A company has a CUI enclave for handling all CUI processed, stored, and transmitted through the organization. While interviewing the IT manager, the CCA asks how assets that can, but are not intended to, handle CUI are identified. The IT manager refers to the CUI system's network diagram (which includes these assets) as well as the asset inventory (which lists these assets as Contractor Risk Managed Assets).
Which other artifact MUST also mention these assets?
A. The identification and authentication policy should show how these assets are identified.An Assessor is evaluating whether an OSC has implemented adequate controls to meet AC.L2-3.1.7: Privileged Functions. The OSC has procedures that define privileged vs. non-privileged account provisioning and an access control policy that restricts execution of certain functions only to privileged.
What might the Assessor do to further evaluate the implementation of this practice?
A. Examine system logs to verify automatic updates are being applied.You are a Lead Assessor tasked with conducting a CMMC Assessment for an OSC seeking to secure its CMMC Level 2 certification. The OSC has previously conducted a self-assessment and engaged a Registered Practitioner Organization (RPO) for a preliminary evaluation. As part of the CMMC Assessment process, you begin by determining the necessary evidence for each practice or process across the OSC's organizational functional areas. You consider both the adequacy and sufficiency of the evidence in relation to the CMMC's requirements. After initial preparations, you and the OSC's POC schedule a joint review session to align on the scope and expectations for the upcoming assessment.
What is the primary focus of the `Sufficiency' criterion during the evidence verification process in a CMMC assessment?
A. Confirming the evidence has been reviewed and approved by all stakeholders.A software development company is applying for a CMMC Level 2 assessment. As the Lead Assessor, you request access to the company's System Security Plan (SSP) as part of the initial objective evidence for validating the scope.
Which of the following is true about the software development company's obligations in honoring the request?
A. The software development company can refuse to provide the SSP if they deem it contains proprietary information.You are assessing an OSC that develops applications handling Controlled Unclassified Information (CUI).
As part of the assessment, you review their vulnerability scanning process. According to their risk assessment policy, the OSC conducts system vulnerability scans every three months. However, they also utilize a centralized, automated vulnerability scanning tool that performs daily scans. Upon discovering any vulnerabilities, the OSC's team applies patches and rescans their systems. Their environment includes backend database servers, web applications with custom Java code, virtual machine hosts running containerized applications, network firewalls, routers, switches, and developer workstations.
During the assessment, you find that their scanning solution integrates the latest vulnerability feeds from the National Vulnerability Database (NVD), Open Vulnerability and Assessment Language (OVAL), and vendor sources. The tool generates reports using Common Vulnerability Scoring System (CVSS) metrics, and even remotely connected developer laptops are included in the scans. However, upon reviewing the vulnerability reports, you observe that the same high/critical vulnerabilities persist month after month without evidence of remediation.Furthermore, there is no record of source code scanning for their custom applications, and virtual machine hosts running the containerized applications are not included in the scans.
Which of the following would be an appropriate compensating control or mitigation for the lack of source code scanning?
A. Deploy web application firewalls in front of the custom applicationsDuring your review of an OSC's system security control, you focus on CMMC practice SC.L2-3.13.9 - Connections Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company's internal network. The server operating system utilizes default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work.
How could the firewall be configured to help achieve the objectives of CMMC practice SC.L2-3.13.9 - Connections Termination, for the remote access application?
A. Creating firewall rules to identify and terminate connections associated with the CUI access application that have been inactive for a predefined periodDuring a readiness assessment for CoolPlanes Inc., Liz, a CCA, discovers a folder of technical drawings and illustrations of the aircraft that CoolPlanes produces. Liz has a younger brother, J.D., who loves airplanes. She thinks a large printed copy of one of the illustrations would make an excellent gift for J.D.'s birthday next month. She copies the drawing and sends it to be printed on a large canvas when she gets home.
Which of the following principles of the CMMC Code of Professional Conduct did Liz most likely violate?
A. ObjectivityYou are the Lead Assessor of a C3PAO assessment team conducting a CMMC assessment for an OSC.
The CMMC Assessment Guide - Level 2 lists assessment methods and objects that you are expected to use to validate the OSC's implementation.
Which of the following is FALSE about the use of assessment methods and objects?
A. Assessment methods are used to make specific determinations called for in the determination statementsWhile examining controls on the use of portable storage devices, an assessor conducts an interview with a mid-level internal system administrator. The administrator describes the process to check out portable storage devices, which includes a user emailing IT staff directly, verifying that the media classification label matches the data classification, and limiting use of the device to a specified external system.
What is a MISSING element for the assessment of AC.L2-3.1.21: Portable Storage Use?
A. Method of destruction of portable storage devicesYou have been sent to assess an OSC's implementation of CMMC practices, one of which is AC.L2-3.1.11
- Session Termination.
In assessing the contractor's implementation of AC.L2-3.1.11, you'll likely need to examine the following specifications, EXCEPT?
A. Mechanisms for implementing user session terminationNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.