Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions
Questions # 31:

Where can a listing of all federal agencies' CUI indices and categories be found?

Options:

A.

32 CFR Section 2002


B.

Official CUI Registry


C.

Executive Order 13556


D.

Official CMMC Registry


Expert Solution
Questions # 32:

An Assessment Team is conducting interviews with team members about their roles and responsibilities. The team member responsible for maintaining the antivirus program knows that it was deployed but has very little knowledge on how it works. Is this adequate for the practice?

Options:

A.

Yes, the antivirus program is available, so it is sufficient.


B.

Yes, antivirus programs are automated to run independently.


C.

No, the team member must know how the antivirus program is deployed and maintained.


D.

No, the team member's interview answers about deployment and maintenance are insufficient.


Expert Solution
Questions # 33:

Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?

Options:

A.

Availability


B.

Confidentiality


C.

Information Integrity


D.

Respect for Intellectual Property


Expert Solution
Questions # 34:

Which resource contains authoritative data classifications of CUI?

Options:

A.

NARA


B.

CMMC-AB


C.

DoD Contractors FAQ


D.

OSC's privacy policies


Expert Solution
Questions # 35:

What is a PRIMARY activity that is performed while conducting an assessment?

Options:

A.

Develop assessment plan.


B.

Collect and examine evidence.


C.

Verify readiness to conduct assessment.


D.

Deliver recommended assessment results.


Expert Solution
Questions # 36:

A machining company has been awarded a contract with the DoD to build specialized parts. Testing of the parts will be done by the company using in-house staff and equipment. For a Level 1 Self-Assessment, what type of asset is this?

Options:

A.

CUI Asset


B.

In-scope Asset


C.

Specialized Asset


D.

Contractor Risk Managed Asset


Expert Solution
Questions # 37:

During the planning phase of the Assessment Process. C3PAO staff are reviewing the various entities associated with an OSC that has requested a CMMC Level 2 Assessment. Which term describes the people, processes, and technology external to the HQ Organization that participate in the assessment but will not receive a CMMC Level unless an enterprise Assessment is conducted?

Options:

A.

Host Unit


B.

Organization


C.

Coordinating Unit


D.

Supporting Organization/Unit


Expert Solution
Questions # 38:

A Lead Assessor is preparing to conduct a Readiness Review during Phase 1 of the Assessment Process. How much evidence MUST be gathered for each practice?

Options:

A.

A sufficient amount


B.

At least 2 Assessment Objects


C.

Evidence that is deemed adequate


D.

Evidence to support at least 2 Assessment Methods


Expert Solution
Questions # 39:

While conducting a CMMC Level 2 Assessment, a CCP is reviewing an OSC's personnel security process. They have a policy that describes screening individuals prior to authorizing access to CUI, but it does not mention what organizations should be looking for in an individual. There is no link to a process or procedural document. What should the OSC evaluate when screening individuals prior to accessing CUI?

Options:

A.

They are trusted and well liked


B.

They are a hard and loyal worker


C.

Their conduct, integrity, and loyalty


D.

Their functionality, reliability, and ability to adapt


Expert Solution
Questions # 40:

An organization that manufactures night vision cameras is looking for help to address the gaps identified in physical access control systems. Which certified individual should they approach for implementation support?

Options:

A.

CCA of the C3PAO performing the assessment


B.

RP of an organization not part of the assessment


C.

Practitioner of the organization performing the assessment LTP


D.

DoD Contract Official of the organization performing the assessment


Expert Solution
Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions