A Lead Assessor is ensuring all actions have been completed to conclude a Level 2 Assessment. The final Assessment Results Package has been properly reviewed and is ready to be uploaded. What other materials is the Lead Assessor responsible for maintaining and protecting?
Correct Answer: A
The Lead Assessor is responsible for protecting and maintaining all assessment records, notes, and information gathered during the assessment process. This includes working papers and supplemental documentation that may be needed for auditability or dispute resolution. Supporting Extracts from Official Content: * CAP v2.0, Post-Assessment Responsibilities (§3.17): "The Lead Assessor must ensure that all assessment artifacts, notes, and information are archived or disposed of in accordance with C3PAO policy." Why Option A is Correct: * The CAP specifies that notes and information from the assessment must be preserved or disposed of according to policy. * Options B, C, and D list items not required in the CAP. The "letter" and "quality control report" are not part of the Lead Assessor's required maintained materials. References (Official CMMC v2.0 Content): * CMMC Assessment Process (CAP) v2.0, Phase 3 Post-Assessment (§3.17).
CMMC-CCP Exam Question 47
Which NIST SP defines the Assessment Procedure leveraged by the CMMC?
Correct Answer: D
Which NIST SP Defines the Assessment Procedures for CMMC? CMMC Level 2 isdirectly based on NIST SP 800-171, and the assessment procedures used in CMMC assessments are derived fromNIST SP 800-171A. Step-by-Step Breakdown: #1. NIST SP 800-171A Defines Assessment Procedures NIST SP 800-171Ais titled " Assessing Security Requirements for Controlled Unclassified Information (CUI) " . It providesdetailed assessment objectives and test proceduresfor evaluating compliance withNIST SP 800-171 security requirements, whichCMMC Level 2 is fully aligned with. CMMC Assessors use 800-171Aas abaseline for assessing the effectiveness of security controls. #2. Why the Other Answer Choices Are Incorrect: (A) NIST SP 800-53# 800-53 defines security controlsfor federal information systems, but it doesnot provide assessment procedures specific to CMMC. (B) NIST SP 800-53A# 800-53A provides assessment procedures for 800-53 controls, butCMMC is based on NIST SP 800-171, not 800-53. (C) NIST SP 800-171# 800-171 defines security requirements, butit does not provide assessment procedures. Theassessment proceduresare in800-171A. Final Validation from CMMC Documentation: TheCMMC Assessment Guide (Level 2)explicitly states that assessment procedures are derived fromNIST SP 800-171A. Thus, the correct answer is:
CMMC-CCP Exam Question 48
A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?
Correct Answer: C
Contractors that handle Covered Defense Information (CDI) are required to report cyber incidents to the Department of Defense within 72 hours of discovery. Supporting Extracts from Official Content: DFARS 252.204-7012(c)(1): "When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, the Contractor shall conduct a review... and rapidly report the cyber incident to DoD within 72 hours of discovery." Why Option C is Correct: The regulation explicitly specifies 72 hours. Options A (24 hrs), B (48 hrs), and D (96 hrs) do not align with DFARS requirements. References (Official CMMC v2.0 Content and Source Documents): DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting. CMMC v2.0 Governance - Source Documents list includes DFARS 252.204-7012.
CMMC-CCP Exam Question 49
A CCP is consulting with an OSC. In the course of an interview, the OSC representative asks the CCP what basic safeguarding requirements must be met with respect to CMMC Level 1. The CCP tells the representative that this publication contains all the requirements from:
Correct Answer: D
The correct answer is D because CMMC Level 1 is based on the basic safeguarding requirements in FAR Clause 52.204-21 , not on the full NIST SP 800-171 or DFARS 252.204-7012 requirements. The official CMMC Model Overview states that Level 1 focuses on protecting Federal Contract Information (FCI) and consists of security requirements that correspond to the basic safeguarding requirements specified in 48 CFR 52.204-21 , commonly referred to as the FAR Clause. It also states that Level 2 is the level that incorporates the 110 security requirements from NIST SP 800-171 Rev. 2 for protection of Controlled Unclassified Information (CUI) . FAR 52.204-21 applies to covered contractor information systems that process, store, or transmit Federal Contract Information. The clause requires contractors to apply basic safeguarding requirements and procedures, including limiting system access to authorized users, controlling external connections, protecting information on publicly accessible systems, identifying and authenticating users, and sanitizing or destroying media containing FCI before disposal or reuse. Option A is incorrect because NIST SP 800-171 is associated with CMMC Level 2, not Level 1. Option B is incorrect because the cited DFARS clause number is not the CMMC Level 1 source. Option C is incorrect because DFARS 252.204-7012 is tied to safeguarding covered defense information and implementing NIST SP 800-171 for CUI, not the Level 1 basic safeguarding baseline.
CMMC-CCP Exam Question 50
In the CMMC Model, how many practices are included in Level 2?
Correct Answer: C
How Many Practices Are Included in CMMC Level 2? CMMC Level 2is designed to alignfullywithNIST SP 800-171, which consists of110 security controls (practices). This meansall 110 practicesfrom NIST SP 800-171 are required for aCMMC Level 2 certification. Breakdown of Practices in CMMC 2.0 CMMC Level Number of Practices Level 1 17 practices(Basic Cyber Hygiene) Level 2 110 practices(Aligned with NIST SP 800-171) Level 3 Not yet finalized but expected to exceed 110 Since CMMC Level 2 mandatesall 110 NIST SP 800-171 practices, the correct answer isC. 110 practices. Why the Other Answers Are Incorrect A). 17 practices #Incorrect.17 practicesapply only toCMMC Level 1, not Level 2. B). 72 practices #Incorrect. There is no CMMC level with72 practices. D). 180 practices #Incorrect. CMMC Level 2only requires 110 practices, not 180. CMMC Official References CMMC 2.0 Model- Confirms thatLevel 2 includes 110 practicesaligned withNIST SP 800-171. NIST SP 800-171 Rev. 2- Outlines the110 security controlsrequired for handlingControlled Unclassified Information (CUI). Thus,option C (110 practices) is the correct answer, as per official CMMC guidance.