Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70track

Free Cyber AB CMMC-CCP Practice Exam with Questions & Answers | Set: 5

Questions 41

A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?

Options:
A.

The process is running correctly.

B.

It is out of scope as this is a new acquisition.

C.

The new acquisition is considered Specialized Assets.

D.

Practice is NOT MET since the objective was not implemented.

Cyber AB CMMC-CCP Premium Access
Questions 42

The practices in CMMC Level 2 consists of the security requirements specified in:

Options:
A.

NISTSP 800-53.

B.

NISTSP 800-171.

C.

48 CFR 52.204-21.

D.

DFARS 252.204-7012.

Questions 43

What activities are conducted while developing an assessment plan?

Options:
A.

The C3PAO decides the Assessment Team members and notifies the Lead Assessor.

B.

The Lead Assessor and the OSC’s sponsor determine the assessment resources and schedule.

C.

The C3PAO’s project manager is responsible for handling potential conflicts of interest.

D.

The evidence collection approach can be finalized when the Lead Assessor conducts an onsite assessment.

Questions 44

Which are guiding principles in the CMMC Code of Professional Conduct?

Options:
A.

Objectivity, information integrity, and higher accountability

B.

Objectivity, information integrity, and proper use of methods

C.

Proper use of methods, higher accountability, and objectivity

D.

Proper use of methods, higher accountability, and information integrity

Questions 45

Which organization is the governmental authority responsible for identifying and marking CUI?

Options:
A.

NARA

B.

NIST

C.

CMMC-AB

D.

Department of Homeland Security

Questions 46

Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?

Options:
A.

DoD OUSD

B.

Authorized holder

C.

Information Disclosure Official

D.

Presidential authorized Original Classification Authority

Questions 47

When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?

Options:
A.

When under the control of the DoD

B.

When the document is considered secret

C.

When a document is being shared outside of the organization

D.

When a derivative document's original information is not CUI

Questions 48

Who is responsible for identifying and verifying Assessment Team Member qualifications?

Options:
A.

C3PAO

B.

CMMC-AB

C.

Lead Assessor

D.

CMMC Marketplace

Questions 49

When an OSC requests an assessment by a C3PAO, who selects the Lead Assessor for the assessment?

Options:
A.

OSC

B.

C3PAO

C.

C3PAO and OSC

D.

OSC and Lead Assessor

Questions 50

Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1, Guidelines for Media Sanitation?

Options:
A.

Clear, purge, destroy

B.

Clear, redact, destroy

C.

Clear, overwrite, purge

D.

Clear, overwrite, destroy

Exam Code: CMMC-CCP
Certification Provider: Cyber AB
Exam Name: Certified CMMC Professional (CCP) Exam
Last Update: Mar 18, 2026
Questions: 221

Cyber AB Related Exams

How to pass Cyber AB CMMC-CCA - Certified CMMC Assessor (CCA) Exam Exam

Cyber AB Free Exams

Cyber AB Free Exams