[Q122-Q142] Dumps for Free Cyber AB CMMC-CCP Practice Exam Questions [Dec 05, 2025]

Share

Dumps for Free Cyber AB CMMC-CCP Practice Exam Questions [Dec 05, 2025] 

CMMC-CCP Dumps PDF And Certification Training


Cyber AB CMMC-CCP Exam Syllabus Topics:

TopicDetails
Topic 1
  • CMMC-AB Code of Professional Conduct (Ethics): This section of the exam measures the integrity of cybersecurity professionals by evaluating their understanding of the CMMC-AB Code of Professional Conduct. It emphasizes ethical responsibilities, including confidentiality, objectivity, professionalism, conflict-of-interest avoidance, and respect for intellectual property, ensuring candidates can uphold ethical standards throughout their CMMC-related duties.
Topic 2
  • CMMC Model Construct and Implementation Evaluation: This section of the exam measures the evaluative skills of cybersecurity assessors, focusing on the application and assessment of the CMMC model. It includes understanding its levels, domains, practices, and implementation criteria, and how to assess whether organizations meet the required cybersecurity practices using evidence-based evaluation.
Topic 3
  • CMMC Governance and Source Documents: This section of the exam measures the capabilities of legal or compliance advisors, covering key regulatory frameworks that govern cybersecurity compliance. Topics include Federal Contract Information, Controlled Unclassified Information, the role of NIST SP 800-171, DFARS, FAR, and the structure and requirements of CMMC v2.0, including self-assessments and certification levels.

 

NEW QUESTION # 122
An OSC lead has provided company information, identified that they are seeking CMMC Level 2, stated that they handle FCI. identified stakeholders, and provided assessment logistics. The OSC has provided the company's cyber hygiene practices that are posted on every workstation, visitor logs, and screenshots of the configuration of their FedRAMP-approved applications. The OSC has not won any DoD government contracts yet but is working on two proposals Based on this information, which statement BEST describes the CMMC Level 2 Assessment requirements?

  • A. Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract.
  • B. Ready because there is no need to certify this company until after they win a DoD contract.
  • C. Not ready because the OSC still lacks artifacts that prove they have implemented all the CMMC Level
    2 Assessment requirements.
  • D. Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification.

Answer: C

Explanation:
CMMC Level 2 Readiness and Certification RequirementsCMMCLevel 2is required forOrganizations Seeking Certification (OSCs) that handle Controlled Unclassified Information (CUI)and aligns withNIST SP
800-171's 110 security controls.
* Key Readiness Indicators for a Level 2 Assessment:
* The OSC must have implemented all 110 security practices from NIST SP 800-171.
* Documented and validated cybersecurity policies and procedures must exist.
* The OSC must be prepared to provide objective evidence (artifacts) proving compliance.
* Why the OSC in the Question is Not Ready:
* They have not won a DoD contract yet# This means they do not yet have a contractually definedCUI environment, which is the foundation for defining their security scope.
* They have only provided FCI-related artifacts(e.g., visitor logs, workstation policies, FedRAMP configurations).
* Lack of full documentation of CMMC Level 2 controls# The assessment requiresevidence for all
110 security practices(e.g., system security plans, incident response records, security awareness training documentation).
* A. "Ready because there is no need to certify this company until after they win a DoD contract."
* Incorrect# Some organizationsseek certification proactivelybefore winning contracts. However, readiness depends on implementingall 110 required controls, not contract status alone.
* B. "Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract."
* Incorrect# CMMC Level 2focuses on CUI, not just FCI. While FCI protection is important, the assessment's focus is onCUI security requirements, which arenot fully addressed by the provided artifacts.
* D. "Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification."
* Incorrect# While it is commendable that the OSC is being proactive,readiness is based on full compliance with NIST SP 800-171, not just intent.
References:NIST SP 800-171 Rev. 2(NIST Official Site)
CMMC 2.0 Level 2 Assessment Guide(Cyber AB)
DFARS 252.204-7012 & CMMC 2.0 Requirements(DoD CIO)
#Final Answer: C. Not ready because the OSC still lacks artifacts that prove they have implemented all the CMMC Level 2 Assessment requirements.


NEW QUESTION # 123
What are CUI protection responsibilities?

