Cyber AB CMMC-CCP Certified CMMC Professional (CCP) Exam Exam Practice Test
Certified CMMC Professional (CCP) Exam Questions and Answers
During an assessment, which phase of the process identifies conflicts of interest?
Options:
Analyze requirements.
Develop assessment plan.
Verify readiness to conduct assessment.
Generate final recommended assessment results.
Answer:
CExplanation:
In the CMMC assessment process, conflicts of interest must be identified early to ensure an impartial and objective evaluation of an organization ' s compliance with CMMC 2.0 requirements. The appropriate phase for identifying conflicts of interest is during the " Verify Readiness to Conduct Assessment " phase.
Step-by-Step Explanation:
Assessment Planning & Conflict of Interest Consideration
Before an assessment begins, theC3PAO (Certified Third-Party Assessment Organization)or theDIBCAC (Defense Industrial Base Cybersecurity Assessment Center) for DOD-led assessmentsmust confirm that there are no conflicts of interest between assessors and the organization being assessed.
A conflict of interest may arise if an assessor haspreviously worked for, consulted with, or provided direct assistance tothe organization under review.
CMMC Assessment Process and Phases
The CMMC assessment process involves multiple steps, and the verification of readiness is acritical early phaseto ensure that the assessment is unbiased:
Analyze Requirements:This phase focuses on defining the assessment scope, but it does not include conflict of interest verification.
Develop Assessment Plan:This phase focuses on structuring the assessment methodology, not on identifying conflicts.
Verify Readiness to Conduct Assessment (Correct Answer):
At this stage, theC3PAO or assessment team must review potential conflicts of interest.
TheDefense Industrial Base Cybersecurity Assessment Center (DIBCAC)also ensures assessors do not have any prior relationships that could compromise the objectivity of the evaluation.
Generate Final Recommended Assessment Results:This phase occurs at the end of the process, after the assessment is complete, so conflict of interest identification is too late by this stage.
Official CMMC Documentation & References
CMMC Assessment Process (CAP) Guide– The CAP details procedures assessors must follow, including conflict of interest verification.
CMMC 2.0 Scoping and Assessment Guides– Published by the Cyber AB and DoD, these guides reinforce the need for impartiality and independence in assessments.
DoD Instruction 5200.48 (Controlled Unclassified Information Program)– Outlines requirements for ensuring objective cybersecurity assessments.
By ensuring conflicts of interest are identified in the " Verify Readiness to Conduct Assessment " phase, the integrity of the CMMC certification process is maintained, ensuring that assessments are conductedfairly, independently, and in accordance with DoD cybersecurity policies.
Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?
Options:
DOD OUSD
Authorized holder
Information Disclosure Official
Presidentially authorized Original Classification Authority
Answer:
BExplanation:
DoDI 5200.48 specifies that Authorized Holders of CUI are responsible for applying appropriate CUI markings. An authorized holder is an individual who has lawful government purpose access to the information. This ensures that responsibility for correctly marking information rests with those who create or handle the material, not only with original classification authorities (which apply to classified information, not CUI).
Reference Documents:
DoDI 5200.48,Controlled Unclassified Information (CUI)
In accordance with NARA directives and Chapter 33 of Title 44 (Records Management Directive), which types of data MUST have policies and procedures for disposal?
Options:
All recorded digital documents
All digital and recorded paper documents
All digital documents and recorded media
All recorded information, regardless of form or characteristics
Answer:
DExplanation:
Under Title 44 U.S.C. Chapter 33 (Records Management) and NARA directives, agencies and organizations must establish policies and procedures for the disposal of all recorded information, regardless of form or characteristics. This includes paper records, electronic documents, digital media, audiovisual files, and any other information format. The requirement ensures consistent handling, retention, and lawful disposal of both federal records and CUI.
Reference Documents:
Title 44, U.S. Code, Chapter 33: Records Management
NARA Records Management Directive
When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?
Options:
When under the control of the DoD
When the document is considered secret
When a document is being shared outside of the organization
When a derivative document ' s original information is not CUI
Answer:
CExplanation:
Background on Legacy Markings and CUI
Legacy markings refer to classification labels used before the implementation of the Controlled Unclassified Information (CUI) Program under DoD Instruction 5200.48.
Documents with legacy markings (such as “For Official Use Only” (FOUO) or “Sensitive But Unclassified” (SBU)) must be reviewed for re-marking or redaction to align with CUI requirements.
When Must Legacy Markings Be Updated?
If the document is retained internally (Answer A - Incorrect): Documents under DoD control do not require immediate re-marking unless they are being shared externally.
If the document is classified as Secret (Answer B - Incorrect): This question is about CUI, not classified information. Secret-level documents follow different marking rules under DoD Manual 5200.01.
If a document is being shared externally (Answer C - Correct):
According to DoD Instruction 5200.48, Section 3.6(a), organizations must review legacy markings before sharing documents outside the organization.
The document must be re-marked in compliance with the CUI Program before dissemination.
If the original document does not contain CUI (Answer D - Incorrect): The original source document ' s status does not affect the requirement to re-mark a derivative document if it contains CUI.
Conclusion
The correct answer is C: Documents with legacy markings must be re-marked or redacted when being shared outside the organization to comply with DoD CUI guidelines.
According to DFARS clause 252.204-7012, who is responsible for determining that Information in a given category should be considered CUI?
Options:
The NARA CUI Executive Agent
The contractor who generated the information
The DoD agency for whom the contractor is performing the work
The military personnel assigned to the contractor for that purpose
Answer:
CExplanation:
DFARS clause 252.204-7012 establishes the safeguarding of Covered Defense Information (CDI), which aligns with CUI categories. The clause specifies that the DoD is responsible for determining whether information is Controlled Unclassified Information (CUI) and marking it accordingly before sharing it with contractors. Contractors do not make determinations about what constitutes CUI; they are responsible for safeguarding information once it is received and marked as CUI.
Reference Documents:
DFARS 252.204-7012,Safeguarding Covered Defense Information and Cyber Incident Reporting
CMMC Model v2.0 Overview, December 2021
Which training is a CCI authorized to deliver through an approved CMMC LTP?
Options:
CMMC-AB approved training
DoD DFARS and CMMC-AB approved training
NARA CUI training and CMMC-AB approved training
DoD DFARS, NARA CUI, and CMMC-AB approved training
Answer:
AExplanation:
A Certified CMMC Instructor (CCI) is only authorized to deliver CMMC-AB (now The Cyber AB) approved training courses through a Licensed Training Provider (LTP). CCI instructors do not deliver DFARS or NARA CUI training under CMMC authorization—only formally approved CMMC courses.
Supporting Extracts from Official Content:
CMMC Ecosystem Roles: “CCIs are authorized to deliver CMMC-AB approved training courses through an LTP.”
Why Option A is Correct:
CCIs teach only CMMC-AB approved training.
Options B, C, and D include external trainings (DFARS or NARA CUI) that are not within the CCI’s scope.
References (Official CMMC v2.0 Content):
CMMC Ecosystem documentation – Roles and Responsibilities of LTPs and CCIs.
===========
What is the BEST document to find the objectives of the assessment of each practice?
Options:
CMMC Glossary
CMMC Appendices
CMMC Assessment Process
CMMC Assessment Guide Levels 1 and 2
Answer:
DExplanation:
1. Understanding the Role of Assessment Objectives in CMMC 2.0
Theassessment objectivesfor each CMMC practice define thespecific criteriathat an assessor uses to evaluate whether a practice is implemented correctly. These objectives break down each control into measurable components, ensuring a structured and consistent assessment process.
To determine where these objectives are best documented, we need to consider theofficial CMMC documentation sources.
2. Why Answer Choice " D " is Correct – CMMC Assessment Guide Levels 1 and 2
TheCMMC Assessment Guide (Levels 1 & 2)is theprimary documentthat provides:
✅The detailedassessment objectivesfor each practice
✅A breakdown of the expectedevidence and implementation details
✅Step-by-stepassessment criteriafor assessors to verify compliance
Each CMMC practice in the Assessment Guide is aligned with the correspondingNIST SP 800-171 or FAR 52.204-21 control, and the guide specifies:
How to assess compliancewith each practice
What evidenceis required for validation
What stepsan assessor should follow
???? Reference from Official CMMC Documentation:
CMMC Assessment Guide – Level 2 (Aligned with NIST SP 800-171)explicitly states:
" Each practice is assessed based on defined assessment objectives to determine if the practice is MET or NOT MET. "
CMMC Assessment Guide – Level 1 (Aligned with FAR 52.204-21)provides similar objectives tailored for foundational cybersecurity requirements.
Thus,CMMC Assessment Guide Levels 1 & 2 are the BEST sources for assessment objectives.
3. Why Other Answer Choices Are Incorrect
Option
Reason for Elimination
A. CMMC Glossary
❌The glossary only defines terminology used in CMMC but does not provide assessment objectives.
B. CMMC Appendices
❌The appendices contain supplementary details, but they do not comprehensively list assessment objectives for each practice.
C. CMMC Assessment Process (CAP)
❌While the CAP document describes the assessmentworkflow and methodology, it does not outline the specific objectives for each practice.
4. Conclusion
To locate thebest reference for assessment objectives, theCMMC Assessment Guide Levels 1 & 2are the most authoritative and detailed sources. They contain step-by-step assessment criteria, ensuring that practices are evaluated correctly.
✅Final Answer:
D. CMMC Assessment Guide Levels 1 and 2
A program manager for a defense contractor saves all FCI data relevant to a contract on a flash drive. Why is the flash drive categorized as an FCI Asset ?
Options:
It is storing FCI.
It is testing FCI.
It is distributing FCI.
It is properly marked as FCI.
Answer:
AExplanation:
CMMC v2.0 scoping defines “in-scope” assets for Level 1 (FCI protection) based on whether the asset processes, stores, or transmits FCI . The DoD CMMC Assessment Scope – Level 1 (v2.13) states: “Assets in scope … are all assets that **process, store, or transmit Federal Contract Information (FCI).” It then defines these terms. Critically for this question, Store is defined as when “FCI is inactive or at rest on an asset (e.g., located on electronic media…).”
A flash drive is “electronic media.” If the program manager places contract-relevant FCI onto the flash drive, the flash drive is now an asset that stores FCI (FCI at rest). Under the scoping guidance, that alone is enough to classify it as an in-scope FCI asset for Level 1 purposes, meaning it falls within the Level 1 assessment scope and must be protected by applicable Level 1 requirements.
The other answer choices do not align to the scoping definitions. “Testing FCI” (B) is not one of the scope-determining criteria in the Level 1 scoping guide. “Distributing FCI” (C) is not the formal criterion either (the guide uses Transmit , not “distribute”). Finally, being “properly marked” (D) does not determine whether something is in scope; the decisive factor is whether the asset processes, stores, or transmits FCI.
Which document is used to protect sensitive and confidential information from being made available by the recipient of that information?
Options:
Legal agreement
CMMC agreement
Assessment agreement
Non-disclosure agreement
Answer:
DExplanation:
The correct document is a Non-Disclosure Agreement (NDA) , because its specific purpose is to restrict a receiving party from disclosing sensitive or confidential information to unauthorized parties. In the official CMMC Assessment Process (CAP) v2.0 , NDAs are called out directly as a required element of the contracting relationship for a Level 2 certification assessment.
CAP v2.0 states that the C3PAO and the OSC must execute a written contractual agreement for the assessment and then specifies that “A mutual non-disclosure agreement (NDA) between the parties shall be incorporated into the contractual agreement or negotiated and executed in a separate document (e.g., stand-alone NDA, master services agreement, etc.).”
This is important because CMMC assessments can involve access to highly sensitive organizational information, including details about system architectures, security implementations, and potentially CUI handling processes. The CAP’s NDA requirement supports controlling dissemination of that information and reinforces the broader confidentiality expectations placed on assessment participants.
While an “assessment agreement” or generic “legal agreement” might contain confidentiality clauses, CAP v2.0 explicitly identifies the NDA instrument (either embedded or standalone) as the mechanism to protect information exchanged during the assessment engagement. Therefore, the best answer—consistent with CMMC v2.0 official process documentation—is D (Non-disclosure agreement) .
For the purpose of determining scope, what needs to be included as part of the assessment but would NOT receive a CMMC certification unless an enterprise assessment is conducted?
Options:
ESP
People
Test equipment
Government property
Answer:
AExplanation:
Per the CMMC Scoping Guidance, External Service Providers (ESPs) must be included in scope if they process, store, or transmit CUI or FCI on behalf of the OSC. However, ESPs do not themselves receive a separate CMMC certification unless they undergo their own assessment or an enterprise-level certification is conducted. Their environment is assessed only as part of the OSC’s scope.
Reference Documents:
CMMC Scoping Guidance for Level 2
CMMC Model v2.0 Overview
In the CMMC Model, how many practices are included in Level 2?
Options:
17 practices
72 practices
110 practices
180 practices
Answer:
CExplanation:
How Many Practices Are Included in CMMC Level 2?
CMMC Level 2is designed to alignfullywithNIST SP 800-171, which consists of110 security controls (practices).
This meansall 110 practicesfrom NIST SP 800-171 are required for aCMMC Level 2 certification.
Breakdown of Practices in CMMC 2.0
CMMC Level
Number of Practices
Level 1
17 practices(Basic Cyber Hygiene)
Level 2
110 practices(Aligned with NIST SP 800-171)
Level 3
Not yet finalized but expected to exceed 110
Since CMMC Level 2 mandatesall 110 NIST SP 800-171 practices, the correct answer isC. 110 practices.
Why the Other Answers Are Incorrect
A. 17 practices
❌Incorrect.17 practicesapply only toCMMC Level 1, not Level 2.
B. 72 practices
❌Incorrect. There is no CMMC level with72 practices.
D. 180 practices
❌Incorrect. CMMC Level 2only requires 110 practices, not 180.
CMMC Official References
CMMC 2.0 Model– Confirms thatLevel 2 includes 110 practicesaligned withNIST SP 800-171.
NIST SP 800-171 Rev. 2– Outlines the110 security controlsrequired for handlingControlled Unclassified Information (CUI).
Thus,option C (110 practices) is the correct answer, as per official CMMC guidance.
The Lead Assessor is presenting the Final Findings Presentation to the OSC. During the presentation, the Assessment Sponsor and OSC staff inform the assessor that they do not agree with the assessment results. Who has the final authority for the assessment results?
Options:
C3PAO
CMMC-AB
Assessment Team
Assessment Sponsor
Answer:
AExplanation:
Who Has the Final Authority Over Assessment Results?
During aCMMC Level 2 assessment, theCertified Third-Party Assessment Organization (C3PAO)is responsible for conducting and finalizing the assessment results.
Key Responsibilities of a C3PAO
✅Leads the assessmentand ensures it follows the CMMC Assessment Process (CAP).
✅Validates compliancewith CMMC Level 2 requirements based onNIST SP 800-171controls.
✅Finalizes the assessment resultsand submits them to theCMMC-ABand theDoD.
✅Handles disagreementsfrom the OSC but hasfinal decision-making authorityon results.
Why " C3PAO " is Correct?
The C3PAO has final authority over the assessment resultsafter considering all evidence and findings.
