Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

CMMC-CCA Leak Questions

Page: 6 / 11
Total 150 questions

Certified CMMC Assessor (CCA) Exam Questions and Answers

Question 21

During an assessment, an assessor is trying to determine if the organization provides protection from malicious code at appropriate locations within organizational information systems. The assessor has decided to use the Interview method to gather evidence. It is BEST to interview:

Options:

A.

System developers

B.

System or network administrators

C.

Personnel with audit and accountability responsibilities

D.

Personnel with security alert and advisory responsibilities

Question 22

During an assessment interview, the interviewee states that anyone can connect to the company Wi-Fi without prior approval. Within which domains is the Wi-Fi configuration covered?

Options:

A.

Media Protection (MP), Access Control (AC), and Physical Protection (PE)

B.

Identification and Authentication (IA), Media Protection (MP), and System and Information Integrity (SI)

C.

Access Control (AC), Identification and Authentication (IA), and System and Communications Protection (SC)

D.

System and Communications Protection (SC), System and Information Integrity (SI), and Physical Protection (PE)

Question 23

A company has a firewall to regulate how data flows into and out of its network. Based on an interview with their IT staff, all connections to their systems are logged, and suspicious traffic generates alerts. Examination of which artifact should give the CCA the details on how these are implemented?

Options:

A.

Physical access logs

B.

Boundary protection procedures

C.

Account management document

D.

Configuration management policy

Question 24

An OSC is a wholly owned subsidiary of a large conglomerate (parent organization). The OSC and the parent organization use ID badges (PKI cards) that contain a PKI certificate and a radio frequency identification (RFID) tag used for building and system access (including systems that process, transmit, or store CUI). The parent organization does not make any decisions on how the OSC runs its security program or other matters of significance. The large conglomerate operates a machine that is used to activate the badges for both itself and the OSC. This machine is isolated in a locked room and has no network connectivity to the OSC.

The badge activation system is:

Options:

A.

In-scope because the parent organization acts as an External Service Provider to the OSC by providing PKI cards.

B.

In-scope because the OSC is part of the large conglomerate and thus any CMMC requirements of the OSC are imputed onto the large conglomerate.

C.

Out-of-scope because the OSC is the one that assigns the appropriate access to a particular PKI card.

D.

Out-of-scope because the badge activation machine is physically and logically isolated from the OSC and it is under the control of the parent organization.

Page: 6 / 11
Total 150 questions