Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 103 Topic 11 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 103 Topic 11 Discussion

CMMC-CCA Exam Topic 11 Question 103 Discussion:
Question #: 103
Topic #: 11

During your assessment of CA.L2-3.12.3 – Security Control Monitoring, the contractor’s CISO informs you that they have established a continuous monitoring program to assess the effectiveness of their implemented security controls. When examining their security planning policy, you determine they have a list of automated tools they use to track and report weekly changes in the security controls. The contractor has also established a feedback mechanism that helps them identify areas of improvement in their security controls. Chatting with employees, you understand the contractor regularly invites resource persons to train them on the secure handling of information and identifying gaps in security controls implemented. You would rely on all of the below evidence to assess the contractor’s implementation of CA.L2-3.12.3 – Security Control Monitoring, EXCEPT?


A.

Records/logs of monitoring activities over time


B.

Customer feedback on the contractor's security measures


C.

Reports or dashboards from the monitoring activities


D.

The contractor’s security monitoring policies and procedures


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.