Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Cyber AB Certified CMMC Professional (CCP) Exam CMMC-CCP Exam Questions

Page: 1 / 15 Total 221 questions

Want more questions? Get Premium Access.

Question 1

Which document is the BEST source for determining the sources of evidence for a given practice?

Correct Answer: D. CMMC Assessment Guide
Explanation:

TheCMMC Assessment Guideis the best source for determining the sources of evidence for a given practice because it provides specific guidance on how organizations should implement and demonstrate compliance with CMMC practices. Each CMMC level has its own assessment guide (e.g.,CMMC Assessment Guide -- Level 1, Level 2), detailing expected evidence and assessment procedures.

Detailed Justification:

CMMC Assessment Guide (Primary Source for Evidence)

TheCMMC Assessment Guideexplicitly outlines the evidence required to verify compliance with each practice.

It provides detailed instructions on assessment objectives, clarifying what assessors should look for when determining compliance.

The guide breaks down each practice intoassessment objectives, helping organizations prepare appropriate documentation and artifacts.

Other Documents and Why They Are Not the Best Choice:

NIST SP 800-53 (Option A)

WhileNIST SP 800-53provides a comprehensive catalog of security and privacy controls, it does not focus on CMMC-specific evidence requirements.

It serves as a foundational cybersecurity framework but does not define the specific artifacts required for CMMC assessment.

NIST SP 800-53A (Option B)

NIST SP 800-53Aprovides guidance on assessing security controls but is not tailored to the CMMC framework.

It includes general control assessment procedures, but theCMMC Assessment Guideis more precise in defining the evidence needed for CMMC compliance.

CMMC Assessment Scope (Option C)

TheCMMC Assessment Scopedocument outlines which systems, assets, and processes are subject to assessment.

While important for defining boundaries, it does not provide details on specific evidence requirements for each practice.

Reference from Official CMMC Documents:

CMMC Assessment Guide (Level 2) -- Section on 'Assessment Objectives'

This document details how evidence is collected and evaluated for each CMMC practice.

Example: ForAC.L2-3.1.1 (Access Control -- Limit System Access), the guide specifies that assessors should verify documented policies, system configurations, and audit logs.

CMMC Model Overview (Official DoD Documents)

Emphasizes thatCMMC Assessment Guidesare the official reference for determining sources of evidence.

Conclusion:

TheCMMC Assessment Guideis the most authoritative source for determining the required evidence for a given practice in CMMC assessments. It provides detailed breakdowns of assessment objectives, required artifacts, and verification steps necessary for compliance.


Question 2

Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?

Correct Answer: D. Configuration Management (CM)
Explanation:

Understanding the Role of Configuration Management (CM) in CMMC 2.0

TheConfiguration Management (CM) domainin CMMC 2.0 ensures that systems aresecurely configured and maintainedto prevent unauthorized or unnecessary changes that could introduce vulnerabilities. One key requirement in CM is torestrict, disable, or prevent the use of nonessential programsto reduce security risks.

Relevant CMMC 2.0 Practice:

CM.L2-3.4.1 -- Establish and enforce security configuration settings for information technology products employed in organizational systems.

This practicerequires organizations to control system configurations, including the removal or restriction ofnonessential programs, functions, ports, and servicestoreduce attack surfaces.

The goal is tominimize exposure to cyber threatsby ensuring only necessary and approved software is running on the system.

Why is the Correct Answer CM (D)?

A . Access Control (AC) Incorrect

Access Control (AC) focuses onmanaging user permissions and accessto systems and data, not restricting programs.

B . Media Protection (MP) Incorrect

Media Protection (MP) deals withprotecting and controlling removable media(e.g., USBs, hard drives) rather than software or system configurations.

C . Asset Management (AM) Incorrect

Asset Management (AM) is aboutidentifying and tracking IT assets, not configuring or restricting software.

