We at Crack4sure are committed to giving students who are preparing for the Cyber AB CMMC-CCP Exam the most current and reliable questions . To help people study, we've made some of our Certified CMMC Professional (CCP) Exam exam materials available for free to everyone. You can take the Free CMMC-CCP Practice Test as many times as you want. The answers to the practice questions are given, and each answer is explained.
What is the BEST document to find the objectives of the assessment of each practice?
CMMC Glossary
CMMC Appendices
CMMC Assessment Process
CMMC Assessment Guide Levels 1 and 2
1. Understanding the Role of Assessment Objectives in CMMC 2.0
Theassessment objectivesfor each CMMC practice define thespecific criteriathat an assessor uses to evaluate whether a practice is implemented correctly. These objectives break down each control into measurable components, ensuring a structured and consistent assessment process.
To determine where these objectives are best documented, we need to consider theofficial CMMC documentation sources.
2. Why Answer Choice " D " is Correct – CMMC Assessment Guide Levels 1 and 2
TheCMMC Assessment Guide (Levels 1 & 2)is theprimary documentthat provides:
?The detailedassessment objectivesfor each practice
?A breakdown of the expectedevidence and implementation details
?Step-by-stepassessment criteriafor assessors to verify compliance
Each CMMC practice in the Assessment Guide is aligned with the correspondingNIST SP 800-171 or FAR 52.204-21 control, and the guide specifies:
How to assess compliancewith each practice
What evidenceis required for validation
What stepsan assessor should follow
???? Reference from Official CMMC Documentation:
CMMC Assessment Guide – Level 2 (Aligned with NIST SP 800-171)explicitly states:
" Each practice is assessed based on defined assessment objectives to determine if the practice is MET or NOT MET. "
CMMC Assessment Guide – Level 1 (Aligned with FAR 52.204-21)provides similar objectives tailored for foundational cybersecurity requirements.
Thus,CMMC Assessment Guide Levels 1 & 2 are the BEST sources for assessment objectives.
3. Why Other Answer Choices Are Incorrect
Option
Reason for Elimination
A. CMMC Glossary
?The glossary only defines terminology used in CMMC but does not provide assessment objectives.
B. CMMC Appendices
?The appendices contain supplementary details, but they do not comprehensively list assessment objectives for each practice.
C. CMMC Assessment Process (CAP)
?While the CAP document describes the assessmentworkflow and methodology, it does not outline the specific objectives for each practice.
4. Conclusion
To locate thebest reference for assessment objectives, theCMMC Assessment Guide Levels 1 & 2are the most authoritative and detailed sources. They contain step-by-step assessment criteria, ensuring that practices are evaluated correctly.
?Final Answer:
D. CMMC Assessment Guide Levels 1 and 2
In the CMMC Model, how many practices are included in Level 2?
17 practices
72 practices
110 practices
180 practices
How Many Practices Are Included in CMMC Level 2?
CMMC Level 2is designed to alignfullywithNIST SP 800-171, which consists of110 security controls (practices).
This meansall 110 practicesfrom NIST SP 800-171 are required for aCMMC Level 2 certification.
Breakdown of Practices in CMMC 2.0
CMMC Level
Number of Practices
Level 1
17 practices(Basic Cyber Hygiene)
Level 2
110 practices(Aligned with NIST SP 800-171)
Level 3
Not yet finalized but expected to exceed 110
Since CMMC Level 2 mandatesall 110 NIST SP 800-171 practices, the correct answer isC. 110 practices.
Why the Other Answers Are Incorrect
A. 17 practices
?Incorrect.17 practicesapply only toCMMC Level 1, not Level 2.
B. 72 practices
?Incorrect. There is no CMMC level with72 practices.
D. 180 practices
?Incorrect. CMMC Level 2only requires 110 practices, not 180.
CMMC Official References
CMMC 2.0 Model– Confirms thatLevel 2 includes 110 practicesaligned withNIST SP 800-171.
NIST SP 800-171 Rev. 2– Outlines the110 security controlsrequired for handlingControlled Unclassified Information (CUI).
Thus,option C (110 practices) is the correct answer, as per official CMMC guidance.
Ethics is a shared responsibility between:
DoD and CMMC-AB.
OSC and sponsors.
CMMC-AB and members of the CMMC Ecosystem.
members of the CMMC Ecosystem and Lead Assessors.
Understanding Ethical Responsibility in the CMMC Ecosystem
Ethics in theCMMC ecosystemis ashared responsibilitybetween theCMMC Accreditation Body (CMMC-AB)and itsmembers. TheCMMC-AB Code of Professional Conductoutlines ethical obligations forassessors, consultants, and other ecosystem participantsto ensure integrity, fairness, and professionalism.
Key Ethical Responsibilities Include:
CMMC-AB ensures the accreditation process remains fair, unbiased, and ethical.
CMMC ecosystem members (assessors, consultants, and organizations) are responsible for upholding ethical practices in assessments and implementations.
Ethical violations can result indisciplinary actions, revocation of certification, or legal consequences.
Why is the Correct Answer " CMMC-AB and Members of the CMMC Ecosystem " (C)?
A. DoD and CMMC-AB ? Incorrect
TheDoD oversees CMMC implementation, butit is not responsible for the ethical conduct of CMMC assessments.
B. OSC and Sponsors ? Incorrect
TheOrganization Seeking Certification (OSC)is responsible for compliance but doesnot oversee ethics in the CMMC ecosystem.
C. CMMC-AB and Members of the CMMC Ecosystem ? Correct
Ethics is explicitly stated as ajoint responsibility of the CMMC-AB and its ecosystem membersin official CMMC guidance.
D. Members of the CMMC Ecosystem and Lead Assessors ? Incorrect
Lead Assessors are part of theCMMC ecosystem, butCMMC-AB is the governing body responsible for ethical oversight.
CMMC 2.0 References Supporting this Answer:
CMMC-AB Code of Professional Conduct
Defines ethical responsibilities forassessors, consultants, and ecosystem members.
