Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Cyber AB CMMC-CCA Practice Exam with Questions & Answers | Set: 4

Questions 31

A company is seeking Level 2 CMMC certification. During the Limited Practice Deficiency Correction Evaluation, the Lead Assessor must decide whether the company can move to a POA&M review. Which condition will result in the Lead Assessor recommending that the OSC’s practice deficiencies move to a POA&M review?

Options:
A.

A final score below 88

B.

A final score of 110

C.

A final score of 80 or better

D.

A final score of 88/110 or better

Cyber AB CMMC-CCA Premium Access
Questions 32

An assessor is examining an organization’s system maintenance program. While reviewing the system maintenance policy and the OSC’s maintenance records for the CUI network, the assessor notices there is no mention of printers. The assessor asks the IT manager if the company has any printers.

Why is the assessor concerned if the OSC has printers?

Options:
A.

Printers must be completely isolated from all non-CUI assets.

B.

Firmware on a network printer needs to have updates as needed.

C.

Printers cannot be used on a CUI network without government approval.

D.

Printers can produce hard copies of CUI data that need to be safeguarded.

Questions 33

An organization’s password policy includes these requirements:

    Passwords must be at least 8 characters in length.

    Passwords must contain at least one uppercase character, one lowercase character, and one numeric digit.

    Passwords must be changed at least every 90 days.

    When a password is changed, none of the previous 3 passwords can be reused.

Per IA.L2-3.5.7: Password Complexity, what requirement is missing from this password policy?

Options:
A.

It does not require MFA.

B.

It does not include a list of prohibited passwords.

C.

It does not specify a minimum change of character requirement.

D.

It does not require the password to contain at least one special character.

Questions 34

While conducting a Level 2 Assessment, the Assessment Team begins reviewing assessment objects. The team identifies concerns with several of the objects presented. Which artifacts would require the MOST verification?

Options:
A.

Current artifacts produced by individuals performing the work

B.

Artifacts created 18 months ago by individuals performing the work

C.

Current artifacts produced by individuals that work for a separate entity of the company

D.

Artifacts created 18 months ago by individuals that work for a separate entity of the company

Questions 35

An OSC seeking Level 2 certification is reviewing the physical security of their building. Currently, the building manager unlocks and locks the doors for business operations. The OSC would like the ability to automatically unlock the door for authorized personnel, track access individually, and maintain access history for all personnel. The BEST approach is for the OSC to:

Options:
A.

Maintain a list of authorized personnel and assign them a building key.

B.

Maintain security cameras to continuously monitor access to the building.

C.

Install a badge system and require each individual to use their badge to gain entry to the building.

D.

Install a keypad system and require the entry code to be changed when an individual leaves the company.

Questions 36

The team is assessing an OSC that uses the cloud for hosting its online services. Which of the following is NOT important for the assessor to consider?

Options:
A.

Devices connecting to the system are authorized.

B.

Processes acting on behalf of a user are authenticated.

C.

Users are authorized as a prerequisite to system access.

D.

FIPS encryption is authenticated as a prerequisite to system access.

Questions 37

An OSC assigns new hires to work on their hire date. Human Resources ensures that all screening activities are completed before the end of the employees’ first week. How should the CCA score PS.L2-3.9.1: Screen Individuals?

Options:
A.

As NOT MET but it can be remediated post-assessment

B.

As NOT MET and this will cause the assessment to fail

C.

As MET since the OSC ensured Human Resources was handling the screening

D.

As NOT MET because all screening must be completed prior to the start of employment

Questions 38

A company describes its organization as having two systems. One system, System Org, covers the entire organization and allows instant messaging, email, and Internet activity. The other system, System CUI, is used for processing, storing, and transmitting CUI data. System CUI interfaces with System Org through security mechanisms and a firewall.

The CMMC Assessment is being done on System CUI only.

What is the BEST way to describe System CUI?

Options:
A.

CUI Assets

B.

In-Scope Assets

C.

Out-of-Scope Assets

D.

CUI Assets and Security Protection Assets

Questions 39

An OSC outsources all of its security incident and event monitoring work to a third-party SOC. Additionally, the OSC utilizes a cloud-hosted antivirus (AV) system to fulfill the requirement of having virus protection without hosting additional servers on-site.

During the scoping discussion, both the SOC and AV should be listed as what type of asset?

Options:
A.

They are CUI Assets due to their operation within a CUI network.

B.

They are Out-of-Scope Assets due to being fully hosted/operated by third parties.

C.

They are Security Protection Assets due to their performance of security functions.

D.

They are Contractor Risk Managed Assets because they are not physically or logically isolated from CUI assets.

Questions 40

An OSC seeking Level 2 certification is working with an ESP. The organization is trying to determine if the ESP is considered within the assessment and is reviewing the Service Level Agreement (SLA) between the organization and the ESP. Which SLA component should be taken into consideration to determine if the ESP is within the assessment scope?

Options:
A.

Services

B.

Intervals

C.

Penalties

D.

Measurements

Exam Code: CMMC-CCA
Certification Provider: Cyber AB
Exam Name: Certified CMMC Assessor (CCA) Exam
Last Update: Sep 12, 2025
Questions: 150

Cyber AB Related Exams

How to pass Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam Exam

Cyber AB Free Exams

Cyber AB Free Exams