  • A. Shielding
  • B. Correcting
  • C. Safeguarding
  • D. Governing

Answer: C

Explanation:
Understanding CUI Protection ResponsibilitiesControlled Unclassified Information (CUI)is sensitive butnot classifiedinformation that requires protection underDoD Instruction 5200.48andDFARS 252.204-7012.
Theprimary responsibilityfor handling CUIis safeguardingit against unauthorized access, disclosure, or modification.
* TheCUI Program (as per NARA and DoD)mandatessafeguarding measuresto protectCUI in both digital and physical forms.
* CMMC 2.0 Level 2 (Advanced) practices align with NIST SP 800-171, which focuses on safeguarding CUIthrough access controls, encryption, and monitoring.
* DFARS 252.204-7012requires DoD contractors to implementcybersecurity safeguardsto protect CUI.
* A. Shielding (Incorrect)-Shieldingis not a cybersecurity term associated with CUI protection.
* B. Governing (Incorrect)-Governing refers to policy-making, not direct protection.
* C. Correcting (Incorrect)-Correcting implies remediation, but the primary responsibility is tosafeguardCUI proactively.
* The correct answer isD. Safeguarding, asCUI protection focuses on implementing cybersecurity safeguards.
References:
DoD Instruction 5200.48 (CUI Program)
DFARS 252.204-7012
CMMC 2.0 Level 2 Practices (NIST SP 800-171)


NEW QUESTION # 124
While conducting a CMMC Assessment, a Lead Assessor is given documentation attesting to Level 1 identification and authentication practices by the OSC. The Lead Assessor asks the CCP to review the documentation to determine if identification and authentication controls are met. Which documentation BEST satisfies the requirements of IA.L1-3.5.1: Identify system users. processes acting on behalf of users, and devices?

  • A. List of unauthorized users that identifies their identities and roles
  • B. User names associated with system accounts assigned to those individuals
  • C. Procedures for implementing access control lists
  • D. Physical access policy that states. "All non-employees must wear a special visitor pass or be escorted."

Answer: B

Explanation:
Understanding IA.L1-3.5.1 (Identification and Authentication Requirements)TheCMMC 2.0 Level
1practiceIA.L1-3.5.1aligns withNIST SP 800-171, Requirement 3.5.1, which mandates that organizationsidentify system users, processes acting on behalf of users, and devicesto ensure proper access control.
To comply with this requirement, anOrganization Seeking Certification (OSC)must maintain documentation that demonstrates:
* A unique identifier (username) for each system user
* Mapping of system accounts to specific individuals
* Identification of devices and automated processes that access systems
* This documentation directly satisfies IA.L1-3.5.1because it showshow system users are uniquely identified and linked to specific accountswithin the environment.
* Alist of users and their assigned accountsconfirms that the organization has a structured method oftracking access and authentication.
* It allows auditors to verify thateach user has a distinct identityand that access control mechanisms are properly applied.
* A. Procedures for implementing access control lists (Incorrect)
* While access control lists (ACLs) are relevant for authorization, they do notidentify users or devicesspecifically, making them insufficient as primary evidence for IA.L1-3.5.1.
* B. List of unauthorized users that identifies their identities and roles (Incorrect)
* Identifying unauthorized users does not fulfill the requirement of trackingauthorizedusers, devices, and processes.
* D. Physical access policy stating "All non-employees must wear a special visitor pass or be escorted" (Incorrect)
* This pertains tophysical security, not system-baseduser identification and authentication.
* The correct answer isC. User names associated with system accounts assigned to those individuals, as thisdirectly satisfies the identification requirement of IA.L1-3.5.1.
References:
CMMC 2.0 Level 1 Practice IA.L1-3.5.1
NIST SP 800-171, Requirement 3.5.1


NEW QUESTION # 125
A CMMC Assessment is being conducted at an OSC's HQ. which is a shared workspace in a multi-tenant building. The OSC is renting four offices on the first floor that can be locked individually. The first-floor conference room is shared with other tenants but has been reserved to conduct the assessment. The conference room has a desk with a drawer that does not lock. At the end of the day, an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?

  • A. Review it, print it, make notes, and then shred it in cross-cut shredder in the print room.
  • B. Review it, and make notes on the computer provided by the client.
  • C. Review it. print it, and leave it in a folder on the table together with the other documents.
  • D. Review it. print it, and put it in the desk drawer.

