Browse all practice questions for the Certified CMMC Assessor (CCA) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certified CMMC Assessor (CCA) Practice Exam course image
More practice questions

These questions are part of the practice quiz. Start practicing

  • What is an observation in the context of a CMMC assessment?
  • What is the function of Information Assurance (IA) in the context of a DMZ?
  • Which of the following best describes the nature of a Process in CMMC?
  • What aspect of maintenance does CMMC Level 2 emphasize in its practices?
  • Contractor Risk Managed Assets (CRMA) must be documented in all of the following EXCEPT:
  • What type of protection must be implemented for organizational systems as per SI.L2-3.14.2?
  • What is the primary purpose of a Security Control Assessment?
  • What is the purpose of a Non-Disclosure Agreement (NDA) in the CMMC assessment?
  • What is the purpose of VPN gateways in a network?
  • What is the purpose of the CMMC Hashing Tool Execution Policy?
  • What are participants in Level 2 certification assessments called?
  • What is the purpose of the final written assessment results submitted by the assessment team?
  • What defines an organization's environment according to the Network Diagram?
  • What is the primary purpose of limiting the use of portable storage devices on external systems according to CMMC practice?
  • What aspect does the Shared Responsibility Matrix aim to clarify?
  • What is necessary when confirming compliance for mobile encryption according to AC.L2-3.1.19?
  • What are Security Boundary Constraints?
  • According to CMMC practice AC.L2-3.1.5, what is required for privileged accounts?
  • Subnetworks in a network architecture are primarily used for what purpose?
  • What describes a Privileged Command as per CMMC?
  • What is the goal of the Non-Duplication assessment planning step?
  • What does a mobile device need regarding data storage?
  • What defines a Security Domain?
  • What does an organizational chart represent in a company?
  • What does the use of session locks ensure regarding visible information?
  • What is a key benefit of non-duplication in CMMC assessments?
  • What must assessors confirm about wireless access according to CMMC practice AC.L2-3.1.17?
  • What does a Computer Security Incident Response Team (CSIRT) do?
  • Which of the following best defines an incident in the CMMC context?
  • What must be included in audit records to support user activity traceability?
  • What should interviews conducted during an assessment demonstrate?
  • Who is responsible for affirming compliance with CMMC Program requirements within an Organization Seeking Assessment?
  • In the context of CMMC, what primarily defines 'logical access'?
  • What defines the assets assessed during a CMMC evaluation?
  • What is classified as test equipment in a CMMC context?
  • Which term refers to the scope of the system and environment being assessed?
  • What does SI.L2-3.14.1 require organizations to do regarding system flaws?
  • What is the required length of the Artifact Retention Period for CMMC assessment artifacts?
  • Which method of authentication is described as insecure within AC.L2-3.1.17?
  • What is a Virtual Local Area Network (VLAN) primarily used for?
  • What is a primary requirement under SI.L2-3.14.3 for organizations regarding security alerts?
  • Which artifact is produced by the hashing tool in the CMMC process?
  • What must tests or demonstrations pass to be considered acceptable evidence?
  • Security Protection Assets (SPAs) primarily provide what function?
  • Operational Technology (OT) primarily interacts with which environment?
  • What key issue must be addressed during the In-Brief Meeting for assessment preparation?
  • Which of the following best describes a CMMC Third-Party Assessment Organization (C3PAO)?
  • What does the principle of least privilege ensure for security functions and accounts?
  • What activities are involved in Phase 3 of the CMMC Assessment Process?
  • Which of the following describes an Enduring Exception?
  • What does the CMMC requirement for system baselining aim to ensure?
  • What must assessors verify regarding security roles according to AT.L2-3.2.2?
  • What does CMMC requirement AC.L2-3.1.13 mandate for OSCs regarding remote access sessions?
  • Which component does a Network Diagram typically include?
  • Which of the following systems is not typically categorized as Operational Technology?
  • What is the purpose of the Separation of Duties principle in CMMC?
  • What characterizes Physical Separation in asset management?
  • What is one of the main objectives of security policies within an organization?
  • What distinguishes Organizations Seeking Certification (OSC) from Organizations Seeking Assessment (OSA)?
