Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 108 Topic 11 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 108 Topic 11 Discussion

CMMC-CCA Exam Topic 11 Question 108 Discussion:
Question #: 108
Topic #: 11

During your review of an OSC’s system security control, you focus on CMMC practice SC.L2-3.13.9 – Connections Termination. The OSC uses a custom web application for authorized personnel to access CUI remotely. Users log in with usernames and passwords. The application is hosted on a dedicated server within the company’s internal network. The server operating system utilizes default settings for connection timeouts. Network security is managed through a central firewall, but no specific rules are configured for terminating inactive connections associated with the CUI access application. Additionally, there is no documented policy or procedure outlining a defined period of inactivity for terminating remote access connections. Interviews with IT personnel reveal that they rely solely on users to remember to log out of the application after completing their work. How could the firewall be configured to help achieve the objectives of CMMC practice SC.L2-3.13.9 – Connections Termination, for the remote access application?


A.

Creating firewall rules to identify and terminate connections associated with the CUI access application that have been inactive for a predefined period


B.

Encrypting all traffic between the user device and the server to protect CUI in transit


C.

Implementing intrusion detection and prevention systems (IDS/IPS) to identify and block suspicious activity on the server


D.

Blocking all incoming traffic to the server hosting the CUI access application, except from authorized IP addresses


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.