During a Level 1 Self-Assessment, a smart thermostat was identified. It is connected to the Internet on the OSC's WiFi network. What type of asset is this?
Correct Answer: D
Understanding Asset Categorization in CMMC 2.0 InCMMC 2.0, assets are categorized into different types based on their function, connectivity, and whether they process, store, or transmitFederal Contract Information (FCI) or Controlled Unclassified Information (CUI). Why "D. Specialized Asset" is Correct? TheCMMC 2.0 Scoping GuidedefinesSpecialized Assetsas assetsthat do not fit traditional IT classificationsbut still exist within the organizational environment. Asmart thermostatis anInternet of Things (IoT) device, which falls underSpecialized Assetsas defined in CMMC. Why Other Answers Are Incorrect? A). FCI Asset (Incorrect) FCI Assets process, store, or transmit Federal Contract Information, which asmart thermostat does not. B). CUI Asset (Incorrect) CUI Assets handle Controlled Unclassified Information, and athermostat does not process CUI. C). In-scope Asset (Incorrect) In-scope Assets include FCI and CUI assets, which asmart thermostat does not qualify as. Conclusion The correct answer isD. Specialized Asset, as asmart thermostat is an IoT device, which falls into theSpecialized Assetcategory. References: CMMC 2.0 Scoping Guide DoD Cybersecurity Guidelines on IoT Devices
CMMC-CCP Exam Question 82
As part of CMMC 2.0, the change to Level 1 Self-Assessments supports "reduced assessment costs" allows all companies at Level 1 (Foundational) to:
Correct Answer: A
Step 1: Review CMMC 2.0 Reforms (Level 1 - Foundational) As part ofCMMC 2.0, the DoD announced changes toreduce burden and costsfor companies that only handleFederal Contract Information (FCI): DoD Statement (CMMC 2.0 Overview): "Level 1 (Foundational) will only require an annual self-assessment, affirming implementation of the 17 FAR 52.204-21 controls." #Step 2: Intent of "Reduced Assessment Costs" The move to allowself-assessments at Level 1was explicitly designed toeliminate the costof hiring third-party assessors for organizations that only handle FCI. Level 1 self-assessments are: Conductedinternally by the OSC, Affirmed annuallyby a senior company official, Submitted via SPRS(Supplier Performance Risk System). #Why the Other Options Are Incorrect B). Opt out of CMMC Assessments #Incorrect. Organizations must still perform aself-assessmentannually - they cannot opt out entirely. C). Have assessment costs reimbursed by the DoD #No such reimbursement mechanism exists. D). Pay no more than $500.00... #No such fixed cost is set or guaranteed in CMMC documentation. UnderCMMC 2.0, all companies atLevel 1 (Foundational)are permitted toconduct self-assessmentsannually to demonstrate compliance, supporting the DoD's goal ofreducing assessment costsfor low-risk contractors.
CMMC-CCP Exam Question 83
Which training is a CCI authorized to deliver through an approved CMMC LTP?
Correct Answer: A
A Certified CMMC Instructor (CCI) is only authorized to deliver CMMC-AB (now The Cyber AB) approved training courses through a Licensed Training Provider (LTP). CCI instructors do not deliver DFARS or NARA CUI training under CMMC authorization-only formally approved CMMC courses. Supporting Extracts from Official Content: CMMC Ecosystem Roles: "CCIs are authorized to deliver CMMC-AB approved training courses through an LTP." Why Option A is Correct: CCIs teach only CMMC-AB approved training. Options B, C, and D include external trainings (DFARS or NARA CUI) that are not within the CCI's scope. References (Official CMMC v2.0 Content): CMMC Ecosystem documentation - Roles and Responsibilities of LTPs and CCIs.
CMMC-CCP Exam Question 84
How many domains does the CMMC Model consist of?
Correct Answer: A
Step 1: Understanding CMMC Domains TheCMMC Model consists of 14 domains, which are based on theNIST SP 800-171 control familieswith additional cybersecurity practices. Eachdomaincontainspractices and processesthat define cybersecurity requirements for organizations seeking CMMC certification. Reference: CMMC 2.0 Model Documentation NIST SP 800-171 Framework Step 2: List of 14 CMMC Domains Access Control (AC) Asset Management (AM)(Introduced in CMMC 2.0 for scoping guidance) Audit and Accountability (AU) Awareness and Training (AT) Configuration Management (CM) Identification and Authentication (IA) Incident Response (IR) Maintenance (MA) Media Protection (MP) Personnel Security (PS) Physical Protection (PE) Risk Management (RM) Security Assessment (CA) System and Communications Protection (SC) Step 3: Why Other Answer Choices Are Incorrect B). 43 domains (Incorrect): The CMMC model does not have43 domains; this number is incorrect. C). 72 domains (Incorrect): There are72 practices in CMMC Level 2, but not72 domains. D). 110 domains (Incorrect): 110 refers to the number of security controls in NIST SP 800-171, which aligns withCMMC Level 2, but these are controls, not domains. Final Confirmation of Correct Answer: The CMMC Model consists of 14 domains based on NIST SP 800-171 control families. Thus, the correct answer is:A. 14 domains
CMMC-CCP Exam Question 85
During a Level 2 Assessment, the OSC has provided an inventory list of all hardware. The list includes servers, workstations, and network devices. Why should this evidence be sufficient for making a scoring determination for AC.L2-3.1.19: Encrypt CUI on mobile devices and mobile computing platforms?
Correct Answer: A
In the context of a Cybersecurity Maturity Model Certification (CMMC) Level 2 Assessment, specific practices must be evaluated to ensure compliance with established security requirements. One such practice is AC.L2-3.1.19, which mandates the encryption of Controlled Unclassified Information (CUI) on mobile devices and mobile computing platforms. Step-by-Step Explanation: Requirement Overview: Practice AC.L2-3.1.19 requires organizations to "Encrypt CUI on mobile devices and mobile computing platforms." This ensures that any CUI accessed, stored, or transmitted via mobile devices is protected through encryption, mitigating risks associated with data breaches or unauthorized access. Assessment of Provided Evidence: During the assessment, the Organization Seeking Certification (OSC) provided an inventory list encompassing servers, workstations, and network devices. Notably, this list lacks any mention of mobile devices or mobile computing platforms. Implications of the Omission: The absence of mobile devices in the inventory suggests that the OSC may not have accounted for all assets that process, store, or transmit CUI. Without a comprehensive inventory that includes mobile devices, it's challenging to verify whether the OSC has implemented the necessary encryption measures for CUI on these platforms. Assessment Determination: Given the incomplete inventory, the evidence is insufficient to make a definitive scoring determination for practice AC.L2-3.1.19. The OSC must provide a detailed inventory that encompasses all relevant devices, including mobile devices and computing platforms, to demonstrate compliance with the encryption requirements for CUI. References: CMMC Model Overview Version 2.13, which outlines the requirements for practice AC.L2-3.1.19. Ensuring a complete and accurate inventory is a critical step in the assessment process, as it forms the basis for evaluating the implementation of security controls across all relevant assets within the organization.