Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Cyber AB CMMC CMMC-CCP Questions and answers with CertsForce

Viewing page 7 out of 7 pages
Viewing questions 61-70 out of questions
Questions # 61:

In the CMMC Model, how many practices are included in Level 2?

Options:

A.

17 practices


B.

72 practices


C.

110 practices


D.

180 practices


Expert Solution
Questions # 62:

A C3PAO is conducting High Level Scoping for an OSC that requested an assessment Which term describes the people, processes, and technology that will be applied to the contract who are requesting a CMMC Level assessment?

Options:

A.

Host Unit


B.

Branch Office


C.

Coordinating Unit


D.

Supporting Organization/Units


Expert Solution
Questions # 63:

During a POA & M closeout assessment , the Lead Assessor and team members verified all evidence provided by the OSC and passed those that satisfied the requirements. Who MUST verify that every failed practice from the initial original assessment has been adequately addressed?

Options:

A.

OSC


B.

CCA


C.

OSC sponsor


D.

Lead Assessor


Expert Solution
Questions # 64:

An assessment is being completed at a client site that is not far from the Lead Assessor's home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?

Options:

A.

Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.


B.

Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.


C.

Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service.


D.

Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.


Expert Solution
Questions # 65:

Two assessors cannot agree if a certain practice should be rated as MET or NOT MET. Who should they consult to determine the final interpretation?

Options:

A.

C3PAO


B.

CMMC-AB


C.

Lead Assessor


D.

Quality Assurance Assessor


Expert Solution
Questions # 66:

While developing an assessment plan for an OSC. it is discovered that the certified assessor will be interviewing a former college roommate. What is the MOST correct action to take?

Options:

A.

Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.


B.

Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.


C.

Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.


D.

Inform the OSC and the C3PAO of the possible conflict of interest, document the conflict and mitigation actions in the assessment plan, and if the mitigation actions are acceptable, continue with the assessment.


Expert Solution
Questions # 67:

A Lead Assessor is ensuring all actions have been completed to conclude a Level 2 Assessment. The final Assessment Results Package has been properly reviewed and is ready to be uploaded. What other materials is the Lead Assessor responsible for maintaining and protecting?

Options:

A.

Any additional notes and information from the Assessment


B.

A final assessment plan, and a Quality Control report from C3PAO


C.

A final assessment plan, and a letter from the Lead Assessor explaining the process


D.

A final assessment plan, a letter from the Lead Assessor explaining the results, and a Quality Control report from C3PAO


Expert Solution
Questions # 68:

Which term describes the process of granting or denying specific requests to obtain and use information, related information processing services, and enter specific physical facilities?

Options:

A.

Access control


B.

Physical access control


C.

Mandatory access control


D.

Discretionary access control


Expert Solution
Viewing page 7 out of 7 pages
Viewing questions 61-70 out of questions