TheCMMC-AB (Option B) does not finalize assessments—it accredits C3PAOs and manages the certification ecosystem.
TheAssessment Team (Option C) supports the C3PAO but does not have final decision authority.
TheAssessment Sponsor (Option D) is a representative from the OSC and does not control the results.
Breakdown of Answer Choices
Option
Description
Correct?
A. C3PAO
✅Correct – C3PAOs finalize and submit assessment results.
B. CMMC-AB
❌Incorrect–The CMMC-AB accredits C3PAOs but doesnot finalize results.
C. Assessment Team
❌Incorrect–They conduct the assessment, but the C3PAO makes final decisions.
D. Assessment Sponsor
❌Incorrect–This is arepresentative of the OSC, not the assessment authority.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)– DefinesC3PAO authorityover final assessment results.
Final Verification and Conclusion
The correct answer isA. C3PAO, as theC3PAO has final decision-making authority over CMMC assessment results.
When an OSC requests an assessment by a C3PAO, who selects the Lead Assessor for the assessment?
Options:
OSC
C3PAO
C3PAO and OSC
OSC and Lead Assessor
Answer:
BExplanation:
The CAP specifies that the C3PAO is responsible for assigning the Lead Assessor to an OSC’s assessment. While the OSC contracts with the C3PAO, the authority to appoint the Lead Assessor resides solely with the C3PAO.
Supporting Extracts from Official Content:
CAP v2.0, Assessment Team Composition (§2.10): “The C3PAO shall designate a qualified Lead Assessor to lead the assessment.”
Why Option B is Correct:
Only the C3PAO has the authority to select and assign the Lead Assessor.
The OSC may influence scheduling and planning but cannot appoint assessors.
Options A, C, and D are inconsistent with CAP requirements.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Assessment Team Roles and Responsibilities (§2.10).
Which activities are involved in ALL assessment methods?
Options:
Exercising one or more assessment objects under specified conditions to compare actual with expected behavior
Conducting discussions with individuals or groups of individuals in an organization to facilitate understanding, achieve clarification, or lead to the location of evidence
Checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment objects or artifacts to facilitate understanding, achieve clarification, or obtain additional evidence
Determining security safeguard existence, functionality, correctness, completeness, and potential for improvement over time
Answer:
DExplanation:
The correct answer is D because the question asks what is involved in all assessment methods, not what defines a single assessment method. Options A, B, and C describe the three individual assessment methods. Option A describes Test, where assessment objects are exercised under specified conditions and actual behavior is compared with expected behavior. Option B describes Interview, where discussions are held with personnel to clarify implementation and locate evidence. Option C describes Examine, where artifacts, specifications, mechanisms, or records are reviewed, inspected, studied, or analyzed. The common purpose across all three is to support a determination about whether the safeguard exists, functions correctly, is complete, and is capable of supporting the required security outcome. NIST SP 800-171A explains that assessment methods are used to facilitate understanding, achieve clarification, or obtain evidence, and that the assessment process gathers information and produces evidence to determine security requirement effectiveness. Therefore, D captures the cross-method assessment purpose, while A, B, and C each capture only one method. Reference/topics: assessment methods, Examine/Interview/Test, assessment objectives, evidence-based determination.
While developing an assessment plan for an OSC. it is discovered that the certified assessor will be interviewing a former college roommate. What is the MOST correct action to take?
Options:
Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.
Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
Inform the OSC and the C3PAO of the possible conflict of interest, document the conflict and mitigation actions in the assessment plan, and if the mitigation actions are acceptable, continue with the assessment.
Answer:
DExplanation:
The Cybersecurity Maturity Model Certification (CMMC) Assessment Process (CAP) outlines strict guidelines regarding conflicts of interest (COI) to ensure the integrity and impartiality of assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs) and Certified Assessors (CAs).
The scenario presented involves a potential conflict of interest due to a prior relationship (former college roommate) between the certified assessor and an individual at the Organization Seeking Certification (OSC). While this prior relationship does not automatically disqualify the assessor, it must be disclosed, documented, and mitigated appropriately.
CMMC Conflict of Interest Handling Process
Inform the OSC and C3PAO of the Potential Conflict of Interest
The CMMC Code of Professional Conduct (CoPC) requires assessors to disclose any potential conflicts of interest.
Transparency ensures that all parties, including the OSC and C3PAO, are aware of the situation.
Document the Conflict and Mitigation Actions in the Assessment Plan
Per CMMC CAP documentation, potential conflicts should be assessed based on their material impact on the objectivity of the assessment.
The conflict and proposed mitigation strategies must be formally recorded in the assessment plan to provide an audit trail.
Determine If the Mitigation Actions Are Acceptable
If the OSC and C3PAO determine that the mitigation actions adequately eliminate or reduce the risk of bias, the assessment may proceed.
Common mitigation strategies include:
Assigning another assessor for interviews with the conflicted individual.
Ensuring that decisions regarding the OSC’s compliance are reviewed independently.
Proceed with the Assessment If Mitigation Is Acceptable
If the mitigation actions sufficiently address the conflict, the assessment may continue under strict adherence to documented procedures.
Why the Other Answers Are Incorrect
A. Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
❌Incorrect. This violates CMMC’s integrity requirements and could result in disciplinary actions against the assessor or invalidation of the assessment. Transparency is mandatory.
B. Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.
❌Incorrect. The CAP does not mandate immediate reassignment unless the conflict is unresolvable. Instead, mitigation strategies should be considered first.
C. Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
❌Incorrect. The passage of time alone does not automatically eliminate a conflict of interest. Proper documentation and mitigation are still required.
CMMC Official References
CMMC Assessment Process (CAP) Document – Defines COI requirements and mitigation actions.
CMMC Code of Professional Conduct (CoPC) – Outlines ethical responsibilities of assessors.
CMMC Accreditation Body (Cyber-AB) Guidance – Provides rules on conflict resolution.
Thus, option D is the most correct choice, as it aligns with the official CMMC conflict of interest procedures.
Which assessment method compares actual-specified conditions with expected behavior?
Options:
Test
Examine
Compile
Interview
Answer:
AExplanation:
Understanding CMMC Assessment Methods
TheCybersecurity Maturity Model Certification (CMMC) 2.0follows theNIST SP 800-171A assessment methodology, which includesthree primary assessment methods:
Examine– Reviewing policies, procedures, system configurations, and documentation.
Interview– Engaging with personnel to validate their understanding and execution of security practices.
Test– Conducting actual technical or operational tests to determine whether security controls function as expected.
Why " Test " is the Correct Answer?
" Test " is the method that compares actual-specified conditions with expected behavior.
It involvesexecuting procedures, configurations, or automated toolsto see if thesystem behaves as required.
For example, if a policy states that multi-factor authentication (MFA) must be enforced, a test would involveattempting to log in without MFAto confirm whether access is blocked as expected.
TheNIST SP 800-171A Guide (Assessment Procedures for CUI)defines testing as an assessment method that:
Actively verifies a security control is functioning
Simulates real-world attack scenarios
Checks compliance through system actions rather than documentation
Why Other Answers Are Incorrect?
B. Examine (Incorrect)
Examining only involvesreviewing policies, procedures, or configurationsbut does not actively test system behavior.
C. Compile (Incorrect)
" Compile " is not an assessment method in CMMC 2.0 or NIST SP 800-171A.
D. Interview (Incorrect)
Interviews are used to gather insights from personnel, but they do not compare actual conditions with expected behavior.
Conclusion
The correct answer isA. Testbecause itactively verifies system performance against expected security conditions.
Which term describes assessing the ability of a unit equipped with a system to support its mission while withstanding cyber threat activity representative of an actual adversary?
Options:
Penetration test
Black hat testing
Red cell assessment
Adversarial assessment
Answer:
DExplanation:
The term Adversarial Assessment is formally defined in DoD cyber terminology. It describes testing that evaluates a unit or system’s ability to perform its mission while facing simulated cyber threat activity representative of a real-world adversary.
Supporting Extracts from Official Content:
DoD Cybersecurity Test and Evaluation Guidebook: “Adversarial Assessment: Test conducted to evaluate a unit’s ability to support its mission while withstanding cyber threat activity representative of an actual adversary.”
Why Option D is Correct:
A penetration test is narrower and focuses on identifying vulnerabilities.
Black hat testing is not an official DoD or CMMC term.
Red cell assessment refers more broadly to force-on-force exercises and is not the term used in CMMC/governing DoD definitions.
References (Official CMMC v2.0 Content and Source Documents):
DoD Cybersecurity Test and Evaluation Guidebook.
CMMC v2.0 Governance – Source Documents (incorporating DoD definitions).
A Level 2 Assessment was conducted for an OSC, and the results are ready to be submitted. Prior to uploading the assessment results, what step MUST the C3PAO complete?
Options:
Pay an assessment submission fee.
Complete an internal review of the results.
Notify the CMMC-AB that submission is forthcoming.
Coordinate a final briefing between the Lead Assessor and the OSC.
Answer:
BExplanation:
According to the CMMC Assessment Process (CAP) and the C3PAO Authorization Requirements, every assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) must undergo a formal Quality Management System (QMS) review before the results are finalized and uploaded to the eMASS (Enterprise Mission Assurance Support Service) or the SPRS (Supplier Performance Risk System).
The Quality Review Requirement: The CAP explicitly states that the C3PAO is responsible for the accuracy and integrity of the assessment findings. Before the Assessment Team Lead can formally submit the package, a person or team within the C3PAO (who was ideally not part of the active assessment team to ensure objectivity) must conduct an internal review. This review ensures that the evidence collected supports the " Met " or " Not Met " determinations and that all CMMC methodology requirements were followed.
Why other options are incorrect:
Option A: While there may be administrative costs associated with maintaining C3PAO status, paying a specific " per-submission fee " is not a mandatory procedural stepwithin the assessment lifecyclethat governs the validity of the results.
Option C: The Cyber AB (CMMC-AB) provides the platform and oversight, but a " forthcoming notification " is not a formal requirement in the CAP; the act of submission itself serves as the notification.
Option D: While a final briefing is a " best practice " and usually occurs during the " Post-Assessment " phase, the internal quality review (Option B) is the regulatory mandate that must be completed to ensure the C3PAO ' s certification of the results is valid and defensible.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section on " Phase 4: Reporting Results, " specifically the sub-section on C3PAO Quality Assurance Review.
C3PAO Quality Management System (QMS) Requirements: Outlines the necessity for internal validation of assessment packages to maintain accreditation.
Validation of findings is an iterative process usually performed during the Daily Checkpoints throughout the entire assessment process. As a validation activity, why are the preliminary findings important?
Options:
It allows the OSC to comment and provide additional evidence.
It determines whether the OSC will be rated MET or NOT MET on their assessment.
It confirms that the Assessment Team ' s findings are right and cannot be changed.
It corroborates the Assessment Team ' s understanding of the CMMC practices and controls.
Answer:
AExplanation:
1. Understanding the Validation of Findings in CMMC Assessments
Validation of findings is an essential part of theCMMC assessment process, ensuring that observations and preliminary conclusions drawn by the assessment team are accurate, fair, and based on complete evidence. This process occurs iteratively during theDaily Checkpointsand is fundamental in determining the overall compliance status of theOrganization Seeking Certification (OSC).
2. The Role of Preliminary Findings in the Assessment Process
Preliminary findings arenot finalbut rather a mechanism for ensuring transparency, accuracy, and fairness. These findings serve several key purposes:
Allows for OSC Input & Clarification: The OSC has an opportunity to review andprovide additional evidencethat may address deficiencies identified by the assessment team.
Prevents Misinterpretations: By allowing the OSC to comment, the assessment team can refine or correct their understanding of the OSC ' s implementation of CMMC practices.
Supports Fair and Informed Ratings: Before finalizing MET or NOT MET determinations, the assessment team ensures they have considered all relevant evidence.
Encourages a Collaborative Assessment Process: This validation activity fosters open communication between assessors and the OSC, reducing disputes and misunderstandings.
3. Why Answer Choice " A " is Correct
The primary purpose of preliminary findings is to allow theOSC to comment and provide additional evidencebefore final determinations are made.
This aligns withCMMC Assessment Process guidance, which emphasizes iterative validation of findings throughDaily Checkpoints and Final Outbriefdiscussions.
The validation of findings ensures thatOSC responses and supplementary evidence are considered, making the assessment process more accurate and fair.
4. Why Other Answer Choices Are Incorrect
Option
Reason for Elimination
B. It determines whether the OSC will be rated MET or NOT MET on their assessment.
Incorrect: Preliminary findings do not directly determine the final rating. The assessment team reviews all collected evidence before making a final decision.
C. It confirms that the Assessment Team ' s findings are right and cannot be changed.
Incorrect: Findings arenot finalat the preliminary stage. The OSC has the opportunity to challenge findings by providing new or clarifying evidence.
D. It corroborates the Assessment Team ' s understanding of the CMMC practices and controls.
Partially Correct but Not the Best Answer: While validation helps refine understanding, itsprimary function is to allow OSC input, making optionA the most accurate choice.
5. Official CMMC References Supporting This Answer
CMMC Assessment Process (CAP) Document:
Section 5.3 – Validation of Findings: " The OSC is given the opportunity to provide additional evidence and comments to clarify or supplement preliminary assessment results. "
Section 5.4 – Daily Checkpoints: " The assessment team discusses preliminary findings with the OSC, allowing the organization to address concerns in real time. "
CMMC 2.0 Level 2 Scoping & Assessment Guide:
Confirms that the assessment process includes continuous dialogue with the OSC before final determinations are made.
6. Conclusion
Preliminary findings are acrucial validation stepin CMMC assessments, ensuring that organizations have the opportunity toprovide additional evidence and clarify potential misunderstandings. This iterative process improves accuracy and fairness in determining compliance with CMMC requirements. Therefore, the correct answer is:
A. It allows the OSC to comment and provide additional evidence.
An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?
Options:
Take it with them to review in the evening.
Leave it on the desk for review the following day.
Put it in the unlocked desk drawer for review the following morning.
Take a picture with the personal phone before securely shredding it.
Answer:
AExplanation:
In this scenario, the primary concern is the protection of Controlled Unclassified Information (CUI) in an environment that lacks sufficient physical security controls (specifically, a lack of a locked cabinet or drawer). According to the CMMC Assessment Process (CAP) and NIST SP 800-171 (specifically the Physical Protection (PE) family), CUI must be protected from unauthorized access at all times.
Responsibility of the Assessor: CMMC Professionals (CCPs and CCAs) are bound by the CMMC Code of Professional Conduct and the C3PAO ' s internal security protocols to ensure that any CUI provided by the Organization Seeking Certification (OSC) is handled securely.
Physical Protection (PE.L2-3.10.1 and PE.L2-3.10.2): These practices require that an organization limit physical access to systems and equipment to authorized users and protect the physical facility. If the provided " hoteling space " does not offer a locked container (like a cabinet) to secure the CUI overnight, leaving it in an unlocked drawer (Option C) or on the desk (Option B) would be a violation of CUI handling requirements and a security risk.
Why Option A is the best " Next " step: In the absence of on-site secure storage, the assessor must maintain positive control of the CUI. Taking the document to a secure location (such as the assessor ' s hotel room or person) where they can ensure it remains under their control is the only viable way to prevent unauthorized access by janitorial staff or other unauthorized personnel at the client site overnight.
