
[Full-Version] 2026 New Preparation Guide of Cyber AB CMMC-CCP Exam
CMMC-CCP Practice Exam - 208 Unique Questions
Cyber AB CMMC-CCP Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
NEW QUESTION # 105
A Level 2 Assessment of an OSC is winding down and the final results are being prepared to present to the OSC. When should the final results be delivered to the OSC?
- A. At the end of every day of the assessment
- B. Either after approval from the C3PAO. or during a separately scheduled final recommended findings review
- C. Either at the final Daily Checkpoint, or during a separately scheduled findings and recommendation review
- D. Daily and during a final separately scheduled review
Answer: C
Explanation:
Understanding the Reporting Process in a CMMC 2.0 Level 2 AssessmentACMMC Level 2 Assessmentconducted by aCertified Third-Party Assessor Organization (C3PAO)follows a structured approach to gathering evidence, evaluating compliance, and reporting findings to theOrganization Seeking Certification (OSC). The reporting process is outlined in theCMMC Assessment Process (CAP) Guide, which specifies how findings should be communicated.
* Daily Checkpoints:
* Throughout the assessment, the assessor team holdsdaily checkpoint meetingswith the OSC to provide updates on progress, observations, and preliminary findings.
* These checkpoints help ensure transparency and allow the OSC to address minor issues as they arise.
* Final Results Delivery:
* Thefinal assessment resultsare typically shared during thefinal daily checkpointOR in aseparately scheduled findings and recommendations reviewmeeting.
* This ensures that the OSC receives a structured and complete summary of the assessment findings before the official report is submitted.
* TheCMMC Assessment Process (CAP) Guide, Section 4.5clearly states that assessment findings should be presentedeither at the last daily checkpoint or during a separately scheduled final review.
* This aligns with best practices formaintaining transparency and ensuring the OSC has clarity on their assessment resultsbefore the final report submission.
* Option A (End of every day)is incorrect because while assessors do provide updates, they do not deliver the "final results" daily.
* Option B (Daily and a separate final review)is misleading, as the CAP Guide allows assessors tochoosebetween the final daily checkpoint OR a separate findings review-not both.
* Option D (After C3PAO approval)is incorrect because theC3PAO does not approve findings before they are communicated to the OSC. The assessment team directly presents the results first.
* CMMC Assessment Process (CAP) Guide, Section 4.5: Reporting and Findings Communication
* CMMC 2.0 Level 2 Assessment Process Overview
* CMMC Assessment Final Report Guidelines
Assessment Communication StructureWhy Option C is CorrectOfficial CMMC Documentation ReferencesFinal VerificationBased on officialCMMC 2.0 documentation, thefinal assessment results should be presented to the OSC either at the last daily checkpoint or in a separately scheduled review session, making Option C the correct answer.
NEW QUESTION # 106
Which document is the BEST source for descriptions of each practice or process contained within the various CMMC domains?
- A. CMMC Assessment Guide Levels 1 and 2
- B. CMMC Assessment Process
- C. CMMC Glossary
- D. CMMC Appendices
Answer: A
Explanation:
Understanding the Best Source for CMMC Practice DescriptionsTheCMMC Assessment Guide (Levels 1 and
2)is theprimaryandmost authoritativedocument for detailed descriptions of each practice and process within the variousCMMC domains.
Step-by-Step Breakdown:#1. What is the CMMC Assessment Guide?
* TheCMMC Assessment Guideprovides detailed explanations of:
* EachCMMC practicewithin its respectivedomain.
* Theassessment objectivesfor verifying implementation.
* Examples ofevidence requiredto demonstrate compliance.
* CMMC 2.0 includes two levels:
* Level 1: 17 basic cybersecurity practices.
* Level 2: 110 practices aligned withNIST SP 800-171.
* TheAssessment Guidedefines howassessorsevaluate compliance.
