Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 22 Topic 3 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 22 Topic 3 Discussion

CMMC-CCA Exam Topic 3 Question 22 Discussion:
Question #: 22
Topic #: 3

A representative of a CMMC Level 2 certified DoD contractor has reached out to you as a CCA for an explanation of FedRAMP equivalency. They want to use a Cloud Service Offering (CSO) from a renowned CSP, but in light of the DoD FedRAMP equivalency memo, they are reluctant. In your conversation, you learn that although the CSO has impressive features, the assessment by a FedRAMP 3PAO resulted in a Plan of Action and Milestones (POA&M) that the CSP is remedying. What is the main reason the contractor shouldn’t use the CSP’s services?


A.

The CSP has not closed out the POA&Ms


B.

The CSO is not DFARS 252.204-7019 compliant


C.

The CSO has not been given JAB P-ATO


D.

The CSO hasn’t fully met (100%) FedRAMP Moderate or equivalent baselines


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.