CMMC Ecosystem Governance Policies
Ethics isjointly managed by CMMC-AB and its accredited ecosystem members.
CMMC Assessment Process (CAP) Document
Outlines ethical expectations forassessors and consultantsduring certification assessments.
An organization that manufactures night vision cameras is looking for help to address the gaps identified in physical access control systems. Which certified individual should they approach for implementation support?
CCA of the C3PAO performing the assessment
RP of an organization not part of the assessment
Practitioner of the organization performing the assessment LTP
DoD Contract Official of the organization performing the assessment
Anorganization seeking helpto address security gaps—such asphysical access control deficiencies—needs acertified professional who can provide implementation supportwithoutbeing involved in the actual CMMC assessment.
Role of a Registered Practitioner (RP)
A Registered Practitioner (RP)is a CMMC-certified individualwho provides consulting and implementation supportto organizations butdoes not perform assessments.
RPs work independently from C3PAOsand canassist in fixing gapsin security controlsbeforeorafteran assessment.
Since RPs are not assessors, they can provide direct remediation supportwithout any conflict of interest.
Why " B. RP of an Organization Not Part of the Assessment " is Correct?
The OSC needs assistance in implementing security controls(not assessment).
An RP is trained and authorized to provide remediation and advisory services.
Conflict of interest rules prevent the assessing C3PAO from providing implementation support.
Why Other Answers Are Incorrect?
A. CCA of the C3PAO performing the assessment (Incorrect)
ACertified CMMC Assessor (CCA)is responsible for conducting the assessmentonly.
TheC3PAO performing the assessment cannot also provide remediationdue to aconflict of interest.
C. Practitioner of the Organization Performing the Assessment LTP (Incorrect)
The assessmentLead Technical Practitioner (LTP)cannot provide remediation support for an OSC they are assessing.
D. DoD Contract Official of the Organization Performing the Assessment (Incorrect)
DoD Contract Officialsoversee contract compliance butdo not provide cybersecurity implementation support.
Conclusion
The correct answer isB. RP of an organization not part of the assessment, asonly independent RPs can assist with remediation and implementation support.
Which phase of the CMMC Assessment Process includes developing the assessment plan?
Phase 1
Phase 2
Phase 3
Phase 4
Understanding the Phases of the CMMC Assessment Process
TheCMMC Assessment Process (CAP)consists of multiple phases, with each phase focusing on a different aspect of the assessment.Developing the assessment planoccurs inPhase 1, which is thePre-Assessment Phase.
Key Activities in Phase 1 – Pre-Assessment Phase
Engagement Agreement: TheOSC (Organization Seeking Certification)and theCertified Third-Party Assessment Organization (C3PAO)formalize the assessment contract.
Developing the Assessment Plan: TheLead Assessorand the assessment team create anAssessment Plan, which outlines:
Scope of the assessment
CMMC Level requirements
Assessment methodology
Timeline and logistics
Initial Data Collection: Review of system documentation, policies, and relevant security controls.
Why is the Correct Answer " Phase 1 " (A)?
A. Phase 1 ? Correct
Phase 1 is where the assessment plan is developed.
It ensuresclarity on scope, methodology, and logistics before the assessment begins.
B. Phase 2 ? Incorrect
Phase 2 is theAssessment Conduct Phase, where assessorsexecutethe plan by examining evidence and interviewing personnel.
C. Phase 3 ? Incorrect
Phase 3 is thePost-Assessment Phase, which involvesfinalizing findings and submitting reports, not developing the plan.
D. Phase (Incomplete Answer) ? Incorrect
The question requires a specific phase, and the correct one isPhase 1.
CMMC 2.0 References Supporting this Answer:
CMMC Assessment Process (CAP) Document
DefinesPhase 1as the stage where the assessment plan is developed.
CMMC Accreditation Body (CMMC-AB) Guidelines
Specifies thatplanning and pre-assessment activities occur in Phase 1.
CMMC 2.0 Certification Workflow
Outlines the assessment planning process as part of theinitial engagementbetween theC3PAO and the OSC.
Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a part of a plan of action?
Completion dates
Milestones to measure progress
Ownership of who is accountable for ensuring plan performance
Budget requirements to implement the plan ' s remediation actions
Under the Cybersecurity Maturity Model Certification (CMMC) 2.0, a Plan of Action (POA) is a critical document that outlines the specific actions a contractor needs to take to remediate cybersecurity deficiencies. While POAs serve as a roadmap for achieving compliance with required controls, the inclusion of certain elements is standardized.
Key Elements of a Plan of Action (POA)
According to the CMMC guidelines and NIST SP 800-171, which underpins many CMMC requirements, a POA typically includes:
Completion Dates: Identifies target deadlines for resolving deficiencies.
Milestones to Measure Progress: Includes interim steps or markers to ensure progress is monitored over time.
Ownership or Accountability: Clearly assigns responsibility for each action item to specific personnel or teams.
What is Generally NOT Part of a POA?
Budget requirements to implement the plan ' s remediation actions (Option D) are generally not included in a POA. While budgeting is critical for ensuring the plan ' s success, it is considered a part of the broaderproject management or resource planning process, not the POA itself. This distinction is intentional to keep the POA focused on actionable items rather than resource allocation.
Supporting Reference
NIST SP 800-171A, Appendix D: Provides an overview of POA components, emphasizing the prioritization of corrective actions, responsibility, and measurable outcomes.
CMMC Level 2 Practices (Aligned with NIST SP 800-171): Specifically, the focus is on actions, timelines, and accountability rather than financial planning.
By excluding budget details, the POA remains a tactical document that supports immediate action and compliance tracking, separate from financial considerations.
While conducting a CMMC Assessment, a Lead Assessor is given documentation attesting to Level 1 identification and authentication practices by the OSC. The Lead Assessor asks the CCP to review the documentation to determine if identification and authentication controls are met. Which documentation BEST satisfies the requirements of IA.L1-3.5.1: Identify system users. processes acting on behalf of users, and devices?
