Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions
Questions # 51:

While conducting a CMMC Level 2 Assessment, the Lead Assessor determines that the OSC has badge readers, pin code pads, and keys for various access points as well as documentation to demonstrate meeting the practice. Which CMMC practice has the OSC MET?

Options:

A.

PE.L1-3.10.5: Control and manage physical access devices


B.

MP.L2-3.8.5: Mark media with necessary CUI markings and distribution limitations


C.

SI.L2-3.14.3: Monitor system security alerts and advisories and take action in response


D.

PS.L2-3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers


Expert Solution
Questions # 52:

In preparation for a CMMC Level 1 Self-Assessment, the IT manager for a DIB organization is documenting asset types in the company's SSP The manager determines that identified machine controllers and assembly machines should be documented as Specialized Assets. Which type of Specialized Assets has the manager identified and documented?

Options:

A.

loT


B.

Restricted IS


C.

Test equipment


D.

Operational technology


Expert Solution
Questions # 53:

Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?

Options:

A.

Availability


B.

Confidentiality


C.

Information Integrity


D.

Respect for Intellectual Property


Expert Solution
Questions # 54:

Who is responsible for ensuring that subcontractors have a valid CMMC Certification?

Options:

A.

CMMC-AB


B.

OUSDA&S


C.

DoD agency or client


D.

Contractor organization


Expert Solution
Questions # 55:

Which statement BEST describes the requirements for a C3PA0?

Options:

A.

An authorized C3PAO must meet some DoD and all ISO/IEC 17020 requirements.


B.

An accredited C3PAO must meet all DoD and some ISO/IEC 17020 requirements.


C.

AC3PAO must be accredited by DoD before being able to conduct assessments.


D.

A C3PAO must be authorized by CMMC-AB before being able to conduct assessments.


Expert Solution
Questions # 56:

What is DFARS clause 252.204-7012 required for?

Options:

A.

All DoD solicitations and contracts


B.

Solicitations and contracts that use FAR part 12 procedures


C.

Procurements solely for the acquisition of commercial off-the-shelf


D.

Commercial off-the-shelf sold in the marketplace without modifications


Expert Solution
Questions # 57:

A CCP is on their first assessment for CMMC Level 2 with an Assessment Team and is reviewing the CMMC Assessment Process to understand their responsibilities. Which method gathers information from the subject matter experts to facilitate understanding and achieve clarification?

Options:

A.

Test


B.

Examine


C.

Interview


D.

Assessment


Expert Solution
Questions # 58:

A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?

Options:

A.

Performed in groups for more efficient use of resources


B.

Recorded for inclusion in the Final Recommended Findings report


C.

Confidential and non-attributable so interviewees can speak without fear of reprisal


D.

Mapped to specific CMMC practices to clearly delineate which practice is being evaluated


Expert Solution
Questions # 59:

A Lead Assessor is ensuring all actions have been completed to conclude a Level 2 Assessment. The final Assessment Results Package has been properly reviewed and is ready to be uploaded. What other materials is the Lead Assessor responsible for maintaining and protecting?

Options:

A.

Any additional notes and information from the Assessment


B.

A final assessment plan, and a Quality Control report from C3PAO


C.

A final assessment plan, and a letter from the Lead Assessor explaining the process


D.

A final assessment plan, a letter from the Lead Assessor explaining the results, and a Quality Control report from C3PAO


Expert Solution
Questions # 60:

An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?

Options:

A.

Take it with them to review in the evening.


B.

Leave it on the desk for review the following day.


C.

Put it in the unlocked desk drawer for review the following morning.


D.

Take a picture with the personal phone before securely shredding it.


Expert Solution
Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions