Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 33 Topic 4 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 33 Topic 4 Discussion

CMMC-CCA Exam Topic 4 Question 33 Discussion:
Question #: 33
Topic #: 4

You are a CCA conducting a CMMC Level 2 assessment for an OSC. During the assessment, you discover that the OSC has implemented a practice using a temporary workaround due to a recent system failure. The workaround meets the practice’s objectives, but it is not documented in their System Security Plan (SSP). How should you evaluate this evidence?


A.

Accept the workaround as sufficient evidence and score the practice as "MET" since it meets the objectives.


B.

Document the lack of SSP inclusion as an evidence gap and assess the practice based on the workaround’s effectiveness.


C.

Score the practice as "NOT MET" due to the absence of documentation in the SSP.


D.

Request the OSC to update the SSP to include the workaround before continuing the assessment.


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.