  • What type of output does the SHA-256 algorithm produce from input data?
  • Which factor is NOT considered when testing incident response capabilities?
  • What does the term "one-way function" refer to in the context of SHA-256?
  • Which type of account typically has the most limited access?
  • What is the main benefit of encrypted remote access?
  • What is a key aspect of the CMMC Level 2 practice for System Auditing per AU.L2-3.3.1?
  • What is a key component of maintenance activities according to the CMMC requirements?
  • Which of the following best describes 'Incident Handling'?
  • What is the primary role of a Firewall in networking?
  • What is a critical measure to address when devices must be removed from the site for repair?
  • What is the role of the Cyber AB in the CMMC assessment process?
  • Which of the following best describes Acquisitions in the context of federal government?
  • What types of devices qualify as mobile devices?
  • Which category does NOT fall under the asset categorization required for CMMC assessment?
  • In the context of industrial environments, what does the Purdue Model help establish?
  • According to AC.L2-3.1.18, what is required for mobile device connections in OSCs?
  • In terms of asset protection, what does the CMMC Level 2 practice necessitate?
  • What is the purpose of an Asset Inventory?
  • What requirement does AT.L2-3.2.1 emphasize for users of organizational systems?
  • Which of the following best describes "Information Flow Control" in the context of OSC?
  • What is prohibited in terms of information system use according to legal notifications?
  • What must organizations do associated with wireless access as indicated by AC.L2-3.1.16?
  • What action should organizations take regarding remote access information?
  • What must a legal notification inform users regarding information system usage?
  • Which assessment activity is overseen by the Quality Assurance Individual?
  • During an assessment, what is the purpose of inviting questions from the OSC in the In-Brief Meeting?
  • In CMMC 2.0, why are physical access controls essential at physical locations?
  • What is included in the effective incident handling process defined by IR.L2-3.6.1?
  • According to IR.L2-3.6.2, how should organizations manage security incidents?
  • What element is necessary to include in audit logs to meet CMMC system auditing requirements?
  • In CMMC, what is essential for an activity to be classified as a Practice?
  • What does "eMASS" refer to in the CMMC context?
  • What comprises a baseline configuration according to CMMC standards?
  • What characteristic describes emergency accounts?
  • Under AC.L2-3.1.15, what is required to execute privileged commands?
  • What type of assets are classified as Specialized Assets?
  • What function does the Artifact Hashing Tool serve in the CMMC assessment process?
  • Which of the following best describes a physical location in system architecture?
  • What does the DoD Assessment Methodology (DoDAM) standardize?
  • What does a Hybrid Assessment involve regarding evidence collection?
  • What is the primary focus of CMMC Level 2 practices regarding organizational systems?
  • What is the primary purpose of physical or logical separation of assets that process CUI?
  • What is the purpose of a Self-Assessment in the context of CMMC?
  • Which of the following is NOT a requirement for assets classified under CRMA?
  • What type of data would typically fall under the category of Security Protection Data (SPD)?
  • Which of the following actions is essential according to the control SI.L1-3.14.4 for organizations to combat malware?
  • Why is it essential to maintain baseline configurations?
  • What describes the ideal implementation of privileged functions according to CMMC?
  • According to the assessment objectives of CMMC practice AC.L2-3.1.3, what must be defined?
  • Logical separation in a system is achieved through what means?
  • What does effective identification of wireless access points help to prevent?
  • What aspect should assessors verify regarding the generated audit records according to AU.L2-3.3.1?
  • What is included in a Service Level Agreement (SLA)?
  • What is characterized by the traditional IT infrastructure within a professional environment?
  • What must organizations ensure when scheduling maintenance activities?
  • Which of the following components would NOT be considered part of a baseline configuration?
  • What is described as a security design principle allowing only the necessary system access?
  • How should organizations approach flaw remediation as per SI.L2-3.14.1?
  • What is required for documentation of Specialized Assets?
  • What is the purpose of a Shared Responsibility Matrix (SRM)?
  • Which component in CMMC assessments ensures compliance with cybersecurity practices?
  • What is the significance of monitoring maintenance and repairs?
  • What defines a contractor in the context of a contract with the DoD?
