CMMC-CCA Exam Details

  • Exam Code
    :CMMC-CCA
  • Exam Name
    :Certified CMMC Assessor (CCA)
  • Certification
    :Cyber AB Certifications
  • Vendor
    :Cyber AB
  • Total Questions
    :527 Q&As
  • Last Updated
    :Jul 12, 2026

Cyber AB CMMC-CCA Online Questions & Answers

  • Question 141:

    A company has a CUI enclave for handling all CUI processed, stored, and transmitted through the organization. While interviewing the IT manager, the CCA asks how assets that can, but are not intended to, handle CUI are identified. The IT manager refers to the CUI system's network diagram (which includes these assets) as well as the asset inventory (which lists these assets as Contractor Risk Managed Assets).

    Which other artifact MUST also mention these assets?

    A. The identification and authentication policy should show how these assets are identified.
    B. The physical protection policy should list these assets as being part of the physical environment of the organization.
    C. The awareness and training program should include these assets so they are covered for all employees.
    D. The SSP should show these assets are managed using the company's risk-based security policies, procedures, and practices.

  • Question 142:

    An Assessor is evaluating whether an OSC has implemented adequate controls to meet AC.L2-3.1.7: Privileged Functions. The OSC has procedures that define privileged vs. non-privileged account provisioning and an access control policy that restricts execution of certain functions only to privileged.

    What might the Assessor do to further evaluate the implementation of this practice?

    A. Examine system logs to verify automatic updates are being applied.
    B. Test whether the application of a patch is captured in system logging.
    C. Test whether a non-privileged user can log into a system where CUI is stored.
    D. Examine a user access list for users that are authorized to access a key management system.

  • Question 143:

    You are a Lead Assessor tasked with conducting a CMMC Assessment for an OSC seeking to secure its CMMC Level 2 certification. The OSC has previously conducted a self-assessment and engaged a Registered Practitioner Organization (RPO) for a preliminary evaluation. As part of the CMMC Assessment process, you begin by determining the necessary evidence for each practice or process across the OSC's organizational functional areas. You consider both the adequacy and sufficiency of the evidence in relation to the CMMC's requirements. After initial preparations, you and the OSC's POC schedule a joint review session to align on the scope and expectations for the upcoming assessment.

    What is the primary focus of the `Sufficiency' criterion during the evidence verification process in a CMMC assessment?

    A. Confirming the evidence has been reviewed and approved by all stakeholders.
    B. Sufficiency verifies that there is enough evidence to comprehensively assess each practice against the CMMC Assessment scope.
    C. Checking if the evidence includes the latest cybersecurity trends and technologies.
    D. Ensuring the evidence covers a wide range of cybersecurity threats.

  • Question 144:

    A software development company is applying for a CMMC Level 2 assessment. As the Lead Assessor, you request access to the company's System Security Plan (SSP) as part of the initial objective evidence for validating the scope.

    Which of the following is true about the software development company's obligations in honoring the request?

    A. The software development company can refuse to provide the SSP if they deem it contains proprietary information.
    B. The software development company is not obligated to provide the SSP until after the assessment has begun.
    C. The software development company can choose to provide a redacted version of the SSP, omitting sensitive information.
    D. The software development company must furnish the Lead Assessor with the SSP.

  • Question 145:

    You are assessing an OSC that develops applications handling Controlled Unclassified Information (CUI).

    As part of the assessment, you review their vulnerability scanning process. According to their risk assessment policy, the OSC conducts system vulnerability scans every three months. However, they also utilize a centralized, automated vulnerability scanning tool that performs daily scans. Upon discovering any vulnerabilities, the OSC's team applies patches and rescans their systems. Their environment includes backend database servers, web applications with custom Java code, virtual machine hosts running containerized applications, network firewalls, routers, switches, and developer workstations.

    During the assessment, you find that their scanning solution integrates the latest vulnerability feeds from the National Vulnerability Database (NVD), Open Vulnerability and Assessment Language (OVAL), and vendor sources. The tool generates reports using Common Vulnerability Scoring System (CVSS) metrics, and even remotely connected developer laptops are included in the scans. However, upon reviewing the vulnerability reports, you observe that the same high/critical vulnerabilities persist month after month without evidence of remediation.Furthermore, there is no record of source code scanning for their custom applications, and virtual machine hosts running the containerized applications are not included in the scans.

    Which of the following would be an appropriate compensating control or mitigation for the lack of source code scanning?

    A. Deploy web application firewalls in front of the custom applications
    B. Increase the frequency of automated vulnerability scans on the production environment
    C. Perform periodic penetration testing and code reviews on the custom applications
    D. Implement secure coding standards and practices during application development

  • Question 146:

    During your review of an OSC's system security control, you focus on CMMC practice SC.L2-3.13.9 - Connections Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system utilizes default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work.

    How could the firewall be configured to help achieve the objectives of CMMC practice SC.L2-3.13.9 - Connections Termination, for the remote access application?

    A. Creating firewall rules to identify and terminate connections associated with the CUI access application that have been inactive for a predefined period
    B. Encrypting all traffic between the user device and the server to protect CUI in transit
    C. Implementing intrusion detection and prevention systems (IDS/IPS) to identify and block suspicious activity on the server
    D. Blocking all incoming traffic to the server hosting the CUI access application, except from authorized IP addresses

  • Question 147:

    During a readiness assessment for CoolPlanes Inc., Liz, a CCA, discovers a folder of technical drawings and illustrations of the aircraft that CoolPlanes produces. Liz has a younger brother, J.D., who loves airplanes. She thinks a large printed copy of one of the illustrations would make an excellent gift for J.D.'s birthday next month. She copies the drawing and sends it to be printed on a large canvas when she gets home.

    Which of the following principles of the CMMC Code of Professional Conduct did Liz most likely violate?

    A. Objectivity
    B. Professionalism
    C. Ethical Practices
    D. Confidentiality

  • Question 148:

    You are the Lead Assessor of a C3PAO assessment team conducting a CMMC assessment for an OSC.

    The CMMC Assessment Guide - Level 2 lists assessment methods and objects that you are expected to use to validate the OSC's implementation.

    Which of the following is FALSE about the use of assessment methods and objects?

    A. Assessment methods are used to make specific determinations called for in the determination statements
    B. The assessment methods define the nature and extent of the assessor's actions
    C. A CCA must use all the specified assessment methods and objects while conducting the CMMCassessment
    D. The Assessment Team has the discretion to use the assessment methods or objects that best fit a CMMC practice during an assessment

  • Question 149:

    While examining controls on the use of portable storage devices, an assessor conducts an interview with a mid-level internal system administrator. The administrator describes the process to check out portable storage devices, which includes a user emailing IT staff directly, verifying that the media classification label matches the data classification, and limiting use of the device to a specified external system.

    What is a MISSING element for the assessment of AC.L2-3.1.21: Portable Storage Use?

    A. Method of destruction of portable storage devices
    B. Recorded management authorization for the use of portable storage devices
    C. An inventory of portable storage devices provided by the National Security Agency
    D. A directory of personnel background checks to be consulted prior to device checkout

  • Question 150:

    You have been sent to assess an OSC's implementation of CMMC practices, one of which is AC.L2-3.1.11

    - Session Termination.

    In assessing the contractor's implementation of AC.L2-3.1.11, you'll likely need to examine the following specifications, EXCEPT?

    A. Mechanisms for implementing user session termination
    B. The access control policy
    C. The session termination policy
    D. System security plan

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.