Why other options are incorrect:
Option B and C: Both fail to protect the CUI from unauthorized access in a non-secure, shared environment.
Option D: Taking a picture of CUI on a personal phone is a major security violation (spillage), as personal devices are generally not authorized to store or process CUI.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section regarding " Assessor Responsibilities for CUI and Proprietary Information. "
NIST SP 800-171 Rev 2: Physical Protection (PE) family (3.10.1, 3.10.2).
DoD Instruction 5200.48: " Controlled Unclassified Information (CUI), " which specifies that CUI must be protected by at least one physical barrier when not in the direct control of an authorized individual.
While conducting a CMMC Level 2 Assessment, the Lead Assessor determines that the OSC has badge readers, pin code pads, and keys for various access points as well as documentation to demonstrate meeting the practice. Which CMMC practice has the OSC MET?
Options:
PE.L1-3.10.5: Control and manage physical access devices
MP.L2-3.8.5: Mark media with necessary CUI markings and distribution limitations
SI.L2-3.14.3: Monitor system security alerts and advisories and take action in response
PS.L2-3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
Answer:
AExplanation:
The presence of badge readers, PIN code pads, and keys directly corresponds to controlling and managing physical access devices, which maps to PE.L1-3.10.5 under the Physical Protection (PE) domain. This practice ensures that only authorized individuals have access to physical areas containing information systems.
The other options address unrelated requirements:
MP.L2-3.8.5 addresses marking CUI media,
SI.L2-3.14.3 addresses monitoring security alerts,
PS.L2-3.9.2 addresses protections during personnel changes.
Reference Documents:
CMMC Model v2.0, Level 1–3 Practices
NIST SP 800-171 Rev. 2, Control PE-3
Which organization is the governmental authority responsible for identifying and marking CUI?
Options:
NARA
NIST
CMMC-AB
Department of Homeland Security
Answer:
AExplanation:
Step 1: Define CUI (Controlled Unclassified Information)
CUI is information thatrequires safeguarding or dissemination controlspursuant to and consistent with applicable law, regulations, and government-wide policies, butis not classifiedunder Executive Order 13526 or the Atomic Energy Act.
✅Step 2: Authority over CUI — NARA’s Role
NARA – National Archives and Records Administration, specifically theInformation Security Oversight Office (ISOO), is thegovernment-wide executive agentresponsible for implementing the CUI program.
Source:
32 CFR Part 2002 – Controlled Unclassified Information (CUI)
Executive Order 13556 – Controlled Unclassified Information
CUI Registry – https://www.archives.gov/cui
NARA:
Maintains theCUI Registry,
Issuesmarking and handling guidance,
DefinesCUI categoriesand their authority under law or regulation,
Trains and informs Federal agencies and contractors on CUI policy.
❌Why the Other Options Are Incorrect
B. NIST
✘NIST (National Institute of Standards and Technology) developstechnical standards(e.g., SP 800-171), but it doesnot define or mark CUI. It helps secure CUI once it’s identified.
C. CMMC-AB (now Cyber AB)
✘The Cyber AB is theCMMC ecosystem’s accreditation body, not a government agency, and hasno authority over CUI classification or marking.
D. Department of Homeland Security (DHS)
✘While DHS mayhandle and protect CUI internally, it is not the executive agent for the CUI program.
NARAis theofficial U.S. government authorityresponsible for defining, categorizing, and marking CUI via theCUI Registryand associated policies underExecutive Order 13556.
Which statement BEST describes an assessor ' s evidence gathering activities?
Options:
Use interviews for assessing a Level 2 practice.
Test all practices or objectives for a Level 2 practice
Test certain assessment objectives to determine findings.
Use examinations, interviews, and tests to gather sufficient evidence.
Answer:
DExplanation:
Under the CMMC Assessment Process (CAP) and CMMC 2.0 guidelines, assessors must gather objective evidence to validate that an organization meets the required security practices and processes. This evidence collection is performed through three primary assessment methods:
Examination – Reviewing documents, records, system configurations, and other artifacts.
Interviews – Speaking with personnel to verify processes, responsibilities, and understanding of security controls.
Testing – Observing system behavior, performing technical validation, and executing controls in real-time to verify effectiveness.
Why Option D is Correct
The CMMC Assessment Process (CAP) states that an assessor must use a combination of evidence-gathering methods (examinations, interviews, and tests) to determine compliance.
CMMC 2.0 Level 2 (Aligned with NIST SP 800-171) requires assessors to verify not only that policies and procedures exist but also that they are implemented and effective.
Solely relying on one method (like interviews in Option A) is insufficient.
Testing all practices or objectives (Option B) is unnecessary, as assessors follow scoping guidance to determine which objectives need deeper examination.
Testing only " certain " objectives (Option C) does not fully align with the requirement of gathering sufficient evidence from multiple methods.
CMMC 2.0 and Official Documentation References
CMMC Assessment Process (CAP) Guide, Section 3.5 – Assessment Methods explicitly defines the use of examinations, interviews, and tests as the foundation of an effective assessment.
CMMC 2.0 Level 2 Practices and NIST SP 800-171 require assessors to validate the presence, implementation, and effectiveness of security controls.
CMMC Appendix E: Assessment Procedures states that an assessor should use multiple sources of evidence to determine compliance.
Final Verification
To ensure compliance with CMMC 2.0 guidelines and official documentation, an assessor must use examinations, interviews, and tests to gather evidence effectively, making Option D the correct answer.
What type of criteria is used to answer the question " Does the Assessment Team have the right evidence? "
Options:
Adequacy criteria
Objectivity criteria
Sufficiency criteria
Subjectivity criteria
Answer:
AExplanation:
According to the CMMC Assessment Process (CAP), specifically during the Phase 3: Conduct Assessment (Evidence Collection and Verification), the Assessment Team must evaluate all collected artifacts, interview notes, and test results against two primary dimensions: Adequacy and Sufficiency.
Adequacy (The " Right " Evidence): This criterion focuses on the quality, relevance, and validity of the evidence. It addresses whether the evidence actually maps to the specific CMMC practice being assessed and whether it is authoritative (e.g., signed, current, and from a trusted source). If an assessor asks, " Is this therightpiece of information to prove this practice is met? " they are testing for Adequacy.
Sufficiency (The " Enough " Evidence): This criterion focuses on the quantity and scope of the evidence. It addresses whether the Assessment Team has collected enough data points (across the required number of assets and using the required methods of Examine, Interview, and Test) to reach a confident conclusion. If an assessor asks, " Do I haveenoughexamples of this practice in action across the entire enclave? " they are testing for Sufficiency.
Why other options are incorrect:
B and D (Objectivity/Subjectivity): While assessors must remain objective, these are not the formal " criteria " used to categorize the evidence collection quality within the CAP framework.
C (Sufficiency): As noted above, Sufficiency is about theamountof evidence, not whether it is thecorrect type(the " right " evidence).
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4, " Collect and Verify Evidence, " which explicitly defines the requirement for evidence to be both adequate and sufficient.
CMMC Level 2 Assessment Guide: Guidance on the application of the Examine, Interview, and Test (E-I-T) methods to ensure evidence quality.
NIST SP 800-171A: The foundation for CMMC assessment procedures, which emphasizes the need for relevant (adequate) evidence to support findings.
During assessment planning, the OSC recommends a person to interview for a certain practice. The person being interviewed MUST be the person who:
Options:
funds that practice.
audits that practice.
supports, audits, and performs that practice.
implements, performs, or supports that practice.
Answer:
DExplanation:
Who Should Be Interviewed During a CMMC Assessment?
During assessment planning, theOrganization Seeking Certification (OSC)may suggest personnel for interviews. However, the person interviewedmustbe someone who:
✅Implementsthe practice (directly responsible for executing it).
✅Performsthe practice (carries out day-to-day security operations).
✅Supportsthe practice (provides necessary resources or oversight).
Why " Implements, Performs, or Supports That Practice " is Correct?
Theassessor needs direct insightsfrom individuals actively involved in the practice.
Funding (Option A)does not providetechnical or operationalinsight into practice execution.
Auditing (Option B)focuses on compliance checks, but auditorsdo not implementthe practice.
Supporting, auditing, and performing (Option C)includesauditors, who arenot necessarily the right interviewees.
Breakdown of Answer Choices
Option
Description
Correct?
A. Funds that practice.
❌Incorrect–Funding is important but doesnot mean direct involvement.
B. Audits that practice.
❌Incorrect–Auditors check compliance but donot implementpractices.
C. Supports, audits, and performs that practice.
❌Incorrect–Auditing isnot a requirementfor interviewees.
D. Implements, performs, or supports that practice.
✅Correct – The interviewee must have direct involvement in execution.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)– Requires that interviewees bedirectly responsiblefor implementing, performing, or supporting the practice.
Final Verification and Conclusion
The correct answer isD. Implements, performs, or supports that practice, as the interviewee mustactively contribute to the execution of the practice.
A server is used to store FCI with a cloud provider long-term. What is the server considered?
Options:
In scope, because the cloud provider will be storing the FCI data
Out of scope, because the cloud provider stores the FCI data long-term
In scope, because the cloud provider is required to be CMMC Level 2 certified
Out of scope, because encryption is always used when the cloud provider stores the FCI data
Answer:
AExplanation:
Assets that store, process, or transmit FCI or CUI are always in scope for CMMC. If a server with a cloud provider is used for long-term storage of FCI, that server is considered in scope because it directly holds covered data.
Supporting Extracts from Official Content:
CMMC Scoping Guide for Level 1: “Assets that store, process, or transmit FCI are in scope.”
CMMC Scoping Guide for Level 2: confirms the same rule applies for CUI.
Why Option A is Correct:
The server stores FCI, making it automatically in scope.
Option B is incorrect because long-term storage does not make an asset out of scope.
Option C is incorrect — Level 1 (FCI) does not require a Level 2 certified provider.
Option D is incorrect because encryption does not remove scope requirements.
References (Official CMMC v2.0 Content):
CMMC Scoping Guide, Level 1.
CMMC Model v2.0, Scoping and Implementation guidance.
===========
In performing scoping, what should the assessor ensure that the scope of the assessment covers?
Options:
All assets documented in the business plan
All assets regardless if they do or do not process, store, or transmit FCI/CUI
All entities, regardless of the line of business, associated with the organization
All assets processing, storing, or transmitting FCI/CUI and security protection assets
Answer:
DExplanation:
Scoping Requirements in CMMC Assessments
TheCMMC 2.0 Scoping GuideandCMMC Assessment Process (CAP) Documentclearly define what should be included in the scope of an assessment.
The assessment scope must cover:
All assets that process, store, or transmit FCI/CUI
Security Protection Assets (ESP)– these assets help protect FCI/CUI, such as firewalls, endpoint detection systems, and encryption mechanisms.
Thus, thecorrect scope includes both:
✅FCI/CUI Assets(Data storage, processing, or transmission assets)
✅Security Protection Assets (ESP)(Firewalls, security tools, etc.)
Why the Other Answers Are Incorrect
A. All assets documented in the business plan
❌Incorrect.Business plans may include assets unrelated to FCI/CUI, making this scopetoo broad. Only assets relevant to FCI/CUI should be assessed.
B. All assets regardless if they do or do not process, store, or transmit FCI/CUI
❌Incorrect. CMMC doesnotrequire organizations to include assets thathave no connection to FCI/CUI.
C. All entities, regardless of the line of business, associated with the organization
❌Incorrect.Only the assets relevant to FCI/CUI or security protection should be assessed. Unrelated business divisions (like a non-federal commercial division) areout-of-scope.
CMMC Official References
CMMC 2.0 Scoping Guide – Level 1 & Level 2
CMMC Assessment Process (CAP) Document
Thus,option D (All assets processing, storing, or transmitting FCI/CUI and security protection assets) is the correct answeras per official CMMC assessment scoping requirements.
Which authority leads the CMMC direction, standards, best practices, and knowledge framework for how to map the controls and processes across different Levels that range from basic cyber hygiene to advanced cyber practices?
Options:
NIST
DoD CIO office
Federal CIO office
Defense Federal Acquisition Regulation Council
Answer:
BExplanation:
Understanding the Role of the DoD CIO Office in CMMC
TheDepartment of Defense (DoD) Chief Information Officer (CIO) officeis theprimary authorityresponsible for leading the direction, standards, and best practices of theCybersecurity Maturity Model Certification (CMMC)framework.
Why " B. DoD CIO Office " is Correct?
The DoD CIO Oversees CMMC Policy and Implementation
TheDoD CIO Office is responsible for the governance and strategic direction of CMMC.
It ensures thatCMMC aligns with DoD cybersecurity policies, such asDoD Instruction 5200.48 (Controlled Unclassified Information)andNIST SP 800-171.
CMMC Development and Evolution
TheDoD CIO played a critical role in launching CMMCto improve cybersecurity across theDefense Industrial Base (DIB).
The CIO office leadspolicy development and updates to the CMMC framework, including the transition fromCMMC 1.0 to CMMC 2.0.
Alignment of CMMC with Federal Cybersecurity Strategy
The DoD CIO ensures that CMMCintegrates with federal cybersecurity policiesandNIST frameworks.
It provides oversight formapping CMMC Levels (1-2-3) to existing cybersecurity standards and controls.
Why Other Answers Are Incorrect?
A. NIST (Incorrect)
TheNational Institute of Standards and Technology (NIST)provides thetechnical framework (NIST SP 800-171, SP 800-172), butNIST does not lead the CMMC program.
C. Federal CIO Office (Incorrect)
TheFederal CIO focuses on broader government IT policiesandnot specifically on DoD cybersecurity requirementslike CMMC.
D. Defense Federal Acquisition Regulation Council (Incorrect)
TheDFARS Counciloverseescontracting regulationsrelated to CMMC (e.g.,DFARS 252.204-7012, 7019, 7020, 7021), but it doesnot lead CMMC standards and best practices.
Conclusion
The correct answer isB. DoD CIO Office, as it isthe lead authority guiding the CMMC framework, standards, and implementation across the Defense Industrial Base (DIB).
A test or demonstration is being performed for the Assessment Team during an assessment. Which environment MUST the OSC perform this test or demonstration?
Options:
Client
Production
Development
Demonstration
Answer:
BExplanation:
Understanding the Assessment Environment Requirement
During aCMMC Level 2 assessment, assessors requireobjective evidencethat security controls are implementedin the actual operating environmentwhereControlled Unclassified Information (CUI)is handled.
This means thattests or demonstrations must be conducted in the production environment, where the organization’s real systems and security controls are in use.
Why Option B (Production) is Correct
Assessment teams need to validate security controls in the actual environment where they are applied, ensuring that security measures are in effect in thereal-world operating conditions.
Option A (Client)is incorrect because " Client " is not a defined assessment environment.
Option C (Development)is incorrect because testing in a development environmentdoes not accurately represent the production security posture.
Option D (Demonstration)is incorrect becausedemonstrations in a separate test environment do not provide valid evidence for CMMC assessments—actual security implementations must be verified in production.
Official CMMC Documentation References
CMMC Assessment Process (CAP) Guide – Section 3.5 (Assessment Methods)
NIST SP 800-171 Assessment Procedures(Verification must occur in the actual system where CUI resides.)
