CMMC-CCP Exam Question 26
In the Code of Professional Conduct, what does the practice of Professionalism require?
Correct Answer: C
What Does the Practice of Professionalism Require in the CMMC Code of Professional Conduct?
TheCMMC Code of Professional Conduct (CoPC)sets ethical and professional standards forCertified CMMC Assessors (CCAs) and Certified CMMC Professionals (CCPs).Professionalismrequireshonesty and integrity in all CMMC-related activities.
Step-by-Step Breakdown:
#1. Professionalism Requires Ethical Behavior
TheCoPC states that professionalismincludes:
Acting with integrityin all assessment-related activities.
Providing truthful and objective assessmentsof cybersecurity practices.
Avoiding deceptive or misleading claimsabout assessments or compliance.
#2. Why the Other Answer Choices Are Incorrect:
(A) Do not copy materials without permission to do so#
This falls underIntellectual Property (IP) protection, notProfessionalism.
(B) Do not make assertions about assessment outcomes#
Assessorsmustprovide findings based on evidence. The rule is aboutnot making false or misleading claims, not about avoiding assertions altogether.
(D) Ensure the security of all information discovered or received#
This falls underConfidentiality, notProfessionalism.
Final Validation from CMMC Documentation:
TheCMMC Code of Professional Conduct (CoPC)definesProfessionalism as requiring honesty and integrityin allCMMC-related activities.
Thus, the correct answer is:
#C. Refrain from dishonesty in all dealings regarding CMMC.
TheCMMC Code of Professional Conduct (CoPC)sets ethical and professional standards forCertified CMMC Assessors (CCAs) and Certified CMMC Professionals (CCPs).Professionalismrequireshonesty and integrity in all CMMC-related activities.
Step-by-Step Breakdown:
#1. Professionalism Requires Ethical Behavior
TheCoPC states that professionalismincludes:
Acting with integrityin all assessment-related activities.
Providing truthful and objective assessmentsof cybersecurity practices.
Avoiding deceptive or misleading claimsabout assessments or compliance.
#2. Why the Other Answer Choices Are Incorrect:
(A) Do not copy materials without permission to do so#
This falls underIntellectual Property (IP) protection, notProfessionalism.
(B) Do not make assertions about assessment outcomes#
Assessorsmustprovide findings based on evidence. The rule is aboutnot making false or misleading claims, not about avoiding assertions altogether.
(D) Ensure the security of all information discovered or received#
This falls underConfidentiality, notProfessionalism.
Final Validation from CMMC Documentation:
TheCMMC Code of Professional Conduct (CoPC)definesProfessionalism as requiring honesty and integrityin allCMMC-related activities.
Thus, the correct answer is:
#C. Refrain from dishonesty in all dealings regarding CMMC.
CMMC-CCP Exam Question 27
An assessor is collecting affirmations. So far, the assessor has collected interviews, demonstrations, emails, messaging, and presentations. Are these appropriate approaches to collecting affirmations?
Correct Answer: C
According to the CMMC Assessment Process (CAP) and the CMMC Level 2 Assessment Guide, an assessment finding is built upon evidence collected through three primary methods: Examine, Interview, and Test. The term " affirmation " in this context refers to the verbal or written statements provided by the Organization Seeking Certification (OSC) personnel to confirm that a practice is implemented as described.
Broad Definition of Evidence: The CAP allows for a wide variety of artifacts to be used as evidence. " Affirmations " are typically captured during the Interview process or found within Examine objects.
Validity of Formats:
Interviews: Direct verbal affirmations from subject matter experts (SMEs).
Emails and Messaging (Chat/Slack/Teams): These are considered valid " Examine " objects (records/artifacts) that serve as written affirmations or evidence of an activity (e.g., an email chain approving a firewall change or a message confirming a system update).
Presentations and Demonstrations: These fall under " Examine " (the presentation slides) and " Test/Examine
" (the demonstration of a mechanism).
