As part of CMMC 2.0, the change to Level 1 Self-Assessments supports "reduced assessment costs" allows all companies at Level 1 (Foundational) to:
Correct Answer: A
Step 1: Review CMMC 2.0 Reforms (Level 1 - Foundational) As part ofCMMC 2.0, the DoD announced changes toreduce burden and costsfor companies that only handleFederal Contract Information (FCI): DoD Statement (CMMC 2.0 Overview): "Level 1 (Foundational) will only require an annual self-assessment, affirming implementation of the 17 FAR 52.204-21 controls." #Step 2: Intent of "Reduced Assessment Costs" The move to allowself-assessments at Level 1was explicitly designed toeliminate the costof hiring third-party assessors for organizations that only handle FCI. Level 1 self-assessments are: Conductedinternally by the OSC, Affirmed annuallyby a senior company official, Submitted via SPRS(Supplier Performance Risk System). #Why the Other Options Are Incorrect B). Opt out of CMMC Assessments #Incorrect. Organizations must still perform aself-assessmentannually - they cannot opt out entirely. C). Have assessment costs reimbursed by the DoD #No such reimbursement mechanism exists. D). Pay no more than $500.00... #No such fixed cost is set or guaranteed in CMMC documentation. UnderCMMC 2.0, all companies atLevel 1 (Foundational)are permitted toconduct self-assessmentsannually to demonstrate compliance, supporting the DoD's goal ofreducing assessment costsfor low-risk contractors.
CMMC-CCP Exam Question 67
CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:
Correct Answer: B
TheCMMC Scoping Guide for Level 2outlines thatCUI assetsinclude systems, applications, and services thatstore, process, or transmitControlled Unclassified Information (CUI). These are the three core functions that defineCUI handlingwithin anOrganization Seeking Certification (OSC). Step-by-Step Breakdown: #1. CUI Assets Defined in CMMC Stored:CUI is saved on hard drives, cloud storage, or databases. Processed:CUI is actively used, modified, or analyzed by applications and users. Transmitted:CUI is sent between systems via email, file transfers, or network communication. #2. Why the Other Answer Choices Are Incorrect: (A) Received and transferred# Whilereceiving and transferring CUIis part of handling CUI, it does not fully cover all CUI asset responsibilities. (C) Entered, edited, manipulated, printed, and viewed# These arespecific actionswithinprocessingbut do not coverstorage or transmission, which are also required for CMMC scoping. (D) Located on electronic media, on system component memory, and on paper# While CUI can exist inelectronic and physical forms, CMMC scoping focuses onhow CUI is actively managed (stored, processed, transmitted)rather than where it physically resides. Final Validation from CMMC Documentation: TheCMMC Level 2 Scoping Guideconfirms thatCUI Assets are categorized based on their role in storing, processing, or transmitting CUI. NIST SP 800-171also defines these three functions as key components of CUI protection.
CMMC-CCP Exam Question 68
The practices in CMMC Level 2 consist of the security requirements specified in:
Correct Answer: B
CMMC Level 2 requires full implementation of the 110 security requirements specified in NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. These practices form the foundation for safeguarding CUI across defense contractor systems. * NIST SP 800-53 is a broader catalog of security controls for federal systems, not specific to CUI in the defense contractor environment. * 48 CFR 52.204-21 establishes basic safeguarding requirements for Federal Contract Information (FCI) and corresponds to CMMC Level 1. * DFARS 252.204-7012 defines safeguarding and incident reporting obligations but does not enumerate the specific security practices required. Thus, Level 2 practices are aligned to NIST SP 800-171. Reference Documents: * CMMC Model v2.0 Overview, December 2021 * NIST SP 800-171 Rev. 2
CMMC-CCP Exam Question 69
Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1, Guidelines for Media Sanitation?
Correct Answer: A
NIST SP 800-88 Rev. 1 is the authoritative guide for media sanitization. It defines three categories of data disposal: Clear, Purge, and Destroy. Supporting Extracts from Official Content: * NIST SP 800-88 Rev. 1: "Media sanitization techniques are divided into three categories: Clear, Purge, and Destroy." Why Option A is Correct: * "Clear, Purge, Destroy" are the exact three categories named. * Redact and Overwrite are not categories; Overwriting is a technique that may fall under Clear. References (Official CMMC v2.0 Content and Source Documents): * NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization.
CMMC-CCP Exam Question 70
What is the MOST common purpose of assessment procedures?
Correct Answer: A
Theprimary goal of CMMC assessment proceduresis to determine whether anOrganization Seeking Certification (OSC)complies with the cybersecurity controls required for its certification level. Themost common purpose of assessment procedures is to obtain evidencethat verifies an organization has properly implemented security practices. Why "A. Obtain Evidence" is Correct? CMMC Assessments Require Evidence Collection TheCMMC Assessment Process (CAP) Guideoutlines that assessors must use three methods to verify compliance: Examine- Reviewing documentation, policies, and system configurations. Interview- Speaking with personnel to confirm understanding and execution. Test- Validating controls through operational or technical tests. All these methods involve obtaining evidenceto support whether a security requirement has been met. Alignment with NIST SP 800-171A CMMC Level 2 assessments follow NIST SP 800-171A, which is designed for evidence-based verification. Assessors rely on documented artifacts, system logs, configurations, and personnel testimony as evidence of compliance. Why Other Answers Are Incorrect? B). Define level of effort (Incorrect) Thelevel of effortrefers to the time and resources needed for an assessment, but this is aplanningactivity, not the primary goal of an assessment. C). Determine information flow (Incorrect) While understandinginformation flowis important for security controls likedata protection and access control, themain purpose of an assessment is to gather evidence-not to determine information flow itself. D). Determine value of hardware and software (Incorrect) Asset valuation may be part of an organization's risk management process, but CMMC assessmentsdo not focus on determining hardware or software value. Conclusion The correct answer isA. Obtain evidence, as theCMMC assessment process is evidence-drivento verify compliance with security controls. References: CMMC Assessment Process (CAP) Guide NIST SP 800-171A (Assessment Procedures for CUI) DoD CMMC 2.0 Scoping and Assessment Guidelines