Cyber AB CMMC-CCA Online Practice
Questions and Exam Preparation
CMMC-CCA Exam Details
Exam Code
:CMMC-CCA
Exam Name
:Certified CMMC Assessor (CCA)
Certification
:Cyber AB Certifications
Vendor
:Cyber AB
Total Questions
:527 Q&As
Last Updated
:Jul 12, 2026
Cyber AB CMMC-CCA Online Questions &
Answers
Question 211:
While assessing an OSC, you realize they have given identifiers to systems, users, and processes.
Examining their documentation, you know they have assigned accounts uniquely to employees, contractors, and subcontractors. The OSC has an automated system that disables any identifiers that are left unused for 6 months. You also learn from interviewing IT security administrators that the OSC has defined a technical and documented policy where identifiers can only be reused after 12 months.
How is the OSC likely to consider CMMC practice IA.L2-3.5.5 - Identifier Reuse if you find issues with its implementation?
A. List it in their SSP B. Track it under limited deficiency correction C. Hire another C3PAO to verify your assessment D. Disregard it as it is not applicable
B. Track it under limited deficiency correction
Question 212:
During a CMMC assessment, the Assessment Team identifies that the OSC has not implemented a practice due to a recent system upgrade that disrupted their previous controls. The OSC requests to include this practice in a POA&M. However, the practice is listed as one that could lead to significant network exploitation if not implemented.
What should the Lead Assessor do?
A. Allow the practice to be included in the POA&M, as it was disrupted by a recent upgrade. B. Mark the practice as "NOT MET" and inform the OSC that it is ineligible for a POA&M due to its critical nature. C. Recommend that the OSC implement the practice immediately and reassess it before concluding the assessment. D. Report the OSC to the Cyber AB for failing to maintain critical controls.
B. Mark the practice as "NOT MET" and inform the OSC that it is ineligible for a POA&M due to its critical nature.
Question 213:
During an assessment, the Lead Assessor determines certain assets to be in-scope which the OSC had considered out-of-scope.
The CCA should reply that for assets to be considered out-of-scope they:
A. Provide security protections to CUI assets. B. Do not provide security protections for CUI assets. C. Can, but are not intended to, process, store, or transmit CUI. D. Are not required to be physically or logically separated from CUI assets.
B. Do not provide security protections for CUI assets.
Explanation
The CMMC Scoping Guidance specifies that Out-of-Scope Assets are those that neither process, store, nor transmit CUI, and do not provide security protections for CUI assets.
Extract:
"Out-of-Scope assets are those that cannot process, store, or transmit CUI, and do not provide security protections for CUI assets."
Thus, the correct answer is Option B
References:
CMMC Scoping Guidance, Asset Categories.
Question 214:
To meet AC.L2-3.1.5: Least Privilege, the following procedure is established:
1. All employees are given a basic, non-privileged user account.
2. System Administrators are given a separate System Administrator account.
3. Database Administrators are given a separate Database Administrator account.
Which steps should be added to BEST meet all of the standards for least privilege?
A. 4. Database Administrators use their Database Administrator accounts to perform privileged functions.5. All users use their basic accounts for non-privileged functions. B. 4. Database Administrators use their Database Administrator accounts to perform privileged functions.5. Non-privileged users use their basic accounts for non-privileged functions. C. 4. Database Administrators use the System Administrator accounts to perform privileged functions.5. All other users use their basic accounts for all authorized functions. D. 4. Database Administrators use the System Administrator accounts to perform privileged functions.5. Non-privileged users use their basic accounts for all authorized functions.
A. 4. Database Administrators use their Database Administrator accounts to perform privileged functions.5. All users use their basic accounts for non-privileged functions.
Explanation
Least privilege requires users to perform privileged functions only with privileged accounts and to use their basic, non-privileged accounts for general activity. This prevents unnecessary exposure of elevated rights and limits attack surfaces. Database Administrators must use their Database Administrator accounts only for DBA tasks, and all users must use their basic accounts for non-privileged tasks.
Exact Extracts:
AC.L2-3.1.5: "Employ the principle of least privilege, including for specific security functions and privileged accounts."
Assessment Objectives: Require separate accounts for privileged and non-privileged activities.
Assessment Guide Clarification: "Privileged accounts should be used only for privileged functions;
standard accounts must be used for all other activities."
Why the other options are not correct:
Option B: States that "non-privileged users use their basic account," but does not explicitly require all users, including administrators, to use their basic accounts for non-privileged tasks.
Option C/D: Incorrectly assign System Administrator accounts to Database Administrators, which violates least privilege.
Administrators must only have the access needed for their role.
References:
CMMC Assessment Guide ?Level 2, Version 2.13: AC.L2-3.1.5, pp. 17?9.
NIST SP 800-171A: Assessment procedures for least privilege and account management.
Question 215:
You are conducting a CMMC assessment for a contractor that handles sensitive defense project data.
Reviewing their documentation shows that the contractor has an on-premises data center that houses CUI on internal servers and file shares. A corporate firewall protects this data center network. However, the contractor also uses a hybrid cloud infrastructure, storing some CUI in Microsoft Azure cloud storage, which can be accessed using ExpressRoute private network connections. Additionally, their engineers connect remotely to the data center to access CUI via a site-to-site VPN from their home networks.
