Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 92 Topic 10 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 92 Topic 10 Discussion

CMMC-CCA Exam Topic 10 Question 92 Discussion:
Question #: 92
Topic #: 10

When assessing a contractor’s implementation of CMMC practices, you examine its SystemSecurity Plan (SSP) to identify its documented measures for audit reduction and reporting. They have a dedicated section in their SSP addressing the Audit and Accountability requirements. You proceed to interview their information security personnel, who informed you that the contractor has a dedicated Security Operations Center (SOC) and uses Splunk to reduce and report audit logs. What key features regarding the deployment of Splunk for AU.L2-3.3.6 – Reduction & Reporting would you be interested in assessing?


A.

Ensure that Splunk is configured with appropriate RBAC to restrict access to log data, reports, and dashboards, ensuring that only authorized personnel can view or modify audit logs


B.

Ensure Splunk can retain audit records for a protracted amount of time


C.

Ensure that Splunk employs various filter rules for reducing audit logs to eliminate non-essential data and processes to analyze large volumes of log files or audit information, identifying anomalies and summarizing the data in a format more meaningful to analysts, thus generating customized reports


D.

Ensure Splunk can support compliance dashboards that provide real-time visibility into CMMC compliance status


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.