New Year Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

Cyber AB CMMC-CCA - Certified CMMC Assessor (CCA) Exam

Page: 5 / 5
Total 150 questions

A CCA is assessing the implementation of SC.L2-3.13.7: Split Tunneling control via the examine method. Which scenario MUST be correct to determine if the practice is MET?

A.

The CCA tested that VPN mechanisms disallow split tunneling.

B.

The CCA corroborated that split tunneling is disabled with a system or network administrator.

C.

The CCA determined that split tunneling mechanisms have been disabled based on the system hardware, software, and architecture.

D.

The CCA evaluated that split tunneling mechanisms have been disabled based on the mechanisms supporting or restricting non-remote connections.

During an assessment, the OSC person being interviewed explains the process for escorting visitors. The individual states that while all visitors are escorted, occasionally a vendor may need access to a small room with only one door and limited standing room. In these cases, the escort sits outside the room and observes the vendor completing the work. Is this practice in line with the escort policy?

A.

No, the escort is not allowed to sit down

B.

No, the escort must always be in the same room

C.

Yes, since the visitor can only use a single entry

D.

Yes, so long as the visitor’s actions can still be viewed by the escort

While conducting a CMMC Level 2 Assessment for a small waveguide manufacturer, the client provides a copy of their CMMC Level 1 Self-Assessment that their senior official has recently approved and uploaded to the Supplier Performance Risk System (SPRS). What type of information may be covered within the Level 1 Self-Assessment that is OUTSIDE the scope of a Level 2 assessment?

A.

CUI in paper format

B.

FCI within the CUI production enclave

C.

FCI data within the description in the contractor self-assessment

D.

Sensitive Compartmented Information (SCI) shredded by an approved vendor

A Lead Assessor is conducting an assessment for an OSC. The OSC is currently using doors and badge access to limit access to private areas of their campus to only authorized personnel. Which item is another means of controlling physical access to areas that contain CUI?

A.

Guards

B.

Cameras

C.

Firewalls

D.

Partition walls

During a CMMC Assessment, the assessor is determining if the Escort Visitors practice is MET. Personnel with which of the following responsibilities would be MOST appropriate to interview?

A.

Repair and facilities maintenance

B.

Local access control and information security

C.

Physical access control and information security

D.

Information technology management and operations