Weekend Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

CMMC-CCA Exam Dumps - Cyber AB CMMC Questions and Answers

Question # 14

An assessor is reviewing whether an organization appropriately analyzed the security impact of a new release of an application. Which of the following documents is MOST useful for the assessor to review?

Options:

A.

A description of the change from the software vendor

B.

Change Control Board (CCB) meeting minutes and supporting documents

C.

System audit logs showing that the change occurred, when, and by whom

D.

A log of security incidents/issues after the change was implemented

Buy Now
Question # 15

During the assessment of a company, the CCA learns that 50% of employees work from home using remote access. After reviewing the Access Control policy and audit logs, the CCA is unsure how the system ensures only employees with correct privileges can access CUI. The CCA decides a Test of functionality is required. Which question is of the LEAST concern to the CCA?

Options:

A.

Are remote access sessions necessary?

B.

Are remote access sessions permitted?

C.

Are remote access sessions monitored?

D.

Are the types of permitted remote access identified?

Buy Now
Question # 16

A company is undergoing a CMMC Level 2 Assessment. The Assessment Team is planning and preparing the assessment. Who is responsible for identifying methods, techniques, and responsibilities for collecting, managing, and reviewing evidence?

Options:

A.

Lead Assessor

B.

Assessment Team Member

C.

C3PAO Quality Oversight Manager

D.

CMMC Quality Assurance Professional

Buy Now
Question # 17

In completing the assessment of practices in the Access Control (AC) domain, a CCA scored AC.L2-3.1.15: Privileged Remote Access as NOT MET. The OSC was notified of this deficiency at the end of day two of the assessment. On day five of the assessment, the OSC’s Assessment Official contacted the CCA to provide evidence that the deficiencies have been corrected.

What is the CCA’s NEXT step?

Options:

A.

This practice is not eligible for deficiency correction and should be scored as NOT MET.

B.

This practice is not eligible for deficiency correction, should be scored as NOT MET, and reevaluated during a POA&M Close-Out Assessment.

C.

This practice is eligible for deficiency correction and should be scored as MET but must be reevaluated during a POA&M Close-Out Assessment.

D.

This practice is eligible for deficiency correction, should be scored as NOT MET, and evaluated during the Limited Deficiency Correction evaluation.

Buy Now
Question # 18

An OSC uses a colocation facility to house its CUI assets. The colocation restricts access to the data center via keycard and requires all entrants to sign in and out. The OSC’s cage and cabinets are further secured with keys accessible only to OSC-authorized personnel.

In order to assess physical controls, the CCA should:

Options:

A.

Physically visit the colocation facility to determine the effectiveness of controls.

B.

Evaluate the colocation facility security process as listed in the service agreement.

C.

Physically visit the colocation facility to determine the effectiveness of controls and review the OSC’s process for maintaining access to the keys.

D.

Evaluate the colocation facility security process as listed in the service agreement and review the OSC’s process for maintaining access to the keys.

Buy Now
Question # 19

Different mechanisms can be used to protect information at rest. Which mechanism is MOST LIKELY to afford protection for information at rest?

Options:

A.

Patching

B.

File share

C.

Secure offline storage

D.

Cryptographic mechanisms

Buy Now
Question # 20

ESPs are exceptionally common today, given that many organizations are turning to secure cloud offerings to establish and maintain compliance. Integral to these relationships is a responsibility matrix, which defines who is responsible for specific items such as security. This can be a very complex assortment of taskings associated with federal compliance, but what is the MOST important thing to remember?

Options:

A.

The ESP is technically not part of the DIB and has no responsibility to be CMMC compliant in its own right.

B.

The CMMC Assessment Team will factor in any documentation provided by the ESP when evaluating the OSC for compliance.

C.

The relationship of an OSC with an ESP is a partnership and the CMMC Assessment will evaluate the ESP at the same time as the OSC.

D.

Only the OSC is being assessed for compliance, and while the ESP may have a lot of responsibilities in the matrix, the OSC is ultimately responsible for meeting the requirements as specified by government mandates.

Buy Now
Question # 21

An organization’s password policy includes these requirements:

    Passwords must be at least 8 characters in length.

    Passwords must contain at least one uppercase character, one lowercase character, and one numeric digit.

    Passwords must be changed at least every 90 days.

    When a password is changed, none of the previous 3 passwords can be reused.

Per IA.L2-3.5.7: Password Complexity, what requirement is missing from this password policy?

Options:

A.

It does not require MFA.

B.

It does not include a list of prohibited passwords.

C.

It does not specify a minimum change of character requirement.

D.

It does not require the password to contain at least one special character.

Buy Now
Question # 22

During a CMMC Assessment, the assessor is determining if the Escort Visitors practice is MET. Personnel with which of the following responsibilities would be MOST appropriate to interview?

Options:

A.

Repair and facilities maintenance

B.

Local access control and information security

C.

Physical access control and information security

D.

Information technology management and operations

Buy Now
Question # 23

An OSC uses an External Service Provider (ESP) to support part of its CUI processing scope. The OSC has selected an accredited ESP with FedRAMP MODERATE authorization. The OSC has a contract requiring the ESP to meet its security requirements. The ESP has provided a Shared Responsibility Matrix (SRM) consistent with the contract terms.

When assessing these assets, what should the assessor MOST carefully review?

Options:

A.

The contract terms to ensure that the OSC’s CMMC Level 2 requirements are in the contract, and the SRM to ensure that the shared responsibilities are well defined.

B.

The contract terms to ensure that the OSC’s CMMC Level 2 requirements are in the contract, and the SRM to ensure that the ESP’s responsibilities are well defined.

C.

The ESP’s FedRAMP MODERATE authorization to ensure the OSC’s CMMC Level 2 requirements are MET, and the SRM to ensure that the ESP’s responsibilities are well defined.

D.

The ESP’s FedRAMP MODERATE authorization to ensure the OSC’s CMMC Level 2 requirements are MET, and the SRM to ensure that the shared responsibilities are well defined.

Buy Now
Exam Code: CMMC-CCA
Exam Name: Certified CMMC Assessor (CCA) Exam
Last Update: Sep 3, 2025
Questions: 150
CMMC-CCA pdf

CMMC-CCA PDF

$29.75  $84.99
CMMC-CCA Engine

CMMC-CCA Testing Engine

$33.25  $94.99
CMMC-CCA PDF + Engine

CMMC-CCA PDF + Testing Engine

$47.25  $134.99