Why Option C is correct: The CMMC framework does not disqualify digital communications like emails or messaging as evidence. In fact, these are often the primary artifacts used to prove that a process (like an approval workflow or notification) is occurring in practice. As long as the assessor can verify the authenticity and integrity of these communications, they are appropriate for collecting affirmations.
Why Option D is less accurate: While screenshots are indeed used as evidence, the core question asks if thespecificlist (interviews, demonstrations, emails, messaging, presentations) is appropriate. Option C directly validates the list provided in the prompt without introducing extraneous elements like screenshots, which- while valid-are not the focus of the " appropriate " determination for the items listed.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4 (Collect and Verify Evidence), which discusses the types of artifacts and " human evidence " (interviews) that support findings.
CMMC Level 2 Assessment Guide: " Assessment Methods " section, clarifying that evidence can include any records (electronic or physical) that demonstrate the implementation of a practice.
NIST SP 800-171A: The underlying standard for assessment procedures, which encourages the use of various evidence types to satisfy assessment objectives.
Broad Definition of Evidence: The CAP allows for a wide variety of artifacts to be used as evidence. " Affirmations " are typically captured during the Interview process or found within Examine objects.
Validity of Formats:
Interviews: Direct verbal affirmations from subject matter experts (SMEs).
Emails and Messaging (Chat/Slack/Teams): These are considered valid " Examine " objects (records/artifacts) that serve as written affirmations or evidence of an activity (e.g., an email chain approving a firewall change or a message confirming a system update).
Presentations and Demonstrations: These fall under " Examine " (the presentation slides) and " Test/Examine
" (the demonstration of a mechanism).
Why Option C is correct: The CMMC framework does not disqualify digital communications like emails or messaging as evidence. In fact, these are often the primary artifacts used to prove that a process (like an approval workflow or notification) is occurring in practice. As long as the assessor can verify the authenticity and integrity of these communications, they are appropriate for collecting affirmations.
Why Option D is less accurate: While screenshots are indeed used as evidence, the core question asks if thespecificlist (interviews, demonstrations, emails, messaging, presentations) is appropriate. Option C directly validates the list provided in the prompt without introducing extraneous elements like screenshots, which- while valid-are not the focus of the " appropriate " determination for the items listed.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4 (Collect and Verify Evidence), which discusses the types of artifacts and " human evidence " (interviews) that support findings.
CMMC Level 2 Assessment Guide: " Assessment Methods " section, clarifying that evidence can include any records (electronic or physical) that demonstrate the implementation of a practice.
NIST SP 800-171A: The underlying standard for assessment procedures, which encourages the use of various evidence types to satisfy assessment objectives.
CMMC-CCP Exam Question 28
Within how many days from the Assessment Final Recommended Findings Brief should the Lead Assessor and Assessment Team Members, if necessary, review the accuracy and validity of (he OSC ' s updated POA
& M with any accompanying evidence or scheduled collections?
& M with any accompanying evidence or scheduled collections?
Correct Answer: B
In theCMMC 2.0 Assessment Process, after theAssessment Final Recommended Findings Brief, theLead Assessor and Assessment Team Membersmustreview the accuracy and validity of the Organization Seeking Certification (OSC)'s updated Plan of Action & Milestones (POA & M) and any accompanying evidence or scheduled collectionswithin180 days.
Relevant CMMC 2.0 Reference:
TheCMMC Assessment Process (CAP)outlines that organizations haveup to 180 daysto address identifieddeficienciesafter their initial assessment.
During this time, the OSC can update itsPOA & M with additional evidenceto demonstrate compliance.
Why is the Correct Answer 180 Days (B)?
A). 90 days # Incorrect
The CMMC CAP does not impose a90-day limiton POA & M updates; instead,180 daysis the standard timeframe.
B). 180 days # Correct
PerCMMC Assessment Process guidelines, theLead Assessor and Teammust review updateswithin 180 days.
C). 270 days # Incorrect
No official CMMC documentation mentions a270-dayreview period.
D). 360 days # Incorrect
The process must be completedfar sooner than 360 daysto maintain compliance.
CMMC 2.0 References Supporting this Answer:
CMMC Assessment Process (CAP) Document
Defines the180-day windowfor the OSC to update itsPOA & M and submit evidencefor review.
CMMC 2.0 Official Guidelines
Specifies that organizations are givenup to 180 daysto remediate deficiencies before reassessment.
Relevant CMMC 2.0 Reference:
TheCMMC Assessment Process (CAP)outlines that organizations haveup to 180 daysto address identifieddeficienciesafter their initial assessment.
During this time, the OSC can update itsPOA & M with additional evidenceto demonstrate compliance.
Why is the Correct Answer 180 Days (B)?
A). 90 days # Incorrect
The CMMC CAP does not impose a90-day limiton POA & M updates; instead,180 daysis the standard timeframe.
B). 180 days # Correct
PerCMMC Assessment Process guidelines, theLead Assessor and Teammust review updateswithin 180 days.
C). 270 days # Incorrect
No official CMMC documentation mentions a270-dayreview period.
D). 360 days # Incorrect
The process must be completedfar sooner than 360 daysto maintain compliance.
CMMC 2.0 References Supporting this Answer:
CMMC Assessment Process (CAP) Document
Defines the180-day windowfor the OSC to update itsPOA & M and submit evidencefor review.
CMMC 2.0 Official Guidelines
Specifies that organizations are givenup to 180 daysto remediate deficiencies before reassessment.
CMMC-CCP Exam Question 29
Which principles are included in defining the CMMC-AB Code of Professional Conduct?
Correct Answer: D
The Cyber AB (formerly CMMC-AB) Code of Professional Conduct (CoPC) is a mandatory agreement that all CMMC ecosystem members-including Certified CMMC Professionals (CCPs) and Certified CMMC Assessors (CCAs)-must adhere to. This code ensures the reliability and trustworthiness of the assessment process.
The fundamental principles that form the foundation of the CoPC include:
Responsibility: This refers to the obligation of the CMMC professional to act in the best interest of the CMMC program, the Department of Defense (DoD), and the public. It includes maintaining professional competence and performing duties with due care.
Confidentiality: Assessors and professionals are granted access to sensitive information, including Controlled Unclassified Information (CUI) and proprietary business data of the Organization Seeking Certification (OSC). They must ensure this information is protected from unauthorized disclosure.
Information Integrity: This principle requires that all data, findings, and reports generated during the assessment are accurate, complete, and have not been tampered with. It ensures that the " Met " or " Not Met " determinations are based on honest evidence.
Why other options are incorrect:
Options A and B (Objectivity): While " Objectivity " is a crucialbehavioralrequirement for an assessor (remaining unbiased), the specific high-level triad often emphasized in the CMMC Professional training and the formal CoPC documentation focuses on the Responsibility-Confidentiality-Integrity framework to align with standard professional ethics and information security pillars.
Options A and C (Classification): " Classification " is a process used for National Security Information (Classified info), whereas CMMC is primarily focused on unclassified information (CUI and FCI).
Classification is not a core principle of the professional code of conduct.
Options A and C (Information Accuracy): While accuracy is vital, it is considered a subset of Information Integrity within the formal definitions provided in the CCP curriculum.
Reference Documents:
CMMC-AB (The Cyber AB) Code of Professional Conduct: The official ethical framework for all credentialed individuals.
CMMC Professional (CCP) Study Guide: Section on " Ethics and the Code of Professional Conduct. " CMMC Assessment Process (CAP): References the ethical standards required to maintain the integrity of the assessment ecosystem.
The fundamental principles that form the foundation of the CoPC include:
Responsibility: This refers to the obligation of the CMMC professional to act in the best interest of the CMMC program, the Department of Defense (DoD), and the public. It includes maintaining professional competence and performing duties with due care.
Confidentiality: Assessors and professionals are granted access to sensitive information, including Controlled Unclassified Information (CUI) and proprietary business data of the Organization Seeking Certification (OSC). They must ensure this information is protected from unauthorized disclosure.
Information Integrity: This principle requires that all data, findings, and reports generated during the assessment are accurate, complete, and have not been tampered with. It ensures that the " Met " or " Not Met " determinations are based on honest evidence.
Why other options are incorrect:
Options A and B (Objectivity): While " Objectivity " is a crucialbehavioralrequirement for an assessor (remaining unbiased), the specific high-level triad often emphasized in the CMMC Professional training and the formal CoPC documentation focuses on the Responsibility-Confidentiality-Integrity framework to align with standard professional ethics and information security pillars.
Options A and C (Classification): " Classification " is a process used for National Security Information (Classified info), whereas CMMC is primarily focused on unclassified information (CUI and FCI).
Classification is not a core principle of the professional code of conduct.
Options A and C (Information Accuracy): While accuracy is vital, it is considered a subset of Information Integrity within the formal definitions provided in the CCP curriculum.
Reference Documents:
CMMC-AB (The Cyber AB) Code of Professional Conduct: The official ethical framework for all credentialed individuals.
CMMC Professional (CCP) Study Guide: Section on " Ethics and the Code of Professional Conduct. " CMMC Assessment Process (CAP): References the ethical standards required to maintain the integrity of the assessment ecosystem.
CMMC-CCP Exam Question 30
When executing a remediation review, the Lead Assessor should:
Correct Answer: C
In the context of the Cybersecurity Maturity Model Certification (CMMC) 2.0, the remediation review process is a critical phase where identified deficiencies from an initial assessment are addressed. The Lead Assessor, representing a Certified Third-Party Assessment Organization (C3PAO), plays a pivotal role in this process.
Role of the Lead Assessor in Remediation Reviews:
Validation of Remediation Efforts:
Objective:Ensure that the Organization Seeking Certification (OSC) has effectively addressed and corrected all deficiencies identified during the initial assessment.
Process:The Lead Assessor reviews the evidence provided by the OSC to confirm that each previously unmet practice now meets the required standards. This involves examining updated policies, procedures, system configurations, and other relevant artifacts.
Delta Assessment Remediation Package Submission:
Definition:A delta assessment focuses on evaluating only the components or practices that were previously found non-compliant or deficient.
Responsibility:After validating the remediation efforts, the Lead Assessor compiles a remediation package that includes:
Detailed documentation of the deficiencies identified in the initial assessment.
Evidence of the corrective actions taken by the OSC.
Findings from the reassessment of the remediated practices.
Internal Quality Review:This remediation package is then submitted for the C3PAO's internal quality review process. The purpose of this review is to ensure the accuracy, completeness, and consistency of the assessment findings before finalizing the certification decision.
Rationale for Selecting Answer C:
Alignment with CMMC Assessment Process:The submission of a delta assessment remediation package for internal quality review is a standard procedure outlined in the CMMC Assessment Process. This step ensures that all remediated items are thoroughly evaluated and validated, maintaining the integrity of the certification process.
Clarification of Incorrect Options:
Option A:"Help OSC to complete planned remediation activities."
The Lead Assessor's role is to assess and validate the OSC's compliance, not to assist in the implementation or completion of remediation activities. Providing such assistance could lead to a conflict of interest and compromise the objectivity of the assessment.
Option B:"Plan two consecutive remediation reviews for an OSC."
The standard process involves conducting a single remediation review after the OSC has addressed the identified deficiencies. Planning multiple consecutive remediation reviews is not a typical practice and could indicate a lack of proper remediation planning by the OSC.
Option D:"Validate that practices previously listed on the POA&M have been removed on an updated Risk Assessment." While it's essential to ensure that deficiencies are addressed, the primary focus of the Lead Assessor during a remediation review is to validate the implementation of remediated practices. Updating the Risk Assessment is the responsibility of the OSC's internal risk management team, not the Lead Assessor.
References:
CMMC Assessment Process v2.0
CyberAB
CMMC Assessment Guide - Level 2
Defense Innovation Unit
These documents provide detailed guidelines on the roles and responsibilities of assessors, the remediation review process, and the procedures for submitting assessment findings for quality review within the CMMC framework.
Role of the Lead Assessor in Remediation Reviews:
Validation of Remediation Efforts:
Objective:Ensure that the Organization Seeking Certification (OSC) has effectively addressed and corrected all deficiencies identified during the initial assessment.
Process:The Lead Assessor reviews the evidence provided by the OSC to confirm that each previously unmet practice now meets the required standards. This involves examining updated policies, procedures, system configurations, and other relevant artifacts.
Delta Assessment Remediation Package Submission:
Definition:A delta assessment focuses on evaluating only the components or practices that were previously found non-compliant or deficient.
Responsibility:After validating the remediation efforts, the Lead Assessor compiles a remediation package that includes:
Detailed documentation of the deficiencies identified in the initial assessment.
Evidence of the corrective actions taken by the OSC.
Findings from the reassessment of the remediated practices.
Internal Quality Review:This remediation package is then submitted for the C3PAO's internal quality review process. The purpose of this review is to ensure the accuracy, completeness, and consistency of the assessment findings before finalizing the certification decision.
Rationale for Selecting Answer C:
Alignment with CMMC Assessment Process:The submission of a delta assessment remediation package for internal quality review is a standard procedure outlined in the CMMC Assessment Process. This step ensures that all remediated items are thoroughly evaluated and validated, maintaining the integrity of the certification process.
Clarification of Incorrect Options:
Option A:"Help OSC to complete planned remediation activities."
The Lead Assessor's role is to assess and validate the OSC's compliance, not to assist in the implementation or completion of remediation activities. Providing such assistance could lead to a conflict of interest and compromise the objectivity of the assessment.
Option B:"Plan two consecutive remediation reviews for an OSC."
The standard process involves conducting a single remediation review after the OSC has addressed the identified deficiencies. Planning multiple consecutive remediation reviews is not a typical practice and could indicate a lack of proper remediation planning by the OSC.
Option D:"Validate that practices previously listed on the POA&M have been removed on an updated Risk Assessment." While it's essential to ensure that deficiencies are addressed, the primary focus of the Lead Assessor during a remediation review is to validate the implementation of remediated practices. Updating the Risk Assessment is the responsibility of the OSC's internal risk management team, not the Lead Assessor.
References:
CMMC Assessment Process v2.0
CyberAB
CMMC Assessment Guide - Level 2
Defense Innovation Unit
These documents provide detailed guidelines on the roles and responsibilities of assessors, the remediation review process, and the procedures for submitting assessment findings for quality review within the CMMC framework.
- Other Version
- 934CyberAB.CMMC-CCP.v2026-06-26.q98
- Latest Upload
- 222Cisco.300-420.v2026-08-13.q190
- 255IIA.IIA-CIA-Part3-CN.v2026-08-13.q328
- 142Fortinet.NSE7_SSE_AD-25.v2026-08-12.q38
- 171CyberAB.CMMC-CCP.v2026-08-12.q96
- 152SAP.C_ARCON.v2026-08-12.q39
- 134SAP.C_CR125.v2026-08-12.q33
- 132NetworkAppliance.NS0-094.v2026-08-12.q38
- 145Netskope.NSK200.v2026-08-11.q42
- 180Oracle.1Z0-997-25.v2026-08-11.q136
- 158Salesforce.Als-Con-201.v2026-08-11.q58
[×]
Download PDF File
Enter your email address to download CyberAB.CMMC-CCP.v2026-08-12.q96 Practice Test
