Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions
Questions # 1:

A CMMC Assessment is being conducted at an OSC's HQ. which is a shared workspace in a multi-tenant building. The OSC is renting four offices on the first floor that can be locked individually. The first-floor conference room is shared with other tenants but has been reserved to conduct the assessment. The conference room has a desk with a drawer that does not lock. At the end of the day, an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?

Options:

A.

Review it. print it, and put it in the desk drawer.


B.

Review it, and make notes on the computer provided by the client.


C.

Review it, print it, make notes, and then shred it in cross-cut shredder in the print room.


D.

Review it. print it, and leave it in a folder on the table together with the other documents.


Expert Solution
Questions # 2:

Which domains are a part of a Level 1 Self-Assessment?

Options:

A.

Access Control (AC), Risk Management


B.

Risk Management (RM). Access Control (AC), and Physical Protection (PE)


C.

Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)


D.

Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)


Expert Solution
Questions # 3:

An OSC has submitted evidence for an upcoming assessment. The assessor reviews the evidence and determines it is not adequate or sufficient to meet the CMMC practice. What can the assessor do?

Options:

A.

Notify the CMMC-AB.


B.

Cancel the assessment.


C.

Postpone the assessment.


D.

Contact the C3PAO for guidance.


Expert Solution
Questions # 4:

What are CUI protection responsibilities?

Options:

A.

Shielding


B.

Governing


C.

Correcting


D.

Safeguarding


Expert Solution
Questions # 5:

The facilities manager for a company has procured a Wi-Fi enabled, mobile application-controlled thermostat for the server room, citing concerns over the inability to remotely gauge and control the temperature of the room. Because the thermostat is connected to the company's FCI network, should it be assessed as part of the CMMC Level 1 Self-Assessment Scope?

Options:

A.

No, because it is OT


B.

No, because it is an loT device


C.

Yes. because it is a restricted IS


D.

Yes, because it is government property


Expert Solution
Questions # 6:

Who is responsible for ensuring that subcontractors have a valid CMMC Certification?

Options:

A.

CMMC-AB


B.

OUSDA&S


C.

DoD agency or client


D.

Contractor organization


Expert Solution
Questions # 7:

A Lead Assessor is presenting an assessment kickoff and opening briefing. What topic MUST be included?

Options:

A.

Gathering evidence


B.

Review of the OSC's SSP


C.

Overview of the assessment process


D.

Examination of the artifacts for sufficiency


Expert Solution
Questions # 8:

When executing a remediation review, the Lead Assessor should:

Options:

A.

help OSC to complete planned remediation activities.


B.

plan two consecutive remediation reviews for an OSC.


C.

submit a delta assessment remediation package for C3PAO's internal quality review.


D.

validate that practices previously listed on the POA&M have been removed on an updated Risk Assessment.


Expert Solution
Questions # 9:

During the planning phase of a CMMC Level 2 Assessment, the Lead Assessor is considering what would constitute the right evidence for each practice. What is the Assessor attempting to verify?

Options:

A.

Adequacy


B.

Sufficiency


C.

Process mapping


D.

Assessment scope


Expert Solution
Questions # 10:

A Lead Assessor has been assigned to a CMMC Assessment During the assessment, one of the assessors approaches with a signed policy. There is one signatory, and that person has since left the company. Subsequently, another person was hired into that position but has not signed the document. Is this document valid?

Options:

A.

The signatory is the authority to implement and enforce the policy, and since that person is no longer with the company, the policy is not valid.


B.

More research on the company policy of creating, implementing, and enforcing policies is needed. If the company has a policy identifying the authority as with the position or person, then the policy is valid.


C.

The signatory does not validate or invalidate the policy. For the purpose of this assessment, ensuring that the policy is current and is being implemented by the individuals who are performing the work is sufficient.


D.

The authority to implement and enforce lies with the position, not the person. As long as that position's authority and responsibilities have not been removed from implementing that domain, it is still a valid policy.


Expert Solution
Viewing page 1 out of 6 pages
Viewing questions 1-10 out of questions