Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse. After a thorough review, the CCP tells the Lead Assessor that all supporting documents fully reflect the performance of the practice and should be accepted because the evidence is:
Correct Answer: B
CMMC Level 1 includes 17 practices derived fromFAR 52.204-21. Among them, theMedia Protection (MP) practicerequires organizations to ensure thatmedia containing FCI is sanitized or destroyed before disposal or release for reuseto prevent unauthorized access. This requirement ensures that any storage devices, hard drives, USBs, or physical documents containingFederal Contract Information (FCI)areproperly disposed of or sanitizedto prevent data leakage. The evidence collected for this practice should demonstrate that an organization has established and followed propermedia sanitization or destruction procedures. Why the Correct Answer is "B. Adequate"? TheCMMC Assessment Process (CAP) Guideoutlines that for an assessment to be considered complete, all submitted evidence must meet the standard ofadequacybefore it is accepted by the Lead Assessor. Definition of "Adequate" Evidence in CMMC: Evidence isadequatewhen itfully demonstrates that a practice has been performed as requiredby CMMC guidelines. TheLead Assessorevaluates whether the submitted documentation meets the CMMC 2.0 Level 1 requirements. If the evidenceaccurately and completely demonstrates the sanitization or destruction of media containing FCI, then it meets the standard ofadequacy. Why Not the Other Options? A). Official- While the evidence may come from an official source, the CMMCdoes not require evidence to be "official", only that it beadequateto confirm compliance. C). Compliant- Compliance is the final result of an assessment, but before compliance is determined, the evidence must first beadequatefor evaluation. D). Subjective- CMMC evidence isobjective, meaning it should be based on verifiable documents, policies, logs, and procedures-not opinions or interpretations. Relevant CMMC 2.0 References: CMMC 2.0 Scoping Guide (Nov 2021)- Specifies that Media Protection (MP) at Level 1 applies only to assets that process, store, or transmit FCI. CMMC Assessment Process (CAP) Guide- Definesadequate evidenceas documentation that completely and clearly supports the implementation of a required security practice. FAR 52.204-21- The source of the Level 1 requirements, which includessanitization and destruction of media containing FCI. Final Justification: The CCP's statement that the evidence"fully reflects the performance of the practice"aligns with the definition ofadequate evidenceunder CMMC. Since adequacy is the key standard used before final compliance decisions are made, the correct answer isB. Adequate.
CMMC-CCP Exam Question 2
An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?
Correct Answer: A
In this scenario, the primary concern is the protection of Controlled Unclassified Information (CUI) in an environment that lacks sufficient physical security controls (specifically, a lack of a locked cabinet or drawer). According to the CMMC Assessment Process (CAP) and NIST SP 800-171 (specifically the Physical Protection (PE) family), CUI must be protected from unauthorized access at all times. Responsibility of the Assessor: CMMC Professionals (CCPs and CCAs) are bound by the CMMC Code of Professional Conduct and the C3PAO's internal security protocols to ensure that any CUI provided by the Organization Seeking Certification (OSC) is handled securely. Physical Protection (PE.L2-3.10.1 and PE.L2-3.10.2): These practices require that an organization limit physical access to systems and equipment to authorized users and protect the physical facility. If the provided "hoteling space" does not offer a locked container (like a cabinet) to secure the CUI overnight, leaving it in an unlocked drawer (Option C) or on the desk (Option B) would be a violation of CUI handling requirements and a security risk. Why Option A is the best "Next" step: In the absence of on-site secure storage, the assessor must maintain positive control of the CUI. Taking the document to a secure location (such as the assessor's hotel room or person) where they can ensure it remains under their control is the only viable way to prevent unauthorized access by janitorial staff or other unauthorized personnel at the client site overnight. Why other options are incorrect: Option B and C: Both fail to protect the CUI from unauthorized access in a non-secure, shared environment. Option D: Taking a picture of CUI on a personal phone is a major security violation (spillage), as personal devices are generally not authorized to store or process CUI. Reference Documents: CMMC Assessment Process (CAP) v1.0: Section regarding "Assessor Responsibilities for CUI and Proprietary Information." NIST SP 800-171 Rev 2: Physical Protection (PE) family (3.10.1, 3.10.2). DoD Instruction 5200.48: "Controlled Unclassified Information (CUI)," which specifies that CUI must be protected by at least one physical barrier when not in the direct control of an authorized individual.
