During the initial assessment framing discussions, the OSC POC attempts to sign off on the agreed-upon terms and scope of the assessment, asserting that they have the authority to enter into a legally binding contract with the C3PAO.
Which of the following must the C3PAO ascertain before the OSC POC signs off on the agreed terms and scope of the assessment?
A. That the C3PAO has provided the POC with all necessary training to make binding decisions.A CMMC assessment involves testing, examining, and interviewing various assessment objects. The definition of an assessment object is provided in NIST SP 800-171A.
Which of the following can an Assessment Object NOT be?
A. ActivitiesTo showcase progress on the performance of their contract, a contractor provides semi-annual demonstrations to their federal client at the client's conference room. The conference room is inside the client's facility, meaning the contractor does not have control over security. All prototypes and documents subject to the contract are guarded by the contractor's staff whenever they are in transit and at the conference room.
How should you, the CCA, handle the conference room when validating the OSC's assessment scope?
A. List it as in scope.During a CMMC assessment, you review the OSC's documented procedures for access control.These procedures detail a user access request and approval process for the organization's Human Resources (HR) information system. You then interview IT personnel responsible for access control, who confirm the documented procedures accurately reflect how access is managed for the HR system. However, the OSC's network diagram reveals the presence of other in-scope systems critical to their operations, such as their Engineering Design Database and Manufacturing Control System. Neither the documented procedures nor the interview addressed access control practices for these additional systems.
Based on the CMMC Assessment Process guidelines on evidence sufficiency, how would you characterize the evidence collected so far regarding access control?
A. Valid but incompleteDuring the assessment of a company, the CCA learns that 50% of employees work from home using remote access. After reviewing the Access Control policy and audit logs, the CCA is unsure how the system ensures only employees with correct privileges can access CUI. The CCA decides a Test of functionality is required.
Which question is of the LEAST concern to the CCA?
A. Are remote access sessions necessary?After you ask to examine some audit records, the contractor's system administrator informs you that there is a process to follow before accessing them. The logs are hashed using SHA-512 algorithms, and the system administrator has to run an algorithm to recalculate the hashes for the audit records to verify their integrity before running a decryption algorithm to decrypt the data. Since this might take some time, you tour the facility while interviewing personnel with audit and accountability roles. You see an employee holding the door for another without using their physical access card. While interviewing the contractor's employees, you find that they can access all audit logging tools and tweak the settings according to their needs or requirements. Upon examining the contractor's access control policy, you realize they have not defined the measures to protect audit logging tools.
Which of the following statements accurately describes the contractor's compliance with protecting audit logging tools from unauthorized access, modification, and deletion, as required by AU.L2-3.3.8 - Audit Protection?
A. The contractor's compliance cannot be determined based on the information providedAssessing a DoD contractor, you observe they have implemented physical security measures to protect their facility housing organizational systems that process or store CUI. The facility has secure locks on all entrances, exits, and windows. Additionally, video surveillance cameras are installed at entry/exit points, and their feeds are monitored by security personnel. Feeds from areas where CUI is processed or stored and meeting rooms where executives meet to discuss things that have to do with CUI and other sensitive matters are segregated and stored on a designated server after monitoring. Walking around the facility, you notice network cables are hanging from the walls. To pass through a door, personnel must swipe their access cards. However, you observe an employee holding the door for others to enter. Although power cables are placed in wiring closets, they aren't locked, and the cabling conduits are damaged.
Which of the following is NOT a concern regarding the contractor's implementation of CMMC practice PE.L2-3.10.2 - Monitor Facility?
A. Video surveillance monitoring at entry/exit pointsAny user who accesses CUI on system media should be authorized and have a lawful business purpose.
While assessing a contractor's implementation of MP.L2-3.8.2 - Media Access, you examine the CUI access logs and the roles of employees. Something catches your eye: an ID of an employee listed as terminated regularly accesses CUI remotely. Walking into the contractor's facilities, you observe the janitor cleaning an office where documents marked CUI are visible on the table. Interviewing the organization's data custodian, they inform you that a media storage procedure is augmented by a physical protection and access control policy.
Based on the scenario and the requirements of CMMC practice MP.L2-3.8.2 - Media Access, which of the following actions would be the highest-priority recommendation for the contractor?
A. Conduct additional training for employees on handling CUI materialsWhat should the Lead Assessor do to BEST ensure the evidence supplied effectively meets the intent of the standard for a practice?
A. Ensure the evidence for each objective under a practice is adequate.An Assessment Team is reviewing the scope of a CMMC assessment for an OSC. The OSC has defined a narrow security boundary for their assessment, which the Assessment Team believes may not adequately protect all sensitive information. The OSC gives reasons for this, including financial constraints, and claims that CUI is only contained within an enclave defined by the boundary. However, after inspecting the facility and interviewing employees, you determine that some assets that may process CUI are outside the enclave.
What is the risk of the OSC defining a security boundary that is too narrow in scope for the CMMC assessment?
A. The OSC will have more systems that need to be managed separately.Nowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.