D . Configuration Management (CM) Correct

CM explicitly coverssecuring system configurationsbyrestricting nonessential programs, ports, services, and functions, making it the correct answer.

CMMC 2.0 Reference Supporting this Answer:

CMMC 2.0 Practice CM.L2-3.4.1(Security Configuration Management)

Requires organizations toenforce security configuration settingsandremove unnecessary programsto protect systems.

NIST SP 800-171 Requirement 3.4.1

Supportssecure configuration settingsandrestricting unauthorized applicationsto prevent security risks.

CMMC 2.0 Level 2 Requirement

This practice is aLevel 2 (Advanced) requirement, meaningorganizations handling Controlled Unclassified Information (CUI)must comply with it.


Question 3

Which assessment method describes the process of reviewing, inspecting, observing, studying, or analyzing assessment objects (i.e., specification, mechanisms, activities)?

Correct Answer: C. Examine
Explanation:

Understanding the 'Examine' Assessment Method in CMMC 2.0

CMMC 2.0 usesthree assessment methodsto evaluate security compliance:

Examine-- Reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, system documentation).

Interview-- Speaking with personnel to verify knowledge and responsibilities.

Test-- Performing technical validation to check system configurations.

Relevant CMMC 2.0 Reference:

TheCMMC Assessment Process (CAP)definesExamineas the method used toreview or analyze assessment objects, such as policies, procedures, configurations, and logs.

Why is the Correct Answer 'Examine' (C)?

A . Test Incorrect

'Test' involvesexecutinga function to validate its security (e.g., verifying access controls through a live system test).

B . Assess Incorrect

'Assess' is a broad term; CMMC explicitly defines 'Examine' as the method for reviewing documentation.

C . Examine Correct

'Examine' is the official term forreviewing policies, procedures, configurations, or logs.

D . Interview Incorrect

'Interview' involvesverbal discussions with personnel, not document analysis.

CMMC 2.0 Reference Supporting this Answer:

CMMC Assessment Process (CAP) Document

Defines 'Examine' asanalyzing assessment objects (e.g., policies, procedures, logs, documentation).

NIST SP 800-171A

Specifies 'Examine' as a method toreview security controls and configurations.


Question 4

In many organizations, the protection of FCI includes devices that are used to scan physical documentation into digital form and print physical copies of digital FCI. What technical control can be used to limit multi-function device (MFD) access to only the systems authorized to access the MFD?

Correct Answer: A. Virtual LAN restrictions
Explanation:

Understanding Multi-Function Device (MFD) Security in CMMC

Multi-function devices (MFDs), such asscanners, printers, and copiers,process, store, and transmit FCI, making them apotential attack surfacefor unauthorized access.

Thebest technical controlto limit MFD access to only authorized systems isVirtual LAN (VLAN) restrictions, whichsegment and isolate network traffic.

Why the Correct Answer is 'A. Virtual LAN (VLAN) Restrictions'?

VLAN Restrictions Provide Network Segmentation

VLANsisolate the MFDfrom unauthorized systems, ensuringonly approved devicescan communicate with it.

Prevents unauthorized network access bylimiting connectionsto specific IPs or subnets.

Meets CMMC 2.0 Network Security Controls

Aligns withCMMC System and Communications Protection (SC) Practicesfor network segmentation and access control.

Reducesthe risk of unauthorized access to scanned and printed FCI.

Why Not the Other Options?

B . Single administrative accountIncorrect

Asingle admin accountdoes not restrict accessbetween devices, only controlswho can configurethe MFD.

C . Documentation showing MFD configurationIncorrect

Documentation helps with compliance butdoes not actively restrict access.

D . Access lists only known to the IT administratorIncorrect

Access lists should besystem-enforced, not just 'known' to the administrator.

Relevant CMMC 2.0 Reference:

CMMC Practice SC.3.192 (Network Segmentation)-- Requires restricting access usingnetwork segmentation techniques such as VLANs.