The following evidence would help determine if the contractor is properly authorizing and enforcing controls on CUI data flow across their environment, EXCEPT?
A. Reviewing firewall and ExpressRoute connections B. Reviewing audit logs related to the VPN connections C. Analyzing policies, records, and configurations related to data center connections D. Analyzing CCTV footage
D. Analyzing CCTV footage
Question 216:
During a company's assessment, the CCA notices that the server room door is kept open with a fan in the entryway because the cooling system is inadequate and the machines are overheating. According to the physical protection policy, the server room's keypad is the mechanism for managing and controlling access to this equipment, and only the IT team should have access to the server room. However, with the door open, the keypad is not necessary, and anyone can enter the room.
The CCA asks the IT manager how access to this room is protected while the door is open.
Which response would allow the company to still meet the physical security requirement?
A. "Only employees are allowed in this area." B. "We trust our employees not to enter the room if they are not supposed to." C. "The server is located inside another room that only the IT team has access to." D. "The CEO emailed all employees that the server room door would be kept open but only the IT team should enter."
C. "The server is located inside another room that only the IT team has access to."
Explanation
The Physical Protection (PE) Domain requires implementation of physical access controls to prevent unauthorized access to CUI systems. Simply trusting employees or sending communications is not sufficient. However, if the server is located inside a secondary restricted room that only the IT team can access, then adequate physical protection controls are still in place.
Extract from PE.L2-3.10.x (Physical Protection Practices):
"Organizations must limit physical access to systems, equipment, and environments that process, store, or transmit CUI to authorized individuals only."
Thus, placing the server within an additional restricted access-controlled room ensures compliance, even if the outer door is propped open for cooling.
Question 217:
During a CMMC assessment, the OSC's PoC asks the Lead Assessor if they can skip the daily checkpoint meetings to save time, promising to provide all evidence upfront.
What should the Lead Assessor do?
A. Agree to skip the meetings if all evidence is provided upfront. B. Explain that daily checkpoint meetings are a required part of the CMMC Assessment Process and cannot be skipped. C. Allow skipping the meetings but require written updates instead. D. Consult with the C3PAO to determine if the meetings can be waived.
B. Explain that daily checkpoint meetings are a required part of the CMMC Assessment Process and cannot be skipped.
Question 218:
During the Planning Phase of the Assessment Plan, the assessor determines that the Client will likely include sensitive and proprietary CUI.
What should the assessor consider as part of their virtual data collection techniques for this information?
A. The Client is responsible for safeguarding the data during collection, not the assessor. B. The assessor is responsible for safeguarding the data during collection, not the client. C. The assessor should record the risks and mitigations to protect the CUI categories handled. D. The client and assessor should record the risks and mitigations to protect the CUI categories handled.
D. The client and assessor should record the risks and mitigations to protect the CUI categories handled.
Explanation
Applicable Requirement (CAP - Planning Phase): Both the OSC (Client) and the CCA are responsible for protecting sensitive evidence and CUI during assessment. This includes documenting risks and mitigations for how such information is handled, especially during virtual collection.
Why Option D is Correct: CAP requires assessors and OSCs to jointly establish processes ensuring safeguarding of CUI evidence. Both parties must record and agree to risks and mitigations as part of the assessment plan.
Why Other Options Are Insufficient: Option A &
B: Responsibility is shared, not one-sided.
Option C: Recording by the assessor alone does not fulfill CAP's joint responsibility requirement.
References (CCA Official Sources):
CMMC Assessment Process (CAP) v1.0 - Planning Phase (Handling CUI and Sensitive Evidence) Code of Professional Conduct - Assessor responsibility for safeguarding CUI
Question 219:
An OSC's network diagram shows a separate network segment (192.168.50.0/24) designated for its engineering department. This segment restricts access to specific engineering resources. While the servers are physically located in a shared data center, the network configuration isolates them logically.
Through which of the following does the network segmentation create isolation for the engineering department's resources?
A. Logical separation through network configuration B. Physical barriers within the data center C. Encryption of engineering data at rest D. Requirement of a security badge to access the data center
A. Logical separation through network configuration
Question 220:
A company has a server in its own Virtual Cloud used as a CUI enclave. There is a point-to-point VPN between the OSC's office and the cloud environment. Designated users have direct access to the enclave when in the office.
When working remotely, those users must establish a VPN connection between their company laptop and the cloud server.
During the assessment, the CCA asks the IT manager about external connections.
How many external connections are within the boundary for this assessment?
A. The system has one external connection through the VPN when working outside the office. B. The system has no external connections since the OSC operates the connections and the enclave. C. The system has one external connection through the dedicated VPN between the office and the Cloud. D. The system has two external connections: one through the user-initiated VPNs and one to the company's office.
D. The system has two external connections: one through the user-initiated VPNs and one to the company's office.
Explanation
External connections are defined as connections crossing the OSC's assessment boundary.
Here:
The dedicated VPN from office to cloud = one external connection.
The user-initiated VPNs from remote laptops to cloud = a second external connection.
Extract:
"External connections include all system interfaces that cross the assessment boundary, including VPNs initiated by users or established between sites."
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cyber AB exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your CMMC-CCA exam preparations
and Cyber AB certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.