Summer Special - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: top65certs

New Release CMMC-CCA CMMC Questions

Page: 7 / 11
Total 150 questions

Certified CMMC Assessor (CCA) Exam Questions and Answers

Question 25

Both FCI and CUI are stored by an OSC on the same network. Server A contains file shares with FCI, and Server B contains file shares with CUI. The OSC hopes each server would only undergo the assessment for the classification of data it contains. What is the MOST correct assessment situation in this scenario?

Options:

A.

Due to the presence of CUI on the network, a Level 2 certification is required for the network

B.

Server A may undergo a Level 1 self-assessment, while Server B must obtain a Level 2 certification

C.

Due to the presence of FCI on the network, only a Level 1 self-assessment is required for the network

D.

The network must be segmented to separate FCI from CUI before any assessments can be conducted

Question 26

A company seeking Level 2 certification has several telecommunications closets throughout its office building. The closets contain network systems and devices that are used to transmit CUI. Which method would be BEST to ensure that only authorized personnel can access the network systems and devices housed within the closets?

Options:

A.

Label the door with “Authorized Personnel Only” and maintain an authorized personnel list.

B.

Install locks with badge readers on the closet doors and maintain an authorized list.

C.

Install security cameras to monitor closet entrances and maintain an authorized personnel list.

D.

Install keypad door locks on the closet doors and only provide the code to IT department personnel.

Question 27

An organization has contracted with a third party for system maintenance and support. The third-party personnel all work remotely. Which of the following should an assessor assure is in place?

Options:

A.

Only third-party personnel can perform system maintenance functions.

B.

Third-party personnel need to be identified and monitored while performing maintenance.

C.

The number of third-party personnel who can access the organization’s systems concurrently is limited.

D.

Remote access to systems used by the third party for maintenance functions is terminated automatically based on a defined set of criteria.

Question 28

An OSC has two business locations. At each location, the OSC has a wireless guest network to which non-OSC employees are allowed access. The guest network is not password protected and it connects devices within the local OSC’s LAN. Based on this information, does the OSC meet the requirements of Level 2 for network access restriction?

Options:

A.

No, the OSC needs to go through an additional assessment.

B.

No, the OSC has not met the network access restriction requirements.

C.

Yes, there are no network access restriction requirements.

D.

Yes, the OSC has met the network access restriction requirements.

Page: 7 / 11
Total 150 questions