Cyber AB CMMC-CCA Online Practice
Questions and Exam Preparation
CMMC-CCA Exam Details
Exam Code
:CMMC-CCA
Exam Name
:Certified CMMC Assessor (CCA)
Certification
:Cyber AB Certifications
Vendor
:Cyber AB
Total Questions
:527 Q&As
Last Updated
:Jul 12, 2026
Cyber AB CMMC-CCA Online Questions &
Answers
Question 411:
While conducting a CMMC Level 2 gap analysis with a large defense contractor, a CMMC RP confirms that the organization uses a RADIUS server for authentication.
What additional method could be used to comply with AC.L2-3.1.17: Wireless Access Protection?
A. Layer 3 switch B. Intrusion detection solution C. WPA2-Enterprise encryption D. Frequency-hopping wireless access
C. WPA2-Enterprise encryption
Explanation
Applicable Requirement: AC.L2-3.1.17 -"Authorize wireless access prior to allowing such connections."
Correct Interpretation: Strong authentication and encryption methods (e.g., WPA2-Enterprise, WPA3- Enterprise) are required to protect wireless communications and enforce authorization.
Why Option C is Correct: WPA2-Enterprise uses 802.1X authentication (often with RADIUS), ensuring that only authorized users/devices can connect. This directly supports AC.L2-3.1.17.
Why Other Options Are Insufficient:
Option A (Layer 3 switch): Network hardware but not specifically a wireless access control mechanism.
Option B (IDS): Detects intrusions but does not prevent or authorize wireless access.
Option D (Frequency-hopping): Obsolete method, not aligned with modern encryption/authentication requirements.
A contractor allows for the use of mobile devices in contract performance. Some employees access designs and specifications classified as CUI on such devices like tablets and smartphones. After assessing AC.L2-3.1.18 - Mobile Device Connection, you find that the contractor maintains a meticulous record of mobile devices that connect to its information systems. AC.L2-3.1.19 - Encrypt CUI on Mobile requires that the contractor implements measures to encrypt CUI on mobile devices and mobile computing platforms. The contractor uses device-based encryption where all the data on a mobile device is encrypted.
Which of the following is a reason why would you recommend container-based over full-device-based encryption?
A. Container-based encryption offers granular control over sensitive data, improves device performance by encrypting selectively, and enhances security in Bring-Your-Own-Device (BYOD) environments B. Container-based encryption is more cost-effective C. It is more user-friendly and easier to deploy on a large scale D. Full-device encryption is not compatible with modern mobile operating systems
A. Container-based encryption offers granular control over sensitive data, improves device performance by encrypting selectively, and enhances security in Bring-Your-Own-Device (BYOD) environments
Question 413:
A Defense Contractor is preparing for their upcoming CMMC Level 2 assessment. One of the key controls they need to address is CMMC practice MP.L2-3.8.5 - Media Accountability, which deals with maintaining accountability for media containing CUI during transport outside of controlled areas. The organization regularly needs to transport physical media, such as hard drives and backup tapes, between their primary data center and an off-site storage facility. In the past, they have simply used standard packaging and commercial shipping services to move this media.
Which of the following best describes a control that maintains accountability for media containing CUI during transport outside of controlled areas?
A. Using tamper-proof packaging and a reputable shipping service with tracking B. Implementing strong passwords for all user accounts C. Training employees on information security best practices D. Restricting access to the system where the CUI data resides
A. Using tamper-proof packaging and a reputable shipping service with tracking
Question 414:
An OSC and a C3PAO Assessment Team are in the early stages of preparing for their CMMC assessment. During the process of confirming the corporate identity for the assessment, the Assessment Team discovers that the OSC does not have a valid Commercial and Government Entity (CAGE) code issued by the Department of Defense. The team is now considering the implications of this finding and the next steps they should take.
When confirming the corporate identity to be assessed, what can happen if you determine that the HQ organization doesn't have a valid CAGE code?
A. You would help the OSC register and obtain a CAGE code from the DoD. B. The assessment cannot continue. C. You would request a waiver from the DoD. D. You would continue with the assessment as planned.
B. The assessment cannot continue.
Question 415:
When a new employee is issued a laptop, only the user's credentials need to be set up. According to the IT department, the IT manager is the only person who can change laptop setup and user privileges.
What documentation should be examined to determine if this is the case?
A. System audit logs B. Inventory records C. Acceptable use policy D. Remote access procedures
A. System audit logs
Explanation
Applicable Requirement: AC.L2-3.1.5 -"Employ the principle of least privilege, including for specific security functions and privileged accounts."
Why A is Correct: Audit logs document when privileged functions (such as account creation, privilege changes, or configuration changes) occur, who performed them, and whether access control restrictions are enforced. Reviewing logs is the only way to confirm the IT manager alone has the capability.
Why Other Options Are Insufficient:
Option B (Inventory records): Shows ownership, not privilege changes.
Option C (Acceptable use): Policy guidance, not enforcement evidence.
Option D (Remote access): Deals with remote connections, not privilege management.
An OSC uses a colocation facility to house its CUI assets. The colocation restricts access to the data center via keycard and requires all entrants to sign in and out. The OSC's cage and cabinets are further secured with keys accessible only to OSC-authorized personnel.
In order to assess physical controls, the CCA should:
A. Physically visit the colocation facility to determine the effectiveness of controls. B. Evaluate the colocation facility security process as listed in the service agreement. C. Physically visit the colocation facility to determine the effectiveness of controls and review the OSC's process for maintaining access to the keys. D. Evaluate the colocation facility security process as listed in the service agreement and review the OSC's process for maintaining access to the keys.
C. Physically visit the colocation facility to determine the effectiveness of controls and review the OSC's process for maintaining access to the keys.
