commands
Reveal answer details
Close answer details
Question 67
Single choice
An OSC is undergoing a CMMC assessment by a C3PAO. The assessment team has been on-site for several days, reviewing the OSC's systems, policies, and procedures against the CMMC requirements. Each day, the assessment team holds a "daily checkpoint" meeting with the OSC's security team and representatives. This checkpoint serves an important purpose in the overall assessment process. What is the significance of the Daily Checkpoint meeting in the CMMC assessment process?
-
A
It allows the Lead Assessor to finalize the assessment findings independently.
-
B
It is optional and not necessary for the assessment process.
-
C
It is solely for updating the OSC on the assessment progress.
-
D
It provides an opportunity for the Assessment Team to review and verify additional evidence.
Reveal answer details
Close answer details
Question 68
Single choice
During an assessment, it is uncovered that a CCA worked as a consultant for the OSC through their RPO. Unfortunately, the CCA didn't disclose this when their C3PAO appointed them to participate in the assessment. Did the CCA behave professionally? If not, what issues are likely to arise?
-
A
Yes, the CCA behaved professionally.
-
B
-
C
-
D
No, breach of confidentiality.
Reveal answer details
Close answer details
Question 69
Single choice
Removable media can pose significant cybersecurity risks to an organization if not adequately controlled and secured. Understanding the dangers of this, an OSC has crafted a meticulous removable media policy. It defines removable media, types of removable media, examples of removable media, etc. The policy limits the use of removable media unless authorized; even then, the media must be scanned for malware. Organizational removable media has specific signatures unique to organizational systems and provided to a defined group of personnel. Any data stored on such media is encrypted, and the OSC has disabled autorun and closed some ports on their computer systems. The contractor also has deployed an endpoint protection solution for every employee searched while entering or leaving the facility. Users must also pass through a walk-in metal detector to ensure they do not sneak in thumb drives and SD cards. Based on the OSC's effort, how would you score their implementation of CMMC practice MP.L2-3.8.7 - Removable Media?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 70
Single choice
In assessing an OSC's CUI handling practices, you learn they use an approved algorithm (AES-256) to encrypt the data to ensure its confidentiality. However, the encryption module they are using has not been validated under the FIPS 140 standard. The OSC believes that using an approved algorithm is sufficient to comply with the CMMC practice for CUI encryption requirements. Which of the following would be the most appropriate next step for the assessor?
-
A
Interview personnel responsible for cryptographic protection to determine if FIPS-validated cryptography is used elsewhere in the organization
-
B
Test the encryption mechanism by attempting to decrypt the encrypted data without the proper keys
-
C
Recommend that the OSC switch to a different, approved algorithm
-
D
Accept the OSC's implementation as compliant, given that they are using a strong encryption algorithm
Reveal answer details
Close answer details
Question 71
Single choice
You are a CCA participating in an assessment exercise for an OSC. You have completed the exercise, and the OSC has hashed the evidence artifacts in accordance with the CMMC Artifact Hashing Tool User Guide. What is the next step for your Assessment Team with respect to the Evidence Artifact Hashes?
-
A
Tell the OSC to encrypt the hash.
-
B
Upload the Hashes to the OSC's CMMC eMASS.
-
C
Upload them to your C3PAO's cloud instance.
-
D
Nothing, the assessment is complete.
Reveal answer details
Close answer details
Question 72
Single choice
During your review of an OSC's system security control, you focus on CMMC practice SC.L2-3.13.9 - Connections Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system utilizes default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work. Based on the scenario, what is the MOST concerning aspect from a CMMC compliance perspective regarding CMMC practice SC.L2-3.13.9 - Connections Termination?