Answer: A


NEW QUESTION # 126
The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?

  • A. Gaps or deltas due to any reciprocity model are recorded as met
  • B. Documented rationale for each failed practice
  • C. Affirmation for each practice or control
  • D. Suggested improvements for each failed practice

Answer: B

Explanation:
Understanding the CMMC Level 2 Final Report RequirementsFor aCMMC Level 2 Assessment, theFinal CMMC Assessment Results Reportmust include:
Assessment findings for each practice
Final ratings (MET or NOT MET) for each practice
A detailed rationale for each practice rated as NOT MET
The CMMC Assessment Process (CAP) Guidestates that if a practice is markedNOT MET, theassessors must provide a rationale explaining why it failed.
This rationale helps theOSC understand what needs remediationand, if applicable, whether the deficiency can be addressed via aPlan of Action & Milestones (POA&M).
TheFinal Report serves as an official recordand must be submitted as part of theresults package.
A). Affirmation for each practice or control (Incorrect)
While the report includes aMET/NOT MET ratingfor each practice,affirmation is not a required component.
C). Suggested improvements for each failed practice (Incorrect)
Assessors do not provide recommendations for improvement-they only document findings and rationale.
Providing suggestions would create aconflict of interestperCMMC-AB Code of Professional Conduct.
D). Gaps or deltas due to any reciprocity model are recorded as met (Incorrect) If an organization isleveraging reciprocity (e.g., FedRAMP, Joint Surveillance Voluntary Assessments), gapsmust still be documented-not automatically marked as "MET." The correct answer isB. Documented rationale for each failed practice, as this is amandatory requirement in the Final CMMC Assessment Results Report.
References:
CMMC Assessment Process (CAP) Guide
DFARS 252.204-7021


NEW QUESTION # 127
What is the LAST step when developing an assessment plan for an OSC?

  • A. Update the assessment plan and schedule as needed
  • B. Verify the readiness to conduct the assessment.
  • C. Perform certification assessment readiness review.
  • D. Obtain and record commitment to the assessment plan.

Answer: B

Explanation:
Last Step in Developing an Assessment Plan for an OSCDeveloping anassessment planinvolves:
Defining the assessment scope(e.g., systems, networks, locations).
Planning test activities(e.g., interviews, evidence review, technical testing).
Verifying the OSC's readiness(e.g., ensuring required documents are available).
Updating the assessment plan and schedule as needed.
Final Step: Obtaining and recording the OSC's commitment to the assessment plan.
Why is obtaining commitment the last step?#Theassessment cannot proceed unless the OSC agrees to the finalized plan.
#This ensuresOSC leadership understands the scope, timeline, and responsibilities.
#TheC3PAO must document this commitmentto formalize the agreement.
A). Verify the readiness to conduct the assessment # Incorrect
Readiness verification happens earlierin the planning process, not as the last step.
B). Perform certification assessment readiness review # Incorrect
Areadiness review is conducted before finalizing the plan, not at the very end.
C). Update the assessment plan and schedule as needed # Incorrect
Updating the plan happens before commitment is obtained; it is not the final step.
D). Obtain and record commitment to the assessment plan # Correct
This is the final step before conducting the assessment. The OSC must formally agree to the plan.
Why is the Correct Answer "D. Obtain and record commitment to the assessment plan"?
CMMC Assessment Process (CAP) Document
States that theOSC must confirm agreement to the assessment plan before execution.
CMMC-AB Guidelines for C3PAOs
Specifies thatfinalizing the assessment plan requires documented commitment from the OSC.
CMMC Assessment Guide
Outlines thatassessments cannot begin without formal approval of the plan.
CMMC 2.0 References Supporting This Answer.
Final Answer #D. Obtain and record commitment to the assessment plan.


NEW QUESTION # 128
An OSC has submitted evidence for an upcoming assessment. The assessor reviews the evidence and determines it is not adequate or sufficient to meet the CMMC practice. What can the assessor do?

  • A. Postpone the assessment.
  • B. Cancel the assessment.
  • C. Notify the CMMC-AB.
  • D. Contact the C3PAO for guidance.

