Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions
Questions # 41:

The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections. How should the team score practices in which the evidence shows the deficiencies have been corrected?

Options:

A.

MET


B.

POA&M


C.

NOT MET


D.

NOT APPLICABLE


Expert Solution
Questions # 42:

Which example represents a Specialized Asset?

Options:

A.

SOCs


B.

Hosted VPN services


C.

Consultants who provide cybersecurity services


D.

All property owned or leased by the government


Expert Solution
Questions # 43:

During an assessment, the Lead Assessor reviews the evidence for each CMMC in-scope practice that has been reviewed, verified, rated, and discussed with the OSC during the daily reviews. The Assessment Team records the final recommended MET or NOT MET rating and prepares to present the results to the assessment participants during the final review with the OSC and sponsor. As a part of this presentation, which document MUST include the attendee list, time/date, location/meeting link, results from all discussed topics, including any resulting actions, and due dates from the OSC or Assessment Team?

Options:

A.

Final log report


B.

Final CMMC report


C.

Final and recorded OSC CMMC report


D.

Final and recorded Daily Checkpoint log


Expert Solution
Questions # 44:

During a Level 1 Self-Assessment, a smart thermostat was identified. It is connected to the Internet on the OSC's WiFi network. What type of asset is this?

Options:

A.

FCI Asset


B.

CUI Asset


C.

In-scope Asset


D.

Specialized Asset


Expert Solution
Questions # 45:

CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:

Options:

A.

received and transferred.


B.

stored, processed, and transmitted.


C.

entered, edited, manipulated, printed, and viewed.


D.

located on electronic media, on system component memory, and on paper.


Expert Solution
Questions # 46:

As part of CMMC 2.0, the change to Level 1 Self-Assessments supports "reduced assessment costs" allows all companies at Level 1 (Foundational) to:

Options:

A.

to conduct self-assessments.


B.

opt out of CMMC Assessments.


C.

have assessment costs reimbursed by the DoD.


D.

pay no more than $500.00 for their annual assessment.


Expert Solution
Questions # 47:

During Phase 4 of the Assessment process, what MUST the Lead Assessor determine and recommend to the C3PAO concerning the OSC?

Options:

A.

Ability


B.

Eligibility


C.

Capability


D.

Suitability


Expert Solution
Questions # 48:

A company is working with a CCP from a contracted CMMC consulting company. The CCP is asked where the Host Unit is required to document FCI and CUI for a CMMC Assessment. How should the CCP respond?

Options:

A.

"In the SSP. within the asset inventory, and in the network diagranY'


B.

"Within the hardware inventory, data (low diagram, and in the network diagram"


C.

"Within the asset inventory, in the proposal response, and in the network diagram"


D.

"In the network diagram, in the SSP. within the base inventory, and in the proposal response'"


Expert Solution
Questions # 49:

A CCP is working as an Assessment Team Member on a CMMC Level 2 Assessment. The Lead Assessor has assigned the CCP to assess the OSC's Configuration Management (CM) domain. The CCP's first interview is with a subject-matter expert for user-installed software. With respect to user-installed software, what facet should the CCP's interview focus on?

Options:

A.

Controlled and monitored


B.

Removed from the system


C.

Scanned for malicious code


D.

Limited to mission-essential use only


Expert Solution
Questions # 50:

Which statement BEST describes a LTP?

Options:

A.

Creates DoD-licensed training


B.

Instructs a curriculum approved by CMMC-AB


C.

May market itself as a CMMC-AB Licensed Provider for testing


D.

Delivers training using some CMMC body of knowledge objectives


Expert Solution
Viewing page 5 out of 6 pages
Viewing questions 41-50 out of questions