Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions
Questions # 11:

When scoping a Level 2 assessment, which document is useful for understanding the process to successfully implement practices required for the various Levels of CMMC?

Options:

A.

NISTSP 800-53


B.

NISTSP 800-88


C.

NISTSP 800-171


D.

NISTSP 800-172


Expert Solution
Questions # 12:

Which statement is NOT a measure to determine if collected evidence is sufficient?

Options:

A.

Evidence covers the sampled organization


B.

Evidence is not required if the practice is ISO certified


C.

Evidence covers the model scope of the Assessment (Target CMMC Level)


D.

Evidence corresponds to the sampled organization in the evidence collection approach


Expert Solution
Questions # 13:

There are 15 practices that are NOT MET for an OSC's Level 2 Assessment. All practices are applicable to the OSC. Which determination should be reached?

Options:

A.

The OSC may have 90 days for remediating NOT MET practices.


B.

The OSC is not eligible for an option to remediate NOT MET practices.


C.

The OSC may be eligible for an option to remediate NOT MET practices.


D.

The OSC is not eligible for an option to remediate after the assessment is canceled.


Expert Solution
Questions # 14:

What type of information is NOT intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not including information provided by the government to the public (such as on public websites) or simple transactional information, such as necessary to process payments?

Options:

A.

CDI


B.

CTI


C.

CUI


D.

FCI


Expert Solution
Questions # 15:

Which statement BEST describes the key references a Lead Assessor should refer to and use the:

Options:

A.

DoD adequate security checklist for covered defense information.


B.

CMMC Model Overview as it provides assessment methods and objects.


C.

safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment.


D.

published CMMC Assessment Guide practice descriptions for the desired certification level.


Expert Solution
Questions # 16:

An OSC has submitted evidence for an upcoming assessment. The assessor reviews the evidence and determines it is not adequate or sufficient to meet the CMMC practice. What can the assessor do?

Options:

A.

Notify the CMMC-AB.


B.

Cancel the assessment.


C.

Postpone the assessment.


D.

Contact the C3PAO for guidance.


Expert Solution
Questions # 17:

A CMMC Level 1 Self-Assessment identified an asset in the OSC's facility that does not process, store, or transmit FCI. Which type of asset is this considered?

Options:

A.

FCI Assets


B.

Specialized Assets


C.

Out-of-Scope Assets


D.

Government-Issued Assets


Expert Solution
Questions # 18:

For CMMC Assessments, during Phase 1 of the CMMC Assessment Process, which are responsible for identifying potential conflicts of information?

Options:

A.

C3PAO and OSC


B.

OSC and CMMC-AB


C.

CMMC-AB and C3PAO


D.

Lead Assessor and Assessment Team Members


Expert Solution
Questions # 19:

Which CMMC Levels meet the standards of protecting FCI (Federal Contract Information) ?

Options:

A.

Level 1


B.

Level 2


C.

Levels 2 and 3


D.

Levels 1, 2, and 3


Expert Solution
Questions # 20:

Who is responsible for identifying and verifying Assessment Team Member qualifications?

Options:

A.

C3PAO


B.

CMMC-AB


C.

Lead Assessor


D.

CMMC Marketplace


Expert Solution
Viewing page 2 out of 7 pages
Viewing questions 11-20 out of questions