#2. Why the Other Answer Choices Are Incorrect:
* (A) CMMC Glossary#
* TheGlossaryprovidesdefinitions of termsused in CMMC but does not describe specific practices in detail.
* (B) CMMC Appendices#
* Appendicesinclude supplementary information likereferences and scoping guidance, but they do not provide full descriptions of practices.
* (C) CMMC Assessment Process#
* TheAssessment Process Guideexplainshowassessments are conducted, but it doesnot describe each practicein detail.
Final Validation from CMMC Documentation:TheCMMC Assessment Guide (Levels 1 and 2)is theofficialsource for descriptions of eachCMMC practice and process, making it thebest referencefor understanding compliance requirements.
NEW QUESTION # 107
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
- A. demonstrate expertise on the CMMC requirements.
- B. be a senior person in the company.
- C. have a security clearance.
- D. provide clarity and understanding of their practice activities.
Answer: D
Explanation:
Interview Selection in CMMC AssessmentsDuring aCMMC assessment, theLead Assessormust work with theOrganization Seeking Certification (OSC)to select personnel for interviews. The goal is to:
#Verify that personnel understand andperform security-related practices.
#Ensure that individuals canexplain how they implement CMMC requirements.
#Gain insight intoactual cybersecurity operationsrather than just documented policies.
The best interviewees are those whodirectly engage with security practicesand canclearly explain how they perform their duties.
CMMC assessmentsrely on interviewsto validate that security practices areimplemented effectively.
Themost valuable intervieweesare those who canexplainhow security measures are appliedin day-to-day operations.
CMMC Assessment Process (CAP)emphasizes that assessors should speak tothose actively involved in security practicesrather than just senior management or policy owners.
Why "Providing Clarity and Understanding" Is KeyThus,option D is the correct choicebecause the Lead Assessor should prioritizeinterviewing personnel who can clearly explain how CMMC practices are implemented.
A). Have a security clearance.#Incorrect.Security clearance is not a requirementfor CMMC assessments. The focus is onpractical implementation of security controls, not classified work.
B). Be a senior person in the company.#Incorrect. Senior executives may not be involved in theactual implementation of security controls. The best interviewees are those whoperform the work, not just oversee it.
C). Demonstrate expertise on the CMMC requirements.#Incorrect. Whileunderstanding CMMC is important, expertise alonedoes not guarantee practical knowledgeof security controls. The key is thatinterviewees must provide clarity on how they perform security tasks.
Why the Other Answers Are Incorrect
CMMC Assessment Process (CAP) Document- Guides interview selection based on personnel who perform security functions.
NIST SP 800-171 & CMMC 2.0- Emphasize that cybersecurity controls must beactively implemented, not just documented.
CMMC Official ReferencesThus,option D (Provide clarity and understanding of their practice activities) is the correct answeras per official CMMC assessment guidelines.
NEW QUESTION # 108
During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?
- A. Lead Assessor
- B. C3PAO
- C. Advisory Board
- D. CCP
Answer: A
NEW QUESTION # 109
The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?
- A. Gaps or deltas due to any reciprocity model are recorded as met
- B. Suggested improvements for each failed practice
- C. Documented rationale for each failed practice
- D. Affirmation for each practice or control
Answer: D
NEW QUESTION # 110
CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:
- A. located on electronic media, on system component memory, and on paper.
- B. stored, processed, and transmitted.
- C. entered, edited, manipulated, printed, and viewed.
- D. received and transferred.
Answer: B
Explanation:
TheCMMC Scoping Guide for Level 2outlines thatCUI assetsinclude systems, applications, and services thatstore, process, or transmitControlled Unclassified Information (CUI). These are the three core functions that defineCUI handlingwithin anOrganization Seeking Certification (OSC).
Step-by-Step Breakdown:#1. CUI Assets Defined in CMMC
Stored:CUI is saved on hard drives, cloud storage, or databases.
Processed:CUI is actively used, modified, or analyzed by applications and users.
Transmitted:CUI is sent between systems via email, file transfers, or network communication.
#2. Why the Other Answer Choices Are Incorrect:
(A) Received and transferred#
Whilereceiving and transferring CUIis part of handling CUI, it does not fully cover all CUI asset responsibilities.
(C) Entered, edited, manipulated, printed, and viewed#
These arespecific actionswithinprocessingbut do not coverstorage or transmission, which are also required for CMMC scoping.
(D) Located on electronic media, on system component memory, and on paper# While CUI can exist inelectronic and physical forms, CMMC scoping focuses onhow CUI is actively managed (stored, processed, transmitted)rather than where it physically resides.
TheCMMC Level 2 Scoping Guideconfirms thatCUI Assets are categorized based on their role in storing, processing, or transmitting CUI.
NIST SP 800-171also defines these three functions as key components of CUI protection.
Final Validation from CMMC Documentation:
NEW QUESTION # 111
An assessment procedure consists of an assessment objective, potential assessment methods, and assessment objects. Which statement is part of an assessment objective?
- A. Determination statement related to the practice
- B. Examination, interviews, and testing
- C. Specifications and mechanisms
- D. Exercising assessment objects under specified conditions
Answer: A
NEW QUESTION # 112
In the CMMC Model, how many practices are included in Level 2?
- A. 110 practices
- B. 72 practices
- C. 180 practices
- D. 17 practices
Answer: A
Explanation:
* CMMC Level 2is designed to alignfullywithNIST SP 800-171, which consists of110 security controls (practices).
* This meansall 110 practicesfrom NIST SP 800-171 are required for aCMMC Level 2 certification.
How Many Practices Are Included in CMMC Level 2?Breakdown of Practices in CMMC 2.0CMMC Level Number of Practices Level 1
17 practices(Basic Cyber Hygiene)
Level 2
110 practices(Aligned with NIST SP 800-171)
Level 3
Not yet finalized but expected to exceed 110
Since CMMC Level 2 mandatesall 110 NIST SP 800-171 practices, the correct answer isC. 110 practices.
* A. 17 practices#Incorrect.17 practicesapply only toCMMC Level 1, not Level 2.
* B. 72 practices#Incorrect. There is no CMMC level with72 practices.
* D. 180 practices#Incorrect. CMMC Level 2only requires 110 practices, not 180.
Why the Other Answers Are Incorrect
* CMMC 2.0 Model- Confirms thatLevel 2 includes 110 practicesaligned withNIST SP 800-171.
* NIST SP 800-171 Rev. 2- Outlines the110 security controlsrequired for handlingControlled Unclassified Information (CUI).
CMMC Official ReferencesThus,option C (110 practices) is the correct answer, as per official CMMC guidance.
NEW QUESTION # 113
A Lead Assessor is planning an assessment and scheduling the test activities. Who MUST perform tests to obtain evidence?
- A. OSC personnel who normally perform that work as the CCP observes
- B. OSC personnel who do not ordinarily perform that work to evaluate the accuracy of the written procedure(s)
- C. Military personnel and the CCP and/or Lead Assessor to test the adequacy of the written procedure(s)
- D. Military personnel assigned to the contractor for that contract to ensure the confidentiality of the CUI
Answer: A
Explanation:
Understanding Who Must Perform Tests in a CMMC AssessmentDuring aCMMC Level 2 Assessment, assessorsmust observe operational activities and security practicesto verify compliance. This process involves:
#Testing security controls and proceduresas part of the assessment.
#Observation of standard work practicesto ensure controls are properly implemented.
#Using operational personnel (OSC employees) who regularly perform the taskto ensure realistic assessment conditions.
Operational personnel (OSC employees) must conduct the actual work while assessors observe.
Certified CMMC Professionals (CCPs) or Lead Assessorsoversee and document the testing process.
Who Performs Tests?
A). OSC personnel who normally perform that work as the CCP observes # Correct CMMC assessments require actual users (OSC personnel) to perform their regular duties while assessors observeto verify security practices.