Procedures for implementing access control lists
List of unauthorized users that identifies their identities and roles
User names associated with system accounts assigned to those individuals
Physical access policy that states. " All non-employees must wear a special visitor pass or be escorted. "
Understanding IA.L1-3.5.1 (Identification and Authentication Requirements)
TheCMMC 2.0 Level 1practiceIA.L1-3.5.1aligns withNIST SP 800-171, Requirement 3.5.1, which mandates that organizationsidentify system users, processes acting on behalf of users, and devicesto ensure proper access control.
To comply with this requirement, anOrganization Seeking Certification (OSC)must maintain documentation that demonstrates:
A unique identifier (username) for each system user
Mapping of system accounts to specific individuals
Identification of devices and automated processes that access systems
Why " C. User names associated with system accounts assigned to those individuals " is Correct?
This documentation directly satisfies IA.L1-3.5.1because it showshow system users are uniquely identified and linked to specific accountswithin the environment.
Alist of users and their assigned accountsconfirms that the organization has a structured method oftracking access and authentication.
It allows auditors to verify thateach user has a distinct identityand that access control mechanisms are properly applied.
Why Other Answers Are Incorrect?
A. Procedures for implementing access control lists (Incorrect)
While access control lists (ACLs) are relevant for authorization, they do notidentify users or devicesspecifically, making them insufficient as primary evidence for IA.L1-3.5.1.
B. List of unauthorized users that identifies their identities and roles (Incorrect)
Identifying unauthorized users does not fulfill the requirement of trackingauthorizedusers, devices, and processes.
D. Physical access policy stating " All non-employees must wear a special visitor pass or be escorted " (Incorrect)
This pertains tophysical security, not system-baseduser identification and authentication.
Conclusion
The correct answer isC. User names associated with system accounts assigned to those individuals, as thisdirectly satisfies the identification requirement of IA.L1-3.5.1.
What is DFARS clause 252.204-7012 required for?
All DoD solicitations and contracts
Solicitations and contracts that use FAR part 12 procedures
Procurements solely for the acquisition of commercial off-the-shelf
Commercial off-the-shelf sold in the marketplace without modifications
Within what amount of time MUST convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not connected with activities that relate to carrying out a Lead Assessor role, be reported to the CMMC Accreditation Body?
90 days.
30 days.
3 days.
7 days.
The correct answer is B , 30 days. The official CMMC Program rule at 32 CFR Part 170 , Subpart C, requires CMMC ecosystem members to report certain criminal matters to the Accreditation Body within 30 days . The rule specifically includes convictions, guilty pleas, and no contest pleas involving crimes such as fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or similar offenses in civil or criminal legal proceedings. This requirement applies whether or not the offense is directly connected to the individual’s CMMC ecosystem role.
This requirement is important because CMMC ecosystem roles, including Lead Assessors, depend on trustworthiness, professional integrity, impartiality, and reliability. A Lead Assessor participates in activities that may affect whether an OSC receives a CMMC certification, so criminal conduct involving dishonesty or misuse of funds is highly relevant to the integrity of the ecosystem. Option A , 90 days, is incorrect because the reporting window is shorter. Option C , 3 days, and option D , 7 days, are also incorrect because they do not match the official 30-day reporting requirement. Although older training materials may use the term “CMMC-AB,” the current terminology commonly refers to the Accreditation Body or The Cyber AB. The required reporting period remains 30 days .
===========
Companies that knowingly defraud the government by not being in compliance with cybersecurity regulations are at risk of being held liable for:
The contract value plus a penalty as stated in the Cyber Claims Act
The contract value plus a penalty as stated in the False Claims Act
Three times the contract value plus a penalty as stated in the Cyber Claims Act
Three times the contract value plus a penalty as stated in the False Claims Act
The False Claims Act (31 U.S.C. §§ 3729–3733) imposes liability on companies that knowingly misrepresent compliance in order to receive or retain federal contracts. Penalties include treble damages (three times the government’s losses) plus additional penalties per claim.
Supporting Extracts from Official Content:
False Claims Act: “Any person who knowingly submits false claims to the Government is liable for three times the Government’s damages plus a penalty.”
DOJ Cyber-Fraud Initiative (2021): confirms the FCA is applied to cases of misrepresenting compliance with cybersecurity requirements.
Why Option D is Correct:
The applicable law is the False Claims Act, not a “Cyber Claims Act” (which does not exist).
The FCA specifies treble damages plus penalties, which exactly matches Option D.
References (Official CMMC v2.0 Governance and Source Documents):
False Claims Act (31 U.S.C. §§ 3729–3733).
DOJ Cyber-Fraud Initiative (2021), applied to CMMC-related compliance misrepresentation.
===========
When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?
When under the control of the DoD
When the document is considered secret
When a document is being shared outside of the organization
When a derivative document ' s original information is not CUI
Background on Legacy Markings and CUI
Legacy markings refer to classification labels used before the implementation of the Controlled Unclassified Information (CUI) Program under DoD Instruction 5200.48.
Documents with legacy markings (such as “For Official Use Only” (FOUO) or “Sensitive But Unclassified” (SBU)) must be reviewed for re-marking or redaction to align with CUI requirements.
When Must Legacy Markings Be Updated?
If the document is retained internally (Answer A - Incorrect): Documents under DoD control do not require immediate re-marking unless they are being shared externally.
If the document is classified as Secret (Answer B - Incorrect): This question is about CUI, not classified information. Secret-level documents follow different marking rules under DoD Manual 5200.01.
If a document is being shared externally (Answer C - Correct):
According to DoD Instruction 5200.48, Section 3.6(a), organizations must review legacy markings before sharing documents outside the organization.
The document must be re-marked in compliance with the CUI Program before dissemination.
If the original document does not contain CUI (Answer D - Incorrect): The original source document ' s status does not affect the requirement to re-mark a derivative document if it contains CUI.
Conclusion
The correct answer is C: Documents with legacy markings must be re-marked or redacted when being shared outside the organization to comply with DoD CUI guidelines.
Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?
Availability
Confidentiality
Information Integrity
Respect for Intellectual Property
The requirement to exercise due care in protecting information gathered during an assessment aligns with the principle ofConfidentialityunder theCMMC Code of Professional Conduct (CoPC). This ensures that sensitive assessment data, findings, and any Controlled Unclassified Information (CUI) remain protected even after the engagement concludes.
Step-by-Step Breakdown:
Definition of Confidentiality in CMMC Context:
Confidentiality refers to protecting sensitive information from unauthorized disclosure.
In the context of a CMMC assessment, it includes safeguarding assessment artifacts, findings, and other sensitive data collected during the evaluation process.
CMMC Code of Professional Conduct (CoPC) References:
TheCMMC Code of Professional Conductstates that assessors and organizations must handle all collected information with discretion andensure its protection post-engagement.
Clause on " Maintaining Confidentiality " specifies that assessors must:
Not disclose sensitive information to unauthorized parties.
Secure data in storage and transmission.
Retain and dispose of data securely in accordance with federal regulations.
Alignment with NIST 800-171 & CMMC Practices:
CMMC Level 2 incorporates NIST SP 800-171 controls, which include:
Requirement 3.1.3:“Control CUI at rest and in transit” to ensure unauthorized individuals do not gain access.
Requirement 3.1.4:“Separate the duties of individuals to reduce risk” ensures that assessment findings are only shared with authorized personnel.
These requirements align with the duty toexercise due carein protecting assessment-related information.
Why the Other Options Are Incorrect:
(A) Availability:This refers to ensuring data is accessible when needed but does not directly relate to protecting gathered information post-assessment.
(C) Information Integrity:This focuses on preventing unauthorized modifications rather than restricting disclosure.
(D) Respect for Intellectual Property:While related to ethical handling of proprietary data, it does not directly cover post-engagement confidentiality requirements.
Final Validation from CMMC Documentation:
TheCMMC Code of Professional ConductandNIST SP 800-171control requirements confirm thatConfidentialityis the correct answer, as it directly pertains to protecting information post-assessment.
Thus, the correct answer isB. Confidentiality.
An OSC receives an email with " CUI//SP-PRVCY//FED Only " in the body of the message Which organization ' s website should the OSC go to identify what this marking means?
NARA
CMMC-AB
DoD Contractors FAQ page
DoD 239.7601 Definitions page
Understanding CUI Markings and the Role of NARA
What Does " CUI//SP-PRVCY//FED Only " Mean?
The email containsControlled Unclassified Information (CUI)withspecific categories and dissemination controls.
CUI//SP-PRVCY//FED Onlybreaks down as follows:
CUI? Controlled Unclassified Information designation.
SP-PRVCY?Specifiedcategory forPrivacy Information(SP stands for " Specified " ).
FED Only? Restriction forFederal Government use only(not for contractors or the public).
Who Maintains the Official CUI Registry?
TheNational Archives and Records Administration (NARA) oversees the CUI Programand maintains the officialCUI Registry(https://www.archives.gov/cui).
The CUI Registry providesdefinitions, marking guidance, and categoriesfor all CUI labels, including " SP-PRVCY " and dissemination controls like " FED Only. "
Why NARA is the Correct Answer:
NARA is the governing body responsible for defining and managing CUI markings.
Any organization handling CUI shouldrefer to the NARA CUI Registryfor official marking interpretations.
DoD contractors and other organizationsmust comply with NARA guidelines when handling, marking, and disseminating CUI.
Clarification of Incorrect Options:
B. CMMC-AB– TheCMMC Accreditation Bodymanages certification assessments butdoes not define or interpret CUI markings.
C. DoD Contractors FAQ Page– The DoD may provide general contractor guidance, butCUI markings are governed by NARA, not an FAQ page.
D. DoD 239.7601 Definitions Page– This refers to generalDoD acquisition definitions, butCUI categories and markings fall under NARA’s authority.
An assessor has been working with an OSC ' s point of contact to plan and prepare for their upcoming assessment. What is one of the MOST important things to remember when analyzing requirements for an assessment?
Scoping an assessment is easy and worry-free.
The initial plan cannot be changed once agreed upon.
There is a determined amount of time that the OSC ' s point of contact has to submit evidence and rough order-of-magnitude.
Assessors need to continuously review and update the requirements and plan for the assessment as information is gathered.
Planning and preparing for aCMMC assessmentinvolves collaboration between theassessorand theOrganization Seeking Certification (OSC)to determine scope, required evidence, and logistics. This planning process isdynamicand must adapt as new information emerges.
Why the Correct Answer is " D " ?
Assessment Scope and Requirements May Change
As assessors gather evidence and analyze the environment,new details about assets, networks, and security controlsmay require adjustments to the assessment plan.
TheCMMC Assessment Process (CAP) Guideemphasizes that assessmentrequirements and scope should be continuously reviewed and updatedto reflect real-time findings.
Assessors Follow an Adaptive Approach
DuringCMMC assessments, organizations may discover additionalFCI or CUI assets, which can change the required security practices to be evaluated.
Assessors shouldrevise the assessment approach accordinglyrather than strictly following an initial, unchangeable plan.
Why Not the Other Options?
A. Scoping an assessment is easy and worry-free?Incorrect
Scoping is acritical and complex processthat requires careful evaluation of the OSC’s information systems and assets.
CMMC Scoping Guidestates thatidentifying in-scope assets is crucial and requires significant effort.
B. The initial plan cannot be changed once agreed upon?Incorrect
Theinitial assessment plan is a starting point, butit must be flexiblebased on real-time findings.
CMMC CAP Guideemphasizescontinuous refinementduring the assessment process.
C. There is a determined amount of time that the OSC ' s point of contact has to submit evidence and rough order-of-magnitude?Incorrect
While there aretimelines, the key focus is ensuring thatall necessary evidence is gathered accuratelyrather than rushing to meet a strict deadline.
Relevant CMMC 2.0 References:
CMMC Assessment Process (CAP) Guide– States that assessment requirements and planning should be updated as additional information is gathered.
