Question 1
An OSC creates standard user accounts with limited capabilities and administrator accounts with full system access. A standard user initiates the uninstall of the anti-virus software, which is organizationally defined as a privileged function. Which of the following would indicate AC.L2-3.1.7: Privileged Functions is properly implemented?
Applicable Requirement: AC.L2-3.1.7 --- ''Prevent non-privileged users from executing privileged functions and capture the execution of such functions in audit logs.''
Correct Interpretation:
A non-privileged (standard) user should be prevented from performing privileged functions (e.g., uninstalling security software).
The attempt must be logged to provide traceability and support accountability.
Why C is Correct: It demonstrates both prevention (software not uninstalled) and auditing (attempt captured in a log), exactly matching the practice.
Why Other Options Are Insufficient:
A: Prevention is shown, but there is no evidence of logging.
B: Function was not prevented, so requirement not met.
D: Logging exists, but privileged action was not prevented.
Reference (CCA Official Sources):
NIST SP 800-171 Rev. 2 --- AC.L2-3.1.7
NIST SP 800-171A --- AC.L2-3.1.7 Assessment Objectives
CMMC Assessment Guide -- Level 2, AC.L2-3.1.7