Skip to main content

CMMC-CCA Real Exam Questions

Certified CMMC Assessor (CCA)

527 questions available · Page 1 of 53

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

During a readiness assessment for CoolPlanes Inc., Liz, a CCA, discovers a folder of technical drawings and illustrations of the aircraft that CoolPlanes produces. Liz has a younger brother, J.D., who loves airplanes. She thinks a large printed copy of one of the illustrations would make an excellent gift for J.D.'s birthday next month. She copies the drawing and sends it to be printed on a large canvas when she gets home.

Which of the following principles of the CMMC Code of Professional Conduct did Liz most likely violate?

  1. A

    Objectivity

  2. B

    Professionalism

  3. C

    Ethical Practices

  4. D

    Confidentiality

Show answer and explanation

Correct answer: D

Question 2 Single choice

You decide to interview the IT security team to understand if and how a contractor has implemented audit failure alerting. You learn they have deployed AlienVault OSSIM, a feature-rich security information and
event management (SIEM) tool. The SIEM tool has been configured to send automatic alerts to system
and network administrators if an event affects the audit logging process. Alerts are generated for the defined events that lead to failure in audit logging and can be found in the notification section of the SIEM portal. However, the alerts are sent to the specified personnel 24 hours after the occurrence of an event.

As an assessor evaluating the implementation of AU.L2-3.3.4 - Audit Failure Alerting, which of the following would be a key consideration regarding theevidence provided by the contractor?

  1. A

    Ensuring the defined alert notification methods (e.g., email, SMS) are secure and encrypted

  2. B

    Verifying that the types of audit logging failures defined cover a comprehensive range of potential scenarios

  3. C

    Determining if the documented personnel roles for alert notification align with the organization's hierarchy

  4. D

    Checking if the alert notification process integrates with third-party monitoring services

Show answer and explanation

Correct answer: B

Question 3 Single choice

A CMMC assessment involves testing, examining, and interviewing various assessment objects. The definition of an assessment object is provided in NIST SP 800-171A.

Which of the following can an Assessment Object NOT be?

  1. A

    Activities

  2. B

    Specifications

  3. C

    Individuals

  4. D

    Examine

Show answer and explanation

Correct answer: D

Question 4 Single choice

An OSC has a testing laboratory. The lab has several pieces of equipment, including a workstation that is used to analyze test information collected from the test equipment. All equipment is on the same VLAN that is part of the certification assessment. The OSC claims that the workstation is part of the test equipment (Specialized Asset) and only needs to be addressed under risk-based security policies.
However, the OSC states that the data analysis output is CUI.

What is the assessor's BEST response?

  1. A

    Disagree with the OSC and include the workstation in the full assessment.

  2. B

    Disagree with the OSC and score practice CA.L2-3.12.4: System Security Plan as NOT MET.

  3. C

    Agree with the OSC but perform a limited check of the system, not increasing the assessment cost or duration.

  4. D

    Agree with the OSC and determine if it is managed using the contractor's risk-based information security procedures and practices.

Show answer and explanation

Correct answer: A

Explanation

If an asset processes or generates CUI, it is a CUI Asset by definition, regardless of whether it is also part of a test lab or claimed as a Specialized Asset. Specialized Asset handling applies only when the asset does not process, store, or transmit CUI. Since the workstation outputs CUI, it must be assessed fully against CMMC practices.

Exact extracts:
"CUI Assets are those that process, store, or transmit CUI."
"Specialized Assets... do not process, store, or transmit CUI."
"If a Specialized Asset processes CUI, it must be categorized as a CUI Asset and is assessed against all applicable practices."

Why the other options are incorrect: Option B: The issue is not with the SSP practice; it is with misclassification of an asset.
Option C/D: Risk-based treatment applies only to Specialized Assets without CUI, which is not the case here.

References:
CMMC Level 2 Scoping Guide - Specialized Assets CUI Asset definitions.

Question 5 Single choice

When examining a contractor's access control policy and SSP, you observe that system administrators routinely use accounts with elevated privileges for checking email and browsing internal websites.

Why is it critical to implement practice AC.L2-3.1.6 - Non-Privileged Account Use?

