A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?
The practices in CMMC Level 2 consists of the security requirements specified in:
What activities are conducted while developing an assessment plan?
Which are guiding principles in the CMMC Code of Professional Conduct?
Which organization is the governmental authority responsible for identifying and marking CUI?
Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?
When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?
Who is responsible for identifying and verifying Assessment Team Member qualifications?
When an OSC requests an assessment by a C3PAO, who selects the Lead Assessor for the assessment?
Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1, Guidelines for Media Sanitation?
|
PDF + Testing Engine
|
|---|
|
$49.5 |
|
Testing Engine
|
|---|
|
$37.5 |
|
PDF (Q&A)
|
|---|
|
$31.5 |
Cyber AB Free Exams |
|---|
|