You are assessing an OSC that utilizes containerization technology for deploying microservices within a Kubernetes cluster. These microservices leverage various JavaScript frameworks for functionality. While a mobile device management (MDM) solution secures company phones, access to these microservices is primarily through web interfaces.
From a mobile code control perspective, what is the primary concern in this scenario?
A. The lack of mobile device management (MDM) for access through web interfacesAn OSC employs guards to protect the manufacturing shop where the magnetic radar-absorbing coating is manufactured. The Army uses this specific coating for a particular fleet of unmanned aerial vehicles (UAVs). The facility is under constant surveillance with the help of HD CCTVs. Within the OSC's facilities is a Vector Network Analyzer (VNA) that measures the reflection and transmission properties of the coating over a range of frequencies. Guards protect the OSC's anechoic chamber, and anyone entering must use an iris scanner and sign a physical form detailing their name and reason for being there. At the door is a huge sign reading "Authorized Personnel Only."
The OSC has implemented the following physical separation methods to secure its facilities, EXCEPT?
A. SignageAn OSC uses a cloud-based database for storing customer information. Employees access this database through a secure application on their company laptops. The database itself resides on servers managed by the Cloud Service Provider (CSP).
When employees use the application to access customer data, what type of location are they reaching?
A. A secure area within the OSC's data centerAn OSC is undergoing a CMMC Level 2 assessment. The assessment team is reviewing the evidence for configuration management procedures per CMMC Practice CM.L2-3.4.1 - System Baselining. The assessors discover that the OSC has a documented process for creating system baselines. However, upon reviewing a sample server, they find software installed that is not listed in the baseline documentation. The OSC acknowledges the discrepancy and explains that they recently deployed new security software but have not updated the baseline documentation yet.
The following conditions hold true for CMMC practices ineligible for deficiency corrections EXCEPT?
A. Practices that could lead to significant exploitation of the network or exfiltration of CUI.A midsized professional services organization that frequently contracts with government entities is undergoing a CMMC Level 2 assessment. The CCA interviews IT leadership about their audit logging capabilities and determines that a third-party vendor is responsible for correlating and reviewing audit logs. During the interview, they discuss the process that has been implemented by the vendor to provide a monthly summary of their audit log review to the organization.
What issue should the CCA resolve during the interview?
A. The vendor has the ability to provide report generation.An OSC has contacted your C3PAO organization for a prospective CMMC Level 2 assessment. You have been selected to lead the Assessment Team. When ascertaining the assessment conditions and requirements, you discuss the prospective CMMC assessment scope with the OSC.
Before proceeding to Phase 2 of the CMMC assessment process, the OSC must complete the following steps of its high-level scoping process, EXCEPT?
A. Identify and take inventory of the various categories of CMMC assets contained in the networked environment.During the initial engagement with an OSC, they appoint an OSC Point of Contact (PoC). The Assessment Official informs your Assessment Team that they will regularly collaborate with the PoC in their daily engagements and assigns several responsibilities to this Point of Contact.
Which of the following is not one of the OSC PoC's responsibilities?
A. Coordinating site access and communicating visitation policies.A small manufacturing company plans to undergo a CMMC assessment and needs to validate its scope.
The company uses a cloud-based customer relationship management (CRM) system hosted by an external provider to store and process customer information, including FCI and CUI.
Which of the following components should the company include in the scope of their CMMC assessment?
A. The company's internal servers and client computers, but not the cloud-based CRM system or the external service provider.A DoD contractor developing guidance and targeting systems has subcontracted a data analytics company to analyze their data accuracy.
How should the DoD contractor handle the analytics company when preparing a CMMC assessment scope?
A. Include only assets of the analytics company that deal with their equipment data analytics.While assessing an OSC, you realize they have given identifiers to systems, users, and processes.
Examining their documentation, you know they have assigned accounts uniquely to employees, contractors, and subcontractors. The OSC has an automated system that disables any identifiers that are left unused for 6 months. You also learn from interviewing IT security administrators that the OSC has defined a technical and documented policy where identifiers can only be reused after 12 months.
How is the OSC likely to consider CMMC practice IA.L2-3.5.5 - Identifier Reuse if you find issues with its implementation?
A. List it in their SSPNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.