NIST SP 800-171 (SC Family)-- Supportsisolation of sensitive devicesusing VLANs and other segmentation controls.

Final Justification:

SinceVirtual LAN (VLAN) restrictions enforce access control at the network level, the correct answer isA. Virtual LAN (VLAN) restrictions.


Question 5

What service is the MOST comprehensive that the RPO provides?

Correct Answer: C. Consulting services
Explanation:

Understanding the Role of a Registered Provider Organization (RPO)

ARegistered Provider Organization (RPO)is an entity recognized by theCMMC Accreditation Body (CMMC-AB)to provideconsulting servicesto organizations seekingCMMC certification.

Key Functions of an RPO

Consulting servicesto help companies prepare for CMMC assessments.

Guidance on security controlsrequired for compliance.

Assistance with documentation, policy development, and gap analysis.

Preparation for third-party CMMC assessmentsbutdoes not conduct official CMMC assessments(this is the role of a C3PAO).

Why 'Consulting Services' is the Correct Answer?

Consulting servicesare thebroadest and most comprehensivefunction of an RPO.

RPOs do not conduct assessments(eliminating option D).

Training and educationmay be part of consulting but arenot the primary function(eliminating A and B).

Consulting includes training, guidance, documentation assistance, and security readiness, making it themost comprehensive service offered.

Breakdown of Answer Choices

Option

Description

Correct?

A . Training services

Incorrect--RPOs may provide training, but this isnot their primary function.

B . Education services

Incorrect--Similar to training, butnot the most comprehensive service.

C . Consulting services

Correct -- The core function of an RPO is consulting, which includes various readiness services.

D . Assessment services

Incorrect--Only aC3PAO (Certified Third-Party Assessment Organization)can conductofficial CMMC assessments.

Official Reference from CMMC 2.0 Documentation

TheCMMC-AB RPO Programdefines an RPO as aconsulting organization that assists companies in preparing for CMMC certificationbutdoes not perform assessments.

Final Verification and Conclusion

The correct answer isC. Consulting services, asRPOs primarily provide advisory and readiness supportto organizations preparing forCMMC compliance.


Question 6

An Assessment Team Member is conducting a CMMC Level 2 Assessment for an OSC that is in the process of inspecting Assessment Objects for AC.L1-3.1.1: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) to determine the adequacy of evidence provided by the OSC. Which Assessment Method does this activity fall under?

Correct Answer: C. Examine
Explanation:

Understanding Assessment Methods in CMMC 2.0

According to theCMMC Assessment Process (CAP) Guide, assessors usethree primary assessment methodsto determine compliance with security practices:

Examine-- Reviewing documents, policies, configurations, and system records.

Interview-- Speaking with personnel to gather insights into security processes.

Test-- Performing technical validation of system functions and security controls.

Why Option C (Examine) is Correct

TheAssessment Team Memberis inspectingAssessment Objects(e.g., system configurations, user access control settings, policies) to determine if the OSC's evidence is sufficient forAC.L1-3.1.1 (Access Control -- Authorized Users).

This activity aligns directly with theExaminemethod, which involves reviewing artifacts such as:

Access control lists (ACLs)

System user authentication logs

Account management policies

Role-based access control settings

'Observe' (Option B)is incorrect because 'observing' is not an official assessment method in CMMC.

'Test' (Option A)is incorrect because the assessment is not actively executing a function but ratherreviewingevidence.

'Interview' (Option D)is incorrect because no personnel are being questioned---only documentation is being reviewed.

Official CMMC Documentation Reference

CMMC Assessment Process (CAP) Guide, Section 3.5 -- Assessment Methods

CMMC Level 2 Assessment Guide -- Access Control Practices (AC.L1-3.1.1)

Final Verification

Since the activity involves reviewing documents and records to verify access control measures, it falls under theExaminemethod, makingOption C the correct answer.


Question 7

Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?

