Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cyber AB Certified CMMC Assessor (CCA) Exam CMMC-CCA Exam Questions

Page: 1 / 15 Total 150 questions

Want more questions? Get Premium Access.

Question 1

An OSC creates standard user accounts with limited capabilities and administrator accounts with full system access. A standard user initiates the uninstall of the anti-virus software, which is organizationally defined as a privileged function. Which of the following would indicate AC.L2-3.1.7: Privileged Functions is properly implemented?

Correct Answer: C. The antivirus software is not uninstalled, and the attempt is captured in an application audit log.
Explanation:

Applicable Requirement: AC.L2-3.1.7 --- ''Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.''

Correct Interpretation:

A non-privileged (standard) user should be prevented from performing privileged functions (e.g., uninstalling security software).

The attempt must be logged to provide traceability and support accountability.

Why C is Correct: It demonstrates both prevention (software not uninstalled) and auditing (attempt captured in a log), exactly matching the practice.

Why Other Options Are Insufficient:

A: Prevention is shown, but there is no evidence of logging.

B: Function was not prevented, so requirement not met.

D: Logging exists, but privileged action was not prevented.

Reference (CCA Official Sources):

NIST SP 800-171 Rev. 2 --- AC.L2-3.1.7

NIST SP 800-171A --- AC.L2-3.1.7 Assessment Objectives

CMMC Assessment Guide -- Level 2, AC.L2-3.1.7


Question 2

A company has five individual buildings in one business complex. During the assessment, the Assessment Team sees people entering and exiting the buildings and notices that none of the buildings have keypads or locks. The Assessment Team needs to determine how physical access is managed and controlled.

Which artifact BEST describes how access to these buildings is managed?

Correct Answer: D. Physical and Environmental Protection Policy
Explanation:

The Physical and Environmental Protection (PE) Policy is the governing artifact that describes how physical access to facilities and environments is managed and controlled. While the SSP provides a system-wide overview, and access lists provide details of who is authorized, it is the PE Policy that explicitly documents the physical access control measures required under CMMC.

Extract from PE.L2-3.10.1:

''Organizations must develop, document, and disseminate physical and environmental protection policies that govern how access to buildings and systems containing CUI is limited to authorized individuals.''


Question 3

The Lead Assessor is compiling the assessment results, which must contain the status for each of the applicable practices. Some practices have been placed in the limited practice deficiency correction program. Multiple areas have been reviewed, including HQ, host units, and a specific enclave.

In order to properly report the findings, the Lead Assessor MUST:

Correct Answer: B. Confirm the final findings are aggregated to the OSC level.
Explanation:

The CMMC Assessment Process (CAP) requires that results be reported at the OSC level. While findings may be gathered from enclaves or units, the final reporting must be aggregated and scored across the entire OSC assessment boundary.

Extract:

''Final recommended assessment results must be consolidated and reported at the OSC level, regardless of assessment locations or enclaves.''

Thus, the Lead Assessor must ensure aggregation to the OSC level.


Question 4

An OSC is preparing for an assessment and wants to gather evidence that will be used by the Lead Assessor to determine the scope of the assessment. The OSC currently operates a hybrid network, with part of their infrastructure at their physical location and part of their infrastructure in a cloud environment.

What evidence should the OSC collect that would assist the Lead Assessor in determining cloud and hybrid environment constraints?

Correct Answer: D. Cloud Service Provider's Customer Responsibility Matrix
Explanation:

For hybrid and cloud environments, the Customer Responsibility Matrix is the critical artifact. It identifies which security responsibilities are handled by the CSP and which remain with the OSC, directly impacting scope.

Extract:

''The OSC must provide responsibility matrices or equivalent documentation that clearly delineates which security controls are the responsibility of the provider and which are retained by the OSC.''

This is necessary for the Lead Assessor to define assessment scope boundaries.


Question 5

The Lead Assessor and OSC Assessment Official determined the resources, cost, and schedule for an upcoming assessment. The Lead Assessor noted the OSC Assessment Official's preferences regarding the limits of the method and the consequent resource, cost, and schedule constraints to arrive at an optimal Assessment Plan. In this situation, who has responsibility for signing the planning agreement?

Correct Answer: C. OSC Assessment Official and Lead Assessor
Explanation:

The Assessment Plan (planning agreement) must be signed by both the Lead Assessor and the OSC Assessment Official. This formalizes agreement on scope, resources, and methodology. The C3PAO is responsible for overall oversight but does not co-sign the plan.

Exact extracts:

''The Lead Assessor is responsible for developing the Assessment Plan in collaboration with the OSC Assessment Official.''

''Both the Lead Assessor and the OSC Assessment Official must sign the Assessment Plan to proceed.''

''The C3PAO maintains responsibility for quality assurance and submission, but not signing.''

Why other options are incorrect:

A/B: Both signatures are required, not one alone.

D: The C3PAO does not sign the planning agreement.


CMMC Assessment Process (CAP), Assessment Planning.

Question 6

The team is assessing an OSC that uses the cloud for hosting its online services. Which of the following is NOT important for the assessor to consider?

Correct Answer: D. FIPS encryption is authenticated as a prerequisite to system access.
Explanation:

Applicable Requirement: SC.L2-3.13.8 (Cryptographic protection of communications) and IA.L2-3.5.x (Identification and authentication).

Why D is Correct: Encryption must be validated as FIPS 140-2/3 compliant but is never ''authenticated as a prerequisite to access.'' Authentication applies to users, devices, and processes, not cryptographic modules themselves.

Why A, B, C are Correct Considerations:

Devices must be authorized before connecting.

Processes acting on behalf of a user must be authenticated.

Users must be authorized prior to access. These are all directly mapped to AC and IA domains.

