Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam
Where can a listing of all federal agencies' CUI indices and categories be found?
An OSC needs to be assessed on RA.L2-3.11.1: Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. What is in scope for a Level 2 assessment of RA.L2-3.11.1?
What type of information is NOT intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not including information provided by the government to the public (such as on public websites) or simple transactional information, such as necessary to process payments?
Which document is used to protect sensitive and confidential information from being made available by the recipient of that information?
How does the CMMC define a practice?
Which statement BEST describes the requirements for a C3PA0?
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
What type of criteria is used to answer the question "Does the Assessment Team have the right evidence?"
SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC's assessment. How does this affect the assessment scope?
SI.L2-3.14.7: Identify unauthorized use of organizational systems is being assessed using two assessment objectives. The assessment objectives are to determine if authorized use of the system is defined and to determine if unauthorized use of the system is identified. What is the BEST evidence for this practice?
