While reviewing CA.L2-3.12.3: Security Control Monitoring, the CCA notices that the assessment period is defined as one year. An OSC's SSP states that under CA.L2-3.12.3, security controls are monitored using the same one-year periodicity to ensure the continued effectiveness of the controls. The assessor understands that some CMMC practices can reference other practices for the entirety of their implementation. Is the OSC's implementation under CA.L2-3.12.3: Security Control Monitoring acceptable?
Answer : B
The requirement for CA.L2-3.12.3 -- Security Control Monitoring mandates monitoring to be performed on an ongoing basis to ensure the continued effectiveness of the controls. This is not satisfied by a yearly review alone.
CA.L2-3.12.3 Security Control Monitoring -- Monitor security controls on an ongoing basis to ensure the continued effectiveness of the controls.
The OSC's statement in their SSP that monitoring occurs on a one-year periodic basis fails to meet this requirement, because the term 'ongoing basis' implies continual or recurring monitoring activities that occur throughout the system's lifecycle---not a single annual review.
Therefore, the assessor must determine that the OSC's implementation is not acceptable.
Does CMMC Level 2 require that a Cloud Service Provider (CSP) hold a FedRAMP HIGH authorization hosted in a government community cloud (GCC)?
Answer : B
CMMC Level 2 requires CSPs that process, store, or transmit CUI to meet FedRAMP Moderate (or equivalent) authorization, not FedRAMP High. FedRAMP High is not a CMMC requirement but may be required by contract or specific agencies.
Exact Extracts:
DoD CMMC Scoping Guide: ''External Cloud Service Providers must meet FedRAMP Moderate equivalency when storing, processing, or transmitting CUI.''
CMMC Assessment Guide: ''The baseline requirement for CUI in cloud environments is FedRAMP Moderate; higher levels may be contractually required.''
Why other options are not correct:
A: Equivalency is allowed, but only to FedRAMP Moderate level.
C/D: Incorrect, because CMMC Level 2 does not mandate FedRAMP High.
CMMC Assessment Guide -- Level 2, Version 2.13: External Service Providers and FedRAMP Moderate equivalency requirements.
DoD Cloud Computing SRG (referenced in CMMC documentation): CUI requires FedRAMP Moderate baseline.
During an assessment, the team is interviewing the IT staff to understand the ways in which the organization protects backup dat
a. Because the company's backups contain CUI, the Lead Assessor asks the IT engineer which method is used to ensure that the confidentiality of the backup data is being protected. Which implementation is LEAST LIKELY to be acceptable?
Answer : A
When protecting backup data containing CUI, the requirement is to ensure confidentiality through logical or physical security controls appropriate to the sensitivity of CUI. Acceptable implementations include controlling access to CUI (AC family controls), physically securing media (MP family controls), and encrypting files or media (SC family controls). Merely implementing alternative physical controls for site access is insufficient because site access protections do not directly ensure the confidentiality of the backup media itself.
Exact Extracts (from official CMMC Assessor/Study documents and NIST SP 800-171A references):
SC.L2-3.13.16 (Encrypt CUI): ''Employ cryptographic mechanisms to prevent unauthorized disclosure of CUI during storage and transmission unless otherwise protected by alternative physical safeguards.''
MP.L2-3.8.9 (Protect backup CUI): ''Protect the confidentiality of backup CUI at storage locations.''
AC.L2-3.1.3 (Access enforcement): ''Limit access to CUI on the basis of need-to-know to protect confidentiality.''
Physical security references (PE family): ''Physical access controls provide general site protection but are not substitutes for encryption or media protection controls when CUI confidentiality is at risk.''
Why the other options are correct (acceptable methods):
B (Managing who has access to the information): Satisfies Access Control (AC) requirements that limit exposure of CUI only to authorized individuals.
C (Physically securing devices and media): Satisfies Media Protection (MP) requirements, ensuring CUI is stored securely and protected against unauthorized access.
D (Encrypting files or media): Directly satisfies System and Communications Protection (SC) requirements for confidentiality, a highly reliable method.
Why option A is least acceptable:
Alternative physical controls for site access protect buildings or rooms, but they do not directly safeguard backup media confidentiality. If backups are removed, lost, or accessed internally, site access controls alone cannot ensure confidentiality.
Reference (official CCA/CMMC documents):
CMMC Assessment Guide -- Level 2, Version 2.13: Practices SC.L2-3.13.16, MP.L2-3.8.9, AC.L2-3.1.3, and PE family discussion (pp. 93--96, 108--110, 125--127).
NIST SP 800-171A, Assessing Security Requirements for CUI: Related assessment objectives for protecting CUI backup confidentiality.
The assessment team has divided responsibilities to review portions of the OSC's scope, including the Host Unit, the specific enclave, and supporting teams such as a Managed Security Service Provider (MSSP). During evidence review, the team notices that MSSP personnel answered interview questions somewhat differently than OSC personnel. To clarify this inconsistency, the Lead Assessor decides to take all the following steps EXCEPT:
Answer : D
Applicable Requirement (CMMC Assessment Process): The CMMC Assessment Process (CAP) requires assessors to collect, analyze, and reconcile evidence using triangulation (examine, interview, test) to confirm whether requirements are MET or NOT MET. When inconsistencies arise, the assessor must go back to objective evidence such as diagrams, contracts, and notes.
