Pass the Cyber AB CMMC CMMC-CCA Questions and answers with CertsForce

Viewing page 8 out of 12 pages
Viewing questions 71-80 out of questions
Questions # 71:

To transfer CUI between a government client and its internal systems, a defense contractor uses a Secure File-Sharing Application provided by the DoD. However, all data traversing this boundary must pass through a next-generation firewall (NGFW) managed by the contractor’s Network Admin. All CUI is stored on a Solid State Drive (SSD) and accessed through a laptop. What type of asset is the Network Admin?

Options:

A.

Contractor Risk Managed Asset (CRMA)


B.

Security Protection Asset (SPA)


C.

Specialized Asset


D.

CUI Asset


Expert Solution
Questions # 72:

When discussing the OSC’s proposed assessment scope, the Lead Assessor learned that some laptops and workstations share a network with CUI assets, but their users do not work with CUI. These assets do not store CUI or run applications that process CUI. Reviewing the OSC’s SSP, the implemented risk-based security policies, procedures, and practices raised questions and were found to be deficient. What can the Lead Assessor do in this scenario?

Options:

A.

Inform the C3PAO so as to obtain advice on the way forward.


B.

Advise the OSC PoC or Assessment Official to address the identified deficiencies.


C.

Conduct a limited spot check to identify risks.


D.

Validate the scope because the assets do not interact with CUI.


Expert Solution
Questions # 73:

An OSC has submitted an assessment scope that includes some CUI and security protection assets. As a Lead Assessor, you are validating the CMMC assessment scope in preparation for a CMMC assessment for the OSC. How should you handle CUI and Security Protection Assets during the actual CMMC assessment?

Options:

A.

Assess the assets against a subset of the 110 controls.


B.

Conduct limited spot checks.


C.

Review only in the OSC’s SSP.


D.

Assess the assets against the 110 CMMC practices.


Expert Solution
Questions # 74:

An OSC is planning to have a C3PAO perform a CMMC Level 2 assessment. When validating the OSC’s proposed assessment scope, you realize they use an ESP for various cybersecurity services. What action must you, as a CCA, take regarding the ESP?

Options:

A.

Confirm the ESP has a CMMC Level 2 or Level 3 certification.


B.

Accept the OSC’s inclusion of the ESP in their assessment scope.


C.

Advise the OSC to choose another ESP.


D.

Request a self-assessment from the ESP.


Expert Solution
Questions # 75:

When validating an OSC’s assessment scope, an Assessment Team learns that the proposed scope is too narrow and their asset categorization is mixed up. What should the Assessment Team do?

Options:

A.

Review the OSC’s environment and asset categorization to determine the proper scoping for the organization.


B.

Stop the assessment.


C.

Advise the OSC to conduct another scoping exercise that covers all assets.


D.

Require the OSC to refine its security boundaries to include all assets that come into contact with CUI.


Expert Solution
Questions # 76:

To transfer CUI between a government client and its internal systems, a defense contractor uses a Secure File-Sharing Application provided by the DoD. However, all data traversing this boundary must pass through a next-generation firewall (NGFW) managed by the contractor’s Network Admin. All CUI is stored on a Solid State Drive (SSD) and accessed through a laptop. What type of asset is the Secure File-Sharing Application?

Options:

A.

Out of Scope


B.

CUI Asset


C.

Security Protection Asset (SPA)


D.

Contractor Risk Managed Asset (CRMA)


Expert Solution
Questions # 77:

A software development company is applying for a CMMC Level 2 assessment. As the Lead Assessor, you request access to the company’s System Security Plan (SSP) as part of the initial objective evidence for validating the scope. Which of the following is true about the software development company’s obligations in honoring the request?

Options:

A.

The software development company can refuse to provide the SSP if they deem it contains proprietary information.


B.

The software development company is not obligated to provide the SSP until after the assessment has begun.


C.

The software development company can choose to provide a redacted version of the SSP, omitting sensitive information.


D.

The software development company must furnish the Lead Assessor with the SSP.


Expert Solution
Questions # 78:

A software development company uses a cloud-based source code repository and continuous integration/continuous deployment (CI/CD) platform to manage its software development lifecycle. The cloud service provider hosts and manages the source code repository and CI/CD platform. Which of the following statements accurately describes how the OSC should handle the cloud service provider’s assets in the CMMC Assessment Scope?

Options:

A.

Exclude the cloud provider’s assets from the Assessment Scope since they are not owned or managed by the company.


B.

Include the cloud provider’s assets in the Assessment Scope as they handle sensitive code.


C.

Include the cloud service provider’s assets in the certification boundary but exclude them from the assessment scope.


D.

It depends on the contract between the company and the cloud provider.


Expert Solution
Questions # 79:

An aerospace company has requested a CMMC assessment for an enclave only. Your team has verified that the company has a valid CAGE code and is registered with SAM.gov. However, the enclave has no separate CAGE code or SAM registration. Can the assessor proceed with the CMMC assessment solely for the enclave, or is an assessment of the entire aerospace company’s network required?

Options:

A.

The assessor can proceed with the enclave assessment for CMMC Level 2 compliance.


B.

The assessor cannot proceed with the enclave assessment.


C.

The assessor must assess the entire company network.


D.

The assessor can proceed with the enclave assessment, but only for a lower CMMC level.


Expert Solution
Questions # 80:

An OSC has produced two assessment scopes. When the Lead Assessor questioned the OSC PoC why, they detailed that they process, store, or transmit FCI within one assessment scope and CUI in another. Which scope will the OSC obtain a CMMC Level 2 certification for?

Options:

A.

The scope that processes, transmits, or stores FCI


B.

The scope that transmits, processes, or stores CUI


C.

For both assessment scopes


D.

The OSC cannot be certified at Level 2 because they haven’t met Level 1 requirements


Expert Solution
Viewing page 8 out of 12 pages
Viewing questions 71-80 out of questions