  • What does the term External Service Provider (ESP) refer to?
  • What type of technologies do boundary control devices include?
  • Under MA.L2-3.7.2, what is the focus of CMMC practice regarding system maintenance?
  • What is the significance of having a Certificate of CMMC Status?
  • What characterizes out-of-scope assets in CMMC assessments?
  • According to AU.L2-3.3.2, what must be uniquely traced for accountability?
  • Security Protection Assets (SPA) are primarily used for what purpose?
  • What do Restricted Information Systems support?
  • What type of approach is recommended for maintenance activities to avoid risks?
  • What is the main purpose of a CUI Enclave?
  • What must assessors verify regarding the use of portable storage devices containing CUI?
  • Which of the following describes Security Protection Data (SPD)?
  • What is the function of a RADIUS server in accessing wireless networks?
  • What are artifacts in the context of CMMC assessments?
  • What must an organization define regarding session termination conditions?
  • Which of the following represents a network device that requires isolation from internal systems when providing remote access?
  • What allows VLANs to manage data flow and enhance security?
  • Which situation would indicate a too-broad scope for a CMMC assessment?
  • What role do firewalls and proxies play in Information Flow Enforcement Mechanisms?
  • What is a key requirement of the role-based security training outlined in AT.L2-3.2.2?
  • What does CUI stand for?
  • What is a key focus during Phase 4 of the CMMC Assessment Process?
  • Which of the following account types does NOT categorize access privileges?
  • Which aspect of the SHA-256 algorithm makes it suitable for integrity verification?
  • What is the purpose of a Document Traceability Matrix?
  • What is the purpose of the FedRAMP Moderate Equivalency documentation?
  • Which of the following is NOT a characteristic of an External Service Provider?
  • What is the purpose of a session lock?
  • Under SI.L2-3.14.2, where must organizations provide malicious code protection?
  • Under CMMC practice AC.L2-3.1.5, what must organizations implement?
  • What is indicated by the CMMC Status when assessing an information system?
  • Which document outlines the CMMC Security Requirements Level 2?
  • Who conducts the Certification Assessment in a CMMC context?
  • What should assessors determine for remote access routing according to AC.L2-3.1.14?
  • What does the central hub for incident documentation and reporting enhance according to IR.L2-3.6.2?
  • How are logical locations defined within an information system?
  • What does the term "Organization Seeking Assessment (OSA)" refer to?
  • Which of the following best describes the Internet of Things (IoT)?
  • What does SI.L2-3.14.5 emphasize about scanning systems and files?
  • Which of the following is a responsibility of the organization’s security apparatus as outlined in CMMC?
  • What must the OSC enforce according to CMMC practice AC.L2-3.1.3 regarding separation of duties?
  • What type of evidence is necessary to demonstrate compliance with FedRAMP Moderate standards?
  • What is the primary objective of security awareness training?
  • Which method is NOT typically part of the sanitization process?
  • What components should maintenance documentation include according to CMMC Level 2 practices?
  • What does the System Security Plan outline regarding security controls?
  • What does the CMMC Assessment Scope refer to?
  • What is the primary function of boundary control devices in network security?
  • What characterizes a virtual assessment in the CMMC process?
  • What is a Practice in the context of CMMC objectives?
  • What must system-use notification banners display according to CMMC practice AC.L2-3.1.9?
  • What does Evidence Acceptability refer to in CMMC assessments?
  • What function does access control policies serve?
  • What documentation is essential for effective maintenance according to CMMC?
  • What is essential for both parties in a Non-Disclosure Agreement (NDA)?
  • What is a fundamental requirement for a CMMC Level 2 certification assessment to proceed?
  • Which practice limits system access to authorized users and devices?
  • What happens after all evaluations and evidence examinations are completed in a CMMC assessment?
  • Which method does Physical Separation employ for data transfer?
  • What is a fundamental practice for maintaining organizational systems?
  • What is the purpose of evidence validation in CMMC assessments?
  • What is a key requirement of remote access under CMMC practice AC.L2-3.1.12?
  • What role does the Quality Assurance Individual play during the CMMC assessment?
  • What is the purpose of regular updates to malicious code protections described in SI.L1-3.14.4?
