While conducting a CMMC Level 2 Assessment, the Lead Assessor determines that the OSC has badge readers, pin code pads, and keys for various access points as well as documentation to demonstrate meeting the practice. Which CMMC practice has the OSC MET?
Correct Answer: A
The presence of badge readers, PIN code pads, and keys directly corresponds to controlling and managing physical access devices, which maps to PE.L1-3.10.5 under the Physical Protection (PE) domain. This practice ensures that only authorized individuals have access to physical areas containing information systems. The other options address unrelated requirements: MP.L2-3.8.5 addresses marking CUI media, SI.L2-3.14.3 addresses monitoring security alerts, PS.L2-3.9.2 addresses protections during personnel changes. Reference Documents: CMMC Model v2.0, Level 1-3 Practices NIST SP 800-171 Rev. 2, Control PE-3
CMMC-CCP Exam Question 37
While conducting a CMMC Assessment, a Lead Assessor is given documentation attesting to Level 1 identification and authentication practices by the OSC. The Lead Assessor asks the CCP to review the documentation to determine if identification and authentication controls are met. Which documentation BEST satisfies the requirements of IA.L1-3.5.1: Identify system users. processes acting on behalf of users, and devices?
Correct Answer: C
Understanding IA.L1-3.5.1 (Identification and Authentication Requirements) TheCMMC 2.0 Level 1practiceIA.L1-3.5.1aligns withNIST SP 800-171, Requirement 3.5.1, which mandates that organizationsidentify system users, processes acting on behalf of users, and devicesto ensure proper access control. To comply with this requirement, anOrganization Seeking Certification (OSC)must maintain documentation that demonstrates: A unique identifier (username) for each system user Mapping of system accounts to specific individuals Identification of devices and automated processes that access systems Why "C. User names associated with system accounts assigned to those individuals" is Correct? This documentation directly satisfies IA.L1-3.5.1because it showshow system users are uniquely identified and linked to specific accountswithin the environment. Alist of users and their assigned accountsconfirms that the organization has a structured method oftracking access and authentication. It allows auditors to verify thateach user has a distinct identityand that access control mechanisms are properly applied. Why Other Answers Are Incorrect? A). Procedures for implementing access control lists (Incorrect) While access control lists (ACLs) are relevant for authorization, they do notidentify users or devicesspecifically, making them insufficient as primary evidence for IA.L1-3.5.1. B). List of unauthorized users that identifies their identities and roles (Incorrect) Identifying unauthorized users does not fulfill the requirement of trackingauthorizedusers, devices, and processes. D). Physical access policy stating "All non-employees must wear a special visitor pass or be escorted" (Incorrect) This pertains tophysical security, not system-baseduser identification and authentication. Conclusion The correct answer isC. User names associated with system accounts assigned to those individuals, as thisdirectly satisfies the identification requirement of IA.L1-3.5.1. References: CMMC 2.0 Level 1 Practice IA.L1-3.5.1 NIST SP 800-171, Requirement 3.5.1
CMMC-CCP Exam Question 38
Which document is used to protect sensitive and confidential information from being made available by the recipient of that information?
Correct Answer: D
The correct document is a Non-Disclosure Agreement (NDA) , because its specific purpose is to restrict a receiving party from disclosing sensitive or confidential information to unauthorized parties. In the official CMMC Assessment Process (CAP) v2.0 , NDAs are called out directly as a required element of the contracting relationship for a Level 2 certification assessment. CAP v2.0 states that the C3PAO and the OSC must execute a written contractual agreement for the assessment and then specifies that "A mutual non-disclosure agreement (NDA) between the parties shall be incorporated into the contractual agreement or negotiated and executed in a separate document (e. g., stand-alone NDA, master services agreement, etc.)." This is important because CMMC assessments can involve access to highly sensitive organizational information, including details about system architectures, security implementations, and potentially CUI handling processes. The CAP's NDA requirement supports controlling dissemination of that information and reinforces the broader confidentiality expectations placed on assessment participants. While an "assessment agreement" or generic "legal agreement" might contain confidentiality clauses, CAP v2. 0 explicitly identifies the NDA instrument (either embedded or standalone) as the mechanism to protect information exchanged during the assessment engagement. Therefore, the best answer-consistent with CMMC v2.0 official process documentation-is D (Non-disclosure agreement) .
CMMC-CCP Exam Question 39
Which entity requires that organizations handling FCI or CUI be assessed to determine a required Level of cybersecurity maturity?
Correct Answer: A
Step 1: Understanding the Role of the DoD in CMMC TheU.S. Department of Defense (DoD)is the entity thatrequiresorganizations handlingFederal Contract Information (FCI)orControlled Unclassified Information (CUI)to undergo an assessment to determine their required level ofcybersecurity maturityunderCMMC 2.0. This requirement stems from theDFARS 252.204-7021 clause, which mandates CMMC certification for contractors handling FCI or CUI. Reference: DoD CMMC 2.0 Program Overview DFARS 252.204-7021 (CMMC Requirements) Step 2: DoD ' s Cybersecurity Maturity Levels TheDoD determinestherequired cybersecurity maturity levelfor a contract based on the sensitivity of the information involved: CMMC Level 1- Required for organizations handlingFCI(Basic Cyber Hygiene). CMMC Level 2- Required for organizations handlingCUI(Aligned with NIST SP 800-171). CMMC Level 3- Required for organizations handlinghigh-value CUIand facingAdvanced Persistent Threats (APT)(Aligned with a subset ofNIST SP 800-172). Reference: CMMC 2.0 Model Documentation NIST SP 800-171 & 800-172for security controls Step 3: Why Other Answer Choices Are Incorrect B). CISA (Incorrect): TheCybersecurity and Infrastructure Security Agency (CISA)is responsible fornational cybersecuritybut does not mandate CMMC assessments. C). NIST (Incorrect): TheNational Institute of Standards and Technology (NIST)provides the security framework (e.g.,NIST SP 800-171) but does not enforce CMMC compliance. D). CMMC-AB (Incorrect): TheCyber AB (formerly CMMC-AB)is responsible for accreditingC3PAOsand overseeing theCMMC ecosystem, but it does not determine which organizations require assessments. Final Confirmation of Correct answer: The DoD mandates CMMC compliance for organizations handling FCI or CUI. CMMC requirements are enforced through DFARS clauses in DoD contracts. Thus, the correct answer is:A. DoD
CMMC-CCP Exam Question 40
A member of the Assessment Team has been assigned the responsibility of maintaining and protecting information from the OSC. The Assessment Results Package, PCI, CUI, and any notes must be retained and protected from disclosure. To protect the OSC ' s information, which principle should be used, and for how long?
Correct Answer: B
The core protection principle for OSC-provided assessment information (including PCI/CUI, assessment workpapers/notes, and the assessment results package ) is confidentiality / non-disclosure . The CMMC rules require assessors not to disclose OSC information outside the assessment participants, except as required by law. For example, CMMC assessor requirements include not sharing information about an OSC obtained during pre-assessment and assessment activities with anyone not involved in that specific assessment . For retention, the authoritative requirement in the CMMC Program rule (32 CFR Part 170) is that assessment-related records are maintained for six (6) years , unless disposition is otherwise authorized by the CMMC PMO. This record set includes assessment materials and working papers generated during Level 2 certification assessments, and it also includes contractual agreements. Important correction to the multiple-choice options: none of the answers list the official six-year retention period. The best available option is therefore B because it correctly captures the required confidentiality /non-disclosure principle-but the " 3 years " duration in the option does not match the official CMMC v2.0 retention requirement (which is 6 years ).