You are the Lead Assessor for a CMMC Level 2 assessment. The OSC has implemented a practice using a custom-built tool developed by their IT team. The tool appears to meet the practice's objectives, but no formal documentation or testing records exist.
How should you evaluate this evidence?
A. Accept the tool as sufficient evidence since it meets the objectives.When examining a contractor's access control policy and SSP, you observe that system administrators routinely use accounts with elevated privileges for checking email and browsing internal websites.
Why is it critical to implement practice AC.L2-3.1.6 - Non-Privileged Account Use?
A. Enables easier auditing and logging of privileged activitiesDuring an assessment, the OSC was found to have implemented 68% of CMMC practice SC.L2-3.13.11 - CUI Encryption. However, the OSC Assessment Official cited issues with the vendor for not fully implementing the practice. Nonetheless, it has been listed in their POA&M.
Which of the following is true regarding the use of a POA&M during a CMMC assessment?
A. A POA&M addressing unimplemented security requirements is not a substitute for a completed CMMC practiceAn Assessor is examining documents provided by the OSC POC. While reviewing them, the Assessor notes that several of the procedures have very current dates while the bulk do not.
What should the Assessor do in order to decide if these new documents are acceptable as evidence?
A. Ensure the documents were approved by a senior-level manager.Which of the following can be taken into consideration when assessing AC.L2-3.1.3 Privacy & Security Notices?
A. System use notifications during system log-inYou are a Lead Assessor working with your C3PAO to conduct a CMMC Assessment for an OSC. During the preparation and planning phase, you meet with the OSC's Assessment Official to identify the resources and schedule for the upcoming assessment. Together, you review the OSC's pre-assessment information to estimate the level of effort required. You then collaborate to determine the specific resources needed, including the Assessment Team members, facilities, and any support personnel from the OSC. You also discuss scheduling factors like duration, key activities, and potential constraints. Based on these discussions, you develop a Rough Order of Magnitude (ROM) cost estimate and a proposed daily schedule for the assessment activities.
What is your primary responsibility in identifying resources and schedule during Phase 1?
A. Finalizing the contract agreement between the C3PAO and OSC.An OSC undergoing a CMMC Level 2 assessment provides evidence that includes a third-party audit report from a previous year. The report indicates compliance with several CMMC practices, but it does not address the current state of the OSC's systems.
How should the Lead Assessor treat this evidence?
A. Accept the audit report as sufficient evidence for the practices it covers.Some OSCs share real estate with other companies.
To protect FCI/CUI behind unmanned entrances to buildings, floors, or other areas where FCI/CUI is created, used, stored, or transmitted, which of the following is the BEST method?
A. Turnstiles to limit accessDuring your assessment of Defcon's (a contractor) implementation of CMMC Level 2 practices, you notice that their system for displaying security and privacy notices is insufficient. The banners currently in use lack detailed information about Controlled Unclassified Information (CUI) handling requirements and associated legal implications. Additionally, the banners are not consistently displayed across all contractor systems and workstations. Moreover, the banners on login pages disappear automatically after less than 5 seconds, providing insufficient time for users to read and acknowledge the content.
Which of the following is NOT a feature Defcon's updated privacy and security notices should have?
A. A warning about unauthorized use being subject to civil and criminal penaltiesAC.L1-3.1.2 requires OSCs to "limit information system access to the types of transactions and functions that authorized users are permitted to execute." Assessment Objective [a] of AC.L1-3.1.2 requires the Assessor to determine whether "the types of transactions and functions that authorized users are permitted to execute are defined."
What assessment method would you use to determine whether the OSC has met this assessment objective?
A. Interview system developersNowadays, the certification exams become more and more important and required by more and more enterprises when applying for a job. But how to prepare for the exam effectively? How to prepare for the exam in a short time with less efforts? How to get a ideal result and how to find the most reliable resources? Here on Vcedump.com, you will find all the answers. Vcedump.com provide not only Cyber AB exam questions, answers and explanations but also complete assistance on your exam preparation and certification application. If you are confused on your CMMC-CCA exam preparations and Cyber AB certification application, do not hesitate to visit our Vcedump.com to find your solutions here.