Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions
Questions # 21:

The Advanced Level in CMMC will contain Access Control {AC) practices from:

Options:

A.

Level 1.


B.

Level 3.


C.

Levels 1 and 2.


D.

Levels 1,2, and 3.


Expert Solution
Questions # 22:

What is a PRIMARY activity that is performed while conducting an assessment?

Options:

A.

Develop assessment plan.


B.

Collect and examine evidence.


C.

Verify readiness to conduct assessment.


D.

Deliver recommended assessment results.


Expert Solution
Questions # 23:

A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?

Options:

A.

Performed in groups for more efficient use of resources


B.

Recorded for inclusion in the Final Recommended Findings report


C.

Confidential and non-attributable so interviewees can speak without fear of reprisal


D.

Mapped to specific CMMC practices to clearly delineate which practice is being evaluated


Expert Solution
Questions # 24:

A dedicated local printer is used to print out documents with FCI in an organization. This is considered an FCI Asset Which function BEST describes what the printer does with the FCI?

Options:

A.

Encrypt


B.

Manage


C.

Process


D.

Distribute


Expert Solution
Questions # 25:

In the Code of Professional Conduct, what does the practice of Professionalism require?

Options:

A.

Do not copy materials without permission to do so.


B.

Do not make assertions about assessment outcomes.


C.

Refrain from dishonesty in all dealings regarding CMMC.


D.

Ensure the security of all information discovered or received.


Expert Solution
Questions # 26:

While determining the scope for a company's CMMC Level 1 Self-Assessment, the contract administrator includes the hosting providers that manage their IT infrastructure. Which asset type BEST describes the third-party organization?

Options:

A.

ESPs


B.

People


C.

Facilities


D.

Technology


Expert Solution
Questions # 27:

A machining company has been awarded a contract with the DoD to build specialized parts. Testing of the parts will be done by the company using in-house staff and equipment. For a Level 1 Self-Assessment, what type of asset is this?

Options:

A.

CUI Asset


B.

In-scope Asset


C.

Specialized Asset


D.

Contractor Risk Managed Asset


Expert Solution
Questions # 28:

An OSC lead has provided company information, identified that they are seeking CMMC Level 2, stated that they handle FCI. identified stakeholders, and provided assessment logistics. The OSC has provided the company's cyber hygiene practices that are posted on every workstation, visitor logs, and screenshots of the configuration of their FedRAMP-approved applications. The OSC has not won any DoD government contracts yet but is working on two proposals Based on this information, which statement BEST describes the CMMC Level 2 Assessment requirements?

Options:

A.

Ready because there is no need to certify this company until after they win a DoD contract.


B.

Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract.


C.

Not ready because the OSC still lacks artifacts that prove they have implemented all the CMMC Level 2 Assessment requirements.


D.

Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification.


Expert Solution
Questions # 29:

A C3PAO is conducting High Level Scoping for an OSC that requested an assessment Which term describes the people, processes, and technology that will be applied to the contract who are requesting a CMMC Level assessment?

Options:

A.

Host Unit


B.

Branch Office


C.

Coordinating Unit


D.

Supporting Organization/Units


Expert Solution
Questions # 30:

Within how many days from the Assessment Final Recommended Findings Brief should the Lead Assessor and Assessment Team Members, if necessary, review the accuracy and validity of (he OSC's updated POA&M with any accompanying evidence or scheduled collections?

Options:

A.

90 days


B.

180 days


C.

270 days


D.

360 days


Expert Solution
Viewing page 3 out of 6 pages
Viewing questions 21-30 out of questions