B). Military personnel and the CCP and/or Lead Assessor to test the adequacy of the written procedure(s) # Incorrect Military personnel are not responsible for testing contractor security controls.
Assessors observe and evaluate but do not perform testing themselves.
C). Military personnel assigned to the contractor for that contract to ensure the confidentiality of the CUI # Incorrect Military personnel do not perform the testing.
The contractor (OSC) is responsible for implementing and demonstrating security controls.
D). OSC personnel who do not ordinarily perform that work to evaluate the accuracy of the written procedure (s) # Incorrect Personnel unfamiliar with the job should not be used for testing.
Theassessment must reflect real-world conditions, so theactual employees who perform the work must demonstrate the process.
Why is the Correct Answer "A" (OSC personnel who normally perform that work as the CCP observes)?
CMMC Assessment Process (CAP) Document
Specifies thatassessments must observe real operational activities to determine compliance.
CMMC-AB Assessment Methodology
Requirestesting of security controls in a realistic operational environment, meaning actual OSC personnel must perform the tasks.
NIST SP 800-171A (Assessment Procedures for NIST SP 800-171)
Specifies thatinterviews and observations should be conducted with personnel who regularly perform the work.
NEW QUESTION # 114
A contractor stores security policies, system configuration files, and audit logs in a centralized file repository for later review. According to CMMC terminology, the file repository is being used to:
- A. transmit CUI.
- B. store CUI.
- C. generate CUI
- D. protect CUI.
Answer: B
NEW QUESTION # 115
During Phase 4 of the Assessment process, what MUST the Lead Assessor determine and recommend to the C3PAO concerning the OSC?
- A. Ability
- B. Eligibility
- C. Capability
- D. Suitability
Answer: B
Explanation:
What Happens in Phase 4 of the CMMC Assessment Process?Phase 4 of theCMMC Assessment Process (CAP)is theFinal Reporting and Decision Phase. During this phase, theLead Assessormust:
Review all assessment findings
Determine the Organization Seeking Certification's (OSC) eligibility for certification Make a recommendation to the C3PAO (Certified Third-Party Assessment Organization) Ensure that the OSC hasmet the required practices and processes.
Confirm that anydeficiencieshave been corrected or appropriately documented.
Recommendwhether the OSC is eligible for certificationbased on assessment results.
Key Responsibilities of the Lead Assessor in Phase 4:Since theLead Assessor must determine and recommend the OSC's eligibilityto the C3PAO, the correct answer isB. Eligibility.
A). Ability#Incorrect. While assessing an OSC's ability to meet CMMC requirements is part of the process, the final determination in Phase 4 is abouteligibilityfor certification.
C). Capability#Incorrect. Capability refers to an organization'stechnical and operational readiness. The Lead Assessor is making a recommendation oneligibility, not just capability.
D). Suitability#Incorrect. Suitability is not a defined term in theCMMC CAP processfor final assessment recommendations. The correct term iseligibility.
Why the Other Answers Are Incorrect
CMMC Assessment Process (CAP) Document- Specifies that the Lead Assessor must determine and recommend theeligibilityof the OSC in Phase 4.
CMMC 2.0 Model- Defines the assessment process, including certification decision-making.
CMMC Official ReferencesThus,option B (Eligibility) is the correct answer, as per official CMMC guidance.
NEW QUESTION # 116
Which entity requires that organizations handling FCI or CUI be assessed to determine a required Level of cybersecurity maturity?
- A. CMMC-AB
- B. CISA
- C. NIST
- D. DoD
Answer: D
NEW QUESTION # 117
What is objectivity as it applies to activities with the CMMC-AB?
- A. Reporting results of CMMC services completely
- B. Avoiding the appearance of or actual, conflicts of interest
- C. Demonstrating integrity in the use of materials as described in policy
- D. Ensuring full disclosure
Answer: B
Explanation:
nderstanding Objectivity in CMMC-AB ActivitiesObjectivityin CMMC-AB activities refers to therequirement that assessors and C3PAOs remain impartial, unbiased, and free from conflicts of interestwhile conducting assessments and providing CMMC-related services.
Key Aspects of Objectivity in CMMC Assessments:#No conflicts of interest-Assessors must not assess organizations they havefinancial, professional, or personal ties to.
#Unbiased reporting-Findings must bebased solely on evidence, with no external influence.
#Avoiding even the appearance of a conflict-If there isany perception of bias, it must be addressed.
* A. Ensuring full disclosure # Incorrect
* Full disclosure is importantbut doesnot define objectivity. Objectivity meansremaining neutral and free from conflicts.
* B. Reporting results of CMMC services completely # Incorrect
* Whileaccurate reporting is required,objectivity focuses on impartiality, not just completeness.
* C. Avoiding the appearance of or actual, conflicts of interest # Correct
* Objectivity in CMMC-AB activities is primarily about preventing bias and ensuring fair assessments.
* Avoiding conflicts of interest ensures thatassessments are credible and trustworthy.
* D. Demonstrating integrity in the use of materials as described in policy # Incorrect
* Integrity is important, butobjectivity is specifically about avoiding bias and conflicts of interest.
Why is the Correct Answer "C. Avoiding the appearance of or actual, conflicts of interest"?
* CMMC-AB Code of Professional Conduct
* Requiresassessors and C3PAOs to avoid conflicts of interestand maintainimpartiality.
* CMMC Assessment Process (CAP) Document
* Emphasizes that assessments must befree from external influence and conflicts of interest.
* ISO/IEC 17020 Requirements for Inspection Bodies
* Definesobjectivity as avoiding conflicts of interest in the assessment process.
CMMC 2.0 References Supporting This answer:
NEW QUESTION # 118
Evidence gathered from an OSC is being reviewed. Based on the assessment and organizational scope, the Lead Assessor requests the Assessment Team to verify that the coverage by domain, practice. Host Unit.
Supporting Organization/Unit, and enclaves are comprehensive enough to rate against each practice. Which criteria is the assessor referring to?
- A. Adequacy
- B. Sufficiency
- C. Objectivity
- D. Capability
Answer: A
Explanation:
Step 1: Understand the Definitions of Evidence Evaluation CriteriaTheCMMC Assessment Process (CAP) introduces two key criteria for evaluating evidence:
Adequacy- Does the evidencealign with the practice?
Sufficiency- Is the evidencecomprehensive enoughin terms ofcoverage across systems, users, and scope?
CAP v1.0 - Section 3.5.4:
"Evidence must be evaluated for bothadequacy(is it the right evidence?) andsufficiency(is there enough of it across all in-scope assets and areas?) to score a practice as MET."
#Step 2: Applying to the ScenarioIn the question, the Lead Assessor is asking the team toverify that evidence is sufficient across:
Domains
Practices
Host Units
Supporting Organizations
Enclaves
## This is adirect reference to sufficiency, which evaluates whether thebreadth and depthof evidence is enough to make an informed judgment that the control is truly implemented across theentire assessed environment.
A). Adequacy# Adequacy refers to therelevanceof the evidence to the specific practice - not itscoverageacross scope.
B). Capability# Not a term used in evidence validation within CMMC CAP documentation.
D). Objectivity# While objectivity is important, it refers to theunbiased nature of assessment activities, not to theextent of evidence coverage.
#Why the Other Options Are Incorrect
When an assessor evaluates whether the evidence is broad enough across all necessary systems, units, and enclaves to score a practice as MET, they are evaluatingsufficiency- one of the two core criteria for evidence validity in a CMMC assessment.
NEW QUESTION # 119
When assessing SI.L1-3.14.2: Provide protection from malicious code at appropriate locations within organizational information systems, evidence shows that all of the OSC's workstations and servers have antivirus software installed for malicious code protection. A centralized console for the antivirus software management is in place and records show that all devices have received the most updated antivirus patterns.
