Cyber AB Certified CMMC Assessor (CCA) - CMMC-CCA Exam Practice Test

During an assessment, the IT security engineers responsible for password policy for the OSC provided documentation that all passwords are protected using a one-way hashing methodology. As a result, which statement is true?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An OSC seeking Level 2 certification wants to develop and launch a website for customers to purchase items online and submit contact forms. The OSC plans to host the web server in their own data center while also maintaining the security of their internal IT environment. Based on this information, what would be the BEST approach?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
The Lead Assessor has conducted an assessment for an OSC. The OSC's practices have been scored and preliminary results validated. Based on this information, what is the NEXT logical step?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An in-house compliance expert for a large defense contractor is reviewing the organization's training materials for personnel handling CUI. After a widely publicized insider threat incident, management requires that training address insider threat risks. What is a critical component of insider threat awareness training?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
The Lead Assessor is reviewing the Assessment Plan to identify people for interviews regarding a specific Level 2 practice. Some OSC personnel previously interviewed provided only brief answers without meaningful verification. What can the Lead Assessor do to improve this situation going forward?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An OSC seeking Level 2 certification has recently configured system auditing capabilities for all systems within the assessment scope. The audit logs are generated based on the required events and contain the correct content that the organization has defined.
Which of the following BEST describes the next system auditing objective that the organization should define?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A cloud-native OSC uses a vendor's FedRAMP MODERATE authorized cloud environment for all aspects of their CUI needs (identity, email, file storage, office suite, etc.) as well as the vendor's locally installable applications. The OSC properly configured the vendor's cloud-based SIEM system to monitor all aspects of the cloud environment. The OSC's SSP documents SI.L2-3.14.7: Identify Unauthorized Use, defining authorized use and referencing procedures for identifying unauthorized use.
How should the Certified Assessor score this practice?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A company has multiple sites with employees at each site that must access the company's CUI network from their remote locations. The company has set up a single access point for all employees to access the network.
What is the MOST significant factor in determining whether the security on this single access point is adequate?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
An OSC has contracted a C3PAO to perform a Level 2 Assessment. As the Lead Assessor is analyzing the assessment requirements, it is found that the OSC does not have a document detailing the assessment scope.
How can this problem BEST be fixed?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
A company describes its organization as having two systems. One system, System Org, covers the entire organization and allows instant messaging, email, and Internet activity. The other system, System CUI, is used for processing, storing, and transmitting CUI data. System CUI interfaces with System Org through security mechanisms and a firewall.
The CMMC Assessment is being done on System CUI only.
What is the BEST way to describe System CUI?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0