Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions
Questions # 51:

A Lead Assessor and an OSC's Assessment Official have agreed to have the Assessment results presented during the final Daily Checkpoint of the OSC's CMMC Level 2 Assessment. Which document MUST the Lead Assessor use to present assessment findings to the OSC?

Options:

A.

CMMC POA & M Brief


B.

CMMC Findings Brief


C.

CMMC Assessment Tracker Tool


D.

CMMC Recommended Findings template


Expert Solution
Questions # 52:

As part of CMMC 2.0, the change to Level 1 Self-Assessments supports "reduced assessment costs" allows all companies at Level 1 (Foundational) to:

Options:

A.

to conduct self-assessments.


B.

opt out of CMMC Assessments.


C.

have assessment costs reimbursed by the DoD.


D.

pay no more than $500.00 for their annual assessment.


Expert Solution
Questions # 53:

Which are guiding principles in the CMMC Code of Professional Conduct?

Options:

A.

Objectivity, information integrity, and higher accountability


B.

Objectivity, information integrity, and proper use of methods


C.

Proper use of methods, higher accountability, and objectivity


D.

Proper use of methods, higher accountability, and information integrity


Expert Solution
Questions # 54:

During assessment planning, the OSC recommends a person to interview for a certain practice. The person being interviewed MUST be the person who:

Options:

A.

funds that practice.


B.

audits that practice.


C.

supports, audits, and performs that practice.


D.

implements, performs, or supports that practice.


Expert Solution
Questions # 55:

Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?

Options:

A.

Access Control (AC)


B.

Media Protection (MP)


C.

Asset Management (AM)


D.

Configuration Management (CM)


Expert Solution
Questions # 56:

An organization's sales representative is tasked with entering FCI data into various fields within a spreadsheet on a company-issued laptop. This laptop is an FCI Asset being used to:

Options:

A.

process and transmit FCI.


B.

process and organize FCI.


C.

store, process, and transmit FCI.


D.

store, process, and organize FCI.


Expert Solution
Questions # 57:

A CCP is providing consulting services to a company who is an OSC. The CCP is preparing the OSC for a CMMC Level 2 assessment. The company has asked the CCP who is responsible for determining the CMMC Assessment Scope and who validates its CMMC Assessment Scope. How should the CCP respond?

Options:

A.

"The OSC determines the CMMC Assessment Scope, and the CCP validates the CMMC Assessment Scope."


B.

"The OSC determines the CMMC Assessment Scope, and the C3PAO validates the CMMC Assessment Scope."


C.

"The CMMC Lead Assessor determines the CMMC Assessment Scope, and the OSC validates the CMMC Assessment Scope."


D.

"The CMMC C3PAO determines the CMMC Assessment Scope, and the Lead Assessor validates the CMMC Assessment Scope."


Expert Solution
Questions # 58:

A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?

Options:

A.

Performed in groups for more efficient use of resources


B.

Recorded for inclusion in the Final Recommended Findings report


C.

Confidential and non-attributable so interviewees can speak without fear of reprisal


D.

Mapped to specific CMMC practices to clearly delineate which practice is being evaluated


Expert Solution
Questions # 59:

A Lead Assessor is planning an assessment and scheduling the test activities. Who MUST perform tests to obtain evidence?

Options:

A.

OSC personnel who normally perform that work as the CCP observes


B.

Military personnel and the CCP and/or Lead Assessor to test the adequacy of the written procedure(s)


C.

Military personnel assigned to the contractor for that contract to ensure the confidentiality of the CUI


D.

OSC personnel who do not ordinarily perform that work to evaluate the accuracy of the written procedure(s)


Expert Solution
Questions # 60:

During a Level 2 Assessment, an OSC provides documentation that attests that they utilize multifactor authentication on nonlocal remote maintenance sessions. The OSC feels that they have met the controls for the Level 2 certification. What additional measures should the OSC perform to fully meet the maintenance requirement?

Options:

A.

Connections for nonlocal maintenance sessions should be terminated when maintenance is complete.


B.

Connections for nonlocal maintenance sessions should be unlimited to ensure maintenance is performed properly


C.

The nonlocal maintenance personnel complain that restrictions slow down their response time and should be removed.


D.

The maintenance policy states multifactor authentication must have at least two factors applied for nonlocal maintenance sessions.


Expert Solution
Viewing page 6 out of 7 pages
Viewing questions 51-60 out of questions