Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cyber AB CMMC CMMC-CCA Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CMMC-CCA Premium Access

View all detail and faqs for the CMMC-CCA exam


837 Students Passed

97% Average Score

91% Same Questions
Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
Questions # 21:

Which of the following can be taken into consideration when assessing AC.L2-3.1.3 Privacy & Security Notices?

Options:

A.

System use notifications during system log-in

B.

Alerts received from Intrusion Detection and Protection devices

C.

Posters in the workplace warning of the dangers of phishing and shoulder-surfing

D.

Sending out notices in email reminding employees to be conscious of security concerns

Questions # 22:

The client has a Supervisory Control and Data Acquisition (SCADA) system as OT to be evaluated as part of its assessment. In reviewing network architecture and conducting interviews, the assessor determines that a firewall separates the SCADA system from the client’s enterprise network and that CUI is not processed by the SCADA system. Based on this information, what is an appropriate outcome?

Options:

A.

The assessor includes the OT within the assessment

B.

The assessor determines the SCADA system is out-of-scope for the assessment

C.

The assessor includes all systems identified by the client as part of the assessment

D.

The assessor determines that all Specialized Assets are within the scope of the assessment

Questions # 23:

The Lead Assessor concludes that the OSC is not ready for the assessment. After the Readiness Assessment Review, the OSC and the Lead Assessor could choose to:

Options:

A.

Replan or cancel the assessment.

B.

Replan or reschedule the assessment.

C.

Proceed as planned or cancel the assessment.

D.

Proceed as planned or reschedule the assessment.

Questions # 24:

An OSC assigns new hires to work on their hire date. Human Resources ensures that all screening activities are completed before the end of the employees’ first week. How should the CCA score PS.L2-3.9.1: Screen Individuals?

Options:

A.

As NOT MET but it can be remediated post-assessment

B.

As NOT MET and this will cause the assessment to fail

C.

As MET since the OSC ensured Human Resources was handling the screening

D.

As NOT MET because all screening must be completed prior to the start of employment

Questions # 25:

A company has multiple sites with employees at each site that must access the company’s CUI network from their remote locations. The company has set up a single access point for all employees to access the network. What is the MOST significant factor in determining whether the security on this single access point is adequate?

Options:

A.

Remote access is secured and monitored.

B.

Physical access is monitored and controlled.

C.

The security requirements for CUI and FCI are documented.

D.

The remote personnel have notification procedures regarding connection issues.

Questions # 26:

The OSC has not implemented cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission, citing the use of alternative physical safeguards.

Which of the following is NOT an alternative physical safeguard in this scenario?

Options:

A.

Trusted couriers

B.

Lockable casings

C.

Physical access site monitoring

D.

Tamper protections technologies

Questions # 27:

Both the SSP and network diagrams presented to the Lead Assessor by the OSC indicate managed service providers (MSPs) within the assessment boundary. In order to BEST understand the impact of the MSPs, what should the Lead Assessor do?

Options:

A.

Ascertain what employees the MSP has onsite

B.

Request the customer responsibility matrix related to the MSPs

C.

Review the inventory to see how the assets have been classified

D.

Inspect the other initial documents presented including policies and organization charts

Questions # 28:

An OSC has two business locations. At each location, the OSC has a wireless guest network to which non-OSC employees are allowed access. The guest network is not password protected and it connects devices within the local OSC’s LAN. Based on this information, does the OSC meet the requirements of Level 2 for network access restriction?

Options:

A.

No, the OSC needs to go through an additional assessment.

B.

No, the OSC has not met the network access restriction requirements.

C.

Yes, there are no network access restriction requirements.

D.

Yes, the OSC has met the network access restriction requirements.

Questions # 29:

An OSC leases several servers and rack space in a FedRAMP MODERATE authorized colocation data center. Additional servers operate in a LAN room within the company’s facility. Both facilities are within the OSC’s assessment boundary. In order to assess the physical protection of the environment, the Assessor MUST physically examine the visitor and access controls in place in the:

Options:

A.

Data center

B.

OSC’s facility

C.

OSC’s facility and the data center

D.

OSC’s facility and the data center’s customer relationship management regarding physical security

Questions # 30:

A C3PAO has contracted by an OSC to perform its assessment. Before the assessment, the Lead Assessor asks the OSC to provide an extensive list of evidence, some of which is optional and beyond the minimum requirements. The OSC is not able to fulfill the entire request. One missing document was a current and organized list of the OSC’s evidence and mappings.

Given that this is a Level 2 Assessment, what should the Lead Assessor tell the OSC?

Options:

A.

“The OSC’s Assessment Official will be asked to collect evidence when requested by the assessment team.”

B.

“The OSC must provide the Assessment Team with hardcopy evidence. Electronic evidence will only be collected when needed.”

C.

“It’s okay that the document is missing. The Assessment Team will collect all evidence themselves to ensure its integrity.”

D.

“The OSC should provide the Assessment Team with a current and organized list of their evidence and process mappings, but the assessment can continue.”

Viewing page 3 out of 5 pages
Viewing questions 21-30 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.