Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 1 out of 7 pages
Viewing questions 1-10 out of questions
Questions # 1:

A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?

Options:

A.

24 hours


B.

48 hours


C.

72 hours


D.

96 hours


Expert Solution
Questions # 2:

Which regulation allows for whistleblowers to sue on behalf of the federal government?

Options:

A.

NISTSP 800-53


B.

NISTSP 800-171


C.

False Claims Act


D.

Code of Professional Conduct


Expert Solution
Questions # 3:

Within the CMMC Ecosystem which organization ultimately will manage and oversee the training, testing, authorization, and certification of candidate assessors and instructors?

Options:

A.

DoD OUSD


B.

DIB Collaborative Information Sharing Environment


C.

Committee on National Security Systems Instructions


D.

CMMC Assessors and Instructors Certification Organization


Expert Solution
Questions # 4:

A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?

Options:

A.

The process is running correctly.


B.

It is out of scope as this is a new acquisition.


C.

The new acquisition is considered Specialized Assets.


D.

Practice is NOT MET since the objective was not implemented.


Expert Solution
Questions # 5:

Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?

Options:

A.

Level 1


B.

Level 2


C.

Level 3


D.

All levels


Expert Solution
Questions # 6:

Who makes the final determination of the assessment method used for each practice?

Options:

A.

CCP


B.

osc


C.

Site Manager


D.

Lead Assessor


Expert Solution
Questions # 7:

For a CMMC Level 2 certification, which organization maintains a non-disclosure agreement with the OSC?

Options:

A.

NIST


B.

C3PAO


C.

CMMC-AB


D.

OUSD A&S


Expert Solution
Questions # 8:

An assessor is in Phase 3 of the CMMC Assessment Process. The assessor has delivered the final findings, submitted the assessment results package, and provided feedback to the C3PAO and CMMC-AB. What must the assessor still do?

Options:

A.

Determine level recommendation


B.

Archive all assessment artifacts


C.

Determine final practice pass/fail results


D.

Archive or dispose of any assessment artifacts


Expert Solution
Questions # 9:

When are contractors required to achieve a CMMC certificate at the Level specified in the solicitation?

Options:

A.

At the time of award


B.

Upon solicitation submission


C.

Thirty days from the award date


D.

Before the due date of submission


Expert Solution
Questions # 10:

When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:

Options:

A.

Have a security clearance


B.

Be a senior person in the company


C.

Demonstrate expertise on the CMMC requirements


D.

Provide clarity and understanding of their practice activities


Expert Solution
Viewing page 1 out of 7 pages
Viewing questions 1-10 out of questions