Cyber AB Certified CMMC Assessor (CCA) CMMC-CCA Exam Questions

Page: 1 / 14
Total 150 questions
Question 1

The Lead Assessor and OSC Assessment Official determined the resources, cost, and schedule for an upcoming assessment. The Lead Assessor noted the OSC Assessment Official's preferences regarding the limits of the method and the consequent resource, cost, and schedule constraints to arrive at an optimal Assessment Plan. In this situation, who has responsibility for signing the planning agreement?



Answer : C

The Assessment Plan (planning agreement) must be signed by both the Lead Assessor and the OSC Assessment Official. This formalizes agreement on scope, resources, and methodology. The C3PAO is responsible for overall oversight but does not co-sign the plan.

Exact extracts:

''The Lead Assessor is responsible for developing the Assessment Plan in collaboration with the OSC Assessment Official.''

''Both the Lead Assessor and the OSC Assessment Official must sign the Assessment Plan to proceed.''

''The C3PAO maintains responsibility for quality assurance and submission, but not signing.''

Why other options are incorrect:

A/B: Both signatures are required, not one alone.

D: The C3PAO does not sign the planning agreement.


CMMC Assessment Process (CAP), Assessment Planning.

===========

Question 2

An assessor reviews the OSC's data protection policy, which requires full disk encryption on company laptops. While interviewing employees, the assessor learns that employees sometimes access data while teleworking on laptops that do not have full disk encryption.

How should the assessor view the implementation of the OSC's policy?



Answer : B

The Assessment Guide emphasizes that a policy is insufficient unless it is implemented consistently across all applicable assets. Evidence from interviews showing exceptions means the practice is NOT MET.

Extract:

''Policies must not only exist but must also be enforced and implemented consistently. Exceptions indicate non-compliance.''

Thus, the correct answer is B.


Question 3

An OSC leases several servers and rack space in a FedRAMP MODERATE authorized colocation data center. Additional servers operate in a LAN room within the company's facility. Both facilities are within the OSC's assessment boundary. In order to assess the physical protection of the environment, the Assessor MUST physically examine the visitor and access controls in place in the:



Answer : C

Both the OSC's on-premise LAN room and the leased colocation data center are in-scope because they contain systems that process, store, or transmit CUI. Assessors must physically examine visitor and access controls at both locations to confirm compliance with PE practices.

Exact Extracts:

PE.L2-3.10.1: ''Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.''

PE.L2-3.10.3: ''Escort visitors and monitor visitor activity.''

CMMC Assessment Guide: ''Assessors must validate physical protections at all in-scope facilities where CUI assets reside.''

CMMC Scoping Guide: ''Physical protection applies to all facilities within the CMMC Assessment Scope, including colocation facilities.''

Why the other options are not correct:

A/B: Reviewing only one facility is insufficient; both are in scope.

D: Customer relationship management reviews are not substitutes for physical examination by assessors.


CMMC Assessment Guide -- Level 2, Version 2.13: PE practices (pp. 153--159).

CMMC Scoping Guide -- Level 2: Facility requirements.

Question 4

When preparing for an assessment, the assessor determines that the client's proprietary data resides within an enclave. However, the assessor is unable to review policies containing proprietary data onsite and plans to have the policies copied on removable media by the client's IT staff, whom they are scheduled to interview. What should the assessor consider as part of their planning?



Answer : D

Assessor conduct is governed by the CMMC Code of Professional Conduct. Proprietary or sensitive data from the OSC environment cannot leave without express written consent from the OSC's Assessment Official (AO). The AO is the authorized point of control for assessment-related data. This protects client confidentiality and maintains ethical handling of sensitive information.

Exact Extracts:

CMMC Assessor Code of Professional Conduct: ''No proprietary or sensitive information may be removed from an OSC environment without the express written consent of the OSC's designated Assessment Official.''

''Assessors are bound to protect confidentiality and may not transmit data outside of agreed assessment channels without written authorization.''

Why the other options are not correct:

A: Too absolute --- proprietary data can leave if AO provides written consent.

B: IT staff cannot authorize release of proprietary data.

C: POC is not the authority for data release --- only the Assessment Official is.


CMMC Code of Professional Conduct: Confidentiality requirements.

CMMC Assessment Guide -- Level 2: Ethical responsibilities of assessors.

Question 5

During an assessment interview, the interviewee states that anyone can connect to the company Wi-Fi without prior approval. Within which domains is the Wi-Fi configuration covered?