Why Reviewing Network Diagrams Helps (supports A): Network diagrams provide authoritative evidence of scope, data flows, and system boundaries, which helps clarify whether the MSSP's services were accurately described.
Why Reviewing MSSP Agreements Helps (supports B): Agreements (such as interconnection security agreements or service-level agreements) define shared responsibilities and confirm how the MSSP supports security controls. This evidence is critical to resolving inconsistent testimony.
Why Reviewing Notes Helps (supports C): Notes from previous interviews allow the team to pinpoint where answers diverged. This is a valid method of evidence review and aligns with CAP guidance on documenting interviews.
Why Interview Questionnaire Consistency is NOT the Correct Step (refutes D): The CAP emphasizes resolving inconsistencies through additional evidence, not by adjusting or re-checking the questionnaire itself. The consistency of the questionnaire is irrelevant --- what matters is reconciling the evidence provided by both the OSC and MSSP. Thus, this is the action the Lead Assessor would NOT take.
Assessment Guidance Extract (CAP):
''When conflicting evidence is observed, the assessment team must review technical documentation, agreements, and notes to identify the root cause and determine whether additional clarification is required.''
''The interview instrument itself is not a tool for reconciling inconsistencies; rather, objective evidence must be used.''
Reference (CCA Official Sources):
CMMC Assessment Process (CAP) v1.0 --- Section 3: Conducting the Assessment (Interview, Evidence, Triangulation, and Conflict Resolution)
CMMC Assessment Guide -- Level 2, Version 2.13 --- Guidance on the role of External Service Providers (MSSPs) and use of documented agreements as evidence
NIST SP 800-171A --- General assessment methodology: reconcile evidence using examine, interview, and test methods
During discussions with an OSC, the assessment team learned that many employees often need to work from remote locations and, as a result, are permitted to access the organization's internal networks from those remote locations. To ensure secure remote access requirements are being met, remote access sessions need NOT be:
Answer : A
CMMC Level 2 control AC.L2-3.1.12: Remote Access requires that all methods of remote access be authorized, monitored, and controlled to protect CUI when accessed from external locations. The assessment guide specifies that assessors must verify that remote sessions are identified, permitted, and controlled. There is no requirement for remote access sessions to be ''validated'' --- this is not part of the assessment objectives for this practice.
Exact extracts:
''Assessment Objectives ... Determine if:
* remote access methods are identified;
* remote access is authorized prior to allowing such connections;
* remote access sessions are controlled; and
* cryptographic mechanisms are employed to protect confidentiality and integrity of remote access sessions.''
''Remote access to organizational systems is accomplished through the use of managed access control points. A detailed record of all remote access sessions is maintained, and the sessions are subject to monitoring and control.''
Why the other options are required:
Identified (B): OSCs must identify all remote access methods in use.
Permitted (C): Remote access must be explicitly authorized before it is allowed.
Controlled (D): Sessions must be controlled (e.g., via encryption, multifactor authentication, and monitoring).
Validated (A): Not a required assessment objective; it is a distractor option.
Reference (CCA documents / Study Guide):
CMMC Assessment Guide -- Level 2, Version 2.13, AC.L2-3.1.12 ''Remote Access'' (Assessment Objectives; Discussion; Potential Assessment Methods and Objects).
NIST SP 800-171 Rev. 2, 3.1.12 (remote access).
A CCA is asked to validate if an OSC has separated their systems containing CUI from other departments' systems on their local network. Which of the following MUST the CCA assess?
Answer : C
To validate separation of CUI systems from non-CUI systems on a local network, the assessor must evaluate the VLAN configuration. VLANs are a recognized logical segmentation method for separating enclaves, as defined in the CMMC Scoping Guide.
Exact Extracts:
CMMC Scoping Guide: ''Isolation can be achieved by implementing subnetworks with firewalls, routers, and VLANs to ensure separation of CUI assets from out-of-scope assets.''
''CUI Assets must be isolated from non-CUI assets unless those non-CUI assets are designated as Security Protection Assets or Contractor Risk Managed Assets.''
Why other options are not correct:
A (WAN): Wide Area Networks describe external connectivity, not local separation.
B (VPN): VPN provides encrypted remote access but does not enforce local network segmentation.
D (NAT): NAT provides IP translation, not logical separation of traffic.
CMMC Assessment Scope -- Level 2, Version 2.13: Isolation requirements and VLAN as an example (pp. 9--11).
CMMC Assessment Guide -- Level 2: Assessor validation of enclave boundary methods.
A company has a server in its own Virtual Cloud used as a CUI enclave. There is a point-to-point VPN between the OSC's office and the cloud environment. Designated users have direct access to the enclave when in the office. When working remotely, those users must establish a VPN connection between their company laptop and the cloud server.
During the assessment, the CCA asks the IT manager about external connections.
How many external connections are within the boundary for this assessment?
Answer : D
External connections are defined as connections crossing the OSC's assessment boundary. Here:
The dedicated VPN from office to cloud = one external connection.
The user-initiated VPNs from remote laptops to cloud = a second external connection.
Extract:
''External connections include all system interfaces that cross the assessment boundary, including VPNs initiated by users or established between sites.''
Thus, there are two external connections.