Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 3 out of 7 pages
Viewing questions 21-30 out of questions
Questions # 21:

During a Level 2 Assessment, an OSC provides documentation that attests that they utilize multifactor authentication on nonlocal remote maintenance sessions. The OSC feels that they have met the controls for the Level 2 certification. What additional measures should the OSC perform to fully meet the maintenance requirement?

Options:

A.

Connections for nonlocal maintenance sessions should be terminated when maintenance is complete.


B.

Connections for nonlocal maintenance sessions should be unlimited to ensure maintenance is performed properly


C.

The nonlocal maintenance personnel complain that restrictions slow down their response time and should be removed.


D.

The maintenance policy states multifactor authentication must have at least two factors applied for nonlocal maintenance sessions.


Expert Solution
Questions # 22:

When assessing SI.L2-3.14.6: Monitor communications for attack, the CCA interviews the person responsible for the intrusion detection system and examines relevant policies and procedures for monitoring organizational systems. What would be a possible next step the CCA could conduct to gather sufficient evidence?

Options:

A.

Conduct a penetration test


B.

Interview the intrusion detection system's supplier.


C.

Upload known malicious code and observe the system response.


D.

Review an artifact to check key references for the configuration of the IDS or IPS practice for additional guidance on intrusion detection and prevention systems.


Expert Solution
Questions # 23:

The Advanced Level in CMMC will contain Access Control {AC) practices from:

Options:

A.

Level 1.


B.

Level 3.


C.

Levels 1 and 2.


D.

Levels 1,2, and 3.


Expert Solution
Questions # 24:

What is a PRIMARY activity that is performed while conducting an assessment?

Options:

A.

Develop assessment plan.


B.

Collect and examine evidence.


C.

Verify readiness to conduct assessment.


D.

Deliver recommended assessment results.


Expert Solution
Questions # 25:

A contractor stores security policies, system configuration files, and audit logs in a centralized file repository for later review. According to CMMC terminology, the file repository is being used to:

Options:

A.

protect CUI.


B.

transmit CUI.


C.

store CUI.


D.

generate CUI


Expert Solution
Questions # 26:

An organization that manufactures night vision cameras is looking for help to address the gaps identified in physical access control systems. Which certified individual should they approach for implementation support?

Options:

A.

CCA of the C3PAO performing the assessment


B.

RP of an organization not part of the assessment


C.

Practitioner of the organization performing the assessment LTP


D.

DoD Contract Official of the organization performing the assessment


Expert Solution
Questions # 27:

An OSC performing a CMMC Level 1 Self-Assessment uses a legacy Windows 95 computer, which is the only system that can run software that the government contract requires. Why can this asset be considered out of scope?

Options:

A.

It handles CUI


B.

It is a restricted IS


C.

It is government property


D.

It is operational technology


Expert Solution
Questions # 28:

An assessment procedure consists of an assessment objective, potential assessment methods, and assessment objects. Which statement is part of an assessment objective?

Options:

A.

Specifications and mechanisms


B.

Examination, interviews, and testing


C.

Determination statement related to the practice


D.

Exercising assessment objects under specified conditions


Expert Solution
Questions # 29:

When a conflict of interest is unavoidable, a CCP should NOT:

Options:

A.

Inform their organization


B.

Take action to minimize its impact


C.

Disclose it to affected stakeholders


D.

Conceal it from the Assessment Team lead


Expert Solution
Questions # 30:

Which phase of the CMMC Assessment Process includes developing the assessment plan?

Options:

A.

Phase 1


B.

Phase 2


C.

Phase 3


D.

Phase 4


Expert Solution
Viewing page 3 out of 7 pages
Viewing questions 21-30 out of questions