Pass the Cyber AB CMMC CMMC-CCA Questions and answers with CertsForce

Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions
Questions # 41:

An organization has contracted with a third party for system maintenance and support. The third-party personnel all work remotely. Which of the following should an assessor assure is in place?

Options:

A.

Only third-party personnel can perform system maintenance functions.


B.

Third-party personnel need to be identified and monitored while performing maintenance.


C.

The number of third-party personnel who can access the organization’s systems concurrently is limited.


D.

Remote access to systems used by the third party for maintenance functions is terminated automatically based on a defined set of criteria.


Expert Solution
Questions # 42:

A company is seeking Level 2 CMMC certification. During the Limited Practice Deficiency Correction Evaluation, the Lead Assessor is deciding whether the company can be moved to a POA&M Close-Out. What condition will result if a POA&M Close-Out option cannot be utilized?

Options:

A.

The assessment will be paused until the OSC can meet all practices.


B.

The Lead Assessor will ask the OSC to justify not meeting all the practices.


C.

The OSC will be granted a provisional status until it can meet all the practices.


D.

The Lead Assessor will not recommend the OSC for CMMC Level 2 certification.


Expert Solution
Questions # 43:

A company describes its organization as having two systems. One system, System Org, covers the entire organization and allows instant messaging, email, and Internet activity. The other system, System CUI, is used for processing, storing, and transmitting CUI data. System CUI interfaces with System Org through security mechanisms and a firewall.

The CMMC Assessment is being done on System CUI only.

What is the BEST way to describe System CUI?

Options:

A.

CUI Assets


B.

In-Scope Assets


C.

Out-of-Scope Assets


D.

CUI Assets and Security Protection Assets


Expert Solution
Questions # 44:

A company has four waterjet machines with very limited computing capabilities. The company loads CUI onto these machines for machining parts and uses CUI as necessary for machining.

Should these waterjet machines be part of the CMMC Assessment?

Options:

A.

No, these waterjet machines are Out-of-Scope Assets and do not need to be assessed.


B.

Yes, these waterjet machines are CUI Assets that must be assessed because they handle CUI.


C.

Yes, these waterjet machines are Specialized Assets that are within the scope of a CMMC Assessment.


D.

No, these waterjet machines are Contractor Risk Managed Assets and do not need to be assessed.


Expert Solution
Questions # 45:

An OSC is presenting the CMMC Assessment to the C3PAO along with all supporting documentation. The supporting documents include drawings from a patent application that has not been filed with the patent office and are marked as attorney-client privileged. What document is recommended that the OSC and C3PAO sign?

Options:

A.

Formal contract


B.

Statement of Work


C.

Non-disclosure agreement


D.

Formal disclosure agreement


Expert Solution
Viewing page 5 out of 5 pages
Viewing questions 41-50 out of questions