You have been hired to assess a contractor's implementation of remote access capabilities for information systems that handle CUI. While interviewing the network administrator, you realize they perform privileged activities remotely when at alternate worksites.
Which of the following is the BEST action the contractor can take to address the network administrator's remote execution of privileged activities, as per CMMC practice AC.L2-3.1.15 - Privileged Remote Access?
A. Implement multifactor authentication before authorizing remote access sessions, regardless of privilege levelMobile devices are increasingly becoming important in many contractors' day-to-day activities. Thus, the contractors must institute measures to ensure they are correctly identified and any connections are authorized, monitored, and logged, especially if the devices or their connections process, store, or transmit CUI. You have been hired to assess a contractor's implementation of CMMC practices, one of which is AC.L2-3.1.18. Mobile Device Connections. To successfully test the access control capabilities authorizing mobile device connections to organizational systems, you must first identify what a mobile device is.
Mobile devices connecting to organizational systems must have a device-specific identifier.
Which of the following is the main consideration for a contractor when choosing an identifier?
A. Choosing an identifier that can accommodate all devices and be used consistently within the organizationDuring the on-site assessment, the assessment team thoroughly evaluated an OSC's systems, policies, procedures, and practices against the 110 CMMC Level 2 practices. Initially, they found several deficient areas where practices were not fully met. The OSC took advantage of the Limited Practice Deficiency Correction program, which allowed them to provide additional evidence and implement corrections for certain deficient practices during the assessment period.
What status should the Lead Assessor recommend for CMMC Level 2 Certification if an OSC has 85 out of 110 practices scored as `MET' after applying the Limited Practice Deficiency Correction program?
A. The Lead Assessor will recommend the OSC receive a final finding of "Not Achieved" for CMMC Level 2 Certification. The OSC will be required to correct deficiencies and reapply for CMMC L2 Certification.You are a CCA who is part of an Assessment Team conducting a CMMC assessment on an aerospace company. While analyzing their network architecture, you realize that it includes a Demilitarized Zone (DMZ) to host their public-facing web servers.
What is the primary purpose of a DMZ in a network architecture?
A. To physically isolate the organization's internal network from the internetAn Assessor is evaluating controls put in place by an OSC to restrict the use of privileged accounts. The Assessor interviews privileged users and confirms that the OSC has both a policy and specific procedures governing the use of privileged accounts for security functions.
What else could the Assessor evaluate to validate the assertions made by the interviewed OSC staff?
A. Examine the system architecture of the OSC to identify privileged accountsDuring an assessment, it is uncovered that a CCA worked as a consultant for the OSC through their RPO.
Unfortunately, the CCA didn't disclose this when their C3PAO appointed them to participate in the assessment.
Did the CCA behave professionally?
If not, what issues are likely to arise?
A. Yes, the CCA behaved professionally.You are a CCA participating in an assessment exercise for an OSC. You have completed the exercise, and the OSC has hashed the evidence artifacts in accordance with the CMMC Artifact Hashing Tool User Guide.
What is the next step for your Assessment Team with respect to the Evidence Artifact Hashes?
A. Tell the OSC to encrypt the hash.You are a Lead Assessor working with your C3PAO to conduct a CMMC Assessment for an OSC. During the preparation and planning phase, you meet with the OSC's Assessment Official to identify the resources and schedule for the upcoming assessment. Together, you review the OSC's pre-assessment information to estimate the level of effort required. You then collaborate to determine the specific resources needed, including the Assessment Team members, facilities, and any support personnel from the OSC. You also discuss scheduling factors like duration, key activities, and potential constraints. Based on these discussions, you develop a Rough Order of Magnitude (ROM) cost estimate and a proposed daily schedule for the assessment activities.
Which of the following is not a requirement when identifying resources and schedules?
A. Documenting the names and roles of all assessment participants.An OSC uses an External Service Provider (ESP) to support part of its CUI processing scope. The OSC has selected an accredited ESP with FedRAMP MODERATE authorization. The OSC has a contract requiring the ESP to meet its security requirements. The ESP has provided a Shared Responsibility Matrix (SRM) consistent with the contract terms.
When assessing these assets, what should the assessor MOST carefully review?
A. The contract terms to ensure that the OSC's CMMC Level 2 requirements are in the contract, and the SRM to ensure that the shared responsibilities are well defined.An OSC has a large multi-building facility. One building is used as the OSC's data center. A guard is stationed at the entrance to the data center. A vendor engineer comes onsite to perform maintenance on the storage array in the data center. The guard knows the engineer well and has the engineer fill out the visitor log with the contact person's name and phone number, the reason for the visit, and the date and time.
Since the guard has known the engineer for many years, what is the BEST step the guard should take?
A. Call the contact person and let her know that the engineer is onsite and give the engineer a temporary badge to enter the data center.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.