Correct Answer: B. Phase 2: Conduct Assessment
Explanation:

Understanding the CMMC Assessment Process

TheCMMC Assessment Process (CAP)consists offour phases, each with specific tasks and objectives.

Phase 1: Plan and Prepare Assessment-- Planning, scheduling, and preparing for the assessment.

Phase 2: Conduct Assessment--Gathering and verifying evidence, conducting interviews, and evaluating compliance.

Phase 3: Report Recommended Assessment Results-- Documenting findings and reporting results.

Phase 4: Remediation of Outstanding Assessment Issues-- Allowing the organization to address any deficiencies.

Why 'Phase 2: Conduct Assessment' is Correct?

DuringPhase 2: Conduct Assessment, theAssessment Teamperforms key activities, including:

Identifying required evidencefor compliance verification.

Obtaining and reviewing artifacts(e.g., security policies, configurations, logs).

Verifying the sufficiency of evidenceagainst CMMC practice requirements.

Interviewing key personneland observing cybersecurity implementations.

Since the question specifically mentions'identify, obtain inventory, and verify evidence,'this task directly falls underPhase 2: Conduct Assessment.

Breakdown of Answer Choices

Option

Description

Correct?

A . Phase 1: Plan and Prepare Assessment

Incorrect--This phase focuses onscheduling, logistics, and planning, not evidence collection.

B . Phase 2: Conduct Assessment

Correct -- This phase involves gathering, verifying, and reviewing evidence.

C . Phase 3: Report Recommended Assessment Results

Incorrect--This phasedocumentsresults but doesnotcollect evidence.

D . Phase 4: Remediation of Outstanding Assessment Issues

Incorrect--This phase focuses oncorrective actions, not evidence collection.

Official Reference from CMMC 2.0 Documentation

CMMC Assessment Process Guide (CAP)--Phase 2: Conduct Assessmentexplicitly includes tasks such asgathering and verifying evidence.

Final Verification and Conclusion

The correct answer isB. Phase 2: Conduct Assessment, as this phase includesidentifying, obtaining, and verifying evidence, which is critical for determining CMMC compliance.


Question 8

Companies that knowingly defraud the government by not being in compliance with cybersecurity regulations are at risk of being held liable for:

Correct Answer: D. Three times the contract value plus a penalty as stated in the False Claims Act
Explanation:

The False Claims Act (31 U.S.C. 3729--3733) imposes liability on companies that knowingly misrepresent compliance in order to receive or retain federal contracts. Penalties include treble damages (three times the government's losses) plus additional penalties per claim.

Supporting Extracts from Official Content:

False Claims Act: ''Any person who knowingly submits false claims to the Government is liable for three times the Government's damages plus a penalty.''

DOJ Cyber-Fraud Initiative (2021): confirms the FCA is applied to cases of misrepresenting compliance with cybersecurity requirements.

Why Option D is Correct:

The applicable law is the False Claims Act, not a ''Cyber Claims Act'' (which does not exist).

The FCA specifies treble damages plus penalties, which exactly matches Option D.

Reference (Official CMMC v2.0 Governance and Source Documents):

False Claims Act (31 U.S.C. 3729--3733).

DOJ Cyber-Fraud Initiative (2021), applied to CMMC-related compliance misrepresentation.


Question 9

The director of cybersecurity is considering which company offices and data centers store FCI to ensure an accurate scope for their CMMC Level 1 Self-Assessment. Which asset type is the director considering?

Correct Answer: C. Facilities
Explanation:

For CMMC Level 1 scoping, the DoD's CMMC Scoping Guide -- Level 1 (v2.13) instructs an organization performing a Level 1 self-assessment to consider what is in scope for protecting Federal Contract Information (FCI). Specifically, it states that to appropriately scope a Level 1 self-assessment, the OSA should consider the people, technology, facilities, and external service providers (ESPs) within its environment that process, store, or transmit FCI.

