CMMC-CCA Exam Details

  • Exam Code
    :CMMC-CCA
  • Exam Name
    :Certified CMMC Assessor (CCA)
  • Certification
    :Cyber AB Certifications
  • Vendor
    :Cyber AB
  • Total Questions
    :527 Q&As
  • Last Updated
    :

Cyber AB CMMC-CCA Online Questions & Answers

  • Question 31:

    After numerous discussions and iterations, the OSC and Lead Assessor have finalized the Pre-Assessment Plan, which outlines the key details of how the assessment will be conducted, including the scope, timeline, resource requirements, and other logistical considerations.

    What is the final step before commencing a CMMC assessment?

    A. Obtaining approval from the Lead Assessor.
    B. Reviewing the Pre-Assessment Data Form.
    C. Uploading the Pre-Assessment Data Form into CMMC eMASS.
    D. Creating a new data upload in CMMC eMASS.

  • Question 32:

    During preparations for a CMMC Level 2 Assessment, a client submits a request to their consulting RP to learn more about Specialized Asset requirements. The client is unsure if their camera system, used for safety data collection purposes within their machining shop, should be documented within the SSP.

    Which reason is a satisfactory reason to exclude the camera system from the SSP, and thus the assessment scope?

    A. The video data are deleted every seven days.
    B. The Technology Control Plan does not address the camera system.
    C. The camera data are uploaded to a FedRAMP MODERATE authorized cloud storage system.
    D. The camera system network is physically and logically isolated and does not capture data related to controlled projects.

  • Question 33:

    The DoD has awarded a defense contractor a contract to deliver next-gen jet engine parts. The order requires the contractor to submit the blueprints/CAD files within six months, and once they are validated, the contractor submits a production schedule. The contractor indicates that they should be able to deliver the components in three years.

    Which of the following is true about the dates and schedule of the engine components?

    A. They must be protected under NIST SP 800-171
    B. They must be properly marked and labeled
    C. They are part of the OSC's CUI
    D. They must be protected in accordance with FAR 52.204-21

  • Question 34:

    You are the Lead Assessor of the Assessment Team conducting a CMMC Level 2 assessment for an OSC. You have completed the first phase of the assessment process, which included the assessment kickoff meeting. Now, you are moving into the second phase, which involves collecting and examining evidence to determine the OSC's compliance with the CMMC practices. During the assessment, you find that the OSC has failed to meet the requirements for CMMC practice AU.L2-3.3.4 - Audit Failure Alerting.

    According to the CMMC Assessment Process (CAP), which of the following should be your next step?

    A. Immediately stop the assessment and report the failure to the C3PAO.
    B. Mark the practice as "NOT MET" in the final assessment report without further action.
    C. Provide the OSC with a specific timeframe to remediate the failed practice.
    D. Evaluate the failed practice against the DoD Assessment Methodology and CMMC 2.0 POA&M scoring criteria.

  • Question 35:

    Ron is the Lead Assessor for an OSC's CMMC assessment. His team has scheduled interviews and demonstrations with the OSC's system administrator, Olivia. However, on the first day, the CEO informs Ron that Olivia is very ill and is unavailable. The CEO offers to be interviewed about Olivia's responsibilities instead, even though he does not actually perform those tasks.

    What should Ron do in this scenario?

    A. Have the CEO accompanied by another IT rep during the interview.
    B. Interview the CEO.
    C. It depends on the specific details discussed during the interview with the CEO.
    D. Reschedule the interviews with Olivia or continue with another person who understands and performs Olivia's duties while she is away.

  • Question 36:

    During the initial assessment framing discussions, the OSC POC attempts to sign off on the agreed-upon terms and scope of the assessment, asserting that they have the authority to enter into a legally binding contract with the C3PAO.

    Which of the following must the C3PAO ascertain before the OSC POC signs off on the agreed terms and scope of the assessment?

    A. That the C3PAO has provided the POC with all necessary training to make binding decisions.
    B. That the POC has decision-making authority within the company and can bind the OSC in agreements with the C3PAO.
    C. That the POC has met the DoD Cyber Workforce Requirements.
    D. That the POC has personally reviewed and approved all the assessment terms and scope details.

  • Question 37:

    An OSC specializing in developing directed energy systems plans to bid on a DoD contract to produce a 250kW High Energy Laser Weapon System (HELWS).

    This system is to be deployed on military bases across the globe to protect U.S. servicemen against aerial threats, including mortars, rockets, and unmanned aerial vehicles (UAVs), as well as swarms of mini-UAVs. Because of the sensitivity of the information, the OSC has prohibited using emails to transmit information regarding the project, whether encrypted or otherwise.

    They also have instituted procedures to remove CUI from the email system.

    The documents containing project information from the DoD are likely to contain which banner marking?

    A. CUI//SP-EXPT
    B. CUI//ITAR
    C. CUI//SP-CTI
    D. CUI//SP-ITAR

  • Question 38:

    The SSP for an OSC undergoing an assessment categorizes a device in the inventory that wirelessly connects to the network.

    In order to secure the connection of wireless devices that access a system that transmits, stores, or processes CUI, what are the requirements?

    A. Wireless access must be configured to use FIPS 140 validated cryptography.
    B. Wireless users must be vetted, and an Access Control List maintained for access to CUI.
    C. Wireless access must be configured to use FIPS 140 validated cryptography and limited to authenticated users.
    D. Wireless users must be specifically identified in network diagrams and configured to use FIPS 140 validated cryptography.

  • Question 39:

    An OSC previously received a Conditional CMMC Level 2 Certification during Phase 3 of the assessment process. The OSC has been working on implementing a POA&M to address the practice deficiencies identified during the initial assessment. Now, within 180 days from the Final Recommended Findings Briefing, you are to conduct a POA&M Closeout Assessment. As the Lead Assessor, you and your assessment team review the OSC's updated POA&M, accompanying evidence, and any scheduled observations, interviews, or tests with the aim of validating the implementation of the corrective actions.

    If any practices on the POA&M review fail to result in a score of `MET,' what should the Lead Assessor recommend?

    A. Update the POA&M with the remaining practice deficiencies for the OSC to address.
    B. Recommend the OSC NOT be recommended for CMMC Level 2 Final Certification.
    C. Conduct a follow-up assessment to review the remaining practice deficiencies.
    D. Extend the timeframe for the OSC to address the remaining practice deficiencies.

  • Question 40:

    You are the Lead Assessor of the Assessment Team conducting a CMMC Level 2 assessment for an OSC. You have completed the first phase of the assessment process, which included the assessment kickoff meeting. Now, you are moving into the second phase, which involves collecting and examining evidence to determine the OSC's compliance with the CMMC practices.

    Which of the following is not one of the recommended methods for collecting evidence during a CMMC assessment?

    A. Examine
    B. Self-Assessment by the OSC
    C. Interview
    D. Test

Tips on How to Prepare for the Exams

Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.