Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions
Questions # 31:

A CCP is on their first assessment for CMMC Level 2 with an Assessment Team and is reviewing the CMMC Assessment Process to understand their responsibilities. Which method gathers information from the subject matter experts to facilitate understanding and achieve clarification?

Options:

A.

Test


B.

Examine


C.

Interview


D.

Assessment


Expert Solution
Questions # 32:

The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?

Options:

A.

Expert


B.

Advanced


C.

Optimizing


D.

Continuously Improved


Expert Solution
Questions # 33:

Which domain references the requirements needed to handle physical or digital assets containing CUI?

Options:

A.

Media Protection (MP)


B.

Physical Protection (PE)


C.

System and Information Integrity (SI)


D.

System and Communications Protection (SC)


Expert Solution
Questions # 34:

Prior to initiating an OSC's CMMC Assessment, the Lead Assessor briefed the team on the most important requirements of the assessment. The assessor also insisted that the same results of the findings summary, practice ratings, and Level recommendations must be submitted to the C3PAO for initial processes and review. After several weeks of assessment, the C3PAO completes the internal review, the recommended results are then submitted through the C3PAO for final quality review and rating approval. Which document stipulates these reporting requirements?

Options:

A.

CMMC Assessment reporting requirements


B.

DFARS 52.204-21 assessment reporting requirements


C.

NISTSP 800-171 Revision 2 assessment reporting requirements


D.

DFARS clause 252.204-7012 assessment reporting requirements


Expert Solution
Questions # 35:

Which NIST SP discusses protecting CUI in nonfederal systems and organizations?

Options:

A.

NIST SP 800-37


B.

NIST SP 800-53


C.

NIST SP 800-88


D.

NIST SP 800-171


Expert Solution
Questions # 36:

A C3PAO is near completion of a Level 2 Assessment for an OSC. The CMMC Findings Brief and CMMC Assessment Results documents have been developed. The Final Recommended Assessment Results are being generated. When generating these results, what MUST be included?

Options:

A.

An updated Assessment Plan


B.

Recorded and final updated Daily Checkpoint


C.

Fully executed CMMC Assessment contract between the C3PAO and the OSC


D.

Review documentation for the CMMC Quality Assurance Professional (CQAP)


Expert Solution
Questions # 37:

When assessing SI.L2-3.14.6: Monitor communications for attack, the CCA interviews the person responsible for the intrusion detection system and examines relevant policies and procedures for monitoring organizational systems. What would be a possible next step the CCA could conduct to gather sufficient evidence?

Options:

A.

Conduct a penetration test


B.

Interview the intrusion detection system's supplier.


C.

Upload known malicious code and observe the system response.


D.

Review an artifact to check key references for the configuration of the IDS or IPS practice for additional guidance on intrusion detection and prevention systems.


Expert Solution
Questions # 38:

Two network administrators are working together to determine a network configuration in preparation for CMMC. The administrators find that they disagree on a couple of small items. Which solution is the BEST way to ensure compliance with CMMC?

Options:

A.

Consult with the CEO of the company.


B.

Consult the CMMC Assessment Guides and NIST SP 800-171.


C.

Go with the network administrator's ideas with the least stringent controls.


D.

Go with the network administrator's ideas with the most stringent controls.


Expert Solution
Questions # 39:

The Audit and Accountability (AU) domain has practices in:

Options:

A.

Level 1.


B.

Level 2.


C.

Levels 1 and 2.


D.

Levels 1 and 3.


Expert Solution
Questions # 40:

The evidence needed for each practice and/or process is weight for:

Options:

A.

adequacy and sufficiency.


B.

adequacy and thoroughness.


C.

sufficiency and thoroughness.


D.

sufficiency and appropriateness.


Expert Solution
Viewing page 4 out of 6 pages
Viewing questions 31-40 out of questions