In this scenario, the director is evaluating company offices and data centers where FCI is stored. These are physical locations and physical environments---exactly what the scoping guidance categorizes under Facilities. Facilities in a Level 1 context include physical sites and spaces that may house systems or media containing FCI (e.g., offices, server rooms, data centers), because those locations affect physical access controls, environmental protections, and overall safeguarding of where FCI is handled and stored.

This is distinct from Technology (devices/systems), People (personnel who handle FCI), and ESPs (external providers delivering IT/cyber services). Since the question is explicitly about which offices and data centers store FCI---a physical boundary and location question---the correct asset type is Facilities.


Question 10

Who makes the final determination of the assessment method used for each practice?

Correct Answer: D. Lead Assessor
Explanation:

Who Determines the Assessment Method for Each Practice?

In aCMMC Level 2 Assessment, theLead Assessorhas thefinal authorityin determining theassessment methodused to evaluate each practice.

Key Responsibilities of the Lead Assessor

Ensures theCMMC Assessment Process (CAP) Guideis followed.

Determines whether a practice is evaluated usinginterviews, demonstrations, or document reviews.

Directs theCertified CMMC Professionals (CCPs)and other assessors on themethodologyfor gathering evidence.

Works under aCertified Third-Party Assessment Organization (C3PAO)to ensure proper assessment execution.

Why 'Lead Assessor' is Correct?

CCP (Option A) assists in the assessment but does not make final decisionson methods.

OSC (Option B) is the Organization Seeking Certification, and they do not control assessment methodology.

Site Manager (Option C) may coordinate logistics but has no authority over assessment decisions.

Breakdown of Answer Choices

Option

Description

Correct?

A . CCP

Incorrect--A CCPassistsbut doesnot determine assessment methods.

B . OSC

Incorrect--The OSC is beingassessedand does not decide assessment methods.

C . Site Manager

Incorrect--The Site Manager handles logistics butdoes not control assessment methods.

D . Lead Assessor

Correct -- The Lead Assessor has the final say on the assessment method used.

Official Reference from CMMC 2.0 Documentation

CMMC Assessment Process Guide (CAP)-- Defines theLead Assessor's rolein determining assessment methods.

Final Verification and Conclusion

The correct answer isD. Lead Assessor, as they havefinal decision-making authority over the assessment methodology.


Question 11

Contractor scoping requirements for a CMMC Level 2 Assessment to document the asset in an inventory, in the SSP and on the network diagram apply to:

Correct Answer: B. CUI and Security Protection Asset categories.
Explanation:

According to the CMMC Scoping Guidance, Level 2, assets are categorized to determine the level of assessment rigor required. The requirement to document an asset in the Asset Inventory, the System Security Plan (SSP), and on the Network Diagram is a specific administrative requirement for high-priority asset classes.

CUI Assets: These are assets that process, store, or transmit Controlled Unclassified Information (CUI). They are part of the 'Assessed' group and must be fully documented in the inventory, SSP, and network diagram.

Security Protection Assets (SPA): These are assets that provide security functions or capabilities to the assessment scope (e.g., firewalls, log servers, or AV management consoles), even if they do not process CUI themselves. Because they are critical to the security of CUI, they must also be documented in the inventory, SSP, and network diagram.

Why other options are incorrect:

Option A: 'GUI Assets' is likely a typo or misnomer in this context (possibly meant to refer to CUI assets or a distractor).

Option C: This is incorrect because Contractor Risk Managed Assets (CRMA) and Specialized Assets have different documentation requirements. For instance, while CRMA are documented in the inventory and SSP, they are often not required to be on the network diagram in the same detail as CUI assets, depending on the specific assessment boundary. Out-of-Scope Assets are not documented at all.

Option D: Contractor Risk Managed Assets (CRMA) and Specialized Assets (like IoT, OT, or Restricted Information Systems) are required to be in the Asset Inventory and SSP, but the CMMC Scoping Guidance specifies that the most stringent documentation (Inventory + SSP + Network Diagram) is the primary mandate for those assets directly handling CUI or protecting it (SPAs).