CMMC-CCP Exam Question 3
The Lead Assessor interviews a network security specialist of an OSC. The incident monitoring report for the month shows that no security incidents were reported from OSC's external SOC service provider. This is provided as evidence for RA.L2-3.11.2: Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. Based on this information, the Lead Assessor should conclude that the evidence is:
Correct Answer: A
Understanding RA.L2-3.11.2: Vulnerability Scanning TheRA.L2-3.11.2practice requires organizations to: #Regularly scan for vulnerabilitiesin systems and applications. #Perform scans when new vulnerabilities are identified. #Use vulnerability scanning tools or servicesto proactively detect security weaknesses. Why Is an Incident Monitoring Report Irrelevant? Anincident monitoring reporttrackssecurity incidents, notvulnerability scanning activities. Vulnerability scanning reportsshould include: #A list of vulnerabilities detected. #Remediation actions taken. #Scan frequency and schedule. Theabsence of reported security incidentsdoesnotconfirm that vulnerability scans were performed. Why is the Correct Answer "A. Inadequate because it is irrelevant to the practice"? A). Inadequate because it is irrelevant to the practice # Correct Alack of reported security incidents does not confirm that vulnerability scanning was performed. B). Adequate because it fits well for expected artifacts # Incorrect Incident monitoring reportsare not expected artifactsfor this control.Vulnerability scan reportsare required instead. C). Adequate because no security incidents were reported # Incorrect The absence of incidents does not mean the OSC is performing vulnerability scanning. This isnot valid evidence. D). Inadequate because the OSC's service provider should be interviewed # Incorrect While interviewing the provider may be useful, themain issue is that the provided evidence is irrelevant. Thecorrect evidence (vulnerability scan reports) is missing. CMMC 2.0 References Supporting This Answer: NIST SP 800-171 (Requirement 3.11.2 - Vulnerability Scanning) Defines the requirement toscan for vulnerabilities periodically and when new threats emerge. CMMC Assessment Guide for Level 2 Specifies that evidence for RA.L2-3.11.2 should includevulnerability scan reports, not incident monitoring reports. CMMC 2.0 Model Overview Confirms that organizationsmust proactively identify vulnerabilities through scanning, not just rely on incident detection.
CMMC-CCP Exam Question 4
For CMMC Assessments, during Phase 1 of the CMMC Assessment Process, which are responsible for identifying potential conflicts of information?
Correct Answer: D
In Phase 1 (Planning) of the CMMC Assessment Process, the Lead Assessor is responsible for managing the team and identifying conflicts of interest. Assessment team members must also disclose potential conflicts. Supporting Extracts from Official Content: CAP v2.0, Planning (§2.5-2.8): "The Lead Assessor and Assessment Team Members must identify and disclose any conflicts of interest prior to conducting the assessment." Why Option D is Correct: Only the Lead Assessor and assessment team are responsible for identifying conflicts of interest during Phase 1. Options A, B, and C incorrectly assign this role to organizations that do not hold the responsibility. References (Official CMMC v2.0 Content): CMMC Assessment Process (CAP) v2.0, Phase 1 Planning responsibilities.
CMMC-CCP Exam Question 5
Which principles are included in defining the CMMC-AB Code of Professional Conduct?
Correct Answer: D
The Cyber AB (formerly CMMC-AB) Code of Professional Conduct (CoPC) is a mandatory agreement that all CMMC ecosystem members-including Certified CMMC Professionals (CCPs) and Certified CMMC Assessors (CCAs)-must adhere to. This code ensures the reliability and trustworthiness of the assessment process. The fundamental principles that form the foundation of the CoPC include: Responsibility: This refers to the obligation of the CMMC professional to act in the best interest of the CMMC program, the Department of Defense (DoD), and the public. It includes maintaining professional competence and performing duties with due care. Confidentiality: Assessors and professionals are granted access to sensitive information, including Controlled Unclassified Information (CUI) and proprietary business data of the Organization Seeking Certification (OSC). They must ensure this information is protected from unauthorized disclosure. Information Integrity: This principle requires that all data, findings, and reports generated during the assessment are accurate, complete, and have not been tampered with. It ensures that the " Met " or " Not Met " determinations are based on honest evidence. Why other options are incorrect: Options A and B (Objectivity): While " Objectivity " is a crucialbehavioralrequirement for an assessor (remaining unbiased), the specific high-level triad often emphasized in the CMMC Professional training and the formal CoPC documentation focuses on the Responsibility-Confidentiality-Integrity framework to align with standard professional ethics and information security pillars. Options A and C (Classification): " Classification " is a process used for National Security Information (Classified info), whereas CMMC is primarily focused on unclassified information (CUI and FCI). Classification is not a core principle of the professional code of conduct. Options A and C (Information Accuracy): While accuracy is vital, it is considered a subset of Information Integrity within the formal definitions provided in the CCP curriculum. Reference Documents: CMMC-AB (The Cyber AB) Code of Professional Conduct: The official ethical framework for all credentialed individuals. CMMC Professional (CCP) Study Guide: Section on " Ethics and the Code of Professional Conduct. " CMMC Assessment Process (CAP): References the ethical standards required to maintain the integrity of the assessment ecosystem.