CMMC Scoping Guide (Nov 2021)– Explains that assessors must continually refinein-scope assets and requirementsthroughout the process.
Final Justification:
Assessment planning is a dynamic process.Assessors must continuously review and update the requirements and planas new information emerges, makingDthe correct answer.
A Lead Assessor and an OSC ' s Assessment Official have agreed to have the Assessment results presented during the final Daily Checkpoint of the OSC ' s CMMC Level 2 Assessment. Which document MUST the Lead Assessor use to present assessment findings to the OSC?
CMMC POA & M Brief
CMMC Findings Brief
CMMC Assessment Tracker Tool
CMMC Recommended Findings template
According to the CMMC Assessment Process (CAP), the Lead Assessor must use the CMMC Findings Brief to formally present assessment results to the Organization Seeking Certification (OSC). The Findings Brief ensures consistency across assessments and provides the OSC with an official, standardized presentation of results, including observed strengths, weaknesses, and any non-conformities.
Other options are incorrect because:
POA & M Brief is not part of the official CAP presentation.
CMMC Assessment Tracker Tool is an internal tool used by assessors, not for presentation to the OSC.
Recommended Findings template is not a recognized deliverable in CAP.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
An assessor is collecting affirmations. So far, the assessor has collected interviews, demonstrations, emails, messaging, and presentations. Are these appropriate approaches to collecting affirmations?
No, emails are not appropriate affirmations.
No, messaging is not an appropriate affirmation.
Yes, the affirmations collected by the assessor are all appropriate.
Yes, the affirmations collected by the assessor are all appropriate, as are screenshots.
According to the CMMC Assessment Process (CAP) and the CMMC Level 2 Assessment Guide, an assessment finding is built upon evidence collected through three primary methods: Examine, Interview, and Test. The term " affirmation " in this context refers to the verbal or written statements provided by the Organization Seeking Certification (OSC) personnel to confirm that a practice is implemented as described.
Broad Definition of Evidence: The CAP allows for a wide variety of artifacts to be used as evidence. " Affirmations " are typically captured during the Interview process or found within Examine objects.
Validity of Formats:
Interviews: Direct verbal affirmations from subject matter experts (SMEs).
Emails and Messaging (Chat/Slack/Teams): These are considered valid " Examine " objects (records/artifacts) that serve as written affirmations or evidence of an activity (e.g., an email chain approving a firewall change or a message confirming a system update).
Presentations and Demonstrations: These fall under " Examine " (the presentation slides) and " Test/Examine " (the demonstration of a mechanism).
Why Option C is correct: The CMMC framework does not disqualify digital communications like emails or messaging as evidence. In fact, these are often the primary artifacts used to prove that a process (like an approval workflow or notification) is occurring in practice. As long as the assessor can verify the authenticity and integrity of these communications, they are appropriate for collecting affirmations.
Why Option D is less accurate: While screenshots are indeed used as evidence, the core question asks if thespecificlist (interviews, demonstrations, emails, messaging, presentations) is appropriate. Option C directly validates the list provided in the prompt without introducing extraneous elements like screenshots, which—while valid—are not the focus of the " appropriate " determination for the items listed.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4 (Collect and Verify Evidence), which discusses the types of artifacts and " human evidence " (interviews) that support findings.
CMMC Level 2 Assessment Guide: " Assessment Methods " section, clarifying that evidence can include any records (electronic or physical) that demonstrate the implementation of a practice.
NIST SP 800-171A: The underlying standard for assessment procedures, which encourages the use of various evidence types to satisfy assessment objectives.
Which method facilitates understanding by analyzing gathered artifacts as evidence?
Test
Examine
Behavior
Interview
The CMMC Assessment Process uses three methods: Examine, Interview, and Test. The method that involves analyzing artifacts (documents, system configurations, records, logs, etc.) is Examine.
Supporting Extracts from Official Content:
CMMC Assessment Guide: “Examine consists of reviewing, inspecting, or analyzing assessment objects such as documents, system configurations, or other artifacts to evaluate compliance.”
Why Option B is Correct:
Examine = analyzing artifacts.
Interview = discussions with personnel.
Test = executing technical checks.
Behavior is not an assessment method.
References (Official CMMC v2.0 Content):
CMMC Assessment Guide, Levels 1 and 2 — Assessment Methods (Examine, Interview, Test).
===========
There are 15 practices that are NOT MET for an OSC ' s Level 2 Assessment. All practices are applicable to the OSC. Which determination should be reached?
The OSC may have 90 days for remediating NOT MET practices.
The OSC is not eligible for an option to remediate NOT MET practices.
The OSC may be eligible for an option to remediate NOT MET practices.
The OSC is not eligible for an option to remediate after the assessment is canceled.
According to the CMMC Model and Assessment Guides, specifically the rules governing Plan of Action and Milestones (POA & M) and the remediation period, an Organization Seeking Certification (OSC) is allowed a limited opportunity to remediate certain " Not Met " practices to achieve a " Met " status without failing the assessment entirely.
Here is the breakdown based on CMMC Ecosystem protocols:
The 180-Day POA & M Rule: CMMC Level 2 allows for the use of POA & Ms for specific practices, provided they are not high-priority items (typically 5-point values in the scoring methodology). If an OSC has " Not Met " practices that are eligible for a POA & M, they have up to 180 days to remediate them.
The Remediation Period (Assessment Closeout): During the assessment process itself, there is a " remediation period " (often referred to within the 1-90 day window depending on the specific C3PAO methodology and the CMMC assessment process) where an OSC can fix minor issues identified by the assessor before the final report is submitted.
Eligibility Criteria: The question states there are 15 practices " Not Met. " While this is a high number, the CMMC rule does not automatically disqualify an OSC based solely on thequantityof practices, but rather thetype(weight) of the practices and the resulting score. To be eligible for a conditional " Met " (via POA & M), the OSC must achieve a minimum score (often 80% of the total points) and none of the " Not Met " practices can be those designated as mandatory " Met " (no POA & M allowed) in the CMMC rule.
