CMMC-CCA Exam Question 71

During scoping discussions with a Lead Assessor, the OSC mentions that there are several connected systems within the organization's network. How should an OSC consider security tools in a CMMC Assessment Scope?
  • CMMC-CCA Exam Question 72

    A representative of a CMMC Level 2 certified DoD contractor has reached out to you as a CCA for an explanation of FedRAMP equivalency. They want to use a Cloud Service Offering (CSO) from a renowned CSP, but in light of the DoD FedRAMP equivalency memo, they are reluctant. In your conversation, you learn that although the CSO has impressive features, the assessment by a FedRAMP 3PAO resulted in a Plan of Action and Milestones (POA&M) that the CSP is remedying. What is the main reason the contractor shouldn't use the CSP's services?
  • CMMC-CCA Exam Question 73

    To showcase progress on the performance of their contract, a contractor provides semi-annual demonstrations to their federal client at the client's conference room. The conference room is inside the client's facility, meaning the contractor does not have control over security. All prototypes and documents subject to the contract are guarded by the contractor's staff whenever they are in transit and at the conference room. How should you, the CCA, handle the conference room when validating the OSC's assessment scope?
  • CMMC-CCA Exam Question 74

    Risks are inherent in any organization. As a CCA working within an Assessment Team, you are assessing an OSC's implementation of RA practices. When evaluating RA.L2-3.11.3[b], you want to determine whether vulnerabilities are remediated in accordance with risk assessments. What Assessment Object would you likely examine to make this determination?
  • CMMC-CCA Exam Question 75

    An OSC uses a web application for document management. Employees can access this application from any internet-connected device through a web browser. The application resides on servers in a secure data center managed by a third-party vendor. The OSC maintains separate servers within its network to store the documents. When employees use the web application to upload documents, what type of locations are they interacting with?