OSCs MUST provide documentation that vulnerability scans are performed:
Correct Answer: A
The correct answer is A because CMMC 2.0 Level 2 requirement RA.L2-3.11.2, Vulnerability Scan , requires organizations to "scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified." The official CMMC Model Overview maps this requirement directly to NIST SP 800-171 Rev. 2, 3.11.2 . The official CMMC Level 2 Assessment Guide further breaks this into assessment objectives: the organization must define the frequency for vulnerability scanning, perform scans on organizational systems and applications at that defined frequency, and perform scans when new vulnerabilities are identified. Therefore, the OSC must maintain evidence such as vulnerability scan schedules, scan reports, tool outputs, procedures, policies, or tickets showing that scans occur at the organization's defined frequency and when new vulnerabilities are identified. Option B is incorrect because an RPO may advise or assist, but the scan frequency is not "defined by an accredited RPO" in the CMMC requirement. Option C is incorrect because vulnerability scanning is not limited to penetration testing events. Option D is incorrect because purely ad hoc scanning or scanning only when directed by a security manager does not satisfy the requirement to define and follow a frequency.
CMMC-CCP Exam Question 12
A Lead Assessor is planning an assessment and scheduling the test activities. Who MUST perform tests to obtain evidence?
Correct Answer: A
Understanding Who Must Perform Tests in a CMMC Assessment During aCMMC Level 2 Assessment, assessorsmust observe operational activities and security practicesto verify compliance. This process involves: #Testing security controls and proceduresas part of the assessment. #Observation of standard work practicesto ensure controls are properly implemented. #Using operational personnel (OSC employees) who regularly perform the taskto ensure realistic assessment conditions. Who Performs Tests? Operational personnel (OSC employees) must conduct the actual work while assessors observe. Certified CMMC Professionals (CCPs) or Lead Assessorsoversee and document the testing process. Why is the Correct Answer "A" (OSC personnel who normally perform that work as the CCP observes)? A). OSC personnel who normally perform that work as the CCP observes # Correct CMMC assessments require actual users (OSC personnel) to perform their regular duties while assessors observeto verify security practices. B). Military personnel and the CCP and/or Lead Assessor to test the adequacy of the written procedure(s) # Incorrect Military personnel are not responsible for testing contractor security controls. Assessors observe and evaluate but do not perform testing themselves. C). Military personnel assigned to the contractor for that contract to ensure the confidentiality of the CUI # Incorrect Military personnel do not perform the testing. The contractor (OSC) is responsible for implementing and demonstrating security controls. D). OSC personnel who do not ordinarily perform that work to evaluate the accuracy of the written procedure (s) # Incorrect Personnel unfamiliar with the job should not be used for testing. Theassessment must reflect real-world conditions, so theactual employees who perform the work must demonstrate the process. CMMC 2.0 References Supporting This Answer: CMMC Assessment Process (CAP) Document Specifies thatassessments must observe real operational activities to determine compliance. CMMC-AB Assessment Methodology Requirestesting of security controls in a realistic operational environment, meaning actual OSC personnel must perform the tasks. NIST SP 800-171A (Assessment Procedures for NIST SP 800-171) Specifies thatinterviews and observations should be conducted with personnel who regularly perform the work.
CMMC-CCP Exam Question 13
Which assessment method compares actual-specified conditions with expected behavior?