  1. A

    Enables easier auditing and logging of privileged activities

  2. B

    Mitigates the consequences of a security breach by safeguarding against data loss

  3. C

    Prevents unauthorized modification of security functions

  4. D

    Reduces exposure to threats that might exploit the misuse of privileges

Show answer and explanation

Correct answer: D

Question 6 Single choice

Different mechanisms can be used to protect information at rest.

Which mechanism is MOST LIKELY to afford protection for information at rest?

  1. A

    Patching

  2. B

    File share

  3. C

    Secure offline storage

  4. D

    Cryptographic mechanisms

Show answer and explanation

Correct answer: D

Explanation

Applicable Requirement: SC.L2-3.13.16 -"Protect the confidentiality of CUI at rest."

Why Option D is Correct: Cryptographic mechanisms (e.g., full-disk encryption, database encryption, file encryption) provide the strongest protection for information at rest by preventing unauthorized disclosure if systems or media are accessed.

Why Other Options Are Insufficient: Option A (Patching): Protects against vulnerabilities, but not specific to data-at-rest confidentiality.
Option B (File share): Provides a storage method, not protection.
Option C (Secure offline storage): Helps physically, but not sufficient for digital confidentiality without encryption.

References (CCA Official Sources):
NIST SP 800-171 Rev. 2 - SC.L2-3.13.16 NIST SP 800-171A - SC.L2-3.13.16 Assessment Objectives
CMMC Assessment Guide - Level 2, Data at Rest Protection

Question 7 Single choice

An aerospace company has requested a CMMC assessment for an enclave only. Your team has verified that the company has a valid CAGE code and is registered with SAM.gov. However, the enclave has no separate CAGE code or SAM registration.

Can the assessor proceed with the CMMC assessment solely for the enclave, or is an assessment of the entire aerospace company's network required?

  1. A

    The assessor can proceed with the enclave assessment for CMMC Level 2 compliance.

  2. B

    The assessor cannot proceed with the enclave assessment.

  3. C

    The assessor must assess the entire company network.

  4. D

    The assessor can proceed with the enclave assessment, but only for a lower CMMC level.

Show answer and explanation

Correct answer: A

Question 8 Single choice

You are a CCA working with an OSC that outsources some of its IT operations to a third-party service provider. The service provider has access to the OSC's networks and systems that handle FCI and CUI.
During the scoping process, you need to determine if the OSC should flow down CMMC requirements to this third-party service provider.

In this scenario, when should the OSCflow down CMMC requirements to the third-party service provider?

  1. A

    The OSC should only flow down CMMC requirements if explicitly stated in the contract with the third-party service provider.

  2. B

    The OSC should flow down CMMC requirements to the third-party service provider since they have access to the FCI/CUI environment and can directly or indirectly influence it.

  3. C

    The OSC should never flow down CMMC requirements to third-party service providers.

  4. D

    The OSC should flow down CMMC requirements to the third-party service provider only if they handle
    CUI but not FCI.

Show answer and explanation

Correct answer: B

Question 9 Single choice

You are part of the team conducting a CMMC assessment for an OSC. Because of the sensitive nature of the OSC's technologies, your team signed an NDA. However, you observe one of the Assessment Team members copying something from the OSC's computer systems. You know they don't have permission because the NDA states that the OSC POC will provide any required material.

What should you do in this case?

  1. A

    Inform the OSC of the incident.

  2. B

    Allow them to copy the files.

  3. C

    Approach the team member and remind them of their confidentiality obligations under the CoPC.

  4. D

    Report the team member to the Cyber AB.

Show answer and explanation

Correct answer: C

Question 10 Single choice

A Defense Contractor is preparing for their upcoming CMMC Level 2 assessment. One of the key controls they need to address is CMMC practice MP.L2-3.8.5 - Media Accountability, which deals with maintaining accountability for media containing CUI during transport outside of controlled areas. The organization regularly needs to transport physical media, such as hard drives and backup tapes, between their primary data center and an off-site storage facility. In the past, they have simply used standard packaging and commercial shipping services to move this media.

Which of the following is NOT an assessment method for MP.L2-3.8.5 - Media Accountability?

  1. A

    Testing mechanisms supporting or implementing media storage and media protection

  2. B

    Examining designated controlled areas

  3. C

    Interviewing organizational processes for storing media

  4. D

    Examining procedures addressing media storage and access control policy

Show answer and explanation

Correct answer: C