Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

Which document is the BEST source for determining the sources of evidence for a given practice?

Options:

A.

NISTSP 800-53


B.

NISTSP 800-53A


C.

CMMC Assessment Scope


D.

CMMC Assessment Guide


Expert Solution
Questions # 12:

Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1. Guidelines for Media Sanitation?

Options:

A.

Clear, purge, destroy


B.

Clear redact, destroy


C.

Clear, overwrite, purge


D.

Clear, overwrite, destroy


Expert Solution
Questions # 13:

What service is the MOST comprehensive that the RPO provides?

Options:

A.

Training services


B.

Education services


C.

Consulting services


D.

Assessment services


Expert Solution
Questions # 14:

An assessor is collecting affirmations. So far, the assessor has collected interviews, demonstrations, emails, messaging, and presentations. Are these appropriate approaches to collecting affirmations?

Options:

A.

No, emails are not appropriate affirmations.


B.

No, messaging is not an appropriate affirmation.


C.

Yes, the affirmations collected by the assessor are all appropriate.


D.

Yes, the affirmations collected by the assessor are all appropriate, as are screenshots.


Expert Solution
Questions # 15:

In scoping a CMMC Level 1 Self-Assessment, all of the computers and digital assets that handle FCI are identified. A file cabinet that contains paper FCI is also identified. What can this file cabinet BEST be determined to be?

Options:

A.

In scope, because it is an asset that stores FCI


B.

In scope, because it is part of the same physical location


C.

Out of scope, because they are all only paper documents


D.

Out of scope, because it does not process or transmit FCI


Expert Solution
Questions # 16:

The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?

Options:

A.

Affirmation for each practice or control


B.

Documented rationale for each failed practice


C.

Suggested improvements for each failed practice


D.

Gaps or deltas due to any reciprocity model are recorded as met


Expert Solution
Questions # 17:

A Lead Assessor is planning an assessment and scheduling the test activities. Who MUST perform tests to obtain evidence?

Options:

A.

OSC personnel who normally perform that work as the CCP observes


B.

Military personnel and the CCP and/or Lead Assessor to test the adequacy of the written procedure(s)


C.

Military personnel assigned to the contractor for that contract to ensure the confidentiality of the CUI


D.

OSC personnel who do not ordinarily perform that work to evaluate the accuracy of the written procedure(s)


Expert Solution
Questions # 18:

Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?

Options:

A.

DoD OUSD


B.

Authorized holder


C.

Information Disclosure Official


D.

Presidential authorized Original Classification Authority


Expert Solution
Questions # 19:

Which resource contains authoritative data classifications of CUI?

Options:

A.

NARA


B.

CMMC-AB


C.

DoD Contractors FAQ


D.

OSC's privacy policies


Expert Solution
Questions # 20:

Which code or clause requires that a contractor is meeting the basic safeguarding requirements for FCI during a Level 1 Self-Assessment?

Options:

A.

FAR 52.204-21


B.

22CFR 120-130


C.

DFARS 252.204-7011


D.

DFARS 252.204-7021


Expert Solution
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions