Summer Certification Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = getmirror

Pass the Cyber AB CMMC CMMC-CCA Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam CMMC-CCA Premium Access

View all detail and faqs for the CMMC-CCA exam


837 Students Passed

97% Average Score

91% Same Questions
Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
Questions # 31:

An OSC creates standard user accounts with limited capabilities and administrator accounts with full system access. A standard user initiates the uninstall of the anti-virus software, which is organizationally defined as a privileged function. Which of the following would indicate AC.L2-3.1.7: Privileged Functions is properly implemented?

Options:

A.

The antivirus software is not uninstalled.

B.

The antivirus software is successfully uninstalled.

C.

The antivirus software is not uninstalled, and the attempt is captured in an application audit log.

D.

The antivirus software is successfully uninstalled, and the event is captured in an application audit log.

Questions # 32:

The OSC POC has prepared evidence from an internal pre-assessment for the C3PAO in preparation for a third-party assessment. The OSC POC has identified that there are several ESPs (External Service Providers) involved in protecting the security of the infrastructure. While reviewing the pre-assessment documentation regarding ESPs, the Lead Assessor will be looking for items that are:

Options:

A.

Noted as inherited

B.

Marked as requiring a waiver

C.

Marked as NOT APPLICABLE

D.

Noted as partially implemented

Questions # 33:

A company is seeking Level 2 CMMC certification. During the Limited Practice Deficiency Correction Evaluation, the Lead Assessor must decide whether the company can move to a POA&M review. Which condition will result in the Lead Assessor recommending that the OSC’s practice deficiencies move to a POA&M review?

Options:

A.

A final score below 88

B.

A final score of 110

C.

A final score of 80 or better

D.

A final score of 88/110 or better

Questions # 34:

In validating the OSC’s implementation of AC.L2-3.1.16: Wireless Access Authorization, the CCA observes various personal and non-enterprise devices connected to the OSC’s Wi-Fi. Because organizations handle wireless access differently, the CCA must locate evidence showing who has ultimate authority over wireless access. Which authority is acceptable for authorizing wireless access?

Options:

A.

The CEO mandating IT to add their personal phone to the company Wi-Fi

B.

A written policy executed by the CEO listing the pre-authorization requirements for Wi-Fi connectivity

C.

The CEO emailing the company instructing everyone to put personal devices on the company Wi-Fi

D.

A detailed document from the head of IT with instructions on how to connect to the guest Wi-Fi network

Questions # 35:

During a CMMC Level 2 Assessment, a CCA interviewed a system administrator on the OSC’s procedures around configuration management and endpoint security. The system administrator described how they build and deploy new systems, and noted that some users require specialized applications for their jobs. Users have been asked to email IT when they install and run an additional application so IT can add it to their list of allowed software.

What must the CCA conclude?

Options:

A.

The OSC has properly implemented application deny listing.

B.

The OSC has not properly implemented application allow listing.

C.

IT must deploy an application to report newly installed software.

D.

IT does not have a policy that users notify IT when they install new applications.

Questions # 36:

An OSC is presenting evidence of its fulfillment of CM.L2-3.4.1: System Baselining. It provides:

    System inventory records showing additions/removals of machines,

    Software inventory showing installations/removals, and

    A system component installation plan with software needs and user specifications.

What other documentation MUST the company present to illustrate compliance with CM.L2-3.4.1?

Options:

A.

Documentation of the physical safeguards protecting the “gold” baseline images

B.

Documentation of a formal baseline review integrated with a system development lifecycle

C.

Documentation of any authorized deviations from the system baselines for end-user computers

D.

Documentation of a formal chain of custody for new hardware on which baselines will be installed

Questions # 37:

What should the Lead Assessor do to BEST ensure the evidence supplied effectively meets the intent of the standard for a practice?

Options:

A.

Ensure the evidence for each objective under a practice is adequate.

B.

Ensure the evidence is sufficient to meet the requirements for a practice.

C.

Ensure the evidence is complete, validated, and can be mapped to the practice requirements.

D.

Ensure the evidence covers all the scope and the identified organizations and corresponds to the practice and objectives.

Questions # 38:

The audit team is discussing the OSC’s Risk Managed Assets. For these types of assets, the contractor need NOT:

Options:

A.

Provide a network diagram of the assessment scope.

B.

Ensure they are included in the pre-assessment discussion.

C.

Prepare for the assets to be assessed against CMMC practices.

D.

Show how they are being managed using organizational security policies.

Questions # 39:

A company has a CUI enclave for handling all CUI processed, stored, and transmitted through the organization. While interviewing the IT manager, the CCA asks how assets that can, but are not intended to, handle CUI are identified. The IT manager refers to the CUI system’s network diagram (which includes these assets) as well as the asset inventory (which lists these assets as Contractor Risk Managed Assets). Which other artifact MUST also mention these assets?

Options:

A.

The identification and authentication policy should show how these assets are identified.

B.

The physical protection policy should list these assets as being part of the physical environment of the organization.

C.

The awareness and training program should include these assets so they are covered for all employees.

D.

The SSP should show these assets are managed using the company’s risk-based security policies, procedures, and practices.

Questions # 40:

An OSC has a testing laboratory. The lab has several pieces of equipment, including a workstation that is used to analyze test information collected from the test equipment. All equipment is on the same VLAN that is part of the certification assessment. The OSC claims that the workstation is part of the test equipment (Specialized Asset) and only needs to be addressed under risk-based security policies. However, the OSC states that the data analysis output is CUI. What is the assessor’s BEST response?

Options:

A.

Disagree with the OSC and include the workstation in the full assessment.

B.

Disagree with the OSC and score practice CA.L2-3.12.4: System Security Plan as NOT MET.

C.

Agree with the OSC but perform a limited check of the system, not increasing the assessment cost or duration.

D.

Agree with the OSC and determine if it is managed using the contractor’s risk-based information security procedures and practices.

Viewing page 4 out of 5 pages
Viewing questions 31-40 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.