  • How do organizations reinforce risk-aware behavior as stated in AT.L2-3.2.1?
  • What does equipment sanitization aim to achieve?
  • What does a governing policy artifact for CMMC include?
  • Who reviews the appeals submitted within the CMMC assessment appeals process?
  • What does a Plan in CMMC encompass?
  • What document confirms the compliance status and results of a CMMC assessment?
  • What must be done by the OSA regarding Security Protection Assets (SPAs)?
  • What does the Commercial and Government Entity (CAGE) Code signify in the CMMC assessment process?
  • Why is timely repair and maintenance of systems essential for organizations?
  • What characterizes a Temporary Deficiency in CMMC compliance?
  • What does a Data Flow Diagram illustrate?
  • What is the purpose of the report prepared following a CMMC assessment?
  • What kind of information must the OSC define for audit record content according to AU.L2-3.3.2?
  • What must assessors determine regarding users and nonsecurity functions according to AC.L2-3.1.6?
  • What is required for an artifact to be considered acceptable evidence in a CMMC assessment?
  • What is the consequence of failing to enforce system security policy?
  • Which characteristic best defines a Demilitarized Zone (DMZ)?
  • What encryption method is utilized in WPA2-PSK?
  • Which of the following is NOT a requirement for privileged accounts as per CMMC?
  • What tool is used to help establish context for CMMC Assessment activities?
  • What governs the types of services outlined in a Service Level Agreement?
  • What is the role of a Lead CCA during an assessment?
  • What is the purpose of access enforcement mechanisms?
  • What does AC.L2-3.1.19 require for all CUI on mobile devices?
  • Which organization produces the CMMC doctrine that guides assessment procedures?
  • What does the practice AC.L2-3.1.8 require organizations to define in relation to logon attempts?
  • What does "security relevant information" refer to?
  • What does the document detailing Procedures need to provide?
  • What does an assessment objective express in a CMMC context?
  • What role does the Affirming Official play in an organization?
  • What is the main purpose of a C3PAO being listed as "authorized" or "accredited" in the CMMC Marketplace?
  • What does the CMMCAssessmentLogHash.log file contain?
  • Which type of controls are used to manage data flow within interconnected systems?
  • What is the role of the organization in relation to a contract?
  • Why is it important to have default-deny rules configured for public-facing subnetworks?
  • What does security control inheritance refer to?
  • Why is regular security awareness training necessary?
  • What is the primary objective of the scoping process in CMMC compliance?
  • What does CMMC practice AT.L2‑3.2.3 require for mitigating insider threats?
  • What does the Unique Entity Code (UEI) enable organizations to do?
  • Which term describes the location defined by software and network configurations, such as VLANs?
  • Which action is part of the Process in CMMC?
  • How are portable storage devices defined in the context of information systems?
  • How are security policies typically structured in terms of content?
  • What does the Lead CCA need to explain during the In-Brief Meeting?
  • What defines connected systems in relation to FCI/CUI environments?
  • When developing maintenance policies, what should organizations prioritize?
  • What action does session termination entail?
  • What is a System Security Plan (SSP)?
  • What is the primary requirement for CUI Assets within CMMC?
  • Which approach is NOT a part of reinforcing risk-aware behavior according to CMMC?
  • What does a Government Furnished Equipment (GFE) asset include?
  • What approach should organizations take when performing maintenance activities?
  • What does the term “facility” refer to in the context of enabling actions?
  • How should reviews of maintenance activities be conducted according to CMMC standards?
  • Within how many days must appeals concerning CMMC decisions be submitted?
  • What is the primary goal of an Assessment in the CMMC context?
  • How is an asset defined in relation to CMMC compliance?
  • What is a key requirement of AC.L2-3.1.18 regarding mobile device connections?
  • Who initiates the certification engagement for a CMMC assessment?
  • Which of the following best describes a Procedure in CMMC?
  • What is a key requirement of the practice concerning the flow of Controlled Unclassified Information (CUI)?
  • What common limitation might Specialized Assets face?
  • Who convenes the In-Brief Meeting before assessment activities begin?
  • What defines a portable storage device?
  • What risk is associated with an insider threat?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy