Which entity requires that organizations handling FCI or CUI be assessed to determine a required Level of cybersecurity maturity?
Correct Answer: A
Step 1: Understanding the Role of the DoD in CMMC TheU.S. Department of Defense (DoD)is the entity thatrequiresorganizations handlingFederal Contract Information (FCI)orControlled Unclassified Information (CUI)to undergo an assessment to determine their required level ofcybersecurity maturityunderCMMC 2.0. This requirement stems from theDFARS 252.204-7021 clause, which mandates CMMC certification for contractors handling FCI or CUI. Reference: DoD CMMC 2.0 Program Overview DFARS 252.204-7021 (CMMC Requirements) Step 2: DoD ' s Cybersecurity Maturity Levels TheDoD determinestherequired cybersecurity maturity levelfor a contract based on the sensitivity of the information involved: CMMC Level 1- Required for organizations handlingFCI(Basic Cyber Hygiene). CMMC Level 2- Required for organizations handlingCUI(Aligned with NIST SP 800-171). CMMC Level 3- Required for organizations handlinghigh-value CUIand facingAdvanced Persistent Threats (APT)(Aligned with a subset ofNIST SP 800-172). Reference: CMMC 2.0 Model Documentation NIST SP 800-171 & 800-172for security controls Step 3: Why Other Answer Choices Are Incorrect B). CISA (Incorrect): TheCybersecurity and Infrastructure Security Agency (CISA)is responsible fornational cybersecuritybut does not mandate CMMC assessments. C). NIST (Incorrect): TheNational Institute of Standards and Technology (NIST)provides the security framework (e.g.,NIST SP 800-171) but does not enforce CMMC compliance. D). CMMC-AB (Incorrect): TheCyber AB (formerly CMMC-AB)is responsible for accreditingC3PAOsand overseeing theCMMC ecosystem, but it does not determine which organizations require assessments. Final Confirmation of Correct answer: The DoD mandates CMMC compliance for organizations handling FCI or CUI. CMMC requirements are enforced through DFARS clauses in DoD contracts. Thus, the correct answer is:A. DoD
CMMC-CCP Exam Question 17
A C3PAO Assessment Plan document captures the names of the interviewees, the facilities that will utilized, along with estimated costs and schedule of the assessment. What part of the assessment plan is this?
Correct Answer: A
ACertified Third-Party Assessor Organization (C3PAO)is responsible for conductingCMMC Level 2 Assessments. Before the assessment begins, the C3PAO must develop anAssessment Plan, which includes several key elements. The part of the plan that captures: #Names of interviewees #Facilities to be utilized #Estimated costs #Assessment schedule falls under the"Identify Resources and Schedule"section of the plan. Step-by-Step Breakdown: #1. Identify Resources and Schedule This section of theCMMC Assessment Planoutlines: Thepersonnelinvolved (e.g., interviewees, assessors). Thelocationswhere the assessment will take place. Thetimeline and scheduling details. Theestimated costsassociated with the assessment. This ensures that all necessaryresourcesare allocated and that the assessment proceeds as planned. #2. Why the Other Answer Choices Are Incorrect: (B) Select Assessment Team Members# This section focuses onchoosing the assessorswho will conduct the evaluation, not listing interviewees and facilities. (C) Identify and Manage Assessment Risks# This part of the plandocuments risks(e.g., scheduling conflicts, data access issues), but it doesnot outline names, facilities, or costs. (D) Select and Develop the Evidence Collection Approach# This step defineshowevidence will be gathered (e.g., document reviews, interviews, system testing) but doesnot focus on logistics. Final Validation from CMMC Documentation: TheCMMC Assessment Process Guidestates thatresource identification and schedulingare essential for organizing the assessment. Since this sectioncaptures interviewees, facilities, costs, and the schedule, the correct answer is: #A. Identify resources and schedule.
CMMC-CCP Exam Question 18
For a scoping a CMMC Level 1 Self-Assessment, which asset types are assessed against CMMC practices?
