Cyber AB CMMC-CCA - Questions & Answers
Free preview · every answer includes a full explanation
Product page: https://prepkeys.com/cmmc-cca.html
In assessing an OSC's CUI handling practices, you learn that they use an approved algorithm (AES-256) to encrypt the data to ensure its confidentiality. However, the cryptographic module they are using has not been validated under the FIPS 140 standard. The OSC believes that using an approved algorithm is sufficient to comply with the CMMC practice for CUI encryption requirements.
Where can you find information about a cryptographic module's current status with FIPS?
During your assessment of CA.L2-3.12.3 - Security Control Monitoring, the contractor's CISO informs you that they have established a continuous monitoring program to assess the effectiveness of their implemented security controls. When examining their security planning policy, you determine that they have a list of automated tools they use to track and report weekly changes in the security controls. The contractor has also established a feedback mechanism that helps them identify areas for improvement in their security controls. During discussions with employees, you understand that the contractor regularly invites resource persons to train them on the secure handling of information and identifying gaps in implemented security controls.
Can the contractor place practice CA.L2-3.12.3 - Security Control Monitoring under a POA&M if it is unimplemented or not fully met?
A defense contractor retains your services to assess their information systems for CMMC compliance, particularly configuration management. The contractor uses CFEngine 3 for automated configuration and maintenance of its computer systems and networks. During discussions with the network's system administrators, you determine that they have deployed a modern compliance checking and monitoring tool.
However, when examining their configuration management policy, you notice that the contractor uses security configurations that are different from those recommended by product vendors. The system administrator informs you that they do this to meet the minimum configuration baselines required to achieve compliance and align with organizational policy.
Based on your understanding of the CMMC Assessment Process, how would you score CM.L2-3.4.2 - Security Configuration Enforcement if the contractor is tracking it in a POA&M?
An engineering company works on DoD contracts that involve handling CUI. They use hard-copy media, such as printed paper and microfilms, and digital media, including flash drives, SSDs, DVDs, and internal and external hard drives. During a CMMC assessment, you discover that the engineering company has defined procedures addressing media storage and access governed by an access control policy. All media containing CUI are marked and stored in biometrically locked cabinets. To store CUI on digital media, an authorized user must be identified using their biometrics or authenticated using an integrated MFA solution. To access non-digital media, the user must be on a defined list of authorized personnel and sign three forms. You also learn that the contractor maintains a comprehensive inventory of all CUI media.
Based on the scenario, how would you score the contractor's implementation of CMMC practice MP.L2- 3.8.1 - Media Protection?
During your assessment of CA.L2-3.12.3 - Security Control Monitoring, the contractor's CISO informs you that they have established a continuous monitoring program to assess the effectiveness of their implemented security controls. When examining their security planning policy, you determine that they have a list of automated tools they use to track and report weekly changes in the security controls. The contractor has also established a feedback mechanism that helps them identify areas for improvement in their security controls. During discussions with employees, you understand that the contractor regularly invites resource persons to train them on the secure handling of information and identifying gaps in implemented security controls.
You would rely on all of the following evidence to assess the contractor's implementation of CA.L2-3.12.3 - Security Control Monitoring, EXCEPT?
You have been sent to assess an OSC's implementation of CMMC practices, one of which is AC.L2-3.1.11
- Session Termination.
You expect to find the following items when examining the contractor's list of conditions or trigger events requiring session termination, EXCEPT?
Any user who accesses CUI on system media should be authorized and have a lawful business purpose.
While assessing a contractor's implementation of MP.L2-3.8.2 - Media Access, you examine the CUI access logs and the roles of employees. Something catches your eye: an ID of an employee listed as terminated regularly accesses CUI remotely. Walking into the contractor's facilities, you observe the janitor cleaning an office where documents marked CUI are visible on the table. Interviewing the organization's data custodian, they inform you that a media storage procedure is augmented by a physical protection and access control policy.
Based on the scenario and the requirements of CMMC practice MP.L2-3.8.2 - Media Access, which of the following actions would be the highest-priority recommendation for the contractor?
In ensuring it meets its mandates to protect CUI under CMMC, a contractor has implemented a robust, dynamic session lock with pattern-hiding displays to prevent access and viewing of data. After every 5 minutes of inactivity, the current session is locked and a blank, black screen with a battery life indicator is displayed.
How is Session Lock typically initiated?
You are performing an on-site assessment for a defense contractor that develops and manufactures embedded control systems for military drones. During your documentation review, you discover they have a System Security Plan (SSP) outlining a configuration management process. The SSP mentions the
creation of baseline configurations for their drone control systems, but details are limited. You interview the IT manager responsible for configuration management. They explain they use a commercial configuration management tool to capture hardware and software configurations for the drone systems. They confirm that the baseline configurations include initial software versions but do not track firmware or network configurations. Additionally, while they update software versions through the tool, they do not have a documented process for reviewing and updating baseline configurations in response to security vulnerabilities or system modifications.
Which of the following actions would be the MOST appropriate recommendation for the contractor to improve their compliance with CM.L2-3.4.1 - System Baselining?
You are on-site with an Assessment Team at a medium-sized organization. When discussing how they protect their company's information from malware, spyware, etc., the administrator you are interviewing offers to show you the entire process from start to finish since she had that on her to-do list for the day.
She opens the machine, turns it on, and installs what she says is anti-malware software. She also demonstrates how their deployed Next Generation Firewall (NGFW) works. You have never heard of this software, so you ask her where it was purchased. You later learn it is an open-source solution.
Based on the scenario and the requirements of CMMC practice SI.L2-3.14.6 - Monitor Communications for Attacks, what is your likely determination?