You are part of the team conducting a CMMC assessment for an OSC. Because of the sensitive nature of the OSC's technologies, your team signed an NDA. However, you observe one of the Assessment Team members copying something from the OSC's computer systems. You know they don't have permission because the NDA states that the OSC POC will provide any required material.
What should you do in this case?
A. Inform the OSC of the incident.An OSC uses a third party in all system repairs and has hired an MSP for penetration testing. The third party comes for either adaptive, preventative, perfective, or corrective system maintenance every three months, and the penetration tester does so continuously. Whenever the third party comes for maintenance, there's no documentation of the issues they tackled. On the other hand, the penetration tester delivers meticulously detailed documentation per their contract with the OSC.
To comply with CMMC practice MA.L2- 3.7.1 - Perform Maintenance, what should the OSC implement for the maintenance activities performed by the third-party vendor?
A. Increase the frequency of maintenance activities to monthly intervalsDuring a CMMC assessment for an OSC, the Point of Contact (POC) mentioned they conducted a self-assessment beforehand. The self-assessment was part of the organization's preparations for the CMMC assessment by your C3PAO.
Which publication offers the best guidance for the self-assessment procedures OSCs might use for CMMC compliance?
A. DFARS Clause 252.204-7012The Daily Checkpoint meeting is a required component of the CMMC assessment process. It is conducted at the end of every day and includes the Assessment Team, Lead Assessor, OSC PoC, OSC Assessment Official, and other key personnel.
This meeting helps ensure all the following, EXCEPT?
A. Data collection needs are being met.The OSC prints out documents it receives via email that are marked as CUI.
According to MP.L2-3.8.4: Media Markings, what should the Assessor expect to see on the printouts?
A. A red stamp that states the document contains CUIAn OSC plans to bid for a DoD contract to supply laser welding services to repair a fleet of unmanned aerial vehicles (UAVs). This requires them to be CMMC Level 2 certified since the information they will receive from the DoD is Controlled Technical Information (CTI). However, their repair and welding services require a Computer Numerical Control (CNC) machine to fabricate some crucial parts. Since the welding is mainly automated using robots, the OSC has intelligently integrated its SCADA system with Programmable Logic Controllers (PLCs) for increased accuracy, improved safety and efficiency, and enhanced flexibility.
If the OSC wins the contract, how will the banner marking on documents containing CUI from the DoD be structured?
A. CUI//SP-CTIAn OSC has documented HR and personnel security policies, which are well integrated. A key requirement is that credentials and systems are revoked upon a transfer or termination. Their personnel security policy includes procedures for transfer and termination, a list of system accounts tied to each employee, and management of revoked or terminated credentials and authenticators. Examining the procedures addressing personnel transfer and termination, you learn that besides revoking or terminating system access, authenticators, and credentials, the OSC recovers all company IT equipment, access/ identification cards, and keys from the transferred or terminated employee. They also interview the employee to remind them of their CUI handling obligations even after transfer and require them to sign an NDA. After every termination, they also change the password and other access control mechanisms and notify all the stakeholders that the employee has been terminated or transferred.
Based on the scenario, the OSC can cite the following as evidence of collaborating on their implementation of CMMC practice PS.L2- 3.9.2 - Personnel Actions, EXCEPT?
A. List of usernames and passwords of all the employeesWhen assessing an environment, the CCA determines that CUI is contained within an IoT device.
Which statement MUST be true?
A. The IoT device is a Contractor Risk Managed Asset.An OSC receives a POA&M during their CMMC L2 assessment. 170 days later, they submit an updated POA&M with evidence of all corrective actions.
Can the C3PAO still conduct a close-out assessment?
A. No, the 180-day window has closed.A CCA is reviewing an OSC's evidence for a CMMC practice and finds that the documentation is in draft form, marked "For Internal Use Only," and lacks final approval. The OSC insists it is actively used.
How should the CCA evaluate this evidence?
A. Accept the draft documentation as sufficient since it is actively used.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.