What is the BEST determination that the Lead Assessor should reach regarding the evidence?
- A. It is insufficient, and the audit finding can be rated NOT MET.
- B. It is insufficient, and the Lead Assessor should seek more evidence.
- C. It is sufficient, and the audit finding can be rated as MET.
- D. It is sufficient, and the Lead Assessor should seek more evidence.
Answer: C
Explanation:
Understanding SI.L1-3.14.2: Provide Protection from Malicious CodeThe CMMC Level 1 practiceSI.L1-
3.14.2is based onNIST SP 800-171 Requirement 3.14.2, which requires organizations to:
* Implement malicious code protection(e.g., antivirus, endpoint security software).
* Ensure coverage across all appropriate locations(e.g., workstations, servers, network entry points).
* Keep protection mechanisms updated(e.g., regular signature updates, policy enforcement).
Assessment Criteria for a "MET" Rating:To determine whether the practice isMET, the Lead Assessor must confirm that:
#Antivirus or endpoint protection software is installedon all workstations and servers.
#The solution is centrally managed, ensuring consistent policy enforcement.
#Signature updates are current, meaning systems are protected against new threats.
#Logs or reports demonstrate active monitoring and updates.
Why is the Correct Answer "A. It is sufficient, and the audit finding can be rated as MET"?The provided evidenceconfirms all necessary requirementsfor SI.L1-3.14.2:
#All workstations and servers have antivirus installed#Meets installation requirement.
#A centralized management console is in place#Ensures consistent enforcement.
#Records show antivirus signatures are up to date#Confirms system protection is current.
Because the evidencemeets the requirement, the practice should berated as MET.
* B. It is insufficient, and the audit finding can be rated NOT MET # Incorrect
* The evidence providedmeets all necessary requirements, so the practiceshould not be rated as NOT MET.
* C. It is sufficient, and the Lead Assessor should seek more evidence # Incorrect
* Ifadequate evidence already exists,additional evidence is unnecessary.
* D. It is insufficient, and the Lead Assessor should seek more evidence # Incorrect
* The evidence providedmeets the control requirements, making itsufficient.
Why Are the Other Answers Incorrect?
* CMMC Assessment Process (CAP) Document
* Specifies that a practice can be marked asMET if sufficient evidence is provided.
* NIST SP 800-171 (Requirement 3.14.2)
* Defines the standard formalicious code protection, which ismet by antivirus with active updates.
* CMMC 2.0 Level 1 (Foundational) Requirements
* Clarifies that basic cybersecurity measures likeantivirus installation and updatesmeet compliance forSI.L1-3.14.2.
CMMC 2.0 References Supporting This Answer:
Final Answer:#A. It is sufficient, and the audit finding can be rated as MET.
NEW QUESTION # 120
When scoping a Level 2 assessment, which document is useful for understanding the process to successfully implement practices required for the various Levels of CMMC?
- A. NISTSP 800-171
- B. NISTSP 800-172
- C. NISTSP 800-53
- D. NISTSP 800-88
Answer: A
NEW QUESTION # 121
Which document is the BEST source for determining the sources of evidence for a given practice?
- A. CMMC Assessment Scope
- B. NISTSP 800-53
- C. CMMC Assessment Guide
- D. NISTSP 800-53A
Answer: D
NEW QUESTION # 122
What type of information is NOT intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not including information provided by the government to the public (such as on public websites) or simple transactional information, such as necessary to process payments?
- A. FCI
- B. CDI
- C. CUI
- D. CTI
Answer: A
Explanation:
Understanding Federal Contract Information (FCI)Federal Contract Information (FCI) is defined by48 CFR
52.204-21(Basic Safeguarding of Covered Contractor Information Systems). FCI refers to information that:
Is NOT intended for public release.