Final Verification
SinceCMMC assessments require security controls to be validated in the actual production environment, the correct answer isOption B: Production.
Which principles are included in defining the CMMC-AB Code of Professional Conduct?
Options:
Objectivity, classification, and information accuracy
Objectivity, confidentiality, and information integrity
Responsibility, classification, and information accuracy
Responsibility, confidentiality, and information integrity
Answer:
DExplanation:
The Cyber AB (formerly CMMC-AB) Code of Professional Conduct (CoPC) is a mandatory agreement that all CMMC ecosystem members—including Certified CMMC Professionals (CCPs) and Certified CMMC Assessors (CCAs)—must adhere to. This code ensures the reliability and trustworthiness of the assessment process.
The fundamental principles that form the foundation of the CoPC include:
Responsibility: This refers to the obligation of the CMMC professional to act in the best interest of the CMMC program, the Department of Defense (DoD), and the public. It includes maintaining professional competence and performing duties with due care.
Confidentiality: Assessors and professionals are granted access to sensitive information, including Controlled Unclassified Information (CUI) and proprietary business data of the Organization Seeking Certification (OSC). They must ensure this information is protected from unauthorized disclosure.
Information Integrity: This principle requires that all data, findings, and reports generated during the assessment are accurate, complete, and have not been tampered with. It ensures that the " Met " or " Not Met " determinations are based on honest evidence.
Why other options are incorrect:
Options A and B (Objectivity): While " Objectivity " is a crucialbehavioralrequirement for an assessor (remaining unbiased), the specific high-level triad often emphasized in the CMMC Professional training and the formal CoPC documentation focuses on the Responsibility-Confidentiality-Integrity framework to align with standard professional ethics and information security pillars.
Options A and C (Classification): " Classification " is a process used for National Security Information (Classified info), whereas CMMC is primarily focused on unclassified information (CUI and FCI). Classification is not a core principle of the professional code of conduct.
Options A and C (Information Accuracy): While accuracy is vital, it is considered a subset of Information Integrity within the formal definitions provided in the CCP curriculum.
Reference Documents:
CMMC-AB (The Cyber AB) Code of Professional Conduct: The official ethical framework for all credentialed individuals.
CMMC Professional (CCP) Study Guide: Section on " Ethics and the Code of Professional Conduct. "
CMMC Assessment Process (CAP): References the ethical standards required to maintain the integrity of the assessment ecosystem.
While conducting a CMMC Assessment, an individual from the OSC provides documentation to the assessor for review. The documentation states an incident response capability is established and contains information on incident preparation, detection, analysis, containment, recovery, and user response activities. Which CMMC practice is this documentation attesting to?
Options:
IR.L2-3.6.1: Incident Handling
IR.L2-3.6.2: Incident Reporting
IR.L2-3.6.3: Incident Response Testing
IR.L2-3.6.4: Incident Spillage
Answer:
AExplanation:
Understanding CMMC 2.0 Incident Response Practices
TheIncident Response (IR) domaininCMMC 2.0 Level 2aligns withNIST SP 800-171, Section 3.6, which defines requirements forestablishing and maintaining an incident response capability.
Why " A. IR.L2-3.6.1: Incident Handling " is Correct?
The documentation provideddescribes an incident response capability that includes preparation, detection, analysis, containment, recovery, and user response activities.
IR.L2-3.6.1specifically requires organizations toestablish an incident handling processcovering:
Preparation
Detection & Analysis
Containment
Eradication & Recovery
Post-Incident Response
Why Other Answers Are Incorrect?
B. IR.L2-3.6.2: Incident Reporting (Incorrect)
Incident reporting focuses on reporting incidents to external parties (e.g., DoD, DIBNet),which isnot what the provided documentation describes.
C. IR.L2-3.6.3: Incident Response Testing (Incorrect)
Incident response testing ensures that the response process is regularly tested and evaluated,which isnot the primary focus of the documentation provided.
D. IR.L2-3.6.4: Incident Spillage (Incorrect)
Incident spillage specifically refers to CUI exposure or handling unauthorized CUI incidents,which isnot the scenario described.
Conclusion
The correct answer isA. IR.L2-3.6.1: Incident Handling, as the documentationattests to the establishment of an incident response capability.
A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?
Options:
Performed in groups for more efficient use of resources
Recorded for inclusion in the Final Recommended Findings report
Confidential and non-attributable so interviewees can speak without fear of reprisal
Mapped to specific CMMC practices to clearly delineate which practice is being evaluated
Answer:
CExplanation:
Understanding the Role of a CCP in CMMC Assessments
ACertified CMMC Professional (CCP)is responsible for assistingCertified CMMC Assessors (CCA)in evaluating anOrganization Seeking Certification (OSC)during a CMMC assessment. One key aspect of this process isconducting interviewswith Subject Matter Experts (SMEs) to verify security practices.
Ensuring that interviewees canspeak freely without fear of retaliationiscriticalto obtainingaccurate and unbiased informationabout the implementation of security controls.
Step-by-Step Breakdown:
CMMC Assessment Process and the Role of Interviews
TheCMMC Assessment Guide (Level 2)outlines that interviews are conducted to confirm that security practices are effectively implemented.
Interviewees mustfeel comfortable sharing candid responseswithout concern that their statements will lead tonegative consequenceswithin the organization.
Ensuring Confidentiality and Non-Attribution
DoD Assessment Methodologyspecifies that interviews should be conductedconfidentiallytoprotect the identity of interviewees.
TheCMMC Code of Professional Conduct (CoPC)for assessors and professionals reinforces the requirement to maintain theconfidentialityof assessment participants.
Non-attributionensures that responses are used for evaluation purposeswithout linking statements to specific individuals.
Why the Other Answer Choices Are Incorrect:
(A) Performed in groups for more efficient use of resources:
Group interviews may prevent individuals from speaking openly.
Employees might be hesitant to contradict leadership or peers.
(B) Recorded for inclusion in the Final Recommended Findings report:
Interviews arenot directly recorded or attributedin assessment reports.
Instead, findings are documentedwithout identifying specific individuals.
(D) Mapped to specific CMMC practices to clearly delineate which practice is being evaluated:
While responsesinformwhich practices are being assessed, theprimary goalof an interview is to ensure accurate,unbiased information gathering.
Final Validation from CMMC Documentation:
According to theCMMC Assessment Guide and DoD Assessment Methodology, interview confidentiality iscrucialto gatheringaccurateandunbiasedresponses. This makesconfidentiality and non-attributionthe correct answer.
Thus, the correct answer is:
C. Confidential and non-attributable so interviewees can speak without fear of reprisal.
Who is responsible for ensuring that subcontractors have a valid CMMC Certification?
Options:
CMMC-AB
OUSDA & S
DoD agency or client
Contractor organization
Answer:
DExplanation:
Step 1: Responsibility for Subcontractor Compliance
The prime contractor (contractor organization)is responsible for ensuring thatits subcontractorshave the requiredCMMC certification levelbefore engaging them inDoD contracts that involve FCI or CUI.
This requirement is enforced throughflow-down clausesinDFARS 252.204-7021, which mandates that subcontractors handlingCUImeet the necessaryCMMC Level 2 or Level 3 requirements.
In scoping a CMMC Level 1 Self-Assessment, all of the computers and digital assets that handle FCI are identified. A file cabinet that contains paper FCI is also identified. What can this file cabinet BEST be determined to be?
Options:
In scope, because it is an asset that stores FCI
In scope, because it is part of the same physical location
Out of scope, because they are all only paper documents
Out of scope, because it does not process or transmit FCI
Answer:
AExplanation:
According to the CMMC Scoping Guidance, Level 1, the scope of an assessment includes all assets that process, store, or transmit Federal Contract Information (FCI). CMMC is " information-centric, " meaning the security requirements apply to the information itself, regardless of the media it resides on (digital or physical).
Asset Identification: In a Level 1 assessment, assets are categorized as either FCI Assets or Out-of-Scope Assets. Since the file cabinet is explicitly identified as containing paper FCI, it meets the definition of an asset that stores the protected information.
Basic Safeguarding (FAR 52.204-21): The 17 practices of CMMC Level 1 are derived from the FAR clause for the " Basic Safeguarding of Covered Contractor Information Systems. " However, the physical protection requirements within that set (such as PE.L1-3.10.1, which requires limiting physical access to organizational information systems and equipment) extend to the physical storage locations of that data.
Media Neutrality: CMMC documentation emphasizes that " information systems " include the physical components and the information processed by them. If FCI is printed and stored in a cabinet, that cabinet becomes a physical storage asset within the assessment boundary.
Why other options are incorrect:
Option B: Physical location alone does not bring an asset into scope. For example, a coffee machine in the same room as an FCI computer remains out of scope because it doesn ' t handle FCI. Thecontent(FCI) makes the cabinet in-scope, not its proximity.
Option C: CMMC and the underlying FAR clause do not exempt paper-based information. Protected data must be secured whether it is on a hard drive or a printed sheet.
Option D: While a file cabinet may not " process " or " transmit " data like a computer does, it absolutely stores it. The definition of the scope includes all three functions (process, store, or transmit).
Reference Documents:
CMMC Scoping Guidance, Level 1: Section 2.0 (CMMC Level 1 Asset Categories), which defines FCI Assets as those that process, store, or transmit FCI.
CMMC Assessment Guide, Level 1: Discussion on Physical Protection (PE) practices and their application to physical media.
32 CFR Part 170 (CMMC Program Rule): Definitions of FCI and the requirements for contractor self-assessments.
Which example represents a Specialized Asset?
Options:
SOCs
Hosted VPN services
Consultants who provide cybersecurity services
All property owned or leased by the government
Answer:
DExplanation:
According to the CMMC Scoping Guidance, Level 2, assets are categorized into specific groups to determine how they are treated during an assessment. One of these categories is Specialized Assets.
The CMMC Scoping Guidance defines Specialized Assets as a specific group that includes:
Government Property: Any property owned or leased by the government and provided to the contractor (Government Furnished Equipment or GFE).
Internet of Things (IoT): Physical objects that are embedded with sensors, software, and other technologies for the purpose of connecting and exchanging data.
Operational Technology (OT): Programmable systems or devices that interact with the physical environment (e.g., Industrial Control Systems).
Restricted Information Systems: Systems that have specific configurations or constraints that prevent standard security controls from being applied (e.g., legacy systems).
Test Equipment: Specialized equipment used for testing, such as oscilloscopes or signal generators.
Why other options are incorrect:
Option A (SOCs): A Security Operations Center is typically considered a Security Protection Asset (SPA) because it provides security functions (monitoring/response) for the assessment scope.
Option B (Hosted VPN services): These are generally categorized as External Service Providers (ESPs) or part of the Security Protection Assets, depending on how they are managed and their role in protecting CUI.
Option C (Consultants): These are External Service Providers (ESP) (personnel/organizations), not specialized hardware/software assets.
Treatment of Specialized Assets: Under CMMC Level 2 scoping rules, Specialized Assets must be identified in the Asset Inventory and documented in the System Security Plan (SSP), but they are generally not managed against the CMMC practices unless they process, store, or transmit CUI in a way that falls outside their specialized function.
Reference Documents:
CMMC Scoping Guidance, Level 2 (Version 2.0/2.1): Section 3.1, " Specialized Assets " and Table 3.
32 CFR Part 170 (CMMC Program Rule): Definitions of asset categories and their associated assessment requirements.
Two network administrators are working together to determine a network configuration in preparation for CMMC. The administrators find that they disagree on a couple of small items. Which solution is the BEST way to ensure compliance with CMMC?
Options:
Consult with the CEO of the company.
Consult the CMMC Assessment Guides and NIST SP 800-171.
Go with the network administrator ' s ideas with the least stringent controls.
Go with the network administrator ' s ideas with the most stringent controls.
Answer:
BExplanation:
When preparing forCMMC compliance, organizations must ensure that theirnetwork configurations align with required cybersecurity controls. Ifnetwork administratorsdisagree on certain configurations, the mostobjective and accurateway to resolve the disagreement is by referencingofficial CMMC guidanceandNIST SP 800-171 requirements, which form the foundation of CMMC Level 2.
Step-by-Step Breakdown:
CMMC Assessment Guides as the Primary Reference
TheCMMC Assessment Guides (Level 1 & Level 2)provide clearinterpretationsof security practices.
Theyexplain how each practice should be implemented and assessedduring certification.
NIST SP 800-171 as the Compliance Baseline
CMMC Level 2is based directly onNIST SP 800-171, which outlines the110 security controlsrequired for protectingControlled Unclassified Information (CUI).
Network configurations must complywith NIST-defined security requirements, including:
Access Control (AC) – Ensuring least privilege principles.
Audit and Accountability (AU) – Logging and monitoring network activity.
System and Communications Protection (SC) – Secure network design and encryption.
Why the Other Answer Choices Are Incorrect:
(A) Consult with the CEO of the company:
ACEO is not necessarily a cybersecurity expertand may not be familiar with CMMC technical requirements.
Technical compliance decisions should be based onCMMC and NISTframeworks, not executive opinions.
(C) Go with the network administrator ' s ideas with the least stringent controls:
Choosingless stringent controls increases security riskand could lead toCMMC non-compliance.
(D) Go with the network administrator ' s ideas with the most stringent controls:
While security is important,more stringent controlsmay introduceoperational inefficienciesorunnecessary coststhat are not required for compliance.
The correct approach is to implement what is required by CMMC and NIST SP 800-171, no more and no less.
Final Validation from CMMC Documentation:
TheCMMC Assessment GuidesandNIST SP 800-171 Rev. 2areofficial sourcesthat provide the most reliable guidance on compliance.
CMMC Level 2 is entirely based on NIST SP 800-171, making it the definitive source for resolving security disagreements.
Thus, the correct answer is:
B. Consult the CMMC Assessment Guides and NIST SP 800-171.
To develop an assessment contract and establish a scope of work, which organization does an OSC work with?
Options:
OUSD
RPOs
C3PAOs
CMMC-AB
Answer:
CExplanation:
Under the official CMMC Assessment Process (CAP) v2.0 , the OSC contracts directly with a C3PAO to arrange a Level 2 certification assessment, including the practical scope-of-work elements (timing, logistics, and the terms of performance). CAP v2.0 explicitly states that “The C3PAO shall execute a written contractual agreement for the CMMC Level 2 certification assessment with the OSC” and further clarifies that neither the Cyber AB nor DoD are parties to that contract.
Because the C3PAO is the assessment organization that conducts the certification assessment, it is also the entity the OSC coordinates with during the pre-assessment activities that shape the engagement and scope. CAP v2.0 places key Phase 1 responsibilities on the C3PAO/Lead CCA, including validating the OSC’s assessment scope against applicable scoping requirements and coordinating access to evidence and personnel needed for Phase 2.
By contrast, OUSD provides DoD-level oversight/policy, RPOs and the Cyber AB support the ecosystem, but they do not form the contractual relationship for a specific Level 2 certification assessment. CAP v2.0 is unambiguous that the contract (and any mutually agreed scope-of-work terms) is between the OSC and the C3PAO .
===========
In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?