-
A
The application is hosted on a dedicated server within the company's internal network
-
B
Users log in with usernames and passwords, potentially lacking multi-factor authentication
-
C
The lack of a documented policy or a defined period of inactivity for terminating remote access connections creates uncertainty and inconsistency
-
D
The server operating system utilizes default settings for connection timeouts, which may be insufficient
Reveal answer details
Close answer details
Question 73
Single choice
An OSC has contracted a C3PAO to perform a Level 2 Assessment. As the Lead Assessor is analyzing the assessment requirements, it is found that the OSC does not have a document detailing the assessment scope. How can this problem BEST be fixed?
-
A
The Assessment Team is supposed to generate the document before moving forward.
-
B
The CCA tells the OSC they must provide the document before the assessment can begin.
-
C
The OSC and the Lead Assessor jointly create the document at the beginning of the assessment.
-
D
The Lead Assessor can regulate the assessment and create/adjust the document moving forward.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe OSC is responsible for providing the scoping documentation before the assessment begins. The assessor validates the scoping documentation but does not create it on behalf of the OSC. If the OSC cannot provide scope documentation, the assessment cannot proceed. Exact Extracts: CMMC Scoping Guide: "The OSC must prepare and provide scoping documentation, including network diagrams, asset inventories, and SSP, prior to assessment." CMMC Assessment Guide: "The assessment team validates scoping documentation; it is not the responsibility of the C3PAO or assessor to create the OSC's scope." Why other options are not correct: Option A: Incorrect - assessment teams validate but do not generate scoping documents. Option C: Joint creation is not allowed; OSC must own and prepare documentation. Option D: Lead Assessor cannot create scope; must rely on OSC's provided documentation. References: CMMC Assessment Guide - Level 2, Version 2.13: Pre-assessment scoping requirements (pp. 6-8). CMMC Assessment Scope - Level 2, Version 2.13: OSC responsibilities.
Question 74
Single choice
CMMC practice PS.L2-3.9.1 - Screen Individuals requires individuals to be screened before authorizing access to organizational systems containing CUI. However, in the assessment you are currently conducting, there is no physical evidence confirming the completion of personnel screens, such as background checks, only affirmations derived from an interview session. In an interview with the HR Manager, they informed you that before an individual is hired, they submit their information through a service that performs criminal and financial checks. How would you score the OSC's implementation of CMMC practice PS.L2-3.9.1 - Screen Individuals, objective [a]?
-
A
More information is needed
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 75
Single choice
A contractor plans to bid for a DoD contract and has installed new network file servers to separate their commercial and DoD work. When examining the server documentation, you realize that the server has some open ports. Upon further testing, you determine that the server has some default features that are not essential for file storage or transfer. The server has a default remote desktop functionality that allows users remote access to the server's desktop environment. Files are transferred by default using FTP, which is less secure than the Server Message Block (SMB) protocol. However, the contractor's operations do not require remote access capabilities. Although the roles of each system are defined in their configuration management policy, a user can install any application or service they need. After some interviews, you learn that this ensures every employee is comfortable using a system or software they are most conversant with, despite having defined services or software for carrying out specific functions. Upon speaking with the OSC PoC when assessing CM.L2-3.4.6 - Least Functionality, they acknowledge deficiencies, place the practice in a POA&M, and request that you grant conditional certification. How would you respond?
-
A
Offer to provide consulting services to help them meet CM.L2-3.4.6 - Least Functionality quickly
-
B
Politely decline the OSC's request and inform them that CM.L2-3.4.6 - Least Functionality cannot be placed in a POA&M. Also, inform them that granting conditional CMMC certification when they do not meet the requirement is in violation of the CMMC Code of Professional Conduct (CoPC)
-
C
Walk out of the assessment and file a conflict of interest with the CMMC AB
-
D
Grant them conditional certification
Reveal answer details
Close answer details
Question 76
Single choice
A CCA was part of an Assessment Team tasked with conducting a CMMC assessment for an OSC. Happy to have been part of the team that completed the assessment, the CCA posted the OSC's assessment results on their Twitter/X account. Which CMMC Code of Professional Conduct (CoPC) principle has the CCA violated?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 77
Single choice
A CCA is asked to validate if an OSC has separated their systems containing CUI from other departments' systems on their local network. Which of the following MUST the CCA assess?
