CMMC-CCA Exam Question 76
You are assessing Conedge Ltd, a contractor that develops cryptographic algorithms for classified government networks. In reviewing their network architecture documents, you see they have implemented role-based access controls on their workstations using Active Directory group policies. Software developers are assigned to the "Dev_Roles" group which grants access to compile and test code modules. The "Admin_Roles" group with elevated privileges for system administration activities is restricted to the IT staff. However, when you examine the event logs on a developer workstation, you find evidence that a developer was able to enable debugging permissions to access protected kernel memory - a privileged function. How should execution of the debugging permission be handled to align with AC.L2-3.1.7 - Privileged Functions?
CMMC-CCA Exam Question 77
During the planning and preparation discussions, a key member of the C3PAO Assessment Team falls ill and is unavailable for the originally scheduled assessment dates. The OSC is eager to proceed as planned and has expressed willingness to accommodate a smaller assessment team. If the decision is made to replan or reschedule the assessment, what is the C3PAO's required action, according to the CAP?
CMMC-CCA Exam Question 78
You are a CCA working with an OSC that outsources some of its IT operations to a third-party service provider. The service provider has access to the OSC's networks and systems that handle FCI and CUI.
During the scoping process, you need to determine if the OSC should flow down CMMC requirements to this third-party service provider. In this scenario, when should the OSCflow down CMMC requirements to the third-party service provider?
During the scoping process, you need to determine if the OSC should flow down CMMC requirements to this third-party service provider. In this scenario, when should the OSCflow down CMMC requirements to the third-party service provider?
CMMC-CCA Exam Question 79
An OSC is planning a CMMC Level 2 assessment that your C3PAO will conduct. In Phase 1.6.1 - Access and Verify Evidence, as the Lead Assessor, you are verifying the existence and accessibility of the evidence provided by the OSC. While reviewing the list of evidence mapped against the CMMC practices, you discover that the OSC cannot locate several critical system security policies for key IT systems supporting their DoD contracts. These missing policies are essential for demonstrating compliance with various CMMC practices related to access control, incident response, and system maintenance. According to the CMMC Assessment Process (CAP), which of the following is not permitted for the Lead Assessor to do during the evidence verification stage?
CMMC-CCA Exam Question 80
Certified CMMC Assessors must follow assessment procedures when conducting CMMC assessments. These procedures include a series of steps and tools that the CCA will use in the course of their duties. Which of the following is not part of an assessment procedure?
