Q: 8
During your assessment of Defcon's (a contractor) implementation of CMMC Level 2 practices, you
notice that their system for displaying security and privacy notices is insufficient. The banners
currently in use lack detailed information about Controlled Unclassified Information (CUI)handling
requirements and associated legal implications. Additionally, the banners are not consistently
displayed across all contractor systems and workstations. Moreover, the banners on login pages
disappear automatically after less than 5 seconds, providing insufficient time for users to read and
acknowledge the content. Once the inconsistencies are addressed, when should the contractor’s
privacy and security notice be displayed?
Options
Discussion
B tbh matches CMMC Level 2 wording. D looks tempting for max awareness, but the actual requirement is just logon and when accessing CUI resources. Similar question came up in a practice set too.
B or D? Is the question asking for the best practice or just the minimum required by CMMC Level 2?
Why would D be correct if CMMC Level 2 only requires notices at logon and when accessing CUI apps?
I don’t think it’s D. B fits CMMC Level 2 control wording.
I think D here. Since the banners are for informing users about CUI requirements, having them displayed continuously on all systems would make sure nobody misses them. I remember similar wording in some practice sets, so pretty sure that's what they want. Agree?
Be respectful. No spam.