Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 1 out of 7 pages
Viewing questions 1-10 out of questions
Questions # 1:

A Lead Assessor has been assigned to a CMMC Assessment During the assessment, one of the assessors approaches with a signed policy. There is one signatory, and that person has since left the company. Subsequently, another person was hired into that position but has not signed the document. Is this document valid?

Options:

A.

The signatory is the authority to implement and enforce the policy, and since that person is no longer with the company, the policy is not valid.


B.

More research on the company policy of creating, implementing, and enforcing policies is needed. If the company has a policy identifying the authority as with the position or person, then the policy is valid.


C.

The signatory does not validate or invalidate the policy. For the purpose of this assessment, ensuring that the policy is current and is being implemented by the individuals who are performing the work is sufficient.


D.

The authority to implement and enforce lies with the position, not the person. As long as that position's authority and responsibilities have not been removed from implementing that domain, it is still a valid policy.


Expert Solution
Questions # 2:

Within what amount of time MUST convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not connected with activities that relate to carrying out a Lead Assessor role, be reported to the CMMC Accreditation Body?

Options:

A.

90 days.


B.

30 days.


C.

3 days.


D.

7 days.


Expert Solution
Questions # 3:

When assessing an OSC for CMMC: the Lead Assessor should use the information from the Discussion and Further Discussion sections in each practice because it:

Options:

A.

is normative for an OSC to follow.


B.

contains examples that an OSC must implement.


C.

is mandatory and aligns with FAR Clause 52.204-21.


D.

provides additional information to facilitate the assessment of the practice.


Expert Solution
Questions # 4:

While conducting a CMMC Assessment, an individual from the OSC provides documentation to the assessor for review. The documentation states an incident response capability is established and contains information on incident preparation, detection, analysis, containment, recovery, and user response activities. Which CMMC practice is this documentation attesting to?

Options:

A.

IR.L2-3.6.1: Incident Handling


B.

IR.L2-3.6.2: Incident Reporting


C.

IR.L2-3.6.3: Incident Response Testing


D.

IR.L2-3.6.4: Incident Spillage


Expert Solution
Questions # 5:

The Audit and Accountability (AU) domain has practices in:

Options:

A.

Level 1.


B.

Level 2.


C.

Levels 1 and 2.


D.

Levels 1 and 3.


Expert Solution
Questions # 6:

An OSC performing a CMMC Level 1 Self-Assessment uses a legacy Windows 95 computer, which is the only system that can run software that the government contract requires. Why can this asset be considered out of scope?

Options:

A.

It handles CUI


B.

It is a restricted IS


C.

It is government property


D.

It is operational technology


Expert Solution
Questions # 7:

The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?

Options:

A.

Affirmation for each practice or control


B.

Documented rationale for each failed practice


C.

Suggested improvements for each failed practice


D.

Gaps or deltas due to any reciprocity model are recorded as met


Expert Solution
Questions # 8:

During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?

Options:

A.

CCP


B.

C3PAO


C.

Lead Assessor


D.

Advisory Board


Expert Solution
Questions # 9:

The IT manager is scoping the company's CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?

Options:

A.

ESP


B.

People


C.

Facilities


D.

Technology


Expert Solution
Questions # 10:

An Assessment Team is conducting a Level 2 Assessment at the request of an OSC. The team has begun to score practices based on the evidence provided. At a MINIMUM what is required of the Assessment Team to determine if a practice is scored as MET?

Options:

A.

All three types of evidence are documented for every control.


B.

Examine and accept evidence from one of the three evidence types.


C.

Complete one of the following; examine two artifacts, either observe a satisfactory demonstration of one control or receive one affirmation from the OSC personnel.


D.

Complete two of the following: examine one artifact, either observe a satisfactory demonstration of one control or receive one affirmation from the OSC personnel.


Expert Solution
Viewing page 1 out of 7 pages
Viewing questions 1-10 out of questions