Why " C " is correct: Because we do not know the specific weights of the 15 " Not Met " practices or the total score, we cannot definitively say theywillbe remediated (A) or that they areineligible(B). However, under the CMMC assessment framework, the OSC may be eligible to enter a remediation phase or utilize a POA & M to bridge the gap, provided they meet the scoring threshold and the specific practices allow for it.
Reference Documents:
CMMC Assessment Process (CAP): Defines the phases of assessment including the " Remediation Period. "
32 CFR Part 170 (CMMC Program Rule): Outlines the specific requirements for POA & Ms, the 180-day timeline, and the scoring parameters required to be eligible for a Conditional Certification.
Which term describes the prevention of damage to. protection of, and restoration of computers and electronic communications systems/services, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation?
Cybersecurity
Data security
Network security
Information security
The term that describes " the prevention of damage to, protection of, and restoration of computers and electronic communication systems/services, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and non-repudiation " isCybersecurity.
Step-by-Step Breakdown:
?1. Cybersecurity Defined
Cybersecurityfocuses onprotecting networks, systems, and datafrom cyber threats.
It includes measures to ensure:
Availability(data is accessible when needed).
Integrity(data is accurate and unaltered).
Authentication(verifying users ' identities).
Confidentiality(ensuring only authorized access).
Non-repudiation(preventing denial of actions).
The definition in the questionaligns directly with cybersecurity principles, making it the best answer.
?2. Why the Other Answer Choices Are Incorrect:
(B) Data Security?
Data securityfocusesspecificallyon protectingstored information(e.g., encryption, access controls), but cybersecurity is broader—it includesnetworks, systems, and communication services.
(C) Network Security?
Network securityis asubset of cybersecuritythat focuses on protectingnetwork infrastructure(e.g., firewalls, intrusion detection systems).
The definition in the question includesmore than just networks, so cybersecurity is the better choice.
(D) Information Security?
Information security (InfoSec)is related but broader than cybersecurity.
InfoSeccoversphysical and organizational security(e.g., policies, procedures) in addition todigital protections.
Final Validation from CMMC Documentation:
CMMC and NIST SP 800-171 define cybersecurityas the protection ofsystems, networks, and data from cyber threats.
DoD Cybersecurity Definitions(aligned with NIST) confirm that cybersecurity is the term thatbest fits the definition in the question.
Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?
DOD OUSD
Authorized holder
Information Disclosure Official
Presidentially authorized Original Classification Authority
DoDI 5200.48 specifies that Authorized Holders of CUI are responsible for applying appropriate CUI markings. An authorized holder is an individual who has lawful government purpose access to the information. This ensures that responsibility for correctly marking information rests with those who create or handle the material, not only with original classification authorities (which apply to classified information, not CUI).
Reference Documents:
DoDI 5200.48,Controlled Unclassified Information (CUI)
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
have a security clearance.
be a senior person in the company.
demonstrate expertise on the CMMC requirements.
provide clarity and understanding of their practice activities.
Interview Selection in CMMC Assessments
During aCMMC assessment, theLead Assessormust work with theOrganization Seeking Certification (OSC)to select personnel for interviews. The goal is to:
?Verify that personnel understand andperform security-related practices.
?Ensure that individuals canexplain how they implement CMMC requirements.
?Gain insight intoactual cybersecurity operationsrather than just documented policies.
The best interviewees are those whodirectly engage with security practicesand canclearly explain how they perform their duties.
Why " Providing Clarity and Understanding " Is Key
CMMC assessmentsrely on interviewsto validate that security practices areimplemented effectively.
Themost valuable intervieweesare those who canexplainhow security measures are appliedin day-to-day operations.
CMMC Assessment Process (CAP)emphasizes that assessors should speak tothose actively involved in security practicesrather than just senior management or policy owners.
Thus,option D is the correct choicebecause the Lead Assessor should prioritizeinterviewing personnel who can clearly explain how CMMC practices are implemented.
Why the Other Answers Are Incorrect
A. Have a security clearance.
?Incorrect.Security clearance is not a requirementfor CMMC assessments. The focus is onpractical implementation of security controls, not classified work.
B. Be a senior person in the company.
?Incorrect. Senior executives may not be involved in theactual implementation of security controls. The best interviewees are those whoperform the work, not just oversee it.
C. Demonstrate expertise on the CMMC requirements.
?Incorrect. Whileunderstanding CMMC is important, expertise alonedoes not guarantee practical knowledgeof security controls. The key is thatinterviewees must provide clarity on how they perform security tasks.
CMMC Official References
CMMC Assessment Process (CAP) Document– Guides interview selection based on personnel who perform security functions.
NIST SP 800-171 & CMMC 2.0– Emphasize that cybersecurity controls must beactively implemented, not just documented.
Thus,option D (Provide clarity and understanding of their practice activities) is the correct answeras per official CMMC assessment guidelines.
What is a PRIMARY activity that is performed while conducting an assessment?
Develop assessment plan.
Collect and examine evidence.
Verify readiness to conduct assessment.
Deliver recommended assessment results.
Step 1: Understand the Assessment Phases (CAP v1.0)
TheCMMC Assessment Process (CAP)outlines a structured lifecycle for assessments, including:
Plan and Prepare Phase– Develop the assessment plan (before the assessment starts).
Conduct Assessment Phase– Execute the actual assessment activities.
Report Results Phase– Finalize and deliver the assessment outcomes.
CAP v1.0 – Section 3.5 (Conduct Assessment):
“The assessment team collects, examines, and evaluates evidence to determine if practices are MET or NOT MET.”
?Step 2: Why “Collect and Examine Evidence” Is the Primary Activity
During the“Conduct Assessment” phase, the main activity is to:
Collect evidence(documentation, interviews, testing),
Validate adequacy and sufficiency,
Score practicesas MET/NOT MET.
This is thecore responsibilityof assessorswhile conductingan assessment.
