Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 52 Topic 6 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 52 Topic 6 Discussion

CMMC-CCA Exam Topic 6 Question 52 Discussion:
Question #: 52
Topic #: 6

You are part of the Assessment Team assessing a small defense contractor. You learn that the contractor (ABC Manufacturing) outsources parts of its IT infrastructure and cybersecurity services to a reputable Managed Services Provider (MSP). During a CMMC assessment, the contractor’s Assessment Official claims that several CMMC practices related to system security and monitoring are inherited from the MSP. Which of the following actions should the Lead Assessor take?


A.

Automatically accept the contractor’s claim and score the inherited practices as ‘MET’ without further evaluation.


B.

Recommend that the OSC implement the inherited practices internally, as inheriting from external providers is not allowed.


C.

Score the inherited practices as ‘NOT MET’ and require ABC Manufacturing to implement them internally.


D.

Request evidence from the MSP to verify that their services meet the assessment objectives for the inherited practices and are applicable to ABC Manufacturing’s in-scope assets.


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.