Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions
Questions # 31:

Which document is the BEST source for determining the sources of evidence for a given practice?

Options:

A.

NISTSP 800-53


B.

NISTSP 800-53A


C.

CMMC Assessment Scope


D.

CMMC Assessment Guide


Expert Solution
Questions # 32:

A CMMC Assessment is being conducted at an OSC ' s HQ. which is a shared workspace in a multi-tenant building. The OSC is renting four offices on the first floor that can be locked individually. The first-floor conference room is shared with other tenants but has been reserved to conduct the assessment. The conference room has a desk with a drawer that does not lock. At the end of the day, an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?

Options:

A.

Review it. print it, and put it in the desk drawer.


B.

Review it, and make notes on the computer provided by the client.


C.

Review it, print it, make notes, and then shred it in cross-cut shredder in the print room.


D.

Review it. print it, and leave it in a folder on the table together with the other documents.


Expert Solution
Questions # 33:

During an assessment, the Lead Assessor reviews the evidence for each CMMC in-scope practice that has been reviewed, verified, rated, and discussed with the OSC during the daily reviews. The Assessment Team records the final recommended MET or NOT MET rating and prepares to present the results to the assessment participants during the final review with the OSC and sponsor. As a part of this presentation, which document MUST include the attendee list, time/date, location/meeting link, results from all discussed topics, including any resulting actions, and due dates from the OSC or Assessment Team?

Options:

A.

Final log report


B.

Final CMMC report


C.

Final and recorded OSC CMMC report


D.

Final and recorded Daily Checkpoint log


Expert Solution
Questions # 34:

A C3PAO has conducted a CMMC Level 2 Assessment for an OSC. The results have been reviewed by a CMMC Quality Assurance Professional. What is the final step in the process of submitting assessment results?

Options:

A.

The C3PAO submits the results to the CMMC-AB.


B.

The OSC submits the results, as provided by the Lead Assessor, to the CMMC-AB.


C.

The C3PAO submits the results to Enterprise Mission Assurance Support Service.


D.

The Lead Assessor submits the results to the CMMC-AB.


Expert Solution
Questions # 35:

Who makes the final determination of the assessment method used for each practice?

Options:

A.

CCP


B.

osc


C.

Site Manager


D.

Lead Assessor


Expert Solution
Questions # 36:

When scoping a Level 2 assessment, which document is useful for understanding the process to successfully implement practices required for the various Levels of CMMC?

Options:

A.

NISTSP 800-53


B.

NISTSP 800-88


C.

NISTSP 800-171


D.

NISTSP 800-172


Expert Solution
Questions # 37:

How many cybersecurity levels does the CMMC Model structure contain?

Options:

A.

2 Levels.


B.

3 Levels.


C.

5 Levels.


D.

4 Levels.


Expert Solution
Questions # 38:

What activities are conducted while developing an assessment plan?

Options:

A.

The C3PAO decides the Assessment Team members and notifies the Lead Assessor.


B.

The Lead Assessor and the OSC’s sponsor determine the assessment resources and schedule.


C.

The C3PAO’s project manager is responsible for handling potential conflicts of interest.


D.

The evidence collection approach can be finalized when the Lead Assessor conducts an onsite assessment.


Expert Solution
Questions # 39:

What is DFARS clause 252.204-7012 required for?

Options:

A.

All DoD solicitations and contracts


B.

Solicitations and contracts that use FAR part 12 procedures


C.

Procurements solely for the acquisition of commercial off-the-shelf


D.

Commercial off-the-shelf sold in the marketplace without modifications


Expert Solution
Questions # 40:

Regarding the Risk Assessment (RA) domain, what should an OSC periodically assess?

Options:

A.

Organizational operations, business assets, and employees


B.

Organizational operations, business processes, and employees


C.

Organizational operations, organizational assets, and individuals


D.

Organizational operations, organizational processes, and individuals


Expert Solution
Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions