An OSC has a hardware and software list used to manage company assets.
Which is the BEST evidence to show the OSC is managing the system baseline?
A. Media protectionA company mirrors its FCI/CUI data storage in a cloud environment. Data is managed across multiple virtual machines (VMs).
To satisfy requirements for data security of the LOCAL copy using physical controls, what should the OSC do?
A. Use encrypted transport and storage of FCI/CUI data on the VMs.During a CMMC assessment, the CCAs, CCPs, and Lead Assessor validate the assessment scope provided by the OSC. They must review documents and records specific to the agreed-upon scope and boundaries of the assessment. There are several documents the Assessment Team may review or analyze; some are required, and others not.
Which of the following documents is NOT required when scoping a CMMC Assessment for Level 2 maturity?
A. Network diagramsA contractor has retained you to assess compliance with CMMC practices as part of their triennial review.
During your assessment of the AU domain, you discovered that the contractor has recently installed new nodes and servers on their network infrastructure. To assess their implementation of AU.L2-3.3.7 - Authoritative Time Source, you trigger some events documented to meet AU.L2-3.3.1 - System Auditing across both the new and existing systems, generating audit logs. Upon examining these logs, you notice inconsistencies in the timestamps between newly installed and previously existing nodes. Further investigation reveals that while the contractor has implemented a central Network Time Protocol (NTP) server as the authoritative time source, the new systems are configured to automatically adjust and
synchronize their clocks only when the time difference with the NTP server exceeds 30 seconds.
Based on this scenario, how many points would you score theOSC's implementation of CMMC practice AU.L2-3.3.7 - Authoritative Time Source?
A. 5When conducting a CMMC assessment, the CCA must follow the steps outlined in the CMMC Assessment Process (CAP). This document is organized into several phases, each requiring the CCA to complete specific documents. The CAP also provides templates, some of which the Assessor must use and complete during specific phases.
A CCA must complete all the following documents in Phase 1 of the CAP, EXCEPT?
A. CMMC Assessment Quality Review Checklist.John has just passed the CCA examination and is looking to gain real-world knowledge. You are a CCA working for a leading C3PAO and a friend of John's, and he hears that you are conducting a CMMC assessment and wants to learn about how some documents are completed. He asks if you could provide a CA-RR document you completed during your current engagement to help him understand how various fields are filled out.
Which of the following is the most appropriate course of action?
A. Redact any confidential information from the CA-RR document before sharing it with John.As a CCA, you were the Lead Assessor for a C3PAO Assessment Team that has just completed a CMMC assessment for an OSC. However, an individual has requested under the FOIA that your C3PAO release the assessment results. As the Lead Assessor, your C3PAO wants to hear your views on this request.
What should your recommendation be?
A. Release a redacted version of the assessment results.While reviewing CA.L2-3.12.3: Security Control Monitoring, the CCA notices that the assessment period is defined as one year. An OSC's SSP states that under CA.L2-3.12.3, security controls are monitored using the same one-year periodicity to ensure the continued effectiveness of the controls. The assessor understands that some CMMC practices can reference other practices for the entirety of their implementation.
Is the OSC's implementation under CA.L2-3.12.3: Security Control Monitoring acceptable?
A. No, even when referencing other practices more description is always needed.An OSC undergoing a CMMC Level 2 assessment has provided a detailed System Security Plan (SSP) and supporting evidence. During the assessment, you notice that the SSP references a practice as being fully implemented, but interviews with staff reveal that the practice is not consistently followed.
How should the Lead Assessor proceed?
A. Score the practice as "MET" based on the SSP documentation alone.An aerospace company bids on a DoD contract that requires CMMC Level 2 compliance. The company has multiple divisions, but only the Manufacturing Division will work on the project. The Manufacturing Division has its own IT infrastructure and security policies, but it relies on the company's centralized IT department for some administrative tasks.
Which of the following is the Host Unit in this scenario?
A. The Manufacturing DivisionNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.