An assessor is trying to determine if an OSC performs scans of their information system and real-time scans of files from external sources as files are downloaded or executed.
Which evidence is LEAST LIKELY to help this assessor?
A. System configuration settingsAfter numerous discussions and iterations, the OSC and Lead Assessor have finalized the Pre-Assessment Plan, which outlines the key details of how the assessment will be conducted, including the scope, timeline, resource requirements, and other logistical considerations.
What is the final step before commencing a CMMC assessment?
A. Obtaining approval from the Lead Assessor.Security Protection Assets (SPAs) include people, technologies, and facilities.
Which of the following technologies is not an SPA?
A. Hosted VPN ServicesAn OSC is preparing for a CMMC assessment. It has multiple information systems, some of which process CUI and others that do not. The OSC has identified a specific system that processes CUI and defined this as its system boundary. However, this system is connected to other systems within the OSC that are separately authorized and do not process CUI.
As a Certified CMMC Assessor, which of the following best describes your approach to defining the CMMC Certification Boundary and Assessment Scope for the OSC?
A. The CMMC Certification Boundary and Assessment Scope should include all information systems within the organization, regardless of whether they process CUI or not.SecureLogic Inc. is a cybersecurity consulting firm that provides managed security services to various defense contractors. During a CMMC assessment of one of their clients, the Lead Assessor finds that SecureLogic Inc. has provided evidence supporting several inherited practices related to incident response and vulnerability management.
Which of the following actions should the Lead Assessor take?
A. Automatically score the inherited practices as 'MET' based on SecureLogic Inc.'s evidence.You have been sent to assess an OSC's implementation of CMMC practices, one of which is AC.L2-3.1.11
- Session Termination.
You expect to find the following items when examining the contractor's list of conditions or trigger events requiring session termination, EXCEPT?
A. Time-of-day restrictions on system useDuring your on-site assessment, you examine an OSC's network architecture and the components that make up its defined security boundary. You notice various network devices, servers, and endpoints that are considered part of the OSC's information system. Additionally, the design team also uses a 3D printer to produce model prototypes.
Which of the following is not a boundary component?
A. The virtualization systemsYou are conducting a CMMC assessment for a contractor that develops software applications for the DoD.
During the assessment of the AU domain, you request to examine the contractor's audit and accountability policies, access control procedures, and system configuration documentation related to the management of audit logging functionality. Upon reviewing the documentation, the contractor has implemented a Role-Based Access Control (RBAC) model, where privileged users are assigned different roles based on their responsibilities. One of these roles is the "Audit Administrator" role, which is granted the necessary privileges to manage audit logging functionality across the contractor's systems. However, during interviews with the system administrators, you learn that besides the Audit Administrator role, several other privileged roles, such as the "System Administrator" and "Network Administrator" roles, can also manage audit logging functionality. When you inquire about the rationale behind granting multiple privileged roles access to audit management functions, the contractor's security team explains that this approach allows for better operational flexibility and ensures that different teams can perform audit logging tasks based on their areas of responsibility.
Based on the information provided in the scenario, how would you assess the contractor's compliance with CMMC practice AU.L2- 3.3.9 - Audit Management?
A. Partially Met -The contractor has limited audit management privileges to a subset of privileged users, but the roles may not be appropriately definedAfter the Assessment Team has been formed and the OSC Point of Contact (PoC) and Assessment Official have been identified, your C3PAO appoints John as the Lead Assessor. During the kickoff meeting, John reassures the OSC Assessment Official not to worry; they are guaranteed to pass the
CMMC assessment. If they don't, John has agreed to refund 40% of the assessment fee.
Which of the following is true about John's behavior as a Certified CMMC Assessor?
A. It is unprofessional.During a CMMC Level 2 assessment, the OSC's Assessment Official asks the Lead Assessor if they can provide a preliminary score before the assessment is complete to help prioritize remediation efforts.
What should the Lead Assessor do?
A. Provide a preliminary score based on the evidence reviewed so far.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.