Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Cyber AB CMMC-CCA Practice Exam with Questions & Answers | Set: 5

Questions 41

An assessor reviews the OSC’s data protection policy, which requires full disk encryption on company laptops. While interviewing employees, the assessor learns that employees sometimes access data while teleworking on laptops that do not have full disk encryption.

How should the assessor view the implementation of the OSC’s policy?

Options:
A.

Acceptable because it requires full disk encryption of company laptops.

B.

Insufficient because there are teleworking instances where the policy is not followed.

C.

Acceptable as long as an equivalent technical safeguard is implemented for all teleworking scenarios.

D.

Insufficient because full disk encryption is not required for laptops to comply with CMMC requirements.

Cyber AB CMMC-CCA Premium Access
Questions 42

An OSC is presenting evidence of its fulfillment of CM.L2-3.4.1: System Baselining. It provides:

    System inventory records showing additions/removals of machines,

    Software inventory showing installations/removals, and

    A system component installation plan with software needs and user specifications.

What other documentation MUST the company present to illustrate compliance with CM.L2-3.4.1?

Options:
A.

Documentation of the physical safeguards protecting the “gold” baseline images

B.

Documentation of a formal baseline review integrated with a system development lifecycle

C.

Documentation of any authorized deviations from the system baselines for end-user computers

D.

Documentation of a formal chain of custody for new hardware on which baselines will be installed

Questions 43

The OSC has assembled its documentation relating to how it controls remote access for assessment. The Lead Assessor compared this documentation to the provided topology map and noted several indications of external connections with External Service Providers (ESPs). Which document is MOST LIKELY to show acceptable evidence of the security controls related to the interface between the OSC and the ESP?

Options:
A.

OSC’s access control policy

B.

Interconnection agreement with ESPs

C.

Technical design of the security of the available VPN

D.

Instructions provided to the OSC from the ESP to implement remote access

Questions 44

An OSC has a headquarters (HQ) site and satellite offices A and B. The two satellite offices are connected to the HQ through a VPN. CUI is stored within the HQ LAN room and used by staff at HQ and Site A. When categorizing assets for this assessment, assets at the HQ:

Options:
A.

and Site A contain CUI assets and Site B is out of scope.

B.

and Site A and Site B contain CUI assets since all have access to CUI.

C.

contain CUI assets and Site A and Site B contain only Certification in Risk Management Assurance.

D.

and Site A contain CUI assets and Site B contains only Certification in Risk Assurance.

Questions 45

When a CCA is assessing a control through Examine, what MUST they meet?

Options:
A.

Documents utilized for review must be in their mailed form

B.

Documents must be policy, process, and procedure documents

C.

Training materials reviewed can be in-process as they are for educational purposes

D.

System-level, network, and data flow diagrams must be completed in draft format

Exam Code: CMMC-CCA
Certification Provider: Cyber AB
Exam Name: Certified CMMC Assessor (CCA) Exam
Last Update: Sep 12, 2025
Questions: 150

Cyber AB Related Exams

How to pass Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam Exam

Cyber AB Free Exams

Cyber AB Free Exams