Correct Answer: D
The correct answer is D because CMMC Level 1 scoping is driven by whether an asset processes, stores, or transmits Federal Contract Information (FCI). The Level 1 Scoping Guide states that in- scope assets for a Level 1 self-assessment are all assets that process, store, or transmit FCI, and that these assets are part of the CMMC Assessment Scope and assessed against all Level 1 requirements. The guide also defines transmitting as FCI being transferred from one asset to another through physical or digital transport methods. The other options are attractive but incorrect because IoT, Industrial Internet of Things, Restricted Information Systems, and test equipment are treated as Specialized Assets when they can process, store, or transmit FCI but cannot be fully secured. Specialized Assets are documented and managed but are not assessed against CMMC Level 1 requirements in the same way as ordinary in-scope FCI assets. Therefore, the best answer is the general rule: any non-specialized asset transmitting FCI is assessed against CMMC Level 1 practices. Reference /topics: CMMC Level 1 Scoping, FCI assets, Specialized Assets, process/store/transmit.
CMMC-CCP Exam Question 19
Which assessment method describes the process of reviewing, inspecting, observing, studying, or analyzing assessment objects (i.e., specification, mechanisms, activities)?
Correct Answer: C
Understanding the " Examine " Assessment Method in CMMC 2.0 CMMC 2.0 usesthree assessment methodsto evaluate security compliance: Examine- Reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, system documentation). Interview- Speaking with personnel to verify knowledge and responsibilities. Test- Performing technical validation to check system configurations. Relevant CMMC 2.0 Reference: TheCMMC Assessment Process (CAP)definesExamineas the method used toreview or analyze assessment objects, such as policies, procedures, configurations, and logs. Why is the Correct Answer " Examine " (C)? A). Test # Incorrect " Test " involvesexecutinga function to validate its security (e.g., verifying access controls through a live system test). B). Assess # Incorrect " Assess " is a broad term; CMMC explicitly defines " Examine " as the method for reviewing documentation. C). Examine # Correct " Examine " is the official term forreviewing policies, procedures, configurations, or logs. D). Interview # Incorrect " Interview " involvesverbal discussions with personnel, not document analysis. CMMC 2.0 References Supporting this Answer: CMMC Assessment Process (CAP) Document Defines " Examine " asanalyzing assessment objects (e.g., policies, procedures, logs, documentation). NIST SP 800-171A Specifies " Examine " as a method toreview security controls and configurations.
CMMC-CCP Exam Question 20
A Lead Assessor has been assigned to a CMMC Assessment During the assessment, one of the assessors approaches with a signed policy. There is one signatory, and that person has since left the company. Subsequently, another person was hired into that position but has not signed the document. Is this document valid?
Correct Answer: B
In the context of a CMMC Level 2 Assessment, assessors must evaluate the " Institutionalization " of practices, which includes the review of Policies. The validity of a policy document depends on the Organization Seeking Certification (OSC) ' s internal governance and administrative procedures. Internal Governance (The " Why " ): CMMC does not dictate exactlyhowa company must authorize its policies (e.g., whether a signature must be refreshed immediately upon a personnel change). Instead, the assessor must verify if the document is considered " active " and " authoritative " by the OSC's own standards. The Role of the Assessor: As per the CMMC Assessment Process (CAP) and CCP training materials, an assessor cannot unilaterally declare a policy invalid simply because a signatory has left. The assessor must perform " more research " (typically through Interviews or examining Supplemental Documents) to determine the OSC ' s internal rules for policy management. If the OSC ' s " Policy on Policies " states that a signature is tied to the individual, the document may be expired. If the OSC ' s rules state that the authority is tied to the role/position (which is common in most corporate governance), the policy remains in effect until it is formally rescinded or updated. Distinction from other options: Option A is too restrictive; it assumes a universal rule that doesn ' t exist in the CMMC framework. Option C is incorrect because a signatory (or formal approval)isoften what gives a policy its " authoritative " status in an audit; ignoring it would be a failure of the Examine method. Option D is a common business assumption, but an assessor must verify this via the OSC ' s own procedures rather than assuming it is true for every company. Reference Documents: CMMC Assessment Process (CAP) v1.0: Section on " Examine " methods and evaluating evidence integrity. NIST SP 800-171A: Discussion on " Organizational Policies " as assessment objects and the requirement for policies to be " established and maintained. " CMMC Level 2 Assessment Guide: Clarifies that policies must be " formally documented " and " representative of organizational requirements. "