Q: 11
The Audit and Accountability (AU) domain has practices in:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 12
A Level 2 Assessment of an OSC is winding down and the final results are being prepared to present
to the OSC. When should the final results be delivered to the OSC?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 13
When scoping the organizational system, the scope of applicability for the cybersecurity CUI
practices applies to the components of:
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 14
Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a
part of a plan of action?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 15
During the planning phase of a CMMC Level 2 Assessment, the Lead Assessor is considering what
would constitute the right evidence for each practice. What is the Assessor attempting to verify?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 16
A CMMC Assessment is being conducted at an OSC's HQ. which is a shared workspace in a multi-
tenant building. The OSC is renting four offices on the first floor that can be locked individually. The
first-floor conference room is shared with other tenants but has been reserved to conduct the
assessment. The conference room has a desk with a drawer that does not lock. At the end of the day,
an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 17
The IT manager is scoping the company's CMMC Level 1 Self-Assessment. The manager considers
which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which
asset type is being considered by the IT manager?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 18
A CMMC Assessment Team arrives at an OSC to begin a CMMC Level 2 Assessment. The team checks
in at the front desk and lets the receptionist know that they are here to conduct the assessment. The
receptionist is aware that the team is arriving today and points down a hallway where the conference
room is. The receptionist tells the Lead Assessor to wait in the conference room. as someone will be
there shortly. The receptionist fails to check for credentials and fails to escort the team. The
receptionist's actions are in direct violation of which CMMC practice?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 19
A contractor provides services and data to the DoD. The transactions that occur to handle FCI take
place over the contractor's business network, but the work is performed on contractor-owned
systems, which must be configured based on government requirements and are used to support a
contract. What type of Specialized Asset are these systems?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 11 of 20 · Page 2 / 2