CyberAB certification preparation
CMMC-CCA Practice Questions
Practice exam-style questions, check your answers, and review explanations and source references where they are available.
- Exam
- CMMC-CCA
- Provider
- CyberAB
- Full set
- 325 questions
- Last Update Check
CMMC MA.L2-3.7.6 – Maintenance Personnel requires that maintenance personnel without required
access authorization be supervised during maintenance activities. One of the ways organizations can
achieve this is to develop a documented procedure for supervised maintenance activities. Which of
the following elements should be excluded from the documented procedure?
Question 1 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
A defense contractor retains your services to assess their information systems for CMMC compliance,
particularly configuration management. The contractor uses CFEngine 3 for automated configuration
and maintenance of its computer systems and networks. While chatting with the network’s system
admins, you realize they have deployed a modern compliance checking and monitoring tool.
However, when examining their configuration management policy, you notice the contractor uses
different security configurations than those recommended by product vendors. The system
administrator informs you they do this to meet the minimum configuration baselines required to
achieve compliance and align with organizational policy. Based on your understanding of the CMMC
Assessment Process, how would you score CM.L2-3.4.2 – Security Configuration Enforcement if the
contractor is tracking it in a POA&M?
Question 2 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
The Certification Assessment Readiness Review (CA-RR) aims to determine whether the OSC and the
Assessment Team are ready to conduct the assessment as planned and within the allocated time. It
addresses all of the following aspects of readiness to conduct the assessment except which one?
Question 3 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
When conducting a CMMC assessment, the CCA must follow the steps outlined in the CMMC
Assessment Process (CAP). This document is organized into several phases, each requiring the CCA to
complete specific documents. The CAP also provides templates, some of which the Assessor must
use and complete during specific phases. A CCA must complete all the following documents in Phase
1 of the CAP, EXCEPT?
Question 4 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
In ensuring it meets its mandates to protect CUI under CMMC, a contractor has implemented a
robust, dynamic session lock with pattern-hiding displays to prevent access and viewing of data.
After every 5 minutes of inactivity, the current session is locked and a blank, black screen with a
battery life indicator is displayed. How is Session Lock typically initiated?
Question 5 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
During the planning and preparation discussions, a key member of the C3PAO Assessment Team falls
ill and is unavailable for the originally scheduled assessment dates. The OSC is eager to proceed as
planned and has expressed willingness to accommodate a smaller assessment team. Can the Lead
Assessor proceed with the assessment using a reduced assessment team size?
Question 6 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
During a CMMC assessment, an OSC employee asks the CCA if their current security measures are
“good enough” to pass the assessment. The CCA responds by saying, “I can’t tell you that, but here’s
what the CMMC requires for this practice.” What principle of the CoPC does this response uphold?
Question 7 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
An OSC receives a POA&M during their CMMC L2 assessment. 170 days later, they submit an
updated POA&M with evidence of all corrective actions. Can the C3PAO still conduct a close-out
assessment?
Question 8 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Regarding virtual data collection, which of the following actions is the highest priority?
Question 9 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
When assessing an OSC’s compliance with IR requirements, you realize they have deployed a system
that tracks incidents, documents details, and updates the status throughout the incident response
process. Personnel to whom incidents must be reported are identified and designated. While
examining their documentation, you come across an incident response template that they use to
capture all relevant information and ensure consistency in reporting to the identified authorities and
organizational officials. Interviewing the IR team, you learn there is an escalation process that the
contractor’s cybersecurity team can use to address more serious incidents. From the scenario, the
contractor has met all the required objectives for CMMC practice IR.L2-3.6.2 – Incident Reporting,
meaning its implementation of the said practice will be scored MET with a total of 5 points. For how
long must the OSC retain the incident records?
Question 10 discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 10
Source context
How this practice set is maintained
Maintained by the CertMage content team, this page loads questions from the exam dataset connected to its preparation resource. When an answer includes a supporting reference, it is shown with that answer so you can review the underlying vendor documentation.
Certification objectives, interfaces, and vendor services can change. Verify important details against the provider's current exam guide and documentation before your exam.
