CMMC-CCA Exam Question 31
During a CMMC Level 2 assessment, the Assessment Team discovers that the OSC has implemented a practice using a tool that is not listed in their System Security Plan (SSP). The tool appears to meet the assessment objectives for the practice, but its absence from the SSP raises concerns about documentation accuracy. How should the Lead Assessor proceed?
CMMC-CCA Exam Question 32
When examining a contractor's access control policy and SSP, you observe that system administrators routinely use accounts with elevated privileges for checking email and browsing internal websites. What CMMC practice does this violate?
CMMC-CCA Exam Question 33
During your assessment of Defcon's (a contractor) implementation of CMMC Level 2 practices, you notice that their system for displaying security and privacy notices is insufficient. The banners currently in use lack detailed information about Controlled Unclassified Information (CUI)handling requirements and associated legal implications. Additionally, the banners are not consistently displayed across all contractor systems and workstations. Moreover, the banners on login pages disappear automatically after less than 5 seconds, providing insufficient time for users to read and acknowledge the content. Once the inconsistencies are addressed, when should the contractor's privacy and security notice be displayed?
CMMC-CCA Exam Question 34
During a CMMC assessment, the OSC's IT manager asks the CCA if they can "fix" a non-compliant practice during the assessment to improve their score. The CCA declines and continues the assessment. What CoPC principle does the CCA uphold by refusing to assist?
CMMC-CCA Exam Question 35
Regarding virtual data collection, which of the following actions is the highest priority?
