CMMC-CCA Exam Question 26
An Assessment Team is reviewing the scope of a CMMC assessment for an OSC. The OSC has defined a narrow security boundary for their assessment, which the Assessment Team believes may not adequately protect all sensitive information. The OSC gives reasons for this, including financial constraints, and claims that CUI is only contained within an enclave defined by the boundary. However, after inspecting the facility and interviewing employees, you determine that some assets that may process CUI are outside the enclave.
What is the risk of the OSC defining a security boundary that is too narrow in scope for the CMMC assessment?
What is the risk of the OSC defining a security boundary that is too narrow in scope for the CMMC assessment?
CMMC-CCA Exam Question 27
After a security audit, a contractor documents specific vulnerabilities and deficiencies in an audit report. After examining its POA&M, you realize it has a clearly defined policy on addressing these deficiencies and by when. However, after interviewing the contractor's security and compliance team, you learn that while an audit is regularly conducted, the remediating measures are not always taken, and when taken, they are not always practical. The security and compliance team informs you they have tried reaching the system administrator to explain the repercussions of this without success. What assessment objective has the contractor failed to implement from CMMC practice CA.L2-3.12.2 - Plan of Action?
CMMC-CCA Exam Question 28
During a CMMC assessment, an OSC employee tells the CCA that they don't follow a documented procedure because "it's outdated," but they have an informal process that works better. The informal process appears to meet the practice's objectives. How should the CCA proceed?
CMMC-CCA Exam Question 29
You are part of the Assessment Team assessing a small defense contractor. You learn that the contractor (ABC Manufacturing) outsources parts of its IT infrastructure and cybersecurity services to a reputable Managed Services Provider (MSP). During a CMMC assessment, the contractor's Assessment Official claims that several CMMC practices related to system security and monitoring are inherited from the MSP. Which of the following actions should the Lead Assessor take?
CMMC-CCA Exam Question 30
You are the CCA working with a client to deliver certified consulting services, and the OSC has asked how to ensure their scope is accurate. You mention the use of a data flow diagram, which intrigues the OSC. What would be the first step in constructing the data flow diagram for the OSC?
