Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

CMMC CMMC-CCA Cyber AB Study Notes

Page: 8 / 11
Total 150 questions

Certified CMMC Assessor (CCA) Exam Questions and Answers

Question 29

The client has a Supervisory Control and Data Acquisition (SCADA) system as OT to be evaluated as part of its assessment. In reviewing network architecture and conducting interviews, the assessor determines that a firewall separates the SCADA system from the client’s enterprise network and that CUI is not processed by the SCADA system. Based on this information, what is an appropriate outcome?

Options:

A.

The assessor includes the OT within the assessment

B.

The assessor determines the SCADA system is out-of-scope for the assessment

C.

The assessor includes all systems identified by the client as part of the assessment

D.

The assessor determines that all Specialized Assets are within the scope of the assessment

Question 30

An OSC has a testing laboratory. The lab has several pieces of equipment, including a workstation that is used to analyze test information collected from the test equipment. All equipment is on the same VLAN that is part of the certification assessment. The OSC claims that the workstation is part of the test equipment (Specialized Asset) and only needs to be addressed under risk-based security policies. However, the OSC states that the data analysis output is CUI. What is the assessor’s BEST response?

Options:

A.

Disagree with the OSC and include the workstation in the full assessment.

B.

Disagree with the OSC and score practice CA.L2-3.12.4: System Security Plan as NOT MET.

C.

Agree with the OSC but perform a limited check of the system, not increasing the assessment cost or duration.

D.

Agree with the OSC and determine if it is managed using the contractor’s risk-based information security procedures and practices.

Question 31

Video monitoring is used by an OSC to help meet PE.L2-3.10.2: Monitor Facility. The OSC’s building has three external doors, each with badge access and a network-connected video camera above the door. The video cameras are connected to the same network as employee computers. The OSC contracted a local security company to provide surveillance services. The security company stores the recordings at its premises and requires access to the OSC’s network to manage the video cameras. Which factor is a clear negative finding for the OSC’s assessment?

Options:

A.

Video surveillance needs to be of both private and public areas of the building

B.

A non-certified third party accesses the OSC’s network to manage the cameras

C.

Video surveillance alone does not satisfy the facility monitoring requirement of PE.L2-3.10.2

D.

A non-certified third party’s data center may not store video recordings for a company authorized to process CUI

Question 32

Does CMMC Level 2 require that a Cloud Service Provider (CSP) hold a FedRAMP HIGH authorization hosted in a government community cloud (GCC)?

Options:

A.

No. The CSP can obtain a FedRAMP MODERATE equivalency.

B.

No. The CSP must hold a FedRAMP MODERATE authorization.

C.

Yes. FedRAMP HIGH is required for CUI data controls due to the sensitive nature of the Defense Industrial Base systems.

D.

Yes. FedRAMP HIGH authorization demonstrates the CSP compliance with NIST SP 800-53 and SP 800-171 control requirements.

Page: 8 / 11
Total 150 questions