Answer: D


NEW QUESTION # 129
A Lead Assessor is preparing to conduct a Readiness Review during Phase 1 of the Assessment Process. How much evidence MUST be gathered for each practice?

  • A. Evidence to support at least 2 Assessment Methods
  • B. Evidence that is deemed adequate
  • C. At least 2 Assessment Objects
  • D. A sufficient amount

Answer: D

Explanation:
During a Readiness Review (Phase 1), the purpose is to validate whether an OSC is prepared to move forward with a formal assessment. The CAP specifies that the Lead Assessor must collect sufficient evidence for each practice to make a preliminary determination of readiness.
Supporting Extracts from Official Content:
* CAP v2.0, Readiness Review (§2.14): "The Lead Assessor must collect a sufficient amount of evidence for each practice to determine the OSC's readiness." Why Option A is Correct:
* The requirement is for sufficient evidence; CAP does not mandate a set number of assessment objects or methods.
* Options B, C, and D incorrectly suggest minimum counts or methods that are not part of the readiness review requirements.
References (Official CMMC v2.0 Content):
* CMMC Assessment Process (CAP) v2.0, Phase 1 Readiness Review.


NEW QUESTION # 130
Contractor scoping requirements for a CMMC Level 2 Assessment to document the asset in an inventory, in the SSP and on the network diagram apply to:

  • A. all asset categories except for the Out-of-scope Assets.
  • B. Contractor Risk Managed Assets and Specialized Assets.
  • C. CUI and Security Protection Asset categories.
  • D. GUI Assets.

Answer: A

Explanation:
UnderCMMC Level 2, contractors are required toidentify, document, and categorize assetsinvolved in handlingControlled Unclassified Information (CUI). This is part of thescoping process, which ensures that all security-relevant assets are properly protected and accounted for in the System Security Plan (SSP), asset inventory, and network diagram.
* CMMC Scoping Requirements for Level 2 Assessments:
* TheCMMC Scoping Guide(CMMC v2.0) identifies four asset categories:
* CUI Assets:Systems that store, process, or transmit CUI.
* Security Protection Assets (SPA):Systems providing security functions for CUI Assets (e.
g., firewalls, SIEMs).
* Contractor Risk Managed Assets (CRMA):Assets that interact with CUI but arenot directly controlledby the organization (e.g., personal devices).
* Specialized Assets:These include IoT devices, OT systems, and Government Furnished Equipment (GFE) thatmay require specific security controls.
* Where Documentation is Required:
* The contractor mustdocument all assets (except out-of-scope assets)in:
* The System Security Plan (SSP):A key document detailing security controls and asset categorization.
* An asset inventory:Lists all in-scope assets (CUI Assets, SPAs, CRMA, and Specialized Assets).
* The network diagram:Provides a visual representation of system connectivity and security boundaries.
* Why Out-of-Scope Assets Are Excluded:
* TheCMMC Scoping Guidespecifically states that Out-of-Scope Assets arenot required to be documentedin these compliance artifacts because they haveno direct or indirect interaction with CUI.
* These assets do not require CMMC controls because they are completely isolated from CUI handling environments.
* Why the Other Answer Choices Are Incorrect:
* (A) GUI Assets:There is no specific "GUI Asset" category in CMMC scoping.
* (B) CUI and Security Protection Asset categories:While these are included, this answerexcludesContractor Risk Managed and Specialized Assets, which are also required.
* (D) Contractor Risk Managed Assets and Specialized Assets:These assetsare included in scopingbut this answer excludes CUI Assets and Security Protection Assets, making it incomplete.
Step-by-Step Breakdown:Final Validation from CMMC Documentation:According to theCMMC Assessment Scope Level 2 Guide, allin-scope assetsmust be documented in the SSP, inventory, and network diagram.The only assets excluded are Out-of-Scope Assets.
Thus, the correct answer is:
C: All asset categories except for the Out-of-Scope Assets.


NEW QUESTION # 131
Prior to initiating an OSC's CMMC Assessment, the Lead Assessor briefed the team on the most important requirements of the assessment. The assessor also insisted that the same results of the findings summary, practice ratings, and Level recommendations must be submitted to the C3PAO for initial processes and review. After several weeks of assessment, the C3PAO completes the internal review, the recommended results are then submitted through the C3PAO for final quality review and rating approval. Which document stipulates these reporting requirements?

