Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free Cyber AB CMMC-CCA Practice Exam with Questions & Answers

Questions 1

A company mirrors its FCI/CUI data storage in a cloud environment. Data is managed across multiple virtual machines (VMs). To satisfy requirements for data security of the LOCAL copy using physical controls, what should the OSC do?

Options:
A.

Use encrypted transport and storage of FCI/CUI data on the VMs.

B.

Store FCI/CUI data without encryption for faster access/backup/restore.

C.

Ensure that the VMs are running on hardware that is physically located in a controlled-access facility.

D.

In addition to a password or personal identification number, use physical means to log in such as a smart card or hard token.

Cyber AB CMMC-CCA Premium Access
Questions 2

An OSC is preparing for assessment. Which item of evidence would show the OSC’s efforts to restrict physical access within the OSC’s environment?

Options:
A.

VPN configuration

B.

Switch configuration files

C.

Network architecture drawings

D.

Documented OSC procedures

Questions 3

An Assessment Team is holding a discussion with the system administrator at the OSC to understand their process for ensuring unauthorized users are not able to access CUI.

Which assessment method is being utilized?

Options:
A.

Test method

B.

Observe method

C.

Examine method

D.

Interview method

Questions 4

A manufacturing company is seeking Level 2 certification. The loading docks are currently accessible directly from the company’s main parking lot, which may lead to unauthorized access to facilities. Based on this information, how should this method be modified to BEST meet Level 2 requirements?

Options:
A.

Implement physical perimeter controls, such as turnstiles, to limit access.

B.

Require visitors to check in at the reception desk and maintain a visitor log.

C.

Implement physical perimeter controls, such as cameras, to limit access to only authorized personnel.

D.

Implement physical perimeter controls, such as a gate with a badge system, to limit access to only authorized personnel.

Questions 5

During the Planning Phase of the Assessment Plan, the assessor determines that the Client will likely include sensitive and proprietary CUI. What should the assessor consider as part of their virtual data collection techniques for this information?

Options:
A.

The Client is responsible for safeguarding the data during collection, not the assessor.

B.

The assessor is responsible for safeguarding the data during collection, not the client.

C.

The assessor should record the risks and mitigations to protect the CUI categories handled.

D.

The client and assessor should record the risks and mitigations to protect the CUI categories handled.

Questions 6

During an assessment, the Lead Assessor determines certain assets to be in-scope which the OSC had considered out-of-scope.

The CCA should reply that for assets to be considered out-of-scope they:

Options:
A.

Provide security protections to CUI assets.

B.

Do not provide security protections for CUI assets.

C.

Can, but are not intended to, process, store, or transmit CUI.

D.

Are not required to be physically or logically separated from CUI assets.

Questions 7

During an assessment, the Assessment Team has identified, according to the SSP and network diagram, that there is a mission system that cannot be altered but that has privileged accounts which should have MFA applied. As it is not possible to deploy a typical type of MFA on the mission system, which of the following constitutes a sufficient second factor?

Options:
A.

VPN access to the mission system

B.

User access logs on the mission system

C.

Badge access to the mission system room

D.

Remote access logs on the mission system

Questions 8

ESPs are exceptionally common today, given that many organizations are turning to secure cloud offerings to establish and maintain compliance. Integral to these relationships is a responsibility matrix, which defines who is responsible for specific items such as security. This can be a very complex assortment of taskings associated with federal compliance, but what is the MOST important thing to remember?

Options:
A.

The ESP is technically not part of the DIB and has no responsibility to be CMMC compliant in its own right.

B.

The CMMC Assessment Team will factor in any documentation provided by the ESP when evaluating the OSC for compliance.

C.

The relationship of an OSC with an ESP is a partnership and the CMMC Assessment will evaluate the ESP at the same time as the OSC.

D.

Only the OSC is being assessed for compliance, and while the ESP may have a lot of responsibilities in the matrix, the OSC is ultimately responsible for meeting the requirements as specified by government mandates.

Questions 9

While onsite conducting a CMMC Level 2 assessment at a small architecture firm that handles DoD construction contracts, the client offers a list of personnel for interviews. To answer questions regarding visitor access controls, which personnel would be MOST appropriate for interviewing?

Options:
A.

System Administrator

B.

Front-desk Receptionist

C.

Administrative Assistant

D.

Senior Architecture Partner

Questions 10

The OSC’s network consists of a single network switch that connects all devices. This includes the OSC’s OT equipment, which processes CUI. The OT controller requires an unsupported operating system.

What can the Lead Assessor BEST conclude about the overall compliance with MA.L2-3.7.1: Perform Maintenance?

Options:
A.

It is MET only if every asset that is not a Specialized Asset is maintained.

B.

It is MET only if the environments are demarcated on the baseline diagram.

C.

It is NOT MET because industrial equipment should not be processing CUI.

D.

It is NOT MET because the OSC has not managed the risk of a CUI system being outdated.

Exam Code: CMMC-CCA
Certification Provider: Cyber AB
Exam Name: Certified CMMC Assessor (CCA) Exam
Last Update: Sep 14, 2025
Questions: 150

Cyber AB Related Exams

How to pass Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam Exam

Cyber AB Free Exams

Cyber AB Free Exams