Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Cyber AB CMMC-CCA Practice Exam with Questions & Answers | Set: 3

Questions 21

An assessor is trying to determine if an OSC performs scans of their information system and real-time scans of files from external sources as files are downloaded or executed.

Which evidence is LEAST LIKELY to help this assessor?

Options:
A.

System configuration settings

B.

System Information and Integrity Policy

C.

Alerts from the anti-virus software

D.

Interviews with personnel with configuration management responsibility

Cyber AB CMMC-CCA Premium Access
Questions 22

A C3PAO has contracted by an OSC to perform its assessment. Before the assessment, the Lead Assessor asks the OSC to provide an extensive list of evidence, some of which is optional and beyond the minimum requirements. The OSC is not able to fulfill the entire request. One missing document was a current and organized list of the OSC’s evidence and mappings.

Given that this is a Level 2 Assessment, what should the Lead Assessor tell the OSC?

Options:
A.

“The OSC’s Assessment Official will be asked to collect evidence when requested by the assessment team.”

B.

“The OSC must provide the Assessment Team with hardcopy evidence. Electronic evidence will only be collected when needed.”

C.

“It’s okay that the document is missing. The Assessment Team will collect all evidence themselves to ensure its integrity.”

D.

“The OSC should provide the Assessment Team with a current and organized list of their evidence and process mappings, but the assessment can continue.”

Questions 23

An OSC processes data in its owned data center. The data center includes a very early smoke detection apparatus (VESDA). The apparatus only captures log information from its sensors around the data center. It is not intended, nor capable of, processing CUI. The VESDA is on a separate VLAN and is in a separate locked room in the data center.

Should the assessor agree that the VESDA is out-of-scope?

Options:
A.

Yes. The VESDA is physically and logically separated from the other data center equipment, and it is not intended nor capable of processing CUI.

B.

No. Even though the sensors are out-of-scope, the VESDA could provide access to the outside network if sensors were misused, and CUI could be exfiltrated.

C.

No. Even though the VESDA controller is in a locked room and on a separate VLAN, the VESDA is an essential security function as an early warning system.

D.

Yes. The VESDA serves a non-data processing purpose and is only connected to sensors. Sensors are out-of-scope, so the VESDA is out-of-scope.

Questions 24

When a new employee is issued a laptop, only the user’s credentials need to be set up. According to the IT department, the IT manager is the only person who can change laptop setup and user privileges. What documentation should be examined to determine if this is the case?

Options:
A.

System audit logs

B.

Inventory records

C.

Acceptable use policy

D.

Remote access procedures

Questions 25

A CCA is asked to validate if an OSC has separated their systems containing CUI from other departments’ systems on their local network. Which of the following MUST the CCA assess?

Options:
A.

Area Network (WAN)

B.

Virtual Private Network (VPN)

C.

Virtual Local Area Network (VLAN)

D.

Network Address Translation (NAT)

Questions 26

While examining the customer responsibility matrix submitted by the OSC for one of its Cloud Service Providers (CSPs), the Assessor notes that the matrix was substantially completed by the OSC’s RPO. In fact, there is a statement from the RPO that the CSP has met the requirements for FedRAMP MODERATE.

In order to accept that this CSP is qualified to perform some of the practices on behalf of the OSC, what should occur?

Options:
A.

The CSP must have its service certified for FedRAMP by a certified C3PAO.

B.

The OSC should provide the contract documents for the CSP specifying that it must meet NIST SP 800-171 practices.

C.

The OSC must be able to demonstrate that the CSP is providing its services in a manner that complies with CMMC Level 2.

D.

There must be other evidence that an independent firm has confirmed the security controls meeting FedRAMP MODERATE are in place.

Questions 27

The Lead Assessor concludes that the OSC is not ready for the assessment. After the Readiness Assessment Review, the OSC and the Lead Assessor could choose to:

Options:
A.

Replan or cancel the assessment.

B.

Replan or reschedule the assessment.

C.

Proceed as planned or cancel the assessment.

D.

Proceed as planned or reschedule the assessment.

Questions 28

A company is seeking Level 2 CMMC certification. During the Limited Practice Deficiency Correction Evaluation, the Lead Assessor is deciding whether the company can be moved to a POA&M Close-Out. What condition will result if a POA&M Close-Out option cannot be utilized?

Options:
A.

The assessment will be paused until the OSC can meet all practices.

B.

The Lead Assessor will ask the OSC to justify not meeting all the practices.

C.

The OSC will be granted a provisional status until it can meet all the practices.

D.

The Lead Assessor will not recommend the OSC for CMMC Level 2 certification.

Questions 29

While conducting an assessment, an assessor is determining if privileged accounts are used for non-privileged functions. While interviewing a user with a privileged account, the assessor should ask if the person interviewed:

Options:
A.

Knows which other users have privileged accounts

B.

Is knowledgeable of role-based access control privileges

C.

Uses their privileged account to research vulnerabilities on the Internet

D.

Can show how IT staff provision privileged and non-privileged accounts

Questions 30

An OSC seeking Level 2 certification is migrating to a fully cloud-based environment. The organization wants to select a Cloud Service Provider (CSP) that can share responsibilities for CMMC Level 2 requirements. Assume both CSPs can equally provide the technical capabilities and business value required.

    CSP A has SOC 2 certification and is California Consumer Privacy Act (CCPA) and Health Insurance Portability and Accountability Act (HIPAA) compliant.

    CSP B has SOC 2 and FedRAMP Moderate certifications.

Based on this information, which CSP is MOST LIKELY to be acceptable?

Options:
A.

CSP A

B.

CSP B

C.

Both CSP A and B

D.

Neither CSP A nor B

Exam Code: CMMC-CCA
Certification Provider: Cyber AB
Exam Name: Certified CMMC Assessor (CCA) Exam
Last Update: Sep 12, 2025
Questions: 150

Cyber AB Related Exams

How to pass Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam Exam

Cyber AB Free Exams

Cyber AB Free Exams