Cyber AB CMMC-CCP - Certified CMMC Professional (CCP) Exam
What banner markings MUST a document that contains CUI include?
Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a part of a plan of action?
During a Level 2 Assessment, the OSC has provided an inventory list of all hardware. The list includes servers, workstations, and network devices. Why should this evidence be sufficient for making a scoring determination for AC.L2-3.1.19: Encrypt CUI on mobile devices and mobile computing platforms?
Regarding the Risk Assessment (RA) domain, what should an OSC periodically assess?
What is a PRIMARY activity that is performed while conducting an assessment?
Which term describes " the protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to. or modification of information " ?
While conducting a CMMC Level 2 Assessment, a CCP is reviewing an OSC ' s personnel security process. They have a policy that describes screening individuals prior to authorizing access to CUI, but it does not mention what organizations should be looking for in an individual. There is no link to a process or procedural document. What should the OSC evaluate when screening individuals prior to accessing CUI?
Which domains are a part of a Level 1 Self-Assessment?
A Lead Assessor is ensuring all actions have been completed to conclude a Level 2 Assessment. The final Assessment Results Package has been properly reviewed and is ready to be uploaded. What other materials is the Lead Assessor responsible for maintaining and protecting?
Which statement BEST describes an assessor ' s evidence gathering activities?