?Why the Other Options Are Incorrect
A. Develop assessment plan
?This occurs in thePlan and Preparephasebeforeconducting the assessment.
C. Verify readiness to conduct assessment
?Readiness verification is part ofpre-assessment activities, not during the assessment itself.
D. Deliver recommended assessment results
?This is done during theReport Resultsphase after the assessment has been conducted.
Theprimary activity performed during the actual executionof a CMMC assessment iscollecting and examining evidenceto determine compliance with practices.
According to DFARS clause 252.204-7012, who is responsible for determining that Information in a given category should be considered CUI?
The NARA CUI Executive Agent
The contractor who generated the information
The DoD agency for whom the contractor is performing the work
The military personnel assigned to the contractor for that purpose
DFARS clause 252.204-7012 establishes the safeguarding of Covered Defense Information (CDI), which aligns with CUI categories. The clause specifies that the DoD is responsible for determining whether information is Controlled Unclassified Information (CUI) and marking it accordingly before sharing it with contractors. Contractors do not make determinations about what constitutes CUI; they are responsible for safeguarding information once it is received and marked as CUI.
Reference Documents:
DFARS 252.204-7012,Safeguarding Covered Defense Information and Cyber Incident Reporting
CMMC Model v2.0 Overview, December 2021
A server is used to store FCI with a cloud provider long-term. What is the server considered?
In scope, because the cloud provider will be storing the FCI data
Out of scope, because the cloud provider stores the FCI data long-term
In scope, because the cloud provider is required to be CMMC Level 2 certified
Out of scope, because encryption is always used when the cloud provider stores the FCI data
Assets that store, process, or transmit FCI or CUI are always in scope for CMMC. If a server with a cloud provider is used for long-term storage of FCI, that server is considered in scope because it directly holds covered data.
Supporting Extracts from Official Content:
CMMC Scoping Guide for Level 1: “Assets that store, process, or transmit FCI are in scope.”
CMMC Scoping Guide for Level 2: confirms the same rule applies for CUI.
Why Option A is Correct:
The server stores FCI, making it automatically in scope.
Option B is incorrect because long-term storage does not make an asset out of scope.
Option C is incorrect — Level 1 (FCI) does not require a Level 2 certified provider.
Option D is incorrect because encryption does not remove scope requirements.
References (Official CMMC v2.0 Content):
CMMC Scoping Guide, Level 1.
CMMC Model v2.0, Scoping and Implementation guidance.
===========
Which principles are included in defining the CMMC-AB Code of Professional Conduct?
Objectivity, classification, and information accuracy
Objectivity, confidentiality, and information integrity
Responsibility, classification, and information accuracy
Responsibility, confidentiality, and information integrity
The Cyber AB (formerly CMMC-AB) Code of Professional Conduct (CoPC) is a mandatory agreement that all CMMC ecosystem members—including Certified CMMC Professionals (CCPs) and Certified CMMC Assessors (CCAs)—must adhere to. This code ensures the reliability and trustworthiness of the assessment process.
The fundamental principles that form the foundation of the CoPC include:
Responsibility: This refers to the obligation of the CMMC professional to act in the best interest of the CMMC program, the Department of Defense (DoD), and the public. It includes maintaining professional competence and performing duties with due care.
Confidentiality: Assessors and professionals are granted access to sensitive information, including Controlled Unclassified Information (CUI) and proprietary business data of the Organization Seeking Certification (OSC). They must ensure this information is protected from unauthorized disclosure.
Information Integrity: This principle requires that all data, findings, and reports generated during the assessment are accurate, complete, and have not been tampered with. It ensures that the " Met " or " Not Met " determinations are based on honest evidence.
Why other options are incorrect:
Options A and B (Objectivity): While " Objectivity " is a crucialbehavioralrequirement for an assessor (remaining unbiased), the specific high-level triad often emphasized in the CMMC Professional training and the formal CoPC documentation focuses on the Responsibility-Confidentiality-Integrity framework to align with standard professional ethics and information security pillars.
Options A and C (Classification): " Classification " is a process used for National Security Information (Classified info), whereas CMMC is primarily focused on unclassified information (CUI and FCI). Classification is not a core principle of the professional code of conduct.
Options A and C (Information Accuracy): While accuracy is vital, it is considered a subset of Information Integrity within the formal definitions provided in the CCP curriculum.
Reference Documents:
CMMC-AB (The Cyber AB) Code of Professional Conduct: The official ethical framework for all credentialed individuals.
CMMC Professional (CCP) Study Guide: Section on " Ethics and the Code of Professional Conduct. "
CMMC Assessment Process (CAP): References the ethical standards required to maintain the integrity of the assessment ecosystem.
Which CMMC Levels focus on protecting CUI from exfiltration?
Levels 1 and 2
Levels 1 and 3
Levels 2 and 3
Levels 1, 2, and 3
Level 1 only addresses the protection of Federal Contract Information (FCI) and does not include requirements for safeguarding Controlled Unclassified Information (CUI).
Level 2 is explicitly designed to protect Controlled Unclassified Information (CUI). It requires implementation of all 110 security requirements from NIST SP 800-171 Rev. 2, which directly support the safeguarding of CUI and help prevent its unauthorized disclosure or exfiltration.
Level 3 builds on Level 2 by including a subset of requirements from NIST SP 800-172. These additional practices are designed to enhance the protection of CUI against advanced persistent threats (APTs), further strengthening defenses against exfiltration.
Therefore, the levels that focus on protecting CUI from exfiltration are Levels 2 and 3.
Reference Documents:
CMMC Model v2.0 Overview (DoD, December 2021)
NIST SP 800-171 Rev. 2,Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
NIST SP 800-172,Enhanced Security Requirements for Protecting Controlled Unclassified Information
SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC ' s assessment. How does this affect the assessment scope?
Any existing telephone system is in scope even if it is not using VoIP technology.
An error has been made and the Lead Assessor should be contacted to correct the error.
VoIP technology is within scope, and it uses FlPS-validated encryption, so it does not need to be assessed.
