Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Cyber AB CMMC-CCP Practice Exam with Questions & Answers | Set: 2

Questions 11

An OSC has requested a C3PAO to conduct a Level 2 Assessment. The C3PAO has agreed, and the two organizations have collaborated to develop the Assessment Plan. Who agrees to and signs off on the Assessment Plan?

Options:
A.

OSC and Sponsor

B.

OSC and CMMC-AB

C.

Lead Assessor and C3PAO

D.

C3PAO and Assessment Official

Cyber AB CMMC-CCP Premium Access
Questions 12

In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?

Options:
A.

In scope

B.

Out of scope

C.

OSC point of contact

D.

Assessment Team Member

Questions 13

When are contractors required to achieve a CMMC certificate at the Level specified in the solicitation?

Options:
A.

At the time of award

B.

Upon solicitation submission

C.

Thirty days from the award date

D.

Before the due date of submission

Questions 14

After completing a Level 2 Assessment, a C3PAO is preparing to upload the Assessment Results Package to Enterprise Mission Assurance Support Service. Which document MUST be included as part of the final assessment results package?

Options:
A.

Final Report

B.

Certification rating

C.

Summary-level findings

D.

All Daily Checkpoint logs

Questions 15

The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?

Options:
A.

Expert

B.

Advanced

C.

Optimizing

D.

Continuously Improved

Questions 16

Which term describes " the protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to. or modification of information " ?

Options:
A.

Adopted security

B.

Adaptive security

C.

Adequate security

D.

Advanced security

Questions 17

Which document specifies the CMMC Level 1 practices that correspond to basic safeguarding requirements?

Options:
A.

NIST SP 800-171

B.

NIST SP 800-171b

C.

48 CFR 52.204-21

D.

DFARS 252.204-7012

Questions 18

Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit. Supporting Organization/Unit, or enclave has been met?

Options:
A.

OSC

B.

Assessment Team

C.

Authorizing official

D.

Assessment official

Questions 19

When assessing SI.L1-3.14.2: Provide protection from malicious code at appropriate locations within organizational information systems, evidence shows that all of the OSC ' s workstations and servers have antivirus software installed for malicious code protection. A centralized console for the antivirus software management is in place and records show that all devices have received the most updated antivirus patterns. What is the BEST determination that the Lead Assessor should reach regarding the evidence?

Options:
A.

It is sufficient, and the audit finding can be rated as MET.

B.

It is insufficient, and the audit finding can be rated NOT MET.

C.

It is sufficient, and the Lead Assessor should seek more evidence.

D.

It is insufficient, and the Lead Assessor should seek more evidence.

Questions 20

A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?

Options:
A.

24 hours

B.

48 hours

C.

72 hours

D.

96 hours

Exam Code: CMMC-CCP
Certification Provider: Cyber AB
Exam Name: Certified CMMC Professional (CCP) Exam
Last Update: Jul 31, 2026
Questions: 236

Cyber AB Related Exams

How to pass Cyber AB CMMC-CCA - Certified CMMC Assessor (CCA) Exam Exam

Cyber AB Free Exams

Cyber AB Free Exams