Options:
In scope
Out of scope
OSC point of contact
Assessment Team Member
Answer:
AExplanation:
Understanding Scoping in CMMC Level 1 Self-Assessments
Federal Contract Information (FCI)is any informationnot intended for public releasethat is provided or generated under aU.S. Government contracttodevelop or deliver a product or service.
Enhanced Security Personnel (ESP)refers to employees, contractors, or third parties whohave access to FCIwithin anOrganization Seeking Certification (OSC).
UnderCMMC 2.0 Scoping Guidance, anypersonnel, system, or asset with access to FCI is considered in scopefor a CMMC Level 1 assessment.
Why Option A (In scope) is Correct
Since theESP employee has access to FCI, theymustbe included in the assessment scope.
Option B (Out of scope)is incorrect because anyone with access to FCI is automatically considered part of theCMMC Level 1 boundary.
Option C (OSC point of contact)is incorrect because thepoint of contactis typically an administrative or compliance representative, not necessarily someone with FCI access.
Option D (Assessment Team Member)is incorrect because anESP employee is not part of the assessment team but rather a subject of the assessment.
Official CMMC Documentation References
CMMC Level 1 Scoping Guide, Section 2 – Defining Scope for FCI
CMMC Assessment Process (CAP) Guide – Roles and Responsibilities
Federal Acquisition Regulation (FAR) 52.204-21(Basic Safeguarding of FCI)
Final Verification
Since theESP employee has access to FCI, they are consideredin scopefor the CMMC Level 1 self-assessment, makingOption A the correct answer.
The Assessment Team has completed the assessment and determined the preliminary practice ratings. The preliminary practice ratings must be shared with the OSC prior to being finalized for submission. Based on this information, the assessor should present the preliminary practice ratings:
Options:
During the final Daily Checkpoint
After discussing with the CMMC-AB
Via email after the final Daily Checkpoint
Over the phone after the final Daily Checkpoint
Answer:
AExplanation:
According to the CMMC Assessment Process (CAP) v2.0, assessors are required to conduct Daily Checkpoint Meetings at the end of each day to summarize progress with the OSC (Organization Seeking Certification). The final Daily Checkpoint is where preliminary practice ratings are shared, before the quality assurance review and Out-Brief. The Out-Brief is reserved for the presentation of final results. Additionally, Department of Defense regulations (32 CFR §170.17(c)(2)) provide a 10-business-day re-evaluation window for requirements marked NOT MET before the final report is delivered, which necessitates that the OSC see preliminary ratings during the assessment process itself.
Supporting Extracts from Official Content:
CAP v2.0, §2.23: “The assessment team shall host a Daily Checkpoint Meeting with the OSC at the end of each assessment day to summarize progress.”
CAP v2.0, §3.7: “The C3PAO shall conduct the quality assurance review… prior to the conduct of the Out-Brief Meeting.”
CAP v2.0, §3.10: “The purpose of the Out-Brief Meeting is to convey the results of the assessment to the OSC.”
32 CFR §170.17(c)(2): “A security requirement assessed as NOT MET may be re-evaluated… for 10 business days… if the CMMC Assessment Findings Report has not been delivered.”
Why Option A is Correct:
The CAP specifies that Daily Checkpoint Meetings are the formal, structured mechanism for assessors to communicate progress and preliminary findings to the OSC.
The final Daily Checkpoint provides the OSC with visibility into the preliminary practice ratings before they are finalized, ensuring transparency and alignment.
The Out-Brief is explicitly for conveying the final assessment results after the C3PAO has completed QA.
Federal regulation (32 CFR §170.17(c)(2)) requires the OSC to have access to preliminary results so they can provide additional evidence for re-evaluation before the report is locked, further confirming that this exchange must occur at the final Daily Checkpoint.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0: Sections 2.23 (Daily Checkpoints), 3.7–3.10 (QA and Out-Brief).
32 CFR §170.17(c)(2): Security Requirement Re-evaluation Window.
DoD CMMC Assessment Guide – Level 2 (v2.13): Guidance on MET/NOT MET determinations and findings.
Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?
Options:
Availability
Confidentiality
Information Integrity
Respect for Intellectual Property
Answer:
BExplanation:
The requirement to exercise due care in protecting information gathered during an assessment aligns with the principle ofConfidentialityunder theCMMC Code of Professional Conduct (CoPC). This ensures that sensitive assessment data, findings, and any Controlled Unclassified Information (CUI) remain protected even after the engagement concludes.
Step-by-Step Breakdown:
Definition of Confidentiality in CMMC Context:
Confidentiality refers to protecting sensitive information from unauthorized disclosure.
In the context of a CMMC assessment, it includes safeguarding assessment artifacts, findings, and other sensitive data collected during the evaluation process.
CMMC Code of Professional Conduct (CoPC) References:
TheCMMC Code of Professional Conductstates that assessors and organizations must handle all collected information with discretion andensure its protection post-engagement.
Clause on " Maintaining Confidentiality " specifies that assessors must:
Not disclose sensitive information to unauthorized parties.
Secure data in storage and transmission.
Retain and dispose of data securely in accordance with federal regulations.
Alignment with NIST 800-171 & CMMC Practices:
CMMC Level 2 incorporates NIST SP 800-171 controls, which include:
Requirement 3.1.3:“Control CUI at rest and in transit” to ensure unauthorized individuals do not gain access.
Requirement 3.1.4:“Separate the duties of individuals to reduce risk” ensures that assessment findings are only shared with authorized personnel.
These requirements align with the duty toexercise due carein protecting assessment-related information.
Why the Other Options Are Incorrect:
(A) Availability:This refers to ensuring data is accessible when needed but does not directly relate to protecting gathered information post-assessment.
(C) Information Integrity:This focuses on preventing unauthorized modifications rather than restricting disclosure.
(D) Respect for Intellectual Property:While related to ethical handling of proprietary data, it does not directly cover post-engagement confidentiality requirements.
Final Validation from CMMC Documentation:
TheCMMC Code of Professional ConductandNIST SP 800-171control requirements confirm thatConfidentialityis the correct answer, as it directly pertains to protecting information post-assessment.
Thus, the correct answer isB. Confidentiality.
What is the BEST description of the purpose of FAR clause 52 204-21?
Options:
It directs all covered contractors to install the cyber security systems listed in that clause.
It describes all of the safeguards that contractors must take to secure covered contractor IS.
It describes the minimum standard of care that contractors must take to secure covered contractor IS.
It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.
Answer:
CExplanation:
Understanding FAR Clause 52.204-21
TheFederal Acquisition Regulation (FAR) Clause 52.204-21is titled " Basic Safeguarding of Covered Contractor Information Systems. " This clause establishesminimum cybersecurity requirementsforfederal contractorsthat handleFederal Contract Information (FCI).
Key Purpose of FAR Clause 52.204-21
Theprimary objectiveof FAR 52.204-21 is to ensure that contractors applybasic cybersecurity protectionsto theirinformation systemsthat process, store, or transmitFCI. Theseminimum safeguarding requirementsserve as abaseline security standardfor contractors doing business with theU.S. government.
Why " Minimum Standard of Care " is Correct?
FAR 52.204-21 doesnotrequire contractors to install specific cybersecurity tools (eliminating option A).
Itoutlines only the minimum safeguards, notallcybersecurity controls needed for complete security (eliminating option B).
CMMC certification isnotmandated by this clause alone (eliminating option D).
Instead, it establishesa baseline " standard of care " that all federal contractorsmust followto protectFCI(making option C correct).
Breakdown of Answer Choices
Option
Description
Correct?
A. It directs all covered contractors to install the cybersecurity systems listed in that clause.
❌Incorrect–The clause doesnotspecify tools or require specific cybersecurity systems.
B. It describes all of the safeguards that contractors must take to secure covered contractor IS.
❌Incorrect–It only setsminimumrequirements, notall possiblesecurity measures.
C. It describes the minimum standard of care that contractors must take to secure covered contractor IS.
✅Correct – The clause defines basic safeguards as a minimum security standard.
D. It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.
❌Incorrect–FAR 52.204-21 doesnot mandateCMMC certification; that requirement comes from DFARS 252.204-7012 and 7021.
Minimum Safeguarding Requirements Under FAR 52.204-21
The clause defines15 basic security controls, which align withCMMC Level 1. Some examples include:
✅Access Control– Limit access to authorized users.
✅Identification & Authentication– Authenticate system users.
✅Media Protection– Sanitize media before disposal.
✅System & Communications Protection– Monitor and control network connections.
Official References from CMMC 2.0 and FAR Documentation
FAR 52.204-21– Establishes thebasic safeguarding requirementsfor FCI.
CMMC 2.0 Level 1– Directly aligns withFAR 52.204-21 controls.
Final Verification and Conclusion
The correct answer isC. It describes the minimum standard of care that contractors must take to secure covered contractor IS.This aligns withFAR 52.204-21 requirementsas abaseline security standard for FCI.
Which statement BEST describes the key references a Lead Assessor should refer to and use the:
Options:
DoD adequate security checklist for covered defense information.
CMMC Model Overview as it provides assessment methods and objects.
safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment.
published CMMC Assessment Guide practice descriptions for the desired certification level.
Answer:
DExplanation:
Key References for a Lead Assessor in a CMMC Assessment
ALead Assessorconducting aCMMC assessmentmust rely onofficial CMMC guidance documentsto evaluate whether anOrganization Seeking Certification (OSC)meets the required cybersecurity practices.
Most Relevant Reference: CMMC Assessment Guide
TheCMMC Assessment Guideprovidesdetailed descriptionsof eachpractice and processat the specificCMMC level being assessed.
It defines:
✔Theassessment objectivesfor each practice.
✔Therequired evidencefor compliance.
✔Thescoring criteriato determine if a practice isMET or NOT MET.
Why is the Correct Answer " D. Published CMMC Assessment Guide practice descriptions for the desired certification level " ?
A. DoD adequate security checklist for covered defense information → Incorrect
TheDoD adequate security checklistis related toDFARS 252.204-7012 compliance, butCMMC assessmentsfollow theCMMC Assessment Guide.
B. CMMC Model Overview as it provides assessment methods and objects → Incorrect
TheCMMC Model Overviewprovideshigh-level guidance, butdoes not contain specific assessment criteria.
C. Safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment → Incorrect
FAR 52.204-21is relevant toCMMC Level 1 (FCI protection), butCMMC Level 2 follows NIST SP 800-171and requiresCMMC Assessment Guidesfor validation.
D. Published CMMC Assessment Guide practice descriptions for the desired certification level → Correct
TheCMMC Assessment Guideis theofficial documentused to determine if anOSC meets the required security practices for certification.
CMMC 2.0 References Supporting This Answer:
CMMC Assessment Process (CAP) Document
Specifies thatLead Assessors must use the CMMC Assessment Guidefor official scoring.
CMMC Assessment Guide for Level 1 & Level 2
Providesdetailed descriptions, assessment methods, and scoring criteriafor each practice.
CMMC-AB Guidance for Certified Third-Party Assessment Organizations (C3PAOs)
Confirms thatCMMC assessments must follow the Assessment Guide, not general DoD security policies.
Final Answer:
✔D. Published CMMC Assessment Guide practice descriptions for the desired certification level.
What service is the MOST comprehensive that the RPO provides?
Options:
Training services
Education services
Consulting services
Assessment services
Answer:
CExplanation:
Understanding the Role of a Registered Provider Organization (RPO)
ARegistered Provider Organization (RPO)is an entity recognized by theCMMC Accreditation Body (CMMC-AB)to provideconsulting servicesto organizations seekingCMMC certification.
Key Functions of an RPO
✅Consulting servicesto help companies prepare for CMMC assessments.
✅Guidance on security controlsrequired for compliance.
✅Assistance with documentation, policy development, and gap analysis.
✅Preparation for third-party CMMC assessmentsbutdoes not conduct official CMMC assessments(this is the role of a C3PAO).
Why " Consulting Services " is the Correct Answer?
Consulting servicesare thebroadest and most comprehensivefunction of an RPO.
RPOs do not conduct assessments(eliminating option D).
Training and educationmay be part of consulting but arenot the primary function(eliminating A and B).
Consulting includes training, guidance, documentation assistance, and security readiness, making it themost comprehensive service offered.
Breakdown of Answer Choices
Option
Description
Correct?
A. Training services
❌Incorrect–RPOs may provide training, but this isnot their primary function.
B. Education services
❌Incorrect–Similar to training, butnot the most comprehensive service.
C. Consulting services
✅Correct – The core function of an RPO is consulting, which includes various readiness services.
D. Assessment services
❌Incorrect–Only aC3PAO (Certified Third-Party Assessment Organization)can conductofficial CMMC assessments.
Official References from CMMC 2.0 Documentation
TheCMMC-AB RPO Programdefines an RPO as aconsulting organization that assists companies in preparing for CMMC certificationbutdoes not perform assessments.
Final Verification and Conclusion
The correct answer isC. Consulting services, asRPOs primarily provide advisory and readiness supportto organizations preparing forCMMC compliance.
A company is working with a CCP from a contracted CMMC consulting company. The CCP is asked where the Host Unit is required to document FCI and CUI for a CMMC Assessment. How should the CCP respond?
Options:
" In the SSP. within the asset inventory, and in the network diagranY '
" Within the hardware inventory, data (low diagram, and in the network diagram "
" Within the asset inventory, in the proposal response, and in the network diagram "
" In the network diagram, in the SSP. within the base inventory, and in the proposal response ' "
Answer:
AExplanation:
ACertified CMMC Professional (CCP)advising anOrganization Seeking Certification (OSC)must ensure thatFederal Contract Information (FCI)andControlled Unclassified Information (CUI)are properly documented within required security documents.
Step-by-Step Breakdown:
✅1. System Security Plan (SSP)
CMMC Level 2requires anSSPto documenthow CUI is protected, including:
Security controlsimplemented
Asset categorization(CUI Assets, Security Protection Assets, etc.)
Policies and proceduresfor handling CUI
✅2. Asset Inventory
Anasset inventorylistsall relevant IT systems, applications, and hardwarethat store, process, or transmitCUI or FCI.
TheCMMC Scoping Guiderequires OSCs to identifyCUI-relevant assetsas part of their compliance.
✅3. Network Diagram
Anetwork diagramvisually representshow data flows across systems, showing:
WhereCUI is transmitted and stored
Security boundaries protectingCUI Assets
Connectivity betweenCUI Assets and Security Protection Assets
✅4. Why the Other Answer Choices Are Incorrect:
(B) Within the hardware inventory, data flow diagram, and in the network diagram❌
While adata flow diagramis useful,hardware inventory alone is insufficientto document CUI.
(C) Within the asset inventory, in the proposal response, and in the network diagram❌
Aproposal responseis not a required document for CMMC assessments.
(D) In the network diagram, in the SSP, within the base inventory, and in the proposal response❌
Base inventoryis not a specific CMMC documentation requirement.
Final Validation from CMMC Documentation:
TheCMMC Assessment Guideconfirms that FCI and CUI must be documented in:
The SSP
The asset inventory
The network diagram
Thus, the correct answer is:
✅A. " In the SSP, within the asset inventory, and in the network diagram. "
The Lead Assessor interviews a network security specialist of an OSC. The incident monitoring report for the month shows that no security incidents were reported from OSC ' s external SOC service provider. This is provided as evidence for RA.L2-3.11.2: Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. Based on this information, the Lead Assessor should conclude that the evidence is:
Options:
inadequate because it is irrelevant to the practice.
adequate because it fits well for expected artifacts.
adequate because no security incidents were reported.
inadequate because the OSC ' s service provider should be interviewed.