-
A
-
B
Virtual Private Network (VPN)
-
C
Virtual Local Area Network (VLAN)
-
D
Network Address Translation (NAT)
Reveal answer details
Close answer details
Correct answerC
ExplanationTo validate separation of CUI systems from non-CUI systems on a local network, the assessor must evaluate the VLAN configuration. VLANs are a recognized logical segmentation method for separating enclaves, as defined in the CMMC Scoping Guide. Exact Extracts: CMMC Scoping Guide: "Isolation can be achieved by implementing subnetworks with firewalls, routers, and VLANs to ensure separation of CUI assets from out-of-scope assets." "CUI Assets must be isolated from non-CUI assets unless those non-CUI assets are designated as Security Protection Assets or Contractor Risk Managed Assets." Why other options are not correct: Option A (WAN): Wide Area Networks describe external connectivity, not local separation. Option B (VPN): VPN provides encrypted remote access but does not enforce local network segmentation. Option D (NAT): NAT provides IP translation, not logical separation of traffic. References: CMMC Assessment Scope - Level 2, Version 2.13: Isolation requirements and VLAN as an example (pp.9- 11). CMMC Assessment Guide - Level 2: Assessor validation of enclave boundary methods.
Question 78
Single choice
John, a CCA, has been assigned by his C3PAO to conduct a CMMC assessment for an OSC. During the assessment, John notices that the OSC's security practices leave much to be desired. After speaking with the OSC's IT staff, John offers to connect them with a vendor he knows who sells a vulnerability management tool that could address some of their weaknesses. According to the CMMC CoPC, which of the following best describes John's actions?
-
A
John acted appropriately by trying to help the OSC improve its security posture.
-
B
John did not show respect for intellectual property.
-
C
John's actions were deemed acceptable since he did not directly profit from connecting the OSC with the vendor.
-
D
John violated the principles of professionalism and objectivity by soliciting business for a third-party vendor while serving on the Assessment Team.
Reveal answer details
Close answer details
Question 79
Single choice
You are a Lead Assessor, and an OSC has engaged your C3PAO firm to conduct a CMMC assessment. As the Lead Assessor, you are responsible for identifying, documenting, and communicating any potential risks that could impact the successful completion of the planned assessment. You need to evaluate various risk categories and develop mitigation plans to ensure a smooth assessment process. If a member of the Assessment Team is at risk of being delayed and is unable to start the assessment on time, which of the following would be an appropriate mitigation plan?
-
A
Proceed with the assessment without the delayed team member
-
B
Request additional resources from the OSC to compensate for the delayed team member
-
C
Reschedule the assessment for a later date
-
D
Identify an alternate resource to shadow the Assessment Team member and potentially act as a successor
Reveal answer details
Close answer details
Question 80
Single choice
Sarah, a Certified CMMC Assessor, is conducting an assessment for DataSecure, a cloud service provider that hosts various applications for the Defense Industrial Base (DIB). During the assessment, Sarah encounters a complex and highly specialized cloud architecture that leverages cutting-edge technologies such as containerization, serverless computing, and advanced security controls. As Sarah reviews the evidence provided by DataSecure for the relevant CMMC practices, she realizes that some of the evidence and implementations are unlike anything she has encountered in previous assessments. What is the most appropriate action for Sarah to take as a CCA in this scenario?
-
A
Request DataSecure to simplify their architecture and align with more traditional IT practices for easier evaluation.
-
B
Strictly adhere to a standardized assessment checklist, regardless of DataSecure's unique architecture.
-
C
Defer the assessment until she can receive additional training on the specific technologies used by DataSecure.
-
D
Thoroughly research and understand DataSecure's cloud architecture, seek clarification from subject matter experts, and evaluate the evidence within the context of their specialized environment.
Reveal answer details
Close answer details
|