Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 27 Topic 3 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 27 Topic 3 Discussion

CMMC-CCA Exam Topic 3 Question 27 Discussion:
Question #: 27
Topic #: 3

A CCA is assessing an OSC that uses a complex multi-cloud architecture with resources distributed across multiple Cloud Service Providers (CSPs). During the evaluation, the CCA encounters challenges in verifying the authorization methods used for external connections to the various cloud resources (AC.L1-3.1.20). Additionally, the assessor finds limited documentation of the cryptographic mechanisms implemented to protect the confidentiality of remote access sessions (AC.L2-3.1.13) to cloud-based data. While the OSC has network monitoring tools in place, the sheer volume of data makes it difficult to identify and track specific remote access activities. What challenges might the CCA face while assessing the OSC’s cloud and hybrid environment for compliance with CMMC remote access requirements?


A.

Outdated network infrastructure and insufficient bandwidth


B.

Excessive focus on physical security measures while neglecting logical controls


C.

Difficulty verifying access control policies and lack of qualified personnel


D.

Difficulty in verifying external connection authorization methods and limited evidence of cryptographic mechanisms for remote access


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.