Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 77 Topic 8 Discussion

Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Question # 77 Topic 8 Discussion

CMMC-CCA Exam Topic 8 Question 77 Discussion:
Question #: 77
Topic #: 8

A software development company is applying for a CMMC Level 2 assessment. As the Lead Assessor, you request access to the company’s System Security Plan (SSP) as part of the initial objective evidence for validating the scope. Which of the following is true about the software development company’s obligations in honoring the request?


A.

The software development company can refuse to provide the SSP if they deem it contains proprietary information.


B.

The software development company is not obligated to provide the SSP until after the assessment has begun.


C.

The software development company can choose to provide a redacted version of the SSP, omitting sensitive information.


D.

The software development company must furnish the Lead Assessor with the SSP.


Get Premium CMMC-CCA Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.