Is provided by or generated for the government under a contract.
Is necessary to develop or deliver a product or service to the government.
Excludes publicly available government information(such as information on public websites).
Excludes simple transactional information(e.g., necessary to process payments).
In the context ofCMMC 2.0, organizations thatprocess, store, or transmit FCImust meetCMMC Level 1 (Foundational), which requires implementing17 basic safeguarding practicesoutlined inFAR 52.204-21.
A). CDI (Controlled Defense Information)# Incorrect
This term was used inDFARS 252.204-7012but has been replaced byCUI (Controlled Unclassified Information)in CMMC discussions.
B). CTI (Cyber Threat Intelligence)# Incorrect
This refers to intelligence on cyber threats, tactics, and indicators, not contractual data.
C). CUI (Controlled Unclassified Information)# Incorrect
CUI is sensitive information requiring additional safeguarding but is a separate category from FCI.
D). FCI (Federal Contract Information)#Correct
The definition of FCI explicitly matches the description given in the question.
Why is the Correct Answer FCI (D)?
FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) Defines FCI and the required safeguards.
Establishes17 cybersecurity practicesfor FCI protection.
CMMC 2.0 Framework
Level 1 (Foundational)is required for contractors handlingFCI.
Ensures compliance withbasic safeguarding requirementsoutlined inFAR 52.204-21.
NIST SP 800-171 and DFARS 252.204-7012
FCI doesnotrequire compliance withNIST SP 800-171, butCUI does.
CMMC 2.0 References Supporting this Answer
NEW QUESTION # 123
CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:
- A. located on electronic media, on system component memory, and on paper.
- B. stored, processed, and transmitted.
- C. entered, edited, manipulated, printed, and viewed.
- D. received and transferred.
Answer: B
Explanation:
TheCMMC Scoping Guide for Level 2outlines thatCUI assetsinclude systems, applications, and services thatstore, process, or transmitControlled Unclassified Information (CUI). These are the three core functions that defineCUI handlingwithin anOrganization Seeking Certification (OSC).
Step-by-Step Breakdown:#1. CUI Assets Defined in CMMC
* Stored:CUI is saved on hard drives, cloud storage, or databases.
* Processed:CUI is actively used, modified, or analyzed by applications and users.
* Transmitted:CUI is sent between systems via email, file transfers, or network communication.
#2. Why the Other Answer Choices Are Incorrect:
* (A) Received and transferred#
* Whilereceiving and transferring CUIis part of handling CUI, it does not fully cover all CUI asset responsibilities.
* (C) Entered, edited, manipulated, printed, and viewed#
* These arespecific actionswithinprocessingbut do not coverstorage or transmission, which are also required for CMMC scoping.
* (D) Located on electronic media, on system component memory, and on paper#
* While CUI can exist inelectronic and physical forms, CMMC scoping focuses onhow CUI is actively managed (stored, processed, transmitted)rather than where it physically resides.
* TheCMMC Level 2 Scoping Guideconfirms thatCUI Assets are categorized based on their role in storing, processing, or transmitting CUI.
* NIST SP 800-171also defines these three functions as key components of CUI protection.
Final Validation from CMMC Documentation:
NEW QUESTION # 124
Which authority leads the CMMC direction, standards, best practices, and knowledge framework for how to map the controls and processes across different Levels that range from basic cyber hygiene to advanced cyber practices?
- A. Federal CIO office
- B. DoD CIO office
- C. NIST
- D. Defense Federal Acquisition Regulation Council
Answer: B
NEW QUESTION # 125
......
Latest Questions CMMC-CCP Guide to Prepare Free Practice Tests: https://www.trainingdump.com/Cyber-AB/CMMC-CCP-practice-exam-dumps.html
Reliable CMMC-CCP Dumps Questions Available as Web-Based Practice Test Engine: https://drive.google.com/open?id=11zuKNnGZChTBHH4YH2a6Xm1l10QWzT4c