Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions
Questions # 11:

While conducting a CMMC Assessment, an individual from the OSC provides documentation to the assessor for review. The documentation states an incident response capability is established and contains information on incident preparation, detection, analysis, containment, recovery, and user response activities. Which CMMC practice is this documentation attesting to?

Options:

A.

IR.L2-3.6.1: Incident Handling


B.

IR.L2-3.6.2: Incident Reporting


C.

IR.L2-3.6.3: Incident Response Testing


D.

IR.L2-3.6.4: Incident Spillage


Expert Solution
Questions # 12:

A program manager for a defense contractor saves all FCI data relevant to a contract on a flash drive. Why is the flash drive categorized as an FCI Asset ?

Options:

A.

It is storing FCI.


B.

It is testing FCI.


C.

It is distributing FCI.


D.

It is properly marked as FCI.


Expert Solution
Questions # 13:

Prior to initiating an OSC's CMMC Assessment, the Lead Assessor briefed the team on the most important requirements of the assessment. The assessor also insisted that the same results of the findings summary, practice ratings, and Level recommendations must be submitted to the C3PAO for initial processes and review. After several weeks of assessment, the C3PAO completes the internal review, the recommended results are then submitted through the C3PAO for final quality review and rating approval. Which document stipulates these reporting requirements?

Options:

A.

CMMC Assessment reporting requirements


B.

DFARS 52.204-21 assessment reporting requirements


C.

NISTSP 800-171 Revision 2 assessment reporting requirements


D.

DFARS clause 252.204-7012 assessment reporting requirements


Expert Solution
Questions # 14:

The evidence needed for each practice and/or process is weighed for:

Options:

A.

Adequacy and sufficiency


B.

Adequacy and thoroughness


C.

Sufficiency and thoroughness


D.

Sufficiency and appropriateness


Expert Solution
Questions # 15:

A Level 2 Assessment of an OSC is winding down and the final results are being prepared to present to the OSC. When should the final results be delivered to the OSC?

Options:

A.

At the end of every day of the assessment


B.

Daily and during a final separately scheduled review


C.

Either at the final Daily Checkpoint, or during a separately scheduled findings and recommendation review


D.

Either after approval from the C3PAO. or during a separately scheduled final recommended findings review


Expert Solution
Questions # 16:

A CCP is working as an Assessment Team Member on a CMMC Level 2 Assessment. The Lead Assessor has assigned the CCP to assess the OSC's Configuration Management (CM) domain. The CCP's first interview is with a subject-matter expert for user-installed software. With respect to user-installed software, what facet should the CCP's interview focus on?

Options:

A.

Controlled and monitored


B.

Removed from the system


C.

Scanned for malicious code


D.

Limited to mission-essential use only


Expert Solution
Questions # 17:

In the CMMC Model, how many practices are included in Level 1?

Options:

A.

15 practices


B.

17 practices


C.

72 practices


D.

110 practices


Expert Solution
Questions # 18:

What is objectivity as it applies to activities with the CMMC-AB?

Options:

A.

Ensuring full disclosure


B.

Reporting results of CMMC services completely


C.

Avoiding the appearance of or actual, conflicts of interest


D.

Demonstrating integrity in the use of materials as described in policy


Expert Solution
Questions # 19:

A CMMC Assessment is being conducted at an OSC's HQ. which is a shared workspace in a multi-tenant building. The OSC is renting four offices on the first floor that can be locked individually. The first-floor conference room is shared with other tenants but has been reserved to conduct the assessment. The conference room has a desk with a drawer that does not lock. At the end of the day, an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?

Options:

A.

Review it. print it, and put it in the desk drawer.


B.

Review it, and make notes on the computer provided by the client.


C.

Review it, print it, make notes, and then shred it in cross-cut shredder in the print room.


D.

Review it. print it, and leave it in a folder on the table together with the other documents.


Expert Solution
Questions # 20:

The IT manager is scoping the company's CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?

Options:

A.

ESP


B.

People


C.

Facilities


D.

Technology


Expert Solution
Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions