Which assessment method describes the process of reviewing, inspecting, observing, studying, or analyzing assessment objects (i.e., specification, mechanisms, activities)?
Correct Answer: C
Understanding the " Examine " Assessment Method in CMMC 2.0 CMMC 2.0 usesthree assessment methodsto evaluate security compliance: Examine- Reviewing, inspecting, observing, studying, or analyzing assessment objects (e.g., policies, system documentation). Interview- Speaking with personnel to verify knowledge and responsibilities. Test- Performing technical validation to check system configurations. Relevant CMMC 2.0 Reference: TheCMMC Assessment Process (CAP)definesExamineas the method used toreview or analyze assessment objects, such as policies, procedures, configurations, and logs. Why is the Correct Answer " Examine " (C)? A). Test # Incorrect " Test " involvesexecutinga function to validate its security (e.g., verifying access controls through a live system test). B). Assess # Incorrect " Assess " is a broad term; CMMC explicitly defines " Examine " as the method for reviewing documentation. C). Examine # Correct " Examine " is the official term forreviewing policies, procedures, configurations, or logs. D). Interview # Incorrect " Interview " involvesverbal discussions with personnel, not document analysis. CMMC 2.0 References Supporting this Answer: CMMC Assessment Process (CAP) Document Defines " Examine " asanalyzing assessment objects (e.g., policies, procedures, logs, documentation). NIST SP 800-171A Specifies " Examine " as a method toreview security controls and configurations.
CMMC-CCP Exam Question 67
Which CMMC Levels meet the standards of protecting FCI (Federal Contract Information) ?
Correct Answer: D
In CMMC v2.0, Level 1 is explicitly the level that "focuses on the protection of FCI " and is composed of the basic safeguarding requirements aligned to FAR 52.204-21 . This directly establishes Level 1 as meeting the standard for protecting FCI. However, the question asks which levels meet the standard of protecting FCI-not which level is primarily intended for FCI. The official CMMC Model Overview (Version 2.0) states that the CMMC levels and associated sets of practices are cumulative , meaning that to achieve a higher level, an organization must also demonstrate achievement of the preceding lower levels. Because Level 2 and Level 3 certifications require meeting lower-level requirements as part of achieving the higher certification, an organization certified at Level 2 or Level 3 necessarily satisfies the Level 1 requirements that protect FCI. In addition, the later Model Overview v2.13 reiterates the structure of the model: Level 1 requirements correspond to FAR 52.204-21 safeguards (FCI), while Level 2 and Level 3 focus on CUI protection at increasing rigor. Taken together, the official documents support that Levels 1, 2, and 3 all meet the standard for protecting FCI, with Level 1 being the foundational baseline and Levels 2/3 building on it.
CMMC-CCP Exam Question 68
SI.L2-3.14.7: Identify unauthorized use of organizational systems is being assessed using two assessment objectives. The assessment objectives are to determine if authorized use of the system is defined and to determine if unauthorized use of the system is identified. What is the BEST evidence for this practice?
Correct Answer: D
For SI.L2-3.14.7 (Identify Unauthorized Use) , the assessment objectives focus on two outcomes: (a) the organization has defined authorized use of the system, and (b) the organization identifies unauthorized use when it occurs. The strongest evidence is therefore evidence that the organization actively monitors systems and can detect and recognize activity outside the defined authorized-use baseline. In the DoD CMMC Assessment Guide - Level 2 (v2.13) , the "Potential Assessment Methods and Objects" for SI.L2-3.14.7 emphasize artifacts that are directly tied to monitoring and detection-such as a continuous monitoring strategy , system and information integrity policy , procedures addressing system monitoring tools and techniques , and technical monitoring capabilities (e.g., tools/techniques like IDS/IPS , audit record monitoring , and network monitoring ). These artifacts are exactly what demonstrate that unauthorized use is being identified in practice (alerts, logs, correlation, and review processes) and that authorized use is defined (policies/standards that establish what "authorized" looks like so "unauthorized" can be recognized). By contrast, risk assessment/response and incident response may be related program elements, but they are not the primary evidence that the organization is continuously detecting unauthorized use. The assessment guide's focus on monitoring artifacts makes System monitoring the best evidence.
CMMC-CCP Exam Question 69
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
Correct Answer: D
Per the CMMC Assessment Process (CAP), when planning an assessment, the Lead Assessor must coordinate with the Organization Seeking Certification (OSC) to select interview participants who can provide clarity and understanding of their practice activities. The intent is to interview individuals directly involved with and knowledgeable about the processes and practices under review, rather than selecting personnel based solely on rank, clearance, or formal expertise in CMMC. This ensures the assessment is evidence-based and grounded in how practices are actually performed within the OSC. Reference Documents: * CMMC Assessment Process (CAP), v1.0