  • A. DFARS 52.204-21 assessment reporting requirements
  • B. CMMC Assessment reporting requirements
  • C. DFARS clause 252.204-7012 assessment reporting requirements
  • D. NISTSP 800-171 Revision 2 assessment reporting requirements

Answer: B

Explanation:
The correct answer isA. CMMC Assessment Reporting Requirementsbecause this document specifically outlines thestructured processthat Certified Third-Party Assessment Organizations (C3PAOs) must follow when conducting and reporting CMMC assessments.
* Understanding the CMMC Assessment Process
* TheLead Assessorbriefs the team on theassessment requirementsand theevaluation criteriabefore the assessment begins.
* Throughout the assessment,findings summaries, practice ratings, and level recommendationsare documented and reported.
* These findings are internally reviewed by theC3PAObefore they are formally submitted forquality review and final rating approval.
* Key Document Stipulating Reporting Requirements: CMMC Assessment Reporting Requirements
* This documentspecifically details how assessments must be reportedwithin theCMMC ecosystem.
* It describes the structured process for assessment submission, internalC3PAO reviews, andquality checks by the CMMC-ABbefore an organization can receive a final certification decision.
* It ensures thatresults are consistent, transparent, and aligned with DoD cybersecurity compliance expectations.
* Why Other Options Are Incorrect:
* B. DFARS 52.204-21 Assessment Reporting Requirements
* This clause only specifiesbasic safeguardingof Federal Contract Information (FCI) but doesnotdictate the reporting process for CMMC assessments.
* C. NIST SP 800-171 Revision 2 Assessment Reporting Requirements
* WhileNIST SP 800-171 Rev. 2outlines security controls, it doesnotdefine how CMMC assessments must be conducted and reported.
* D. DFARS Clause 252.204-7012 Assessment Reporting Requirements
* This DFARS clause focuses onincident reportingandcyber incident response requirementsbut does not detail theCMMC assessment reporting process.
* CMMC Assessment Reporting Requirements, issued byThe Cyber ABandDoD, governs how C3PAOs must report assessment results.
* CMMC Assessment Process (CAP)also outlines reporting workflows for certification.
Step-by-Step Breakdown:Official Reference:Thus, theCMMC Assessment Reporting Requirementsdocument is the authoritative source that dictates the reporting procedures for CMMC assessments.


NEW QUESTION # 132
In the Code of Professional Conduct, what does the practice of Professionalism require?

  • A. Refrain from dishonesty in all dealings regarding CMMC.
  • B. Do not make assertions about assessment outcomes.
  • C. Do not copy materials without permission to do so.
  • D. Ensure the security of all information discovered or received.

Answer: A


NEW QUESTION # 133
An assessment is being completed at a client site that is not far from the Lead Assessor's home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?

  • A. Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service.
  • B. Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.
  • C. Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.
  • D. Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.

Answer: D

Explanation:
Best Practices for Handling Sensitive Assessment InformationCMMC assessments involve handlingsensitive and potentially CUI-related documents. Assessors must follow strictsecurity policiesto avoid unauthorized access, data leaks, or non-compliance withCMMC 2.0 and NIST SP 800-171 requirements.
Why Logging into the Client VPN on the Client Laptop is the Best Approach:
Ensures Data Protection:The client laptop is likely configured to meet security controls required for handling assessment-related materials.
Prevents Data Spillage:Keeping all assessment-related activities within the client's secured environment reduces the risk ofdata leakage or unauthorized storage.
Maintains Compliance with CMMC/NIST Guidelines:Using aproperly configured client laptop and secured connectionensures compliance withNIST SP 800-171 controls on secure remote access(Requirement3.13.12).
A). "Log into the secure cloud storage service to save copies of the documents on both the work and client laptops." Incorrect#Sensitive data should not be duplicated across multiple systems, especially a non-client-approved laptop. Storing it on an unauthorized systemviolates data handling best practices.
C). "Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service." Incorrect# Theassessor's laptop may not be authorizedorsecuredto handle client data. CMMC guidelines emphasizeusing approved, secured systemsfor assessment-related information.
D). "Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick." Incorrect# Transferring sensitive documents via USBintroduces security risks, including unauthorized data storage and potential malware contamination.
Home office workstationsare unlikely to be authorized for handling CMMC-sensitive data.
References:NIST SP 800-171 Rev. 2, Control 3.13.12 ("Use of Secure Remote Access") CMMC 2.0 Level 2 Assessment Process Guide(Cyber AB) DoD CUI Handling Guidelines(DoD CIO)
#Final Answer B. Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.


NEW QUESTION # 134
When assessing SI.L1-3.14.2: Provide protection from malicious code at appropriate locations within organizational information systems, evidence shows that all of the OSC's workstations and servers have antivirus software installed for malicious code protection. A centralized console for the antivirus software management is in place and records show that all devices have received the most updated antivirus patterns.
What is the BEST determination that the Lead Assessor should reach regarding the evidence?

  • A. It is sufficient, and the audit finding can be rated as MET.
  • B. It is insufficient, and the audit finding can be rated NOT MET.
  • C. It is sufficient, and the Lead Assessor should seek more evidence.
  • D. It is insufficient, and the Lead Assessor should seek more evidence.

Answer: A


NEW QUESTION # 135
Which statement BEST describes the key references a Lead Assessor should refer to and use the:

  • A. published CMMC Assessment Guide practice descriptions for the desired certification level.
  • B. CMMC Model Overview as it provides assessment methods and objects.
  • C. DoD adequate security checklist for covered defense information.
  • D. safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment.

Answer: A

Explanation:
Key References for a Lead Assessor in a CMMC AssessmentALead Assessorconducting aCMMC assessmentmust rely onofficial CMMC guidance documentsto evaluate whether anOrganization Seeking Certification (OSC)meets the required cybersecurity practices.
TheCMMC Assessment Guideprovidesdetailed descriptionsof eachpractice and processat the specificCMMC level being assessed.
It defines:#Theassessment objectivesfor each practice.#Therequired evidencefor compliance.#Thescoring criteriato determine if a practice isMET or NOT MET.
Most Relevant Reference: CMMC Assessment Guide
A). DoD adequate security checklist for covered defense information # Incorrect TheDoD adequate security checklistis related toDFARS 252.204-7012 compliance, butCMMC assessmentsfollow theCMMC Assessment Guide.
B). CMMC Model Overview as it provides assessment methods and objects # Incorrect TheCMMC Model Overviewprovideshigh-level guidance, butdoes not contain specific assessment criteria.
C). Safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment # Incorrect FAR 52.204-21is relevant toCMMC Level 1 (FCI protection), butCMMC Level 2 follows NIST SP 800-
171and requiresCMMC Assessment Guidesfor validation.
D). Published CMMC Assessment Guide practice descriptions for the desired certification level # Correct TheCMMC Assessment Guideis theofficial documentused to determine if anOSC meets the required security practices for certification.
Why is the Correct Answer "D. Published CMMC Assessment Guide practice descriptions for the desired certification level"?
CMMC Assessment Process (CAP) Document
Specifies thatLead Assessors must use the CMMC Assessment Guidefor official scoring.
CMMC Assessment Guide for Level 1 & Level 2
Providesdetailed descriptions, assessment methods, and scoring criteriafor each practice.
CMMC-AB Guidance for Certified Third-Party Assessment Organizations (C3PAOs) Confirms thatCMMC assessments must follow the Assessment Guide, not general DoD security policies.
CMMC 2.0 References Supporting This Answer
Final Answer #D. Published CMMC Assessment Guide practice descriptions for the desired certification level.


NEW QUESTION # 136
Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit, Supporting Organization/Unit, or enclave have been met?

  • A. OSC
  • B. Assessment official
  • C. Assessment Team
  • D. Authorizing official

Answer: C

Explanation:
Per the CMMC Assessment Process (CAP), the Assessment Team is responsible for determining the adequacy and sufficiency of evidence collected during the assessment. The team validates whether practices and components for each in-scope Host Unit, Supporting Organization, or enclave meet the target CMMC level. The OSC (Organization Seeking Certification) provides evidence, but only the Assessment Team makes the verification and scoring determination.
Reference Documents:
* CMMC Assessment Process (CAP), v1.0


NEW QUESTION # 137
During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?

