The Lead Assessor interviews a network security specialist of an OSC. The incident monitoring report for the month shows that no security incidents were reported from OSC's external SOC service provider. This is provided as evidence for RA.L2-3.11.2: Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. Based on this information, the Lead Assessor should conclude that the evidence is:
-
A
inadequate because it is irrelevant to the practice.
-
B
adequate because it fits well for expected artifacts.
-
C
adequate because no security incidents were reported.
-
D
inadequate because the OSC's service provider should be interviewed.
Reveal answer details
Close answer details
The facilities manager for a company has procured a Wi-Fi enabled, mobile application-controlled thermostat for the server room, citing concerns over the inability to remotely gauge and control the temperature of the room. Because the thermostat is connected to the company's FCI network, should it be assessed as part of the CMMC Level 1 Self-Assessment Scope?
-
A
-
B
No, because it is an loT device
-
C
Yes. because it is a restricted IS
-
D
Yes, because it is government property
Reveal answer details
Close answer details
During Phase 4 of the Assessment process, what MUST the Lead Assessor determine and recommend to the C3PAO concerning the OSC?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?
-
A
Affirmation for each practice or control
-
B
Documented rationale for each failed practice
-
C
Suggested improvements for each failed practice
-
D
Gaps or deltas due to any reciprocity model are recorded as met
Reveal answer details
Close answer details
In preparation for a CMMC Level 1 Self-Assessment, the IT manager for a DIB organization is documenting asset types in the company's SSP The manager determines that identified machine controllers and assembly machines should be documented as Specialized Assets. Which type of Specialized Assets has the manager identified and documented?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which phase of the CMMC Assessment Process includes developing the assessment plan?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?
-
A
The process is running correctly.
-
B
It is out of scope as this is a new acquisition.
-
C
The new acquisition is considered Specialized Assets.
-
D
Practice is NOT MET since the objective was not implemented.
Reveal answer details
Close answer details
A CMMC Level 1 Self-Assessment identified an asset in the OSC's facility that does not process, store, or transmit FCI. Which type of asset is this considered?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1. Guidelines for Media Sanitation?
-
A
-
B
-
C
-
D
Clear, overwrite, destroy
Reveal answer details
Close answer details
Question 10
Single choice
Which NIST SP defines the Assessment Procedure leveraged by the CMMC?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 11
Single choice
In CMMC High-Level scoping, which definition BEST describes an HQ organization?
-
A
The entity that carries out the tasks under a contract
-
B
The unit to which a CMMC Level is applied for each contract
-
C
The teams, services, and technologies that provide support to a Host Unit
-
D
The entity legally responsible for the delivery of products or services under a contract
Reveal answer details
Close answer details
Question 12
Single choice
Which term describes the process of granting or denying specific requests to obtain and use information, related information processing services, and enter specific physical facilities?
-
A
-
B
-
C
-
D
Discretionary access control
Reveal answer details
Close answer details
Question 13
Single choice
The practices in CMMC Level 2 consists of the security requirements specified in:
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 14
Single choice
Which domain references the requirements needed to handle physical or digital assets containing CUI?
-
A
-
B
-
C
System and Information Integrity (SI)
-
D
System and Communications Protection (SC)
Reveal answer details
Close answer details
Question 15
Single choice
An OSC has requested a C3PAO to conduct a Level 2 Assessment. The C3PAO has agreed, and the two organizations have collaborated to develop the Assessment Plan. Who agrees to and signs off on the Assessment Plan?
-
A
-
B
-
C
-
D
C3PAO and Assessment Official
Reveal answer details
Close answer details
Question 16
Single choice
While conducting a CMMC Level 2 Assessment, a CCP is reviewing an OSC's personnel security process. They have a policy that describes screening individuals prior to authorizing access to CUI, but it does not mention what organizations should be looking for in an individual. There is no link to a process or procedural document. What should the OSC evaluate when screening individuals prior to accessing CUI?
-
A
They are trusted and well liked
-
B
They are a hard and loyal worker
-
C
Their conduct, integrity, and loyalty
-
D
Their functionality, reliability, and ability to adapt
Reveal answer details
Close answer details
Question 17
Single choice
What is the MOST common purpose of assessment procedures?
-
A
-
B
-
C
Determine information flow.
-
D
Determine value of hardware and software.
Reveal answer details
Close answer details
Question 18
Single choice
Contractor scoping requirements for a CMMC Level 2 Assessment to document the asset in an inventory, in the SSP and on the network diagram apply to:
-
A
-
B
CUI and Security Protection Asset categories.
-
C
all asset categories except for the Out-of-scope Assets.
-
D
Contractor Risk Managed Assets and Specialized Assets.
Reveal answer details
Close answer details
Question 19
Single choice
Which situation MOST clearly represents a conflict of interest during an assessment?
-
A
Assessing an OSC where the assessor knows an employee socially
-
B
Assessing an OSC where the assessor previously provided paid consulting
-
C
Assessing an OSC subcontractor in the same industry
-
D
Assessing an OSC with a prior business referral
Reveal answer details
Close answer details
Question 20
Single choice
A CCP is reviewing AC.L1-3.1.2: Limit information system access to the types of transactions and functions that authorized users are permitted to execute. Which artifact BEST supports this practice?
-
A
-
B
Access control lists mapped to roles
-
C
Security awareness training records
-
D
Reveal answer details
Close answer details
Question 21
Single choice
Which of the following practices belongs to the System and Communications Protection (SC) domain?
-
A
SC.L2-3.13.5: Implement subnetworks for publicly accessible system components
-
B
PE.L1-3.10.3: Escort visitors
-
C
AC.L1-3.1.1: Limit system access to authorized users
-
D
IA.L2-3.5.4: Employ replay-resistant authentication
Reveal answer details
Close answer details
Question 22
Single choice
Which scenario BEST demonstrates a conflict of interest?
-
A
An assessor previously consulted for the OSC on CMMC readiness
-
B
An assessor used to work in the same industry
-
C
An assessor graduated from the same university as an OSC employee
-
D
An assessor knows an OSC employee socially
Reveal answer details
Close answer details
Question 23
Single choice
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
-
A
Have a security clearance
-
B
Be a senior person in the company
-
C
Demonstrate expertise on the CMMC requirements Provide
-
D
clarity and understanding of their practice activities
Reveal answer details
Close answer details
Question 24
Single choice
Which code or clause requires that a contractor is meeting the basic safeguarding requirements for FCI during a Level 1 Self-Assessment?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 25
Single choice
During an assessment, which phase of the process identifies conflicts of interest?
-
A
-
B
-
C
Verify readiness to conduct assessment.
-
D
Generate final recommended assessment results.
Reveal answer details
Close answer details
Question 26
Single choice
While determining the scope for a company's CMMC Level 1 Self-Assessment, the contract administrator includes the hosting providers that manage their IT infrastructure. Which asset type BEST describes the third-party organization?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 27
Single choice
What type of information is NOT intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not including information provided by the government to the public (such as on public websites) or simple transactional information, such as necessary to process payments?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 28
Single choice
Which domains are a part of a Level 1 Self-Assessment?
-
A
Access Control (AC), Risk Management <RM), and Media Protection (MP)
-
B
Risk Management (RM). Access Control (AC), and Physical Protection (PE)
-
C
Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)
-
D
Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)
Reveal answer details
Close answer details
Question 29
Single choice
When executing a remediation review, the Lead Assessor should:
-
A
help OSC to complete planned remediation activities.
-
B
plan two consecutive remediation reviews for an OSC.
-
C
submit a delta assessment remediation package for C3PAO's internal quality review.
-
D
validate that practices previously listed on the POA&M have been removed on an updated Risk Assessment.
Reveal answer details
Close answer details
Question 30
Single choice
Which statement BEST describes the requirements for a C3PA0?
-
A
An authorized C3PAO must meet some DoD and all ISO/IEC 17020 requirements.
-
B
An accredited C3PAO must meet all DoD and some ISO/IEC 17020 requirements.
-
C
AC3PAO must be accredited by DoD before being able to conduct assessments.
-
D
A C3PAO must be authorized by CMMC-AB before being able to conduct assessments.
Reveal answer details
Close answer details
Question 31
Single choice
In the Code of Professional Conduct, what does the practice of Professionalism require?
-
A
Do not copy materials without permission to do so.
-
B
Do not make assertions about assessment outcomes.
-
C
Refrain from dishonesty in all dealings regarding CMMC.
-
D
Ensure the security of all information discovered or received.
Reveal answer details
Close answer details
Question 32
Single choice
An assessment is being completed at a client site that is not far from the Lead Assessor's home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?
-
A
Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.
-
B
Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.
-
C
Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service.
-
D
Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.
Reveal answer details
Close answer details
Question 33
Single choice
Regarding the Risk Assessment (RA) domain, what should an OSC periodically assess?
-
A
Organizational operations, business assets, and employees
-
B
Organizational operations, business processes, and employees
-
C
Organizational operations, organizational assets, and individuals
-
D
Organizational operations, organizational processes, and individuals
Reveal answer details
Close answer details
Question 34
Single choice
Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a part of a plan of action?
-
A
-
B
Milestones to measure progress
-
C
Ownership of who is accountable for ensuring plan performance
-
D
Budget requirements to implement the plan's remediation actions
Reveal answer details
Close answer details
Question 35
Single choice
A CCP is assessing CM.L2-3.4.3: Track, review, approve/disapprove, and audit changes to organizational systems. Which evidence MOST directly supports this practice?
-
A
-
B
Change tickets with approval workflow
-
C
External penetration test report
-
D
Reveal answer details
Close answer details
Question 36
Single choice
In the CMMC Model, how many practices are included in Level 1?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 37
Single choice
A Level 2 Assessment of an OSC is winding down and the final results are being prepared to present to the OSC. When should the final results be delivered to the OSC?
-
A
At the end of every day of the assessment
-
B
Daily and during a final separately scheduled review
-
C
Either at the final Daily Checkpoint, or during a separately scheduled findings and recommendation review
-
D
Either after approval from the C3PAO. or during a separately scheduled final recommended findings review
Reveal answer details
Close answer details
|