Explanation
The Physical Protection (PE) practices require both direct assessor observation of security controls and verification of how the OSC manages access to its cages/cabinets.
Extract:
"Assessors should observe and verify the effectiveness of physical access controls and confirm the OSC's processes for maintaining control over restricted areas and assets."
Thus, the best option is to physically visit the facility and review OSC's key access management process.
References:
CMMC Assessment Guide - Level 2, PE Practices.
Question 417:
An OSC assigns new hires to work on their hire date. Human Resources ensures that all screening activities are completed before the end of the employees' first week.
How should the CCA score PS.L2-3.9.1: Screen Individuals?
A. As NOT MET but it can be remediated post-assessment B. As NOT MET and this will cause the assessment to fail C. As MET since the OSC ensured Human Resources was handling the screening D. As NOT MET because all screening must be completed prior to the start of employment
D. As NOT MET because all screening must be completed prior to the start of employment
Explanation
The control PS.L2-3.9.1: Screen Individuals requires that individuals be screened before authorizing access to organizational systems and CUI. Since employees are assigned to work immediately upon hire, before screenings are complete, this practice is NOT MET. Completing screenings within the first week does not satisfy the requirement.
Exact extracts:
"Screen individuals prior to authorizing access to organizational systems containing CUI." "Assessment Objectives... Determine if: [a] individuals requiring access to CUI are screened before access is granted." "It is not sufficient for screening to occur after access has been authorized."
Why the other options are incorrect:
Option A: Remediation may be possible, but scoring must be NOT MET.
Option B: A single practice being NOT MET does not automatically cause assessment failure (depends on aggregate score).
Option C: HR responsibility does not excuse failure to complete screening before granting access.
You are a CCA evaluating an OSC's proposed CMMC assessment scope when planning and preparing a CMMC assessment. The assessment scope is defined in CMMC Assessment Scope - Level 2.
Which statement best defines the assessment scope according to CMMC guidelines?
A. It focuses solely on the cybersecurity measures implemented within the organization. B. It includes the boundaries within an organization's networked environment that contain all the assets that will be assessed. C. It encompasses the entire organization's IT infrastructure. D. It includes only the physical components of the information system.
B. It includes the boundaries within an organization's networked environment that contain all the assets that will be assessed.
Question 419:
A CCA is conducting an interview with an OSC team member about an offering from a well-known Cloud Service Provider (CSP). The offering is known to be secure, but the OSC has not provided evidence and the person being interviewed is unsure how the offering works.
Will this offering be accepted by the Assessment Team?
A. Yes, because of the process of reciprocity B. No, the OSC failed to train on the offering C. No, because the OSC lacks adequate and sufficient evidence D. Yes, because the CSP offering is a well-known, secure offering
C. No, because the OSC lacks adequate and sufficient evidence
Explanation
CMMC assessments are evidence-based. An offering cannot be accepted solely on reputation or assumptions of security. The OSC must provide adequate and sufficient evidence that the CSP offering meets CMMC requirements. Without evidence, the assessor cannot mark the practice as MET.
Exact Extracts:
CMMC Assessment Guide: "Assessment determinations must be based on objective evidence; absence of evidence results in a finding of NOT MET." "Evidence may include documentation, interviews, and tests but must be sufficient to confirm implementation." "Reciprocity is not granted for external offerings unless evidence is provided."
Why other options are not correct:
Option A (reciprocity): CMMC does not allow blanket reciprocity for cloud offerings without validation.
Option B (training issue): Training is separate; the core issue is lack of evidence.
Option D (well-known CSP): Reputation alone is not evidence; objective evidence is required.
NIST SP 800-171Option A: Requirement to use objective evidence.
Question 420:
Testing is one assessment method the Lead Assessor may choose depending on the assessment scope and evidence provided by the OSC.
During the Plan Phase, the Lead Assessor and OSC POC agree on who the people are that are involved in a particular practice so that it could be tested if determined appropriate.
During the discussion, the OSC POC tells the Lead Assessor that the production system is in use and cannot be stopped for the testing to take place but offers a mirrored system for testing.
The Lead Assessor decides:
A. Only to test the processes conducted by the supporting groups B. Only to test the Customer Matrices that are available C. Not to perform testing as a mirrored system is not an acceptable substitute for the production system D. To ask the OSC for evidence that a mirrored system is exactly the same as the production system to conduct testing
D. To ask the OSC for evidence that a mirrored system is exactly the same as the production system to conduct testing
Explanation
Testing may be performed on a mirrored system if the OSC can demonstrate that it is configured identically to the production system. The assessor must confirm equivalency through objective evidence before accepting test results.
Exact Extracts:
NIST SP 800-171Option A: "Test assessment method involves exercising assessment objects under specified conditions... mirrored or replicated systems may be used if validated as equivalent."
CMMC Assessment Guide: "If production systems cannot be tested, assessors may accept mirrored systems provided evidence demonstrates that the mirrored environment is representative of the production system."
Why the other options are not correct:
Option A/B: Testing must focus on systems and controls, not limited groups or customer matrices.
Option C: Incorrect - mirrored systems are acceptable if validated as equivalent.
Option D: Correct, as validation of equivalency is required.
References:
CMMC Assessment Guide - Level 2, Version 2.13: Testing methods and mirrored systems (pp. 6-8).
Nowadays, the certification exams become more and more important and required by more and more
enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare
for the exam in a short time with less efforts? How to get a ideal result and how to find the
most reliable resources? Here on Vcedump.com, you will find all the answers.
Vcedump.com provide not only Cyber AB exam questions,
answers and explanations but also complete assistance on your exam preparation and certification
application. If you are confused on your CMMC-CCA exam preparations
and Cyber AB certification application, do not hesitate to visit our
Vcedump.com to find your solutions here.