Reference (CCA Official Sources):

NIST SP 800-171 Rev. 2 --- IA and SC requirements

NIST SP 800-171A --- Assessment Objectives for AC/IA wireless and cloud access

CMMC Assessment Guide -- Level 2, Cloud/ESP Considerations


Question 7

ESPs are exceptionally common today, given that many organizations are turning to secure cloud offerings to establish and maintain compliance. Integral to these relationships is a responsibility matrix, which defines who is responsible for specific items such as security. This can be a very complex assortment of taskings associated with federal compliance, but what is the MOST important thing to remember?

Correct Answer: D. Only the OSC is being assessed for compliance, and while the ESP may have a lot of responsibilities in the matrix, the OSC is ultimately responsible for meeting the requirements as specified by government mandates.
Explanation:

The OSC (Organization Seeking Certification) is always responsible for meeting CMMC requirements, regardless of what responsibilities are shared or outsourced to an ESP. ESPs can provide inherited practices (e.g., FedRAMP Moderate for cloud CUI), but the OSC remains accountable for compliance under government mandates.

Exact Extracts:

CMMC Assessment Guide: ''The OSC is the entity being assessed. While an ESP may provide inherited practices, the OSC retains ultimate responsibility for compliance.''

Scoping Guide: ''External Service Providers may meet requirements on behalf of the OSC; however, it is the OSC that is assessed and must demonstrate sufficiency of evidence.''

Why other options are not correct:

A: Incorrect --- ESPs that process CUI must meet FedRAMP Moderate equivalency, even if not directly assessed for CMMC.

B: While true, factoring documentation does not override that OSC remains accountable.

C: ESPs are not assessed at the same time as the OSC; only the OSC receives certification.


CMMC Assessment Guide -- Level 2, Version 2.13: OSC vs ESP responsibility (pp. 11--13).

CMMC Scoping Guide -- Level 2: External Service Providers.

Question 8

Some OSCs share real estate with other companies. To protect FCI/CUI behind unmanned entrances to buildings, floors, or other areas where FCI/CUI is created, used, stored, or transmitted, which of the following is the BEST method?

Correct Answer: D. One-way gates which require proper credentials or intercom authorization to unlock and permit entry
Explanation:

The Physical Protection (PE) practices require that unmanned access points to areas containing CUI be restricted with technical controls that only allow entry to authorized personnel. While cameras, signage, and turnstiles support security, they do not actually prevent access.

Extract from PE.L2-3.10.1:

''Limit physical access to organizational information systems, equipment, and the respective operating environments to authorized individuals.''

The strongest measure listed is one-way gates requiring credentials or intercom authorization, which directly enforces access control.


Question 9

In order to perform an interview, the Lead Assessor MUST ensure interview questions are:

Correct Answer: C. Asked to those who implement, perform, or support the practices
Explanation:

Applicable Requirement: CAP -- Interview Guidance.

Why C is Correct: Interviews must be directed to personnel responsible for implementing, performing, or supporting practices to ensure accurate and objective evidence is collected.

Why Other Options Are Insufficient:

A: Yes/no questions do not provide sufficient evidence detail.

B: OSC personnel cannot ask themselves assessment questions; only assessors may conduct interviews.

D: Group interviews may be used in some cases, but CAP stresses targeted interviews for evidence reliability.

Reference (CCA Official Sources):

CMMC Assessment Process (CAP) v1.0 --- Interview Requirements

NIST SP 800-171A --- Use of Interview as an Assessment Method


Question 10

The OSC has assembled its documentation relating to how it controls remote access for assessment. The Lead Assessor compared this documentation to the provided topology map and noted several indications of external connections with External Service Providers (ESPs). Which document is MOST LIKELY to show acceptable evidence of the security controls related to the interface between the OSC and the ESP?

Correct Answer: B. Interconnection agreement with ESPs
Explanation:

Applicable Requirement (CMMC/NIST): Multiple practices may apply (e.g., AC.L2-3.1.14 ''Control remote access sessions'' and CA.L2-3.12.4 ''Develop, document, and periodically update system security plans''). However, when an OSC uses an External Service Provider (ESP), the key control is the documented agreement defining the terms, conditions, and responsibilities between the OSC and the ESP.

Why Interconnection Agreement is Correct (supports B):

According to the CMMC Assessment Guide (Level 2), acceptable evidence for external connections with ESPs includes ''interconnection security agreements, memoranda of understanding, or contracts that define the security requirements governing the connection.''

These agreements document controls at the interface boundary and ensure both parties understand their responsibilities for protecting CUI.

Why Other Options Are Insufficient:

A . OSC's access control policy --- An internal policy outlines organizational expectations, but it does not constitute binding evidence of controls at the boundary with an ESP.

C . Technical design of VPN security --- Technical configurations demonstrate how connections are secured, but they do not formally document agreed security requirements between OSC and ESP.

D . Instructions from ESP --- ESP-provided setup instructions are not evidence of the OSC's validated control implementation or responsibility-sharing agreement.

Assessment Process Alignment:

The CMMC Assessment Process (CAP) requires assessors to confirm not only technical implementations but also documented agreements that establish accountability for safeguarding CUI.

Evidence such as interconnection agreements is specifically highlighted as objective evidence that the OSC has verified and controlled external system interfaces.

Reference (CCA Official Sources):

CMMC Assessment Guide -- Level 2, Version 2.13 --- External Service Providers and Evidence Requirements for External Connections

NIST SP 800-171 Rev. 2 --- 3.1.20 and 3.13.6 (discussions on external system connections and interconnection agreements)

NIST SP 800-171A --- Assessment Methods for verifying security of external system interfaces