You are assessing Conedge Ltd, a contractor that develops cryptographic algorithms for classified government networks. In reviewing their network architecture documents, you see they have implemented role-based access controls on their workstations using Active Directory group policies. Software developers are assigned to the "Dev_Roles" group which grants access to compile and test code modules.
The "Admin_Roles" group with elevated privileges for system administration activities is restricted to the IT staff. However, when you examine the event logs on a developer workstation, you find evidence that a developer was able to enable debugging permissions to access protected kernel memory - a privileged function.
Which of the following controls could have prevented the developer from executing this privileged function?
A. Removing internet accessA CCA is conducting a CMMC assessment and notices that the OSC's evidence includes a policy document that is outdated by two years. The OSC insists that the policy is still in effect, but staff interviews indicate that newer, undocumented procedures are being followed.
How should the CCA handle this situation?
A. Accept the outdated policy as evidence since the OSC claims it is still in effect.A C3PAO is conducting a Level 2 assessment of a midsized construction contractor that does both private (commercial) and federal work. The contractor's documentation states that all CUI flows through a single building on their office campus and is logically, physically, and administratively isolated from the rest of the environment.
Why might an assessor request access to assess controls within a building or area not listed as in-scope in the documentation?
A. If the assessor sees personnel carrying locked cases into the other building or areaIn an effort to understand whether the OSC appropriately defined the scope to exclude items that should not be assessed, which description does NOT belong in the scope?
A. Data center in another state used by the OSCAfter you ask to examine some audit records, the contractor's system administrator informs you that there is a process to follow before accessing them. The logs are hashed using SHA-512 algorithms, and the system administrator has to run an algorithm to recalculate the hashes for the audit records to verify their integrity before running a decryption algorithm to decrypt the data. Since this might take some time, you tour the facility while interviewing personnel with audit and accountability roles. You see an employee holding the door for another without using their physical access card. While interviewing the contractor's employees, you find that they can access all audit logging tools and tweak the settings according to their needs or requirements. Upon examining the contractor's access control policy, you realize they have not defined the measures to protect audit logging tools.
Considering CMMC AU.L2-3.3.8 - Audit Protection and best practices, which of the following is the MOST concerning finding regarding the employees' access to audit logging tools?
A. Employees have unrestricted access to all audit logging tools and can modify settingsA company describes its organization as having two systems. One system, System Org, covers the entire organization and allows instant messaging, email, and Internet activity. The other system, System CUI, is used for processing, storing, and transmitting CUI data. System CUI interfaces with System Org through security mechanisms and a firewall. The CMMC Assessment is being done on System CUI only.
What is the BEST way to describe System CUI?
A. CUI AssetsA CCA is part of an Assessment Team conducting a CMMC Level 2 assessment. During an interview, an OSC employee admits that a critical security practice is not implemented because "it's too expensive." The CCA responds by suggesting a low-cost alternative solution to implement the practice.
What should the CCA have done instead?
A. Noted the employee's statement and continued the interview without offering any suggestions.An OSC has built an enclave for its production environment. The enclave sits behind a firewall, with all equipment connected through a switch. There is a shipping workstation and physically connected label printer (used for the sales system, which does not process CUI) that the OSC claims are Contractor Risk Managed Assets (CRMA). Other than showing that the shipping workstation and label printer are not intended to store or transmit CUI, and documenting them in the SSP.
How BEST would the OSC show that the shipping workstation and label printer are Contractor Risk Managed Assets?
A. Document in the asset inventory and include them in the network diagram to facilitate scoping discussions during the pre-assessment.An OSC is planning a CMMC Level 2 assessment that your C3PAO will conduct. In Phase 1.6.1 - Access and Verify Evidence, as the Lead Assessor, you are verifying the existence and accessibility of the evidence provided by the OSC. While reviewing the list of evidence mapped against the CMMC practices, you discover that the OSC cannot locate several critical system security policies for key IT systems supporting their DoD contracts. These missing policies are essential for demonstrating compliance with various CMMC practices related to access control, incident response, and system maintenance.
What is the primary role of the CMMC Quality Assurance Professional (CQAP) regarding the Pre-Assessment Form?
A. To verify the accuracy and completeness of the information before uploading to CMMC eMASS.You are the Lead Assessor for a CMMC Level 2 assessment. During the assessment, the OSC provides evidence that a practice is inherited from a cloud service provider (CSP). The CSP has a FedRAMP Moderate authorization, and the OSC argues that this should automatically satisfy the practice's requirements.
How should you respond?
A. Accept the FedRAMP authorization as sufficient evidence and score the practice as "MET."Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.