Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam
An organization's sales representative is tasked with entering FCI data into various fields within a spreadsheet on a company-issued laptop. This laptop is an FCI Asset being used to:
What is a PRIMARY activity that is performed while conducting an assessment?
How are the Final Recommended Assessment Findings BEST presented?
A CMMC Level 1 Self-Assessment identified an asset in the OSC's facility that does not process, store, or transmit FCI. Which type of asset is this considered?
Which standard of assessment do all C3PAO organizations execute an assessment methodology based on?
When assessing an OSC for CMMC: the Lead Assessor should use the information from the Discussion and Further Discussion sections in each practice because it:
Who makes the final determination of the assessment method used for each practice?
Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit, Supporting Organization/Unit, or enclave have been met?
A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?
Which domains are a part of a Level 1 Self-Assessment?