  • A. Advisory Board
  • B. CCP
  • C. C3PAO
  • D. Lead Assessor

Answer: D

Explanation:
During aCMMC readiness review, anOrganization Seeking Certification (OSC)may argue that a specificenclave (network segment or system) is out of scopefor assessment. TheLead Assessor is responsible for verifying and approving this request.
Certified CMMC Professional (CCP)
A CCP supports OSCs inpreparing for assessmentsbutdoes not make final scope determinations.
Certified Third-Party Assessment Organization (C3PAO)
The C3PAOoversees the assessmentbut doesnot personally verify scope exclusions-that falls under theLead Assessor's role.
Lead Assessor (Correct Answer)
TheLead Assessor has the authorityto determine if anenclave is out of scopebased on OSC-provided evidence.
The Lead Assessor followsCMMC Assessment Process (CAP) guidelinesto ensure proper scoping.
Advisory Board
TheCMMC-AB (Advisory Board) does not make scope determinations. It focuses onprogram oversightandcertification processes.
CMMC Assessment Process (CAP) v1.0
TheLead Assessor is responsible for confirming the assessment scopeand determining enclave applicability.
CMMC Scoping Guidance for Level 2 Assessments
Requires theLead Assessor to review and approve any enclave exclusionsbefore finalizing the assessment scope.
Roles and Responsibilities in CMMC Assessments:Official References Supporting the Correct Answer Conclusion:TheLead Assessoris the correct answer because they have the authority to verify scope determinations during the assessment.
#Correct Answer C. Lead Assessor


NEW QUESTION # 138
A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?

  • A. 48 hours
  • B. 96 hours
  • C. 24 hours
  • D. 72 hours

Answer: D

Explanation:
Contractors that handle Covered Defense Information (CDI) are required to report cyber incidents to the Department of Defense within 72 hours of discovery.
Supporting Extracts from Official Content:
* DFARS 252.204-7012(c)(1): "When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, the Contractor shall conduct a review... and rapidly report the cyber incident to DoD within 72 hours of discovery." Why Option C is Correct:
* The regulation explicitly specifies 72 hours.
* Options A (24 hrs), B (48 hrs), and D (96 hrs) do not align with DFARS requirements.
References (Official CMMC v2.0 Content and Source Documents):
* DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
* CMMC v2.0 Governance - Source Documents list includes DFARS 252.204-7012.


NEW QUESTION # 139
A C3PAO has completed a Limited Practice Deficiency Correction Evaluation following an assessment of an OSC. The Lead Assessor has recommended moving deficiencies to a POA&M. but the OSC will remain on an Interim Certification. What is the MINIMUM number of practices that must be scored as MET to initiate this course of action?

  • A. 100 practices
  • B. 110 practices
  • C. 88 practices
  • D. 80 practices

Answer: A

Explanation:
TheLimited Practice Deficiency Correction Evaluationprocess occurs when anOrganization Seeking Certification (OSC)has undergone aCMMC Level 2 Assessmentby aCertified Third-Party Assessment Organization (C3PAO)and hasunresolved deficienciesin some security practices.
According toCMMC 2.0 policy and DFARS 252.204-7021, OSCs can still achieveInterim Certificationif they meet theminimum thresholdof security practices while addressing deficiencies through aPlan of Action & Milestones (POA&M).
TheCMMC 2.0 Interim Rulestates that an OSCmust meet at least 100 out of 110 practicesto qualify for aPOA&M-based remediation.
A maximum of 10 practices can be listed in the POA&Mfor later correction.
Failure to meet at least 100 practices results in failing the assessment outright, requiring a full reassessment after remediation.
The Lead Assessor can recommend POA&M placementonly if the OSC meets at least 100 practices.
Less than 100 practices scored as MET means the OSC does not qualify for a POA&Mand mustretest completely.
DFARS 252.204-7021 and CMMC 2.0 policiesconfirm the100-practice thresholdfor conditional certification.
A). 80 practices (Incorrect)- Falls well below the 100-practice requirement.
B). 88 practices (Incorrect)- Still below the POA&M eligibility threshold.
D). 110 practices (Incorrect)- While meeting 110 practices would be ideal,CMMC allows a POA&M option at
100 practices.
The correct answer isC. 100 practices, as this meets theminimum threshold for POA&M-based Interim Certification.
References:
DFARS 252.204-7021 (CMMC Requirement Clause)
CMMC 2.0 Assessment Process (CAP) Guide
DoD CMMC 2.0 Policy Overview


NEW QUESTION # 140
During a Level 2 Assessment, an OSC provides documentation that attests that they utilize multifactor authentication on nonlocal remote maintenance sessions. The OSC feels that they have met the controls for the Level 2 certification. What additional measures should the OSC perform to fully meet the maintenance requirement?