Correct Answer: A
Understanding CMMC Assessment Methods TheCybersecurity Maturity Model Certification (CMMC) 2.0follows theNIST SP 800-171A assessment methodology, which includesthree primary assessment methods: Examine- Reviewing policies, procedures, system configurations, and documentation. Interview- Engaging with personnel to validate their understanding and execution of security practices. Test- Conducting actual technical or operational tests to determine whether security controls function as expected. Why "Test" is the Correct Answer? "Test" is the method that compares actual-specified conditions with expected behavior. It involvesexecuting procedures, configurations, or automated toolsto see if thesystem behaves as required. For example, if a policy states that multi-factor authentication (MFA) must be enforced, a test would involveattempting to log in without MFAto confirm whether access is blocked as expected. TheNIST SP 800-171A Guide (Assessment Procedures for CUI)defines testing as an assessment method that: Actively verifies a security control is functioning Simulates real-world attack scenarios Checks compliance through system actions rather than documentation Why Other Answers Are Incorrect? B). Examine (Incorrect) Examining only involvesreviewing policies, procedures, or configurationsbut does not actively test system behavior. C). Compile (Incorrect) "Compile" is not an assessment method in CMMC 2.0 or NIST SP 800-171A. D). Interview (Incorrect) Interviews are used to gather insights from personnel, but they do not compare actual conditions with expected behavior. Conclusion The correct answer isA. Testbecause itactively verifies system performance against expected security conditions. References: NIST SP 800-171A, "Assessing Security Requirements for CUI" CMMC 2.0 Assessment Process (CAP) Guide DoD CMMC Scoping and Assessment Guidelines
CMMC-CCP Exam Question 14
In the Code of Professional Conduct, what does the practice of Professionalism require?
Correct Answer: C
What Does the Practice of Professionalism Require in the CMMC Code of Professional Conduct? TheCMMC Code of Professional Conduct (CoPC)sets ethical and professional standards forCertified CMMC Assessors (CCAs) and Certified CMMC Professionals (CCPs).Professionalismrequireshonesty and integrity in all CMMC-related activities. Step-by-Step Breakdown: #1. Professionalism Requires Ethical Behavior TheCoPC states that professionalismincludes: Acting with integrityin all assessment-related activities. Providing truthful and objective assessmentsof cybersecurity practices. Avoiding deceptive or misleading claimsabout assessments or compliance. #2. Why the Other Answer Choices Are Incorrect: (A) Do not copy materials without permission to do so# This falls underIntellectual Property (IP) protection, notProfessionalism. (B) Do not make assertions about assessment outcomes# Assessorsmustprovide findings based on evidence. The rule is aboutnot making false or misleading claims, not about avoiding assertions altogether. (D) Ensure the security of all information discovered or received# This falls underConfidentiality, notProfessionalism. Final Validation from CMMC Documentation: TheCMMC Code of Professional Conduct (CoPC)definesProfessionalism as requiring honesty and integrityin allCMMC-related activities. Thus, the correct answer is: #C. Refrain from dishonesty in all dealings regarding CMMC.
CMMC-CCP Exam Question 15
While conducting a CMMC Level 2 Assessment, a CCP is reviewing an OSC's personnel security process. They have a policy that describes screening individuals prior to authorizing access to CUI, but it does not mention what organizations should be looking for in an individual. There is no link to a process or procedural document. What should the OSC evaluate when screening individuals prior to accessing CUI?
Correct Answer: C
Under NIST SP 800-171, Personnel Security (PS) family, requirement PS.L2-3.9.1, organizations must screen individuals prior to granting access to CUI. The screening is intended to evaluate conduct, integrity, and loyalty to ensure that individuals can be trusted with sensitive information. Supporting Extracts from Official Content: NIST SP 800-171 Rev. 2, PS.L2-3.9.1: "Screen individuals prior to authorizing access to organizational systems containing CUI... Screening is intended to assess an individual's conduct, integrity, judgment, loyalty, and reliability." CMMC Level 2 Assessment Guide (Personnel Security practices): confirms that screening covers conduct, integrity, and loyalty. Why Option C is Correct: The key attributes explicitly listed are conduct, integrity, and loyalty. Options A and B describe subjective or informal measures, not compliance criteria. Option D uses terms not aligned with the official requirement. References (Official CMMC v2.0 Content): NIST SP 800-171 Rev. 2, Personnel Security controls. CMMC Assessment Guide, Level 2 - PS.L2-3.9.1.