Answer:
AExplanation:
Understanding RA.L2-3.11.2: Vulnerability Scanning
TheRA.L2-3.11.2practice requires organizations to:
✔Regularly scan for vulnerabilitiesin systems and applications.
✔Perform scans when new vulnerabilities are identified.
✔Use vulnerability scanning tools or servicesto proactively detect security weaknesses.
Why Is an Incident Monitoring Report Irrelevant?
Anincident monitoring reporttrackssecurity incidents, notvulnerability scanning activities.
Vulnerability scanning reportsshould include:
✔A list of vulnerabilities detected.
✔Remediation actions taken.
✔Scan frequency and schedule.
Theabsence of reported security incidentsdoesnotconfirm that vulnerability scans were performed.
Why is the Correct Answer " A. Inadequate because it is irrelevant to the practice " ?
A. Inadequate because it is irrelevant to the practice → Correct
Alack of reported security incidents does not confirm that vulnerability scanning was performed.
B. Adequate because it fits well for expected artifacts → Incorrect
Incident monitoring reportsare not expected artifactsfor this control.Vulnerability scan reportsare required instead.
C. Adequate because no security incidents were reported → Incorrect
The absence of incidents does not mean the OSC is performing vulnerability scanning. This isnot valid evidence.
D. Inadequate because the OSC ' s service provider should be interviewed → Incorrect
While interviewing the provider may be useful, themain issue is that the provided evidence is irrelevant. Thecorrect evidence (vulnerability scan reports) is missing.
CMMC 2.0 References Supporting This Answer:
NIST SP 800-171 (Requirement 3.11.2 – Vulnerability Scanning)
Defines the requirement toscan for vulnerabilities periodically and when new threats emerge.
CMMC Assessment Guide for Level 2
Specifies that evidence for RA.L2-3.11.2 should includevulnerability scan reports, not incident monitoring reports.
CMMC 2.0 Model Overview
Confirms that organizationsmust proactively identify vulnerabilities through scanning, not just rely on incident detection.
An assessment procedure consists of an assessment objective, potential assessment methods, and assessment objects. Which statement is part of an assessment objective?
Options:
Specifications and mechanisms
Examination, interviews, and testing
Determination statement related to the practice
Exercising assessment objects under specified conditions
Answer:
CExplanation:
Understanding CMMC Assessment Procedures
ACMMC assessment procedureconsists of:
Assessment Objective– Defines what is being evaluated and the expected outcome.
Assessment Methods– Specifies how the evaluation is conducted (e.g.,examination, interviews, testing).
Assessment Objects– Identifies what is being evaluated, such as policies, systems, or people.
Why the Correct Answer is " C " ?
Assessment Objectivesincludedetermination statementsthat describe the expected outcome for each CMMC security practice.
These statements define whether a practice has beenadequately implementedbased ondocumented evidence and assessment findings.
TheCMMC Assessment Process (CAP) GuideandNIST SP 800-171Aspecify that each practice has a determination statement guiding assessment decisions.
Why Not the Other Options?
A. Specifications and mechanisms→Incorrect
These belong toassessment objects, which refer to the systems, policies, and mechanisms being evaluated.
B. Examination, interviews, and testing→Incorrect
These areassessment methods, which describe how assessorsverifycompliance (e.g., through interviews or testing).
D. Exercising assessment objects under specified conditions→Incorrect
This refers toassessment testing, which is a method, not an assessment objective.
Relevant CMMC 2.0 References:
CMMC Assessment Process (CAP) Guide– Describes determination statements as the core of assessment objectives.
NIST SP 800-171A– Defines determination statements as a key element of evaluating security controls.
Final Justification:
Since anassessment objectiveincludes adetermination statementthat describes whether a practice is implemented properly, the correct answer isC.
Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?
Options:
Level 1
Level 2
Level 3
All levels
Answer:
BExplanation:
Understanding Training Requirements in CMMC
The requirement for ensuring thatpersonnel are trained to carry out their assigned information security-related duties and responsibilitiesfirst appears inCMMC Level 2as part ofNIST SP 800-171 control AT.L2-3.2.1.
Key Details on the Training Requirement:
✔AT.L2-3.2.1: " Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. "
✔This control is derived fromNIST SP 800-171and applies toCMMC Level 2 (Advanced).
✔It ensures that employees handlingControlled Unclassified Information (CUI)understand theircybersecurity responsibilities.
Why is the Correct Answer " B. Level 2 " ?
A. Level 1 → Incorrect
CMMC Level 1 does not include this training requirement.Level 1 focuses on basic safeguarding ofFederal Contract Information (FCI)but doesnot require formal cybersecurity training.
B. Level 2 → Correct
The training requirement (AT.L2-3.2.1) first appears in CMMC Level 2, which aligns withNIST SP 800-171.
C. Level 3 → Incorrect
The training requirementalready exists in Level 2. Level 3 builds on Level 2 with additionalrisk management and advanced cybersecurity controls, but training is introduced at Level 2.
D. All levels → Incorrect
CMMC Level 1 does not include this requirement—it is first introduced in Level 2.
CMMC 2.0 References Supporting This Answer:
NIST SP 800-171 (Requirement 3.2.1)
Defines themandatory training requirementfor personnel handling CUI.
CMMC Assessment Guide for Level 2
ListsAT.L2-3.2.1as a required practice under Level 2.
CMMC 2.0 Model Overview
Confirms thatCMMC Level 2 aligns with NIST SP 800-171, which includes security training requirements.
What is DFARS clause 252.204-7012 required for?
Options:
All DoD solicitations and contracts
Solicitations and contracts that use FAR part 12 procedures
Procurements solely for the acquisition of commercial off-the-shelf
Commercial off-the-shelf sold in the marketplace without modifications
Answer:
ADuring a POA & M closeout assessment , the Lead Assessor and team members verified all evidence provided by the OSC and passed those that satisfied the requirements. Who MUST verify that every failed practice from the initial original assessment has been adequately addressed?
Options:
OSC
CCA
OSC sponsor
Lead Assessor
Answer:
DExplanation:
In CMMC v2.0, the closeout activity for remediating previously unmet requirements is handled through the POA & M closeout process described in the CMMC Assessment Process (CAP) v2.0 . CAP v2.0 makes clear that the C3PAO must follow DoD’s POA & M closeout procedures and that the Assessment Team performs the closeout work, with the assessment results then undergoing a required quality assurance (QA) review .
Operationally, the person who must ensure that each previously failed requirement is adequately addressed during the closeout assessment is the Lead Assessor (Lead CCA) , because the Lead CCA is the individual designated to oversee and manage the Assessment Team on behalf of the C3PAO for the conduct of the certification assessment. In other words, while team members may test controls and collect evidence, the Lead CCA is accountable for directing the assessment effort and ensuring that remediation evidence supports updated determinations.
CAP v2.0 also states that a QA individual performs a quality assurance review of the POA & M closeout “upon completion by the Assessment Team,” including checks on the accuracy and completeness of evaluation of POA & M security requirements before upload to eMASS. This reinforces that verification occurs through the assessment team’s work, led by the Lead Assessor , and then independently quality-checked by QA.
===========
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
Options:
have a security clearance.
be a senior person in the company.
demonstrate expertise on the CMMC requirements.
provide clarity and understanding of their practice activities.
Answer:
DExplanation:
Interview Selection in CMMC Assessments
During aCMMC assessment, theLead Assessormust work with theOrganization Seeking Certification (OSC)to select personnel for interviews. The goal is to:
✅Verify that personnel understand andperform security-related practices.
✅Ensure that individuals canexplain how they implement CMMC requirements.
✅Gain insight intoactual cybersecurity operationsrather than just documented policies.
The best interviewees are those whodirectly engage with security practicesand canclearly explain how they perform their duties.
Why " Providing Clarity and Understanding " Is Key
CMMC assessmentsrely on interviewsto validate that security practices areimplemented effectively.
Themost valuable intervieweesare those who canexplainhow security measures are appliedin day-to-day operations.
CMMC Assessment Process (CAP)emphasizes that assessors should speak tothose actively involved in security practicesrather than just senior management or policy owners.
Thus,option D is the correct choicebecause the Lead Assessor should prioritizeinterviewing personnel who can clearly explain how CMMC practices are implemented.
Why the Other Answers Are Incorrect
A. Have a security clearance.
❌Incorrect.Security clearance is not a requirementfor CMMC assessments. The focus is onpractical implementation of security controls, not classified work.
B. Be a senior person in the company.
❌Incorrect. Senior executives may not be involved in theactual implementation of security controls. The best interviewees are those whoperform the work, not just oversee it.
C. Demonstrate expertise on the CMMC requirements.
❌Incorrect. Whileunderstanding CMMC is important, expertise alonedoes not guarantee practical knowledgeof security controls. The key is thatinterviewees must provide clarity on how they perform security tasks.
CMMC Official References
CMMC Assessment Process (CAP) Document– Guides interview selection based on personnel who perform security functions.
NIST SP 800-171 & CMMC 2.0– Emphasize that cybersecurity controls must beactively implemented, not just documented.
Thus,option D (Provide clarity and understanding of their practice activities) is the correct answeras per official CMMC assessment guidelines.
While conducting a CMMC Assessment, a Lead Assessor is given documentation attesting to Level 1 identification and authentication practices by the OSC. The Lead Assessor asks the CCP to review the documentation to determine if identification and authentication controls are met. Which documentation BEST satisfies the requirements of IA.L1-3.5.1: Identify system users. processes acting on behalf of users, and devices?
Options:
Procedures for implementing access control lists
List of unauthorized users that identifies their identities and roles
User names associated with system accounts assigned to those individuals
Physical access policy that states. " All non-employees must wear a special visitor pass or be escorted. "
Answer:
CExplanation:
Understanding IA.L1-3.5.1 (Identification and Authentication Requirements)
TheCMMC 2.0 Level 1practiceIA.L1-3.5.1aligns withNIST SP 800-171, Requirement 3.5.1, which mandates that organizationsidentify system users, processes acting on behalf of users, and devicesto ensure proper access control.
To comply with this requirement, anOrganization Seeking Certification (OSC)must maintain documentation that demonstrates:
A unique identifier (username) for each system user
Mapping of system accounts to specific individuals
Identification of devices and automated processes that access systems
Why " C. User names associated with system accounts assigned to those individuals " is Correct?
This documentation directly satisfies IA.L1-3.5.1because it showshow system users are uniquely identified and linked to specific accountswithin the environment.
Alist of users and their assigned accountsconfirms that the organization has a structured method oftracking access and authentication.
It allows auditors to verify thateach user has a distinct identityand that access control mechanisms are properly applied.
Why Other Answers Are Incorrect?
A. Procedures for implementing access control lists (Incorrect)
While access control lists (ACLs) are relevant for authorization, they do notidentify users or devicesspecifically, making them insufficient as primary evidence for IA.L1-3.5.1.
B. List of unauthorized users that identifies their identities and roles (Incorrect)
Identifying unauthorized users does not fulfill the requirement of trackingauthorizedusers, devices, and processes.
D. Physical access policy stating " All non-employees must wear a special visitor pass or be escorted " (Incorrect)
This pertains tophysical security, not system-baseduser identification and authentication.
Conclusion
The correct answer isC. User names associated with system accounts assigned to those individuals, as thisdirectly satisfies the identification requirement of IA.L1-3.5.1.
An OSC lead has provided company information, identified that they are seeking CMMC Level 2, stated that they handle FCI. identified stakeholders, and provided assessment logistics. The OSC has provided the company ' s cyber hygiene practices that are posted on every workstation, visitor logs, and screenshots of the configuration of their FedRAMP-approved applications. The OSC has not won any DoD government contracts yet but is working on two proposals Based on this information, which statement BEST describes the CMMC Level 2 Assessment requirements?
Options:
Ready because there is no need to certify this company until after they win a DoD contract.
Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract.
Not ready because the OSC still lacks artifacts that prove they have implemented all the CMMC Level 2 Assessment requirements.
Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification.
Answer:
CExplanation:
CMMC Level 2 Readiness and Certification Requirements
CMMCLevel 2is required forOrganizations Seeking Certification (OSCs) that handle Controlled Unclassified Information (CUI)and aligns withNIST SP 800-171 ' s 110 security controls.
Key Readiness Indicators for a Level 2 Assessment:
The OSC must have implemented all 110 security practices from NIST SP 800-171.
Documented and validated cybersecurity policies and procedures must exist.
The OSC must be prepared to provide objective evidence (artifacts) proving compliance.
Why the OSC in the Question is Not Ready:
They have not won a DoD contract yet→ This means they do not yet have a contractually definedCUI environment, which is the foundation for defining their security scope.
They have only provided FCI-related artifacts(e.g., visitor logs, workstation policies, FedRAMP configurations).
Lack of full documentation of CMMC Level 2 controls→ The assessment requiresevidence for all 110 security practices(e.g., system security plans, incident response records, security awareness training documentation).
Clarification of Incorrect Options:
A. " Ready because there is no need to certify this company until after they win a DoD contract. "
Incorrect→ Some organizationsseek certification proactivelybefore winning contracts. However, readiness depends on implementingall 110 required controls, not contract status alone.
B. " Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract. "
Incorrect→ CMMC Level 2focuses on CUI, not just FCI. While FCI protection is important, the assessment’s focus is onCUI security requirements, which arenot fully addressed by the provided artifacts.
D. " Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification. "
Incorrect→ While it is commendable that the OSC is being proactive,readiness is based on full compliance with NIST SP 800-171, not just intent.
What activities are conducted while developing an assessment plan?
Options:
The C3PAO decides the Assessment Team members and notifies the Lead Assessor.
The Lead Assessor and the OSC’s sponsor determine the assessment resources and schedule.
The C3PAO’s project manager is responsible for handling potential conflicts of interest.
The evidence collection approach can be finalized when the Lead Assessor conducts an onsite assessment.
Answer:
BExplanation:
In the CAP v2.0 “preliminary proceedings,” the assessment is “framed” before Phase 1/Phase 2 execution. CAP states the C3PAO works with the OSC’s leadership point(s) of contact (the Affirming Official and/or OSC POC ) “to determine the purview and planning details of the assessment,” explicitly including schedule , personnel , logistics , relevant contractual requirements, and the prospective CMMC Assessment Scope .
Although the question uses the term “OSC sponsor,” the CAP’s official role language is Affirming Official / OSC POC , and the Lead CCA (Lead Assessor) is the assessor counterpart. CAP further explains that the In-Brief Meeting establishes a common understanding of objectives, roles/responsibilities, and the schedule , and the Lead CCA must (at minimum) review the schedule and confirm assessment scope with the OSC.
Option A is incomplete because team assignment is a C3PAO responsibility, but CAP’s “plan” emphasis here is broader framing: availability of personnel/evidence, documentation readiness, timing, and logistics. Option C is incorrect because CAP states C3PAOs are ultimately responsible for managing conflicts of interest and this responsibility cannot be delegated to the assessment team or the OSC. Option D is incorrect because CAP requires evaluation methods and evidence planning activities to be established during Phase 1 planning, not deferred until onsite work.
