While reviewing a contractor's Microsoft Active Directory authentication policies, you observe that the account lockout threshold is configured to allow 5 consecutive invalid login attempts before locking the account for 15 minutes. Additionally, the reset account lockout counter is set to 30 seconds after each unsuccessful login attempt.
Based on this scenario, which of the following statements are TRUE about the contractor's implementation of CMMC practice AC.L2-3.1.8 - Unsuccessful Logon Attempts?
A. The contractor has successfully implemented practice AC.L2-3.1.8 - Unsuccessful Logon Attempts warranting a score of METAn OSC seeking Level 2 certification has a fully cloud-based environment. The assessor must evaluate fulfillment of Level 2 requirements the OSC implements versus those handled by the cloud service provider.
Which document would be BEST to identify the Level 2 requirements handled by the OSC's cloud provider?
A. Zero Trust ArchitectureAn assessor reviews the OSC's data protection policy, which requires full disk encryption on company laptops. While interviewing employees, the assessor learns that employees sometimes access data while teleworking on laptops that do not have full disk encryption.
How should the assessor view the implementation of the OSC's policy?
A. Acceptable because it requires full disk encryption of company laptops.During your review of an OSC's system security control, you focus on CMMC practice SC.L2-3.13.9 - Connections Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system utilizes default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work.
Based on the scenario, what is the MOST concerning aspect from a CMMC compliance perspective regarding CMMC practice SC.L2-3.13.9 - Connections Termination?
A. The application is hosted on a dedicated server within the company's internal networkYou are the Lead Assessor for a CMMC Level 2 assessment. During the assessment, the OSC admits that a practice was implemented only a week before the assessment began due to a last-minute effort to prepare. The practice appears to meet the objectives based on the evidence provided.
How should you evaluate this evidence?
A. Accept the evidence and score the practice as "MET" since it meets the objectives at the time of assessment.After the OSC and the Assessment Team scheduled the initial meeting, they agreed that the initial discussions would be held in the OSC's facilities. Walking into the conference room, the Lead Assessor notices multiple laptops and printers tagged "U.S. Government Owned."
How should the OSC have categorized these assets in their proposed assessment scope?
A. Government PropertyYou are the Lead Assessor for a CMMC assessment. During the Final Findings Briefing, the OSC Assessment Official disputes a "NOT MET" finding, claiming the evidence was misinterpreted.
What is the OSC's recourse according to the CMMC Assessment Process?
A. Request an immediate reassessment by the same Assessment Team.While examining evidence, a CCA is trying to confirm the claim that the OSC has identified all information system users, processes acting on behalf of users, and all devices.
Which of the following provides the STRONGEST evidence of this practice?
A. Lists of system accounts and devices and system audit logs and recordsIn assessing an OSC's CUI handling practices, you learn they use an approved algorithm (AES-256) to encrypt the data to ensure its confidentiality. However, the encryption module they are using has not been validated under the FIPS 140 standard. The OSC believes that using an approved algorithm is sufficient to comply with the CMMC practice for CUI encryption requirements.
Which of the following would be the most appropriate next step for the assessor?
A. Interview personnel responsible for cryptographic protection to determine if FIPS-validated cryptography is used elsewhere in the organizationA CMMC assessment for an OSC finds that it has fully implemented 87 out of 110 practices. Unfortunately, the Assessment Team determines that the POA&M Close-Out Assessment option cannot be used.
Consequently, the OSC will not be recommended for certification. However, the OSC Assessment Official respectfully requests that the Lead Assessor adjust the findings to allow for POA&M close-out and mark a 5-point practice as implemented.
How should the Lead Assessor respond?
A. Politely decline the request and cite ethical reasons of violating the CoPC.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.