CMMC-CCA Exam Question 141

The Cyber AB has completed an investigation into a report submitted by a CCA regarding a potential violation by another CCA. They have determined that the violation falls within the scope of the relevant Industry Working Group's authority. What is the likely course of action for the Cyber AB in this scenario?
  • CMMC-CCA Exam Question 142

    During a CMMC assessment, the Lead Assessor discovers that the OSC has outsourced its incident response to a third-party provider. The OSC provides a contract with the provider but no detailed evidence of the provider's processes. What should the Lead Assessor do?
  • CMMC-CCA Exam Question 143

    Conducting a CMMC assessment for an OSC includes interviewing, testing, or examining various Assessment Objects. As a CCA, you are part of an Assessment Team tasked with evaluating how an OSC has implemented AC.L2-3.1.4 - Separation of Duties. Which of the following is not an Assessment Object you would use to validate the OSC's implementation of AC.L2-3.1.4[a], "the duties of individuals requiring separation to reduce the risk of malevolent activity are defined"?
  • CMMC-CCA Exam Question 144

    Security Protection Assets (SPAs) include people, technologies, and facilities. Which of the following technologies is not an SPA?
  • CMMC-CCA Exam Question 145

    During an assessment, it is uncovered that a CCA worked as a consultant for the OSC through their RPO.
    Unfortunately, the CCA didn't disclose this when their C3PAO appointed them to participate in the assessment. Did the CCA behave professionally? If not, what issues are likely to arise?