Answer : C

Access Control (AC): Wi-Fi access must be restricted to authorized users and devices. CMMC Level 2 incorporates NIST SP 800-171 AC requirements to limit and control access to systems and resources.

Identification and Authentication (IA): Wireless access requires authentication to ensure only authorized individuals/devices can connect (e.g., WPA2-Enterprise, certificates, or strong passwords).

System and Communications Protection (SC): Wi-Fi encryption and secure configuration protect data-in-transit from interception or unauthorized disclosure.

Why Other Options Are Incorrect:

A (MP, AC, PE): Media protection and physical protection are not primary domains for Wi-Fi configuration.

B (IA, MP, SI): Media protection and system/information integrity do not directly address Wi-Fi security.

D (SC, SI, PE): Physical and integrity controls are not central to wireless access security.

Reference (CCA Official Sources):

CMMC Model v2.0 --- Domains AC, IA, SC

NIST SP 800-171 Rev. 2 --- AC.L2-3.1.1, IA.L2-3.5.3, SC.L2-3.13.8 (wireless access, identification/authentication, protection of communications)

NIST SP 800-171A --- Associated assessment objectives verifying Wi-Fi control and encryption

===========


Question 6

While completing the Level 2 Assessment, the Lead Assessor found that the OSC was deficient on a number of CMMC practices. Forty practices were scored as NOT MET, all on the Authorized Deficiency Corrections list. The OSC remediated 17 of those during closeout, leaving 23 practices still NOT MET. What should the Lead Assessor recommend?



Answer : B

Under CMMC 2.0 Level 2, POA&Ms are permitted only for a limited subset of practices and only if the organization achieves at least 80% compliance, with no high-weight practices failed. With 23 practices NOT MET, the OSC falls below this threshold. Therefore, the Lead Assessor must recommend a Fail, requiring remediation and reassessment.

Exact extracts:

''For Level 2, OSCs must achieve a score of at least 80% and cannot fail any high-weighted practices.''

''POA&Ms may be allowed for a small number of selected practices but must be closed within 180 days.''

''If the OSC does not meet minimum requirements, the assessment result is Fail and the OSC must remediate before reapplying.''

Why the other options are incorrect:

A: POA&Ms cannot cover such a large number of deficiencies.

C/D: Interim certification does not exist in CMMC 2.0.


CMMC Assessment Guide -- Level 2, POA&M policy.

DoD CMMC 2.0 Program guidance on minimum passing scores and fail conditions.

Question 7

An Assessor is evaluating controls put in place by an OSC to restrict the use of privileged accounts. The Assessor interviews privileged users and confirms that the OSC has both a policy and specific procedures governing the use of privileged accounts for security functions. What else could the Assessor evaluate to validate the assertions made by the interviewed OSC staff?



Answer : A

For AC.L2-3.1.7 (Restrict Use of Privileged Accounts), it is not enough to rely on interviews or documented procedures. The assessor must also Examine technical evidence to ensure that privileged accounts exist as described and are properly controlled. Reviewing system architecture, account listings, and role assignments validates that privileged access aligns with policy and that inappropriate assignments do not exist.

Exact extracts:

''Assessment Objectives ... Determine if: privileged accounts are identified; privileged functions are restricted to privileged accounts; and use of privileged accounts is monitored.''

''Assessment Methods -- Examine: account management policy; system architecture documentation; system security plan; privileged account listings.''

''Assessment Methods -- Test: attempt to use non-privileged accounts to execute privileged functions.''

Expanded explanation:

Assessors typically proceed in layers:

Interview: Confirm staff knowledge of policy and practice.

Examine: Verify account structures in system architecture or AD group membership lists. This ensures the number and type of privileged accounts match staff descriptions.

Test (if required): Confirm that non-privileged users cannot perform privileged actions.

Why other options are incorrect:

B: Testing non-privileged accounts is useful but is not the next immediate validation step after confirming policy/procedures. Examination comes first.

C: This phrasing implies giving privileged roles to non-privileged functions, which would itself be a finding.

D: Testing with privileged users verifies activity monitoring, but not whether privileged accounts are properly scoped.


CMMC Assessment Guide -- Level 2, AC.L2-3.1.7 ''Restrict Use of Privileged Accounts.''

NIST SP 800-171 Rev. 2, 3.1.7.

===========

Page:    1 / 14   
Total 150 questions