===========
Which standard and regulation requirements are the CMMC Model 2.0 based on?
Options:
NIST SP 800-171 and NIST SP 800-172
DFARS, FIPS 100, and NIST SP 800-171
DFARS, NIST, and Carnegie Mellon University
DFARS, FIPS 100, NIST SP 800-171, and Carnegie Mellon University
Answer:
AExplanation:
TheCybersecurity Maturity Model Certification (CMMC) 2.0is primarily based on two key National Institute of Standards and Technology (NIST) Special Publications:
NIST SP 800-171– " Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations "
NIST SP 800-172– " Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171 "
Reference and Breakdown:
NIST SP 800-171
This document is thecore foundationof CMMC 2.0 and establishes the security requirements for protectingControlled Unclassified Information (CUI)in non-federal systems.
The 110 security controls fromNIST SP 800-171 Rev. 2are mapped directly toCMMC Level 2.
NIST SP 800-172
This supplement includesenhanced security requirementsfor organizations handlinghigh-value CUIthat faces advanced persistent threats (APTs).
These enhanced requirements apply toCMMC Level 3under the 2.0 model.
Eliminating Incorrect Answer Choices:
B. DFARS, FIPS 100, and NIST SP 800-171→Incorrect
WhileDFARS 252.204-7012mandates compliance withNIST SP 800-171,FIPS 100 does not existas a relevant cybersecurity standard.
C. DFARS, NIST, and Carnegie Mellon University→Incorrect
CMMC is aligned with DFARS and NIST but isnot developed or directly influenced by Carnegie Mellon University.
D. DFARS, FIPS 100, NIST SP 800-171, and Carnegie Mellon University→Incorrect
Again,FIPS 100 is not relevant, andCarnegie Mellon Universityis not a defining entity in the CMMC framework.
Official CMMC 2.0 References Supporting the Answer:
CMMC 2.0 Scoping Guide (2023)confirms thatCMMC Level 2 is entirely based on NIST SP 800-171.
CMMC 2.0 Level 3 Draft Documentationexplicitly referencesNIST SP 800-172for enhanced security requirements.
DoD Interim Rule (DFARS 252.204-7021)mandates that organizations meetNIST SP 800-171 for CUI protection.
Final Conclusion:
The CMMC 2.0 model is derivedsolely from NIST SP 800-171 and NIST SP 800-172, makingAnswer A the only correct choice.
A client uses an external cloud-based service to store, process, or transmit data that is reasonably believed to qualify as CUI. According to DFARS clause 252.204-7012. what set of established security requirements MUST that cloud provider meet?
Options:
FedRAMP Low
FedRAMP Moderate
FedRAMP High
FedRAMP Secure
Answer:
BExplanation:
UnderDFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting), if acontractoruses acloud-based serviceto store, process, or transmitControlled Unclassified Information (CUI), the cloud providermustmeet the security requirements ofFedRAMP Moderate or equivalent.
Key Requirements from DFARS 252.204-7012 (c)(1):
CUI stored in the cloud must be protected according to FedRAMP Moderate (or higher) requirements.
The cloud provider must meetFedRAMP Moderate baseline security controls, which align withNIST SP 800-53moderate impact level requirements.
The cloud provider must also ensure compliance withincident reportingandcyber incident response requirementsin DFARS 252.204-7012.
Why is the Correct Answer " FedRAMP Moderate " (B)?
A. FedRAMP Low → Incorrect
FedRAMP Lowis intended for systems withlow confidentiality, integrity, and availability risks, making itinadequate for CUI protection.
B. FedRAMP Moderate → Correct
FedRAMP Moderate is the minimum required level for CUIunder DFARS 252.204-7012.
It provides a security baseline for protectingsensitive but unclassified government data.
C. FedRAMP High → Incorrect
FedRAMP Highapplies to systems handlinghighly sensitive information (e.g., classified or national security data), which is not necessarily required for CUI.
D. FedRAMP Secure → Incorrect
There isno official FedRAMP Secure categoryin FedRAMP guidelines.
CMMC 2.0 References Supporting this Answer:
DFARS 252.204-7012(c)(1)
Specifies thatcontractors using external cloud services for CUI must meet FedRAMP Moderate or equivalent.
CMMC 2.0 Level 2 Requirements
CUI must be protected using NIST SP 800-171 security requirements, whichalign with FedRAMP Moderate controls.
FedRAMP Security Baselines
FedRAMP Moderateis designed for systems that handlesensitive government data, including CUI.
Which government agency are DoD contractors required to report breaches of CUI to?
Options:
FBI
NARA
DoD Cyber Crime Center
Under Secretary of Defense for Intelligence and Security
Answer:
CExplanation:
Who Do DoD Contractors Report CUI Breaches To?
PerDFARS 252.204-7012, all DoD contractors handlingControlled Unclassified Information (CUI)must report cyber incidents to theDoD Cyber Crime Center (DC3).
Key Reporting Requirements
✅Cyber incidents involving CUI must be reported toDC3 within 72 hours.
✅Reports must be submitted via theDoD ' s Cyber Incident Reporting Portal.
✅Contractors mustpreserve forensic evidencefor potential investigation.
Why " DoD Cyber Crime Center " is Correct?
The FBI (Option A) handles criminal investigations, but DoD contractorsmust report cyber incidents to DC3.
NARA (Option B) oversees the CUI Registry, butis not responsible for breach reporting.
The Under Secretary of Defense for Intelligence and Security (Option D) is responsible for intelligence operations, not incident reporting.
Breakdown of Answer Choices
Option
Description
Correct?
A. FBI
❌Incorrect–The FBI handlescriminal cases, not CUI breach reporting.
B. NARA
❌Incorrect–NARA manages theCUI Registry, butdoes not handle breaches.
C. DoD Cyber Crime Center
✅Correct – Per DFARS 252.204-7012, cyber incidents involving CUI must be reported to DC3.
D. Under Secretary of Defense for Intelligence and Security
❌Incorrect–This office doesnothandle cyber incident reports.
Official References from CMMC 2.0 and DFARS Documentation
DFARS 252.204-7012– Requires DoD contractors to report CUI-related cyber incidents toDC3.
DoD Cyber Crime Center (DC3) Website– The official platform forcyber incident reporting.
Final Verification and Conclusion
The correct answer isC. DoD Cyber Crime Center, as perDFARS 252.204-7012, which mandates that all DoD contractors reportCUI breaches to DC3 within 72 hours.
What is the primary intent of the verify evidence and record gaps activity?
Options:
Map test and demonstration responses to CMMC practices.
Conduct interviews to test process implementation knowledge.
Determine the one-to-one relationship between a practice and an assessment object.
Identify and describe differences between what the Assessment Team required and the evidence collected.
Answer:
DExplanation:
Understanding the “Verify Evidence and Record Gaps” Activity in a CMMC Assessment
During aCMMC Level 2 Assessment, theAssessment Teamfollows a structured methodology toverify evidenceand determine whether theOrganization Seeking Certification (OSC)has met all required practices. One of the key activities in this process is " Verify Evidence and Record Gaps " , which ensures that the assessment findings accurately reflect any missing or inadequate compliance evidence.
Step-by-Step Breakdown:
✅1. Primary Intent: Identifying Gaps Between Required and Collected Evidence
TheAssessment Teamcompares the evidence provided by the OSC against theCMMC practice requirements.
If evidence ismissing, insufficient, or inconsistent, assessors mustdocument the gapand describe what is lacking.
This ensures that compliance deficiencies are clearly identified, allowing the OSC to understand what must be corrected.
✅2. How This Process Works in a CMMC Assessment
Assessorsreview collected documentation, system configurations, policies, and interview responses.
They verify that the evidencematches the expected implementationof a practice.
If gaps exist, they arerecordedfor discussion and potential remediation before assessment completion.
✅3. Why the Other Answer Choices Are Incorrect:
(A) Map test and demonstration responses to CMMC practices.❌
Incorrect:While mapping evidence to CMMC practices is part of the assessment, theprimary intentof the " Verify Evidence and Record Gaps " step is toidentify deficiencies, not just mapping responses.
(B) Conduct interviews to test process implementation knowledge.❌
Incorrect:Interviews are a method used during evidence collection, but they arenot the primary focusof the verification and gap analysis step.
(C) Determine the one-to-one relationship between a practice and an assessment object.❌
Incorrect:The assessment teamreviews multiple sources of evidencefor each practice, and some practices require multiple assessment objects. The goal isnot a strict one-to-one mappingbut rathera holistic validation of compliance.
Final Validation from CMMC Documentation:
TheCMMC Assessment Process Guidestates that " Verify Evidence and Record Gaps " is the step where assessorscompare expected evidence against what has been provided and document discrepancies. This ensurestransparent assessment findings and remediation planning.
Thus, the correct answer is:
D. Identify and describe differences between what the Assessment Team required and the evidence collected.
During an assessment, the Lead Assessor reviews the evidence for each CMMC in-scope practice that has been reviewed, verified, rated, and discussed with the OSC during the daily reviews. The Assessment Team records the final recommended MET or NOT MET rating and prepares to present the results to the assessment participants during the final review with the OSC and sponsor. As a part of this presentation, which document MUST include the attendee list, time/date, location/meeting link, results from all discussed topics, including any resulting actions, and due dates from the OSC or Assessment Team?
Options:
Final log report
Final CMMC report
Final and recorded OSC CMMC report
Final and recorded Daily Checkpoint log
Answer:
DExplanation:
Understanding the Final Review Process in a CMMC Assessment
During aCMMC Level 2 Assessment, theAssessment Teamand theOrganization Seeking Certification (OSC)holddaily checkpoint meetingsto discuss progress, review evidence, and ensure transparency.
At theend of the assessment, afinal review meetingis conducted, during which theLead Assessor presents the results. Therecorded Daily Checkpoint logserves as theofficial document summarizing:
Theattendee list
Time, date, and locationof the final review
Final MET or NOT MET ratingsfor all practices
Discussion points, resulting actions, and due datesfor both the OSC and Assessment Team
Why " D. Final and recorded Daily Checkpoint log " is Correct?
TheCMMC Assessment Process (CAP) Guidespecifies that all assessment findings and discussions must bedocumented throughout the assessment in daily checkpoint logs.
TheFinal and Recorded Daily Checkpoint Logincludes all necessary details, such as attendee lists, discussion topics, and action items.
This document isused to ensure all discussed topics and agreed-upon actions are properly tracked and recordedbefore submission.
Why Other Answers Are Incorrect?
A. Final log report (Incorrect)
There isno specific " Final Log Report " required in CMMC assessments.
B. Final CMMC report (Incorrect)
TheFinal CMMC Reportdocuments the overall assessment results butdoes not serve as the official meeting logfor the final review discussion.
C. Final and recorded OSC CMMC report (Incorrect)
This documentdoes not include detailed discussion points from the daily checkpoint meetings.
Conclusion
The correct answer isD. Final and recorded Daily Checkpoint log, as this is the official document that captures thefinal meeting details, discussions, and action items.
Which document is the BEST source for descriptions of each practice or process contained within the various CMMC domains?
Options:
CMMC Glossary
CMMC Appendices
CMMC Assessment Process
CMMC Assessment Guide Levels 1 and 2
Answer:
DExplanation:
Understanding the Best Source for CMMC Practice Descriptions
TheCMMC Assessment Guide (Levels 1 and 2)is theprimaryandmost authoritativedocument for detailed descriptions of each practice and process within the variousCMMC domains.
Step-by-Step Breakdown:
✅1. What is the CMMC Assessment Guide?
TheCMMC Assessment Guideprovides detailed explanations of:
EachCMMC practicewithin its respectivedomain.
Theassessment objectivesfor verifying implementation.
Examples ofevidence requiredto demonstrate compliance.
CMMC 2.0 includes two levels:
Level 1: 17 basic cybersecurity practices.
Level 2: 110 practices aligned withNIST SP 800-171.
TheAssessment Guidedefines howassessorsevaluate compliance.
✅2. Why the Other Answer Choices Are Incorrect:
(A) CMMC Glossary❌
TheGlossaryprovidesdefinitions of termsused in CMMC but does not describe specific practices in detail.
(B) CMMC Appendices❌
Appendicesinclude supplementary information likereferences and scoping guidance, but they do not provide full descriptions of practices.
(C) CMMC Assessment Process❌
TheAssessment Process Guideexplainshowassessments are conducted, but it doesnot describe each practicein detail.
Final Validation from CMMC Documentation:
TheCMMC Assessment Guide (Levels 1 and 2)is theofficialsource for descriptions of eachCMMC practice and process, making it thebest referencefor understanding compliance requirements.
During a Level 1 Self-Assessment, a smart thermostat was identified. It is connected to the Internet on the OSC ' s WiFi network. What type of asset is this?
Options:
FCI Asset
CUI Asset
In-scope Asset
Specialized Asset
Answer:
DExplanation:
Understanding Asset Categorization in CMMC 2.0
InCMMC 2.0, assets are categorized into different types based on their function, connectivity, and whether they process, store, or transmitFederal Contract Information (FCI) or Controlled Unclassified Information (CUI).
Why " D. Specialized Asset " is Correct?
TheCMMC 2.0 Scoping GuidedefinesSpecialized Assetsas assetsthat do not fit traditional IT classificationsbut still exist within the organizational environment.
Asmart thermostatis anInternet of Things (IoT) device, which falls underSpecialized Assetsas defined in CMMC.
Why Other Answers Are Incorrect?
A. FCI Asset (Incorrect)
FCI Assets process, store, or transmit Federal Contract Information, which asmart thermostat does not.
B. CUI Asset (Incorrect)
CUI Assets handle Controlled Unclassified Information, and athermostat does not process CUI.
C. In-scope Asset (Incorrect)
In-scope Assets include FCI and CUI assets, which asmart thermostat does not qualify as.
Conclusion
The correct answer isD. Specialized Asset, as asmart thermostat is an IoT device, which falls into theSpecialized Assetcategory.
In CMMC High-Level scoping, which definition BEST describes an HQ organization?
Options:
The entity that carries out the tasks under a contract
The unit to which a CMMC Level is applied for each contract
The teams, services, and technologies that provide support to a Host Unit
The entity legally responsible for the delivery of products or services under a contract
Answer:
DExplanation:
In CMMC scoping terminology, an HQ Organization is the entity legally responsible for contract performance and delivery of products or services.
Supporting Extracts from Official Content:
CMMC Scoping Guide: “HQ Organization is the legal entity responsible for the performance and delivery of contract requirements.”
Why Option D is Correct:
The HQ Org is legally accountable, while Host Units (option A/B) are subordinate entities.
Option C refers to shared services, not the HQ.
References (Official CMMC v2.0 Content):
CMMC Scoping Guide, High-Level Scoping Definitions.
===========
An Assessment Team is conducting interviews with team members about their roles and responsibilities. The team member responsible for maintaining the antivirus program knows that it was deployed but has very little knowledge on how it works. Is this adequate for the practice?
Options:
Yes, the antivirus program is available, so it is sufficient.
Yes, antivirus programs are automated to run independently.
No, the team member must know how the antivirus program is deployed and maintained.
No, the team member ' s interview answers about deployment and maintenance are insufficient.
Answer:
CExplanation:
For a practice to beadequately implementedin aCMMC Level 2 assessment, theresponsible personnel must demonstrate knowledge of deployment, maintenance, and operationof security tools such asantivirus programs. Simply having the tool in place isnot sufficient—there must be evidence that it isproperly configured, updated, and monitoredto protect against threats.
Step-by-Step Breakdown:
✅1. Relevant CMMC and NIST SP 800-171 Requirements
CMMC Level 2 aligns with NIST SP 800-171, which includes:
Requirement 3.14.5 (System and Information Integrity - SI-3):
" Employautomatedmechanisms toidentify, report, and correctsystem flaws in a timely manner. "
Requirement 3.14.6 (SI-3(2)):
" Employautomated toolsto detect and prevent malware execution. "
These requirements imply that theperson responsible for antivirus must understand how it is deployed and maintainedto ensure compliance.
✅2. Why the Team Member’s Knowledge is Insufficient
Antivirus tools requireregular updates,configuration adjustments, andmonitoringto function properly.
The responsible team member must:
Knowhow the antivirus was deployedacross systems.
Be able toconfirm updates, logs, and alerts are monitored.
Understand how torespond to malware detectionsand failures.
If the team member lacks this knowledge, assessors maydetermine the practice is not fully implemented.
✅3. Why the Other Answer Choices Are Incorrect:
(A) Yes, the antivirus program is available, so it is sufficient.❌
Incorrect:Just having antivirus softwareinstalleddoes not prove compliance. It must bemanaged and maintained.
(B) Yes, antivirus programs are automated to run independently.❌
Incorrect:While automation helps, security toolsrequire oversight, updates, and configuration.
(D) No, the team member ' s interview answers about deployment and maintenance are insufficient.❌
Partially correct but incomplete:Themain issueis that the team membermust have sufficient knowledge, not just that their answers are weak.
Final Validation from CMMC Documentation:
TheCMMC Assessment Guide for SI-3 and SI-3(2)states that personnel mustunderstand the function, deployment, and maintenance of security toolsto ensure proper implementation.
Thus, the correct answer is:
During the review of information that was published to a publicly accessible site, an OSC correctly identifies that part of the information posted should have been restricted. Which item did the OSC MOST LIKELY identify?
Options:
FCI
Change of leadership in the organization
Launching of their new business service line
Public releases identifying major deals signed with commercial entities
Answer:
AExplanation:
Understanding Federal Contract Information (FCI) and Publicly Accessible Information
Federal Contract Information (FCI)isnon-public informationprovided by or generated for the U.S. governmentunder a contractthat isnot intended for public release.
Key Characteristics of FCI:
✔FCI includesdetails related togovernment contracts, project specifics, and performance data.
✔It must be protected under FAR 52.204-21, which requiresbasic safeguarding measuresto prevent unauthorized access.
✔Posting FCI on a public site is a security violationsince it ismeant to be restrictedfrom public disclosure.
Why is the Correct Answer " A. FCI (Federal Contract Information) " ?
A. FCI → Correct
FCI must be protected from unauthorized access, and if it wasincorrectly published online, it should have been restricted.
B. Change of leadership in the organization → Incorrect
Leadership changes are typically public informationand do not require restriction unless they involve sensitive government-related security clearances.
C. Launching of their new business service line → Incorrect
Marketing and business announcementsare generallypublicly availableandnot restricted information.
D. Public releases identifying major deals signed with commercial entities → Incorrect
Commercial contracts and business deals are not considered FCIunless they involvegovernment contracts.
CMMC 2.0 References Supporting This Answer:
FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems)
DefinesFCI as sensitive but unclassified informationthat must beprotected from public disclosure.
CMMC 2.0 Level 1 Requirements
Requires contractors toprotect FCI under basic cybersecurity standardsto prevent unauthorized exposure.
DoD Guidance on FCI Protection
States thatpublishing FCI on public websites violates federal cybersecurity requirements.
An assessor has been working with an OSC ' s point of contact to plan and prepare for their upcoming assessment. What is one of the MOST important things to remember when analyzing requirements for an assessment?
Options:
Scoping an assessment is easy and worry-free.
The initial plan cannot be changed once agreed upon.
There is a determined amount of time that the OSC ' s point of contact has to submit evidence and rough order-of-magnitude.
Assessors need to continuously review and update the requirements and plan for the assessment as information is gathered.
Answer:
DExplanation:
Planning and preparing for aCMMC assessmentinvolves collaboration between theassessorand theOrganization Seeking Certification (OSC)to determine scope, required evidence, and logistics. This planning process isdynamicand must adapt as new information emerges.
Why the Correct Answer is " D " ?
Assessment Scope and Requirements May Change
As assessors gather evidence and analyze the environment,new details about assets, networks, and security controlsmay require adjustments to the assessment plan.
TheCMMC Assessment Process (CAP) Guideemphasizes that assessmentrequirements and scope should be continuously reviewed and updatedto reflect real-time findings.
Assessors Follow an Adaptive Approach
DuringCMMC assessments, organizations may discover additionalFCI or CUI assets, which can change the required security practices to be evaluated.
Assessors shouldrevise the assessment approach accordinglyrather than strictly following an initial, unchangeable plan.
Why Not the Other Options?
A. Scoping an assessment is easy and worry-free→Incorrect
Scoping is acritical and complex processthat requires careful evaluation of the OSC’s information systems and assets.
CMMC Scoping Guidestates thatidentifying in-scope assets is crucial and requires significant effort.
B. The initial plan cannot be changed once agreed upon→Incorrect
Theinitial assessment plan is a starting point, butit must be flexiblebased on real-time findings.
CMMC CAP Guideemphasizescontinuous refinementduring the assessment process.
C. There is a determined amount of time that the OSC ' s point of contact has to submit evidence and rough order-of-magnitude→Incorrect
While there aretimelines, the key focus is ensuring thatall necessary evidence is gathered accuratelyrather than rushing to meet a strict deadline.
Relevant CMMC 2.0 References:
CMMC Assessment Process (CAP) Guide– States that assessment requirements and planning should be updated as additional information is gathered.
CMMC Scoping Guide (Nov 2021)– Explains that assessors must continually refinein-scope assets and requirementsthroughout the process.
Final Justification:
Assessment planning is a dynamic process.Assessors must continuously review and update the requirements and planas new information emerges, makingDthe correct answer.
During a Level 2 Assessment, the OSC has provided an inventory list of all hardware. The list includes servers, workstations, and network devices. Why should this evidence be sufficient for making a scoring determination for AC.L2-3.1.19: Encrypt CUI on mobile devices and mobile computing platforms?
Options:
The inventory list does not specify mobile devices.
The interviewee attested to encrypting all data at rest.
The inventory list does not include Bring Your Own Devices.
The DoD has accepted an alternative safeguarding measure for mobile devices.
Answer:
AExplanation:
In the context of a Cybersecurity Maturity Model Certification (CMMC) Level 2 Assessment, specific practices must be evaluated to ensure compliance with established security requirements. One such practice is AC.L2-3.1.19, which mandates the encryption of Controlled Unclassified Information (CUI) on mobile devices and mobile computing platforms.
Step-by-Step Explanation:
Requirement Overview:
Practice AC.L2-3.1.19 requires organizations to " Encrypt CUI on mobile devices and mobile computing platforms. " This ensures that any CUI accessed, stored, or transmitted via mobile devices is protected through encryption, mitigating risks associated with data breaches or unauthorized access.
Assessment of Provided Evidence:
During the assessment, the Organization Seeking Certification (OSC) provided an inventory list encompassing servers, workstations, and network devices. Notably, this list lacks any mention of mobile devices or mobile computing platforms.
Implications of the Omission:
The absence of mobile devices in the inventory suggests that the OSC may not have accounted for all assets that process, store, or transmit CUI. Without a comprehensive inventory that includes mobile devices, it ' s challenging to verify whether the OSC has implemented the necessary encryption measures for CUI on these platforms.
Assessment Determination:
Given the incomplete inventory, the evidence is insufficient to make a definitive scoring determination for practice AC.L2-3.1.19. The OSC must provide a detailed inventory that encompasses all relevant devices, including mobile devices and computing platforms, to demonstrate compliance with the encryption requirements for CUI.
Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit, Supporting Organization/Unit, or enclave have been met?
Options:
OSC
Assessment Team
Authorizing official
Assessment official
Answer:
BExplanation:
Per the CMMC Assessment Process (CAP), the Assessment Team is responsible for determining the adequacy and sufficiency of evidence collected during the assessment. The team validates whether practices and components for each in-scope Host Unit, Supporting Organization, or enclave meet the target CMMC level. The OSC (Organization Seeking Certification) provides evidence, but only the Assessment Team makes the verification and scoring determination.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
For a CMMC Level 2 certification, which organization maintains a non-disclosure agreement with the OSC?
Options:
NIST
C3PAO
CMMC-AB
OUSD A & S
Answer:
BExplanation:
The Certified Third-Party Assessment Organization (C3PAO) enters into a contractual relationship with the OSC. As part of that contract, the C3PAO maintains a non-disclosure agreement (NDA) to protect sensitive and proprietary information reviewed during the assessment.
Supporting Extracts from Official Content:
CAP v2.0, Roles and Responsibilities (§2.8): “The C3PAO maintains a non-disclosure agreement with the OSC to protect all sensitive information disclosed during the assessment.”
Why Option B is Correct:
Only the C3PAO contracts directly with the OSC and is bound to protect assessment data.
NIST, The Cyber AB (formerly CMMC-AB), and OUSD A & S do not enter NDAs directly with OSCs.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Section on OSC–C3PAO agreements.
===========
During the assessment process, who is the final interpretation authority for recommended findings?
Options:
C3PAO
CMMC-AB
OSC sponsor
Assessment Team Members
Answer:
AExplanation:
According to the CMMC Assessment Process (CAP) and the roles defined within the CMMC Ecosystem, the responsibility for the final determination of assessment findings rests with the C3PAO (Certified Third-Party Assessment Organization).
While the Assessment Team (Lead Assessor and Assessor) performs the legwork—conducting interviews, examining documents, and testing mechanisms—the C3PAO is the legal entity contracted by the OSC (Organization Seeking Certification) to conduct the assessment and issue the recommendation for certification.
Role of the C3PAO: The C3PAO provides the quality assurance and oversight. Once the Assessment Team completes the draft findings, the C3PAO performs a quality or " peer " review to ensure the findings are consistent with CMMC requirements. They hold the final authority over the Recommended Finding (Met, Not Met, or N/A) before it is uploaded to the eMASS (Enterprise Mission Assurance Support Service) or the designated DoD database.
Role of the Cyber AB (formerly CMMC-AB): The Board provides the accreditation for the C3PAOs and manages the ecosystem, but they do not participate in individual assessments or overrule specific technical findings of an assessment unless there is a formal appeal or ethics complaint.
Role of the Assessment Team Members: They collect evidence and make initial determinations, but their findings are subject to the C3PAO’s internal quality management system (QMS) review.
Role of the OSC Sponsor: The OSC is the entity being assessed; they have no authority over the interpretation of findings, though they may provide additional evidence during the remediation period.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section on " Phase 3: Conduct Assessment " and " Phase 4: Reporting Results, " which details the C3PAO’s responsibility for the final package.
C3PAO Authorization Requirements: Outlines the requirement for a quality management review of all assessment findings by the C3PAO before submission to the DoD.
Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit. Supporting Organization/Unit, or enclave has been met?
Options:
OSC
Assessment Team
Authorizing official
Assessment official
Answer:
BExplanation:
Who Verifies the Adequacy and Sufficiency of Evidence?
In the CMMC assessment process, it is theAssessment Teamthat is responsible for verifying whether thepractices and related componentshave been met for each in-scopeHost Unit, Supporting Organization/Unit, or enclave.
TheCMMC Assessment Teamis composed of certified assessors and led by aCertified CMMC Assessor (CCA). Their primary role is to:
Review evidenceprovided by theOrganization Seeking Certification (OSC).
Determine compliancewith required CMMC practices and processes.
Evaluate the sufficiencyof evidence to confirm that all required practices have been properly implemented.
Document and report findingsto the CMMC Accreditation Body (CMMC-AB).
Breakdown of Answer Choices
Option
Description
Correct?
A. OSC (Organization Seeking Certification)
The OSC provides documentation and evidence but doesnotverify its adequacy.
❌Incorrect
B. Assessment Team
✅Responsible for verifying the adequacy and sufficiency of evidence.
✅Correct
C. Authorizing Official
Typically refers to an official responsible for system accreditation underNIST RMF, not CMMC.
❌Incorrect
D. Assessment Official
Not a defined role in the CMMC framework.
❌Incorrect
Official Reference from CMMC 2.0 Documentation
TheCMMC Assessment Process Guide(CAP) outlines theAssessment Team ' sresponsibility in verifying evidence.
TheCMMC Assessment Teamevaluates whether theorganization ' s cybersecurity practices meet CMMC requirements.
Final Verification and Conclusion
The correct answer isB. Assessment Team, as per CMMC 2.0 documentation and official assessment processes.
Which document BEST determines the existence of FCI and/or CUI in scoping an assessment with an OSC?
Options:
OSC SSP
OSC POA & M
OSC Evidence
OSC Contract with DoD
Answer:
DExplanation:
Understanding DFARS Clause 252.204-7012
TheDefense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012is a mandatory cybersecurity clause required inall DoD contracts and solicitationsthat involveControlled Unclassified Information (CUI).
Key Requirements of DFARS 252.204-7012
✅Implements NIST SP 800-171security controls for contractors handlingCUI.
✅Requirescyber incident reportingto theDoD Cyber Crime Center (DC3)within72 hours.
✅Mandatesadequate security measuresto protectDoD information systems.
✅Applies toall DoD contracts, except for those exclusively acquiring COTS items.
Why " All DoD Solicitations and Contracts " is Correct?
Option A (Correct):DFARS 252.204-7012must be included in all DoD contracts and solicitationswhen CUI is involved.
Option B (Incorrect):FAR Part 12 procedures apply tocommercial item acquisitions, but DFARS 7012 appliesregardless of procurement procedures.
Option C (Incorrect):Contractssolely for COTS (Commercial Off-the-Shelf) productsare exemptfrom DFARS 7012.
Option D (Incorrect):COTS itemssold without modificationsarenot requiredto include DFARS 7012.
Official References from DoD and DFARS Documentation
DFARS Clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
NIST SP 800-171– The required cybersecurity standard for contractors under DFARS 7012.
Final Verification and Conclusion
Unlock CMMC-CCP Features
- CMMC-CCP All Real Exam Questions
- CMMC-CCP Exam easy to use and print PDF format
- Download Free CMMC-CCP Demo (Try before Buy)
- Free Frequent Updates
- 100% Passing Guarantee by Activedumpsnet
Questions & Answers PDF Demo
- CMMC-CCP All Real Exam Questions
- CMMC-CCP Exam easy to use and print PDF format
- Download Free CMMC-CCP Demo (Try before Buy)
- Free Frequent Updates
- 100% Passing Guarantee by Activedumpsnet