Q: 1
As defined in the CMMC-AB Code of Professional Conduct, what term describes any contract
between two legal entities?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which standard and regulation requirements are the CMMC Model 2.0 based on?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
A Lead Assessor is performing a CMMC readiness review. The Lead Assessor has already recorded the
assessment risk status and the overall assessment feasibility. At MINIMUM, what remaining
readiness review criteria should be verified?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Which code or clause requires that a contractor is meeting the basic safeguarding requirements for
FCI during a Level 1 Self-Assessment?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
While developing an assessment plan for an OSC. it is discovered that the certified assessor will be
interviewing a former college roommate. What is the MOST correct action to take?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Who will verify the adequacy and sufficiency of evidence to determine whether the practices and
related components for each in-scope Host Unit. Supporting Organization/Unit, or enclave has been
met?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
In late September. CA.L2-3.12.1: Periodically assess the security controls in organizational systems to
determine if the controls are effective in their application is assessed. Procedure specifies that a
security control assessment shall be conducted quarterly. The Lead Assessor is only provided the first
quarter assessment report because the person conducting the second quarter's assessment is
currently out of the office and will return to the office in two hours. Based on this information, the
Lead Assessor should determine that the evidence is;
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
During the planning phase of the Assessment Process. C3PAO staff are reviewing the various entities
associated with an OSC that has requested a CMMC Level 2 Assessment. Which term describes the
people, processes, and technology external to the HQ Organization that participate in the
assessment but will not receive a CMMC Level unless an enterprise Assessment is conducted?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
In many organizations, the protection of FCI includes devices that are used to scan physical
documentation into digital form and print physical copies of digital FCI. What technical control can be
used to limit multi-function device (MFD) access to only the systems authorized to access the MFD?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2