Reference Documents:

CMMC Scoping Guidance, Level 2 (Version 2.0/2.1): Section 3.0, Table 1 (CUI Assets) and Table 2 (Security Protection Assets), which explicitly list the 'Documentation Requirements' for each category.

CMMC Assessment Process (CAP): Section on Scoping Boundaries and Evidence Validation.


Question 12

During the planning phase of a CMMC Level 2 Assessment, the Lead Assessor is considering what would constitute the right evidence for each practice. What is the Assessor attempting to verify?

Correct Answer: B. Sufficiency
Explanation:

Understanding Evidence Sufficiency in CMMC Level 2 Assessments

During aCMMC Level 2 Assessment, theLead Assessormust determine whether the evidence collected for each practice issufficientto support an assessment finding. This aligns with theCMMC Assessment Process (CAP) Guide, which requires assessors to evaluate:

Examinations-- Reviewing documents, configurations, and system records.

Interviews-- Speaking with personnel to confirm implementation and understanding.

Testing-- Observing security controls in action to validate effectiveness.

To determine whether evidence issufficient, the assessor ensures that it:

Directly supports the assessment objective.

Demonstrates that the practice is consistently implemented.

Can be independently verified.

Why Option B (Sufficiency) is Correct

Sufficiencyrefers to whetherenoughevidence has been collected to make an accurate determination about compliance.

Option A (Adequacy)is incorrect because adequacy relates tothe qualityof evidence, while sufficiency focuses on whetherenoughevidence exists.

Option C (Process Mapping)is incorrect because process mapping is used for understanding workflows but is not an assessment verification method.

Option D (Assessment Scope)is incorrect because defining the scope happensbeforeevidence collection, during the planning phase.

Official CMMC Documentation Reference

CMMC Assessment Process (CAP) Guide -- Section 3.6 (Determining Sufficiency of Evidence)

CMMC Level 2 Assessment Guide -- Evidence Collection and Evaluation

Final Verification

Since theLead Assessor is ensuring enough evidence is available to verify compliance, the correct answer isOption B: Sufficiency.


Question 13

A C3PAO has completed a Limited Practice Deficiency Correction Evaluation following an assessment of an OSC. The Lead Assessor has recommended moving deficiencies to a POA&M. but the OSC will remain on an Interim Certification. What is the MINIMUM number of practices that must be scored as MET to initiate this course of action?

Correct Answer: C. 100 practices
Explanation:

TheLimited Practice Deficiency Correction Evaluationprocess occurs when anOrganization Seeking Certification (OSC)has undergone aCMMC Level 2 Assessmentby aCertified Third-Party Assessment Organization (C3PAO)and hasunresolved deficienciesin some security practices.

According toCMMC 2.0 policy and DFARS 252.204-7021, OSCs can still achieveInterim Certificationif they meet theminimum thresholdof security practices while addressing deficiencies through aPlan of Action & Milestones (POA&M).

Minimum Number of Practices Required

TheCMMC 2.0 Interim Rulestates that an OSCmust meet at least 100 out of 110 practicesto qualify for aPOA&M-based remediation.

A maximum of 10 practices can be listed in the POA&Mfor later correction.

Failure to meet at least 100 practices results in failing the assessment outright, requiring a full reassessment after remediation.

Why 'C. 100 Practices' is Correct?

The Lead Assessor can recommend POA&M placementonly if the OSC meets at least 100 practices.

Less than 100 practices scored as MET means the OSC does not qualify for a POA&Mand mustretest completely.

DFARS 252.204-7021 and CMMC 2.0 policiesconfirm the100-practice thresholdfor conditional certification.

Why Other Answers Are Incorrect?

A . 80 practices (Incorrect)-- Falls well below the 100-practice requirement.

B . 88 practices (Incorrect)-- Still below the POA&M eligibility threshold.

D . 110 practices (Incorrect)-- While meeting 110 practices would be ideal,CMMC allows a POA&M option at 100 practices.

Conclusion

The correct answer isC. 100 practices, as this meets theminimum threshold for POA&M-based Interim Certification.


DFARS 252.204-7021 (CMMC Requirement Clause)

CMMC 2.0 Assessment Process (CAP) Guide

DoD CMMC 2.0 Policy Overview

Question 14

Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a part of a plan of action?

Correct Answer: D. Budget requirements to implement the plan's remediation actions
Explanation:

Under the Cybersecurity Maturity Model Certification (CMMC) 2.0, a Plan of Action (POA) is a critical document that outlines the specific actions a contractor needs to take to remediate cybersecurity deficiencies. While POAs serve as a roadmap for achieving compliance with required controls, the inclusion of certain elements is standardized.

Key Elements of a Plan of Action (POA)

According to the CMMC guidelines and NIST SP 800-171, which underpins many CMMC requirements, a POA typically includes:

Completion Dates: Identifies target deadlines for resolving deficiencies.

Milestones to Measure Progress: Includes interim steps or markers to ensure progress is monitored over time.

Ownership or Accountability: Clearly assigns responsibility for each action item to specific personnel or teams.

What is Generally NOT Part of a POA?

Budget requirements to implement the plan's remediation actions (Option D) are generally not included in a POA. While budgeting is critical for ensuring the plan's success, it is considered a part of the broaderproject management or resource planning process, not the POA itself. This distinction is intentional to keep the POA focused on actionable items rather than resource allocation.

Supporting Reference

NIST SP 800-171A, Appendix D: Provides an overview of POA components, emphasizing the prioritization of corrective actions, responsibility, and measurable outcomes.

CMMC Level 2 Practices (Aligned with NIST SP 800-171): Specifically, the focus is on actions, timelines, and accountability rather than financial planning.

By excluding budget details, the POA remains a tactical document that supports immediate action and compliance tracking, separate from financial considerations.


Question 15

Which statement BEST describes an assessor's evidence gathering activities?

Correct Answer: D. Use examinations, interviews, and tests to gather sufficient evidence.
Explanation:

Under the CMMC Assessment Process (CAP) and CMMC 2.0 guidelines, assessors must gather objective evidence to validate that an organization meets the required security practices and processes. This evidence collection is performed through three primary assessment methods:

Examination -- Reviewing documents, records, system configurations, and other artifacts.

Interviews -- Speaking with personnel to verify processes, responsibilities, and understanding of security controls.

Testing -- Observing system behavior, performing technical validation, and executing controls in real-time to verify effectiveness.

Why Option D is Correct

The CMMC Assessment Process (CAP) states that an assessor must use a combination of evidence-gathering methods (examinations, interviews, and tests) to determine compliance.

CMMC 2.0 Level 2 (Aligned with NIST SP 800-171) requires assessors to verify not only that policies and procedures exist but also that they are implemented and effective.

Solely relying on one method (like interviews in Option A) is insufficient.

Testing all practices or objectives (Option B) is unnecessary, as assessors follow scoping guidance to determine which objectives need deeper examination.

Testing only 'certain' objectives (Option C) does not fully align with the requirement of gathering sufficient evidence from multiple methods.

CMMC 2.0 and Official Documentation Reference

CMMC Assessment Process (CAP) Guide, Section 3.5 -- Assessment Methods explicitly defines the use of examinations, interviews, and tests as the foundation of an effective assessment.

CMMC 2.0 Level 2 Practices and NIST SP 800-171 require assessors to validate the presence, implementation, and effectiveness of security controls.

CMMC Appendix E: Assessment Procedures states that an assessor should use multiple sources of evidence to determine compliance.

Final Verification

To ensure compliance with CMMC 2.0 guidelines and official documentation, an assessor must use examinations, interviews, and tests to gather evidence effectively, making Option D the correct answer.