Removable media can pose significant cybersecurity risks to an organization if not adequately controlled and secured. Understanding the dangers of this, an OSC has crafted a meticulous removable media policy. It defines removable media, types of removable media, examples of removable media, etc. The policy limits the use of removable media unless authorized; even then, the media must be scanned for
malware. Organizational removable media has specific signatures unique to organizational systems and provided to a defined group of personnel. Any data stored on such media is encrypted, and the OSC has disabled autorun and closed some ports on their computer systems. The contractor also has deployed an endpoint protection solution for every employee searched while entering or leaving the facility. Users must also pass through a walk-in metal detector to ensure they do not sneak in thumb drives and SD cards.
Based on the OSC's effort, how would you score their implementation of CMMC practice MP.L2-3.8.7 - Removable Media?
A. Not ApplicableAngela, a CCA, is conducting a CMMC assessment for Obsidian Technologies, the OSC. During the assessment, Angela learns that her spouse owns a significant amount of stock in Obsidian Technologies, and she has not disclosed this information to Obsidian Technologies or the C3PAO.
Which CMMC CoPC guiding principle has Angela violated in this scenario?
A. ObjectivityA CCA is conducting a CMMC assessment and notices that the OSC's evidence includes screenshots of system configurations that are not dated. The OSC claims the screenshots are current.
How should the CCA proceed?
A. Accept the screenshots as evidence since the OSC claims they are current.An OSC creates standard user accounts with limited capabilities and administrator accounts with full system access. A standard user initiates the uninstall of the anti-virus software, which is organizationally defined as a privileged function.
Which of the following would indicate AC.L2-3.1.7: Privileged Functions is properly implemented?
A. The antivirus software is not uninstalled.Steve is a Certified CMMC Assessor (CCA) who works for ACME Inc., which is both an RPO and a C3PAO. His aunt Mary works for ABC Holdings, and based on this connection, Steve convinces her boss to hire ACME Inc. to help prepare for a CMMC assessment. Steve leads the team and successfully completes the engagement with ABC Holdings. Six months later, Mary informs Steve that ABC Holdings is ready to perform its CMMC Level 2 assessment. Steve jumps at the opportunity and convinces his management at ACME Inc. to assign him as the lead CCA along with two other employees.
Which of the following is true about Steve's involvement in ABC Holdings' CMMC assessment?
A. Steve has a conflict of interest and should not be involved in officially assessing ABC Holdings.While conducting a Level 2 Assessment, the Assessment Team begins reviewing assessment objects.
The team identifies concerns with several of the objects presented.
Which artifacts would require the MOST verification?
A. Current artifacts produced by individuals performing the workThe Lead Assessor concludes that the OSC is not ready for the assessment. After the Readiness Assessment Review, the OSC and the Lead Assessor could choose to:
A. Replan or cancel the assessment.During a CMMC assessment, the OSC's IT manager asks the CCA if they can "fix" a non-compliant practice during the assessment to improve their score. The CCA declines and continues the assessment.
What CoPC principle does the CCA uphold by refusing to assist?
A. ConfidentialityA CCA is offered a significant discount on cybersecurity software from a vendor whose product they will be evaluating during a CMMC assessment.
How should the CCA handle this situation according to the CoPC's conflict of interest principle?
A. Inform the vendor that they can accept such offers only after the CMMC assessment is done.You are the Lead Assessor for a CMMC assessment of an OSC that has previously obtained ISO 27001 certification for its information security management system. During the initial discussions, the OSC requests that you consider their ISO 27001 certification and grant them credit toward their CMMC certification. They believe there is a significant overlap between CMMC and ISO 27001.
What should your response to the OSC be?
A. Defer the decision on non-duplication credit until the DoD publishes official non-duplication policies.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.