In assessing an OSC's CUI handling practices, you learn that they use an approved algorithm (AES-256) to encrypt the data to ensure its confidentiality. However, the cryptographic module they are using has not been validated under the FIPS 140 standard. The OSC believes that using an approved algorithm is sufficient to comply with the CMMC practice for CUI encryption requirements.
Where can you find information about a cryptographic module's current status with FIPS?
A. NIST CMVPYou are a CCA reviewing the security measures for a defense contractor seeking CMMC Level 2 compliance. CMMC practice PE.L2-3.10.6 - Alternative Work Sites requires the organization to safeguard CUI at alternative work sites, such as employee home offices. You are examining their list of safeguards and the system security plan to assess their compliance.
When assessing a contractor's implementation of CMMC practice PE.L2-3.10.6 - Alternative Work Sites, which of the following would be the least effective method for gathering information?
A. Using Full Disk Encryption (FDE) or container-based encryption to encrypt CUI when stored or transmitted from or to alternate work sitesThe OSC has assembled its documentation relating to how it controls remote access for assessment. The Lead Assessor compared this documentation to the provided topology map and noted several indications of external connections with External Service Providers (ESPs).
Which document is MOST LIKELY to show acceptable evidence of the security controls related to the interface between the OSC and the ESP?
A. OSC's access control policyAn OSC has recently obtained an ISO 27001 certification and a FedRAMP Authorization to Operate (ATO) for its information systems. During the initial stages of the CMMC Assessment Process, the OSC claims that these certifications should grant them automatic credit or exemption from certain CMMC requirements.
As the Lead Assessor, what should be your response?
A. Proceed with the CMMC Assessment as planned, disregarding the OSC's claim about their ISO 27001 and FedRAMP certifications.An OSC is a wholly owned subsidiary of a large conglomerate (parent organization). The OSC and the parent organization use ID badges (PKI cards) that contain a PKI certificate and a radio frequency identification (RFID) tag used for building and system access (including systems that process, transmit, or store CUI). The parent organization does not make any decisions on how the OSC runs its security program or other matters of significance. The large conglomerate operates a machine that is used to activate the badges for both itself and the OSC. This machine is isolated in a locked room and has no network connectivity to the OSC.
The badge activation system is:
A. In-scope because the parent organization acts as an External Service Provider to the OSC by providing PKI cards.NIST SP 800-171A specifies the assessment methods for defining the nature and the extent of a CCA's actions.
What is the purpose of the test assessment method?
A. To review, inspect, observe, or analyze assessment objectsDuring an assessment interview, the interviewee states that anyone can connect to the company Wi-Fi without prior approval.
Within which domains is the Wi-Fi configuration covered?
A. Media Protection (MP), Access Control (AC), and Physical Protection (PE)SecureNet is a mid-sized company that designs and manufactures access control systems for government buildings. These systems utilize Internet of Things (IoT) devices embedded within the access control panels for real-time remote monitoring. SecureNet is undergoing a CMMC Level 2 assessment to comply with new government contracting requirements. During the scope validation stage, the Certified CMMC Assessor (CCA) will review SecureNet's proposed assessment scope with the IT team. The scope includes all servers, workstations, and laptops within SecureNet's network. However, there is no mention
of the IoT devices within the access control panels.
Which of the following asset categories is most likely to encompass the in-scope IoT devices used in SecureNet's access control systems?
A. Security Protection Asset (SPA)During your assessment of CA.L2-3.12.3 - Security Control Monitoring, the contractor's CISO informs you that they have established a continuous monitoring program to assess the effectiveness of their implemented security controls. When examining their security planning policy, you determine that they have a list of automated tools they use to track and report weekly changes in the security controls. The contractor has also established a feedback mechanism that helps them identify areas for improvement in their security controls. During discussions with employees, you understand that the contractor regularly invites resource persons to train them on the secure handling of information and identifying gaps in implemented security controls.
You would rely on all of the following evidence to assess the contractor's implementation of CA.L2-3.12.3 - Security Control Monitoring, EXCEPT?
A. Records/logs of monitoring activities over timeTo verify the scope accuracy and integrity, a Lead Assessor asks for documents supporting some elements of the scope. However, the OSC states that the information is proprietary and requires that the Lead Assessor sign a Non-Disclosure Agreement (NDA) before granting access.
What should the Lead Assessor do?
A. File a complaint with the CMMC Accreditation Body (the Cyber AB).Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.