  • A. Connections for nonlocal maintenance sessions should be terminated when maintenance is complete.
  • B. Connections for nonlocal maintenance sessions should be unlimited to ensure maintenance is performed properly
  • C. The maintenance policy states multifactor authentication must have at least two factors applied for nonlocal maintenance sessions.
  • D. The nonlocal maintenance personnel complain that restrictions slow down their response time and should be removed.

Answer: A

Explanation:
UnderCMMC 2.0 Level 2, which aligns with the requirements ofNIST SP 800-171, maintaining robust control overnonlocal maintenance sessionsis critical. While multifactor authentication (MFA) is a required safeguard for secure access, additional measures must be implemented to fully meet the maintenance requirements as outlined inControl 3.3.5:
Key Requirements for Nonlocal Maintenance:
Termination of Nonlocal Maintenance Sessions:
To reduce the attack surface and prevent unauthorized access, nonlocal maintenance connectionsmust be terminated immediately after the maintenance activity is completed. This is a direct requirement to mitigate risks associated with lingering remote sessions that could be exploited by threat actors.
Supporting Reference:NIST SP 800-171, Control 3.3.5 states: "Ensure that remote maintenance is conducted in a controlled manner and disable connections immediately after use." Multifactor Authentication (MFA):
OSCs are required to implement MFA for nonlocal remote maintenance sessions. MFA must includeat least two factors(e.g., something you know, something you have, or something you are).
While the OSC's use of MFA satisfies part of the requirement, it does not complete the control unless proper termination procedures are in place.
Policy and Procedure Adherence:
The OSC must also document amaintenance policyand ensure it reflects the need for terminating connections post-maintenance. The policy should outline roles, responsibilities, and steps for ensuring secure nonlocal maintenance practices.
Incorrect Options:
B). Unlimited connections:Allowing unrestricted nonlocal maintenance sessions is a significant security risk and violates the principle of least privilege.
C). Removing restrictions:Removing restrictions for convenience directly undermines compliance and security.
D). Multifactor authentication details:While MFA is necessary, the question states the OSC already uses it.
Termination of sessions is the missing requirement.
Conclusion:
The requirement toterminate nonlocal maintenance sessions after maintenance is complete(Option A) is critical for compliance withCMMC 2.0 Level 2andNIST SP 800-171, Control 3.3.5. This ensures that nonlocal maintenance activities are secured against unauthorized access and potential vulnerabilities.


NEW QUESTION # 141
For a CMMC Level 2 certification, which organization maintains a non-disclosure agreement with the OSC?

  • A. CMMC-AB
  • B. OUSD A&S
  • C. C3PAO
  • D. NIST

Answer: C

Explanation:
The Certified Third-Party Assessment Organization (C3PAO) enters into a contractual relationship with the OSC. As part of that contract, the C3PAO maintains a non-disclosure agreement (NDA) to protect sensitive and proprietary information reviewed during the assessment.
Supporting Extracts from Official Content:
* CAP v2.0, Roles and Responsibilities (§2.8): "The C3PAO maintains a non-disclosure agreement with the OSC to protect all sensitive information disclosed during the assessment." Why Option B is Correct:
* Only the C3PAO contracts directly with the OSC and is bound to protect assessment data.
* NIST, The Cyber AB (formerly CMMC-AB), and OUSD A&S do not enter NDAs directly with OSCs.
References (Official CMMC v2.0 Content):
* CMMC Assessment Process (CAP) v2.0, Section on OSC-C3PAO agreements.


NEW QUESTION # 142
......

Check your preparation for Cyber AB CMMC-CCP On-Demand Exam: https://passleader.bootcamppdf.com/CMMC-CCP-exam-actual-tests.html