VoIP technology is not used within scope boundary, so no assessment procedures are specified for this practice.
Understanding SC.L2-3.13.14 – Control and Monitor the Use of VoIP Technologies
TheCMMC 2.0 Level 2requirementSC.L2-3.13.14comes fromNIST SP 800-171, Security Requirement 3.13.14, which mandates that organizations mustcontrol and monitor the use of VoIP (Voice over Internet Protocol) technologiesif used within their system boundary.
If a systemdoes not use VoIP technology, then this control isNot Applicable (N/A)because there is nothing to assess.
Why Option D is Correct
When a requirement is marked as Not Applicable (N/A), it means the OSC does not use the technology or process covered by that controlwithin its assessment boundary.
No assessment procedures are neededsince there is no VoIP system to evaluate.
Option A (Existing telephone system in scope)is incorrect becausetraditional (non-VoIP) telephone systems are not covered by SC.L2-3.13.14—only VoIP is within scope.
Option B (Error, contact the Lead Assessor)is incorrect because markingSC.L2-3.13.14 as N/A is valid if VoIP is not used. This is not an error.
Option C (VoIP in scope but using FIPS-validated encryption, so it doesn’t need to be assessed)is incorrect becauseeven if VoIP uses FIPS-validated encryption, the control would still need to be assessed to ensure monitoring and usage control are in place.
Official CMMC Documentation References
CMMC 2.0 Level 2 Assessment Guide – SC.L2-3.13.14
NIST SP 800-171, Security Requirement 3.13.14
CMMC Scoping Guidance – Determining Not Applicable (N/A) Practices
Final Verification
IfVoIP is not used within the OSC’s system boundary, the control does not require assessment, making Option D the correct answer.
An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?
Take it with them to review in the evening.
Leave it on the desk for review the following day.
Put it in the unlocked desk drawer for review the following morning.
Take a picture with the personal phone before securely shredding it.
In this scenario, the primary concern is the protection of Controlled Unclassified Information (CUI) in an environment that lacks sufficient physical security controls (specifically, a lack of a locked cabinet or drawer). According to the CMMC Assessment Process (CAP) and NIST SP 800-171 (specifically the Physical Protection (PE) family), CUI must be protected from unauthorized access at all times.
Responsibility of the Assessor: CMMC Professionals (CCPs and CCAs) are bound by the CMMC Code of Professional Conduct and the C3PAO ' s internal security protocols to ensure that any CUI provided by the Organization Seeking Certification (OSC) is handled securely.
Physical Protection (PE.L2-3.10.1 and PE.L2-3.10.2): These practices require that an organization limit physical access to systems and equipment to authorized users and protect the physical facility. If the provided " hoteling space " does not offer a locked container (like a cabinet) to secure the CUI overnight, leaving it in an unlocked drawer (Option C) or on the desk (Option B) would be a violation of CUI handling requirements and a security risk.
Why Option A is the best " Next " step: In the absence of on-site secure storage, the assessor must maintain positive control of the CUI. Taking the document to a secure location (such as the assessor ' s hotel room or person) where they can ensure it remains under their control is the only viable way to prevent unauthorized access by janitorial staff or other unauthorized personnel at the client site overnight.
Why other options are incorrect:
Option B and C: Both fail to protect the CUI from unauthorized access in a non-secure, shared environment.
Option D: Taking a picture of CUI on a personal phone is a major security violation (spillage), as personal devices are generally not authorized to store or process CUI.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section regarding " Assessor Responsibilities for CUI and Proprietary Information. "
NIST SP 800-171 Rev 2: Physical Protection (PE) family (3.10.1, 3.10.2).
DoD Instruction 5200.48: " Controlled Unclassified Information (CUI), " which specifies that CUI must be protected by at least one physical barrier when not in the direct control of an authorized individual.
Which domains are a part of a Level 1 Self-Assessment?
Access Control (AC), Risk Management < RM), and Media Protection (MP)
Risk Management (RM). Access Control (AC), and Physical Protection (PE)
Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)
Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)
CMMCLevel 1focuses onbasic cyber hygieneand includes17 practicesderived fromNIST SP 800-171 Rev. 2butonly covers the protection of Federal Contract Information (FCI)—not Controlled Unclassified Information (CUI).
UnlikeLevel 2, which aligns fully withNIST SP 800-171,Level 1 does not require third-party certificationand can beself-assessedby the organization.
Domains Covered in a Level 1 Self-Assessment
CMMC Level 1 practices fall underthree specific domains:
Access Control (AC)– Ensures that only authorized individuals can access FCI.
Physical Protection (PE)– Protects physical access to systems and facilities storing FCI.
Identification and Authentication (IA)– Verifies the identity of users accessing systems containing FCI.
These domains focus on foundational security controls necessary toprotect FCI from unauthorized access.
Official CMMC 2.0 Documentation References
CMMC Model v2.0states thatLevel 1 includes only 17 practicesmapped toNIST SP 800-171requirements specific toAccess Control (AC), Physical Protection (PE), and Identification and Authentication (IA).
CMMC Assessment Guide, Level 1confirms thatRisk Management (RM) and Media Protection (MP) are not included in Level 1, as they pertain to more advanced security measures needed for handlingCUI (Level 2).
Breakdown of Answer Choices
A. Access Control (AC), Risk Management (RM), and Media Protection (MP)? Incorrect.Risk Management (RM) and Media Protection (MP) are Level 2 domains.
B. Risk Management (RM), Access Control (AC), and Physical Protection (PE)? Incorrect.Risk Management (RM) is not part of Level 1.
C. Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)?Correct.These are thethree domains covered in CMMC Level 1 self-assessments.
D. Risk Management (RM), Media Protection (MP), and Identification and Authentication (IA)? Incorrect.Risk Management (RM) and Media Protection (MP) are Level 2 domains.
Conclusion
Thecorrect answer is C. Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA), as these are theonly three domains included in a CMMC Level 1 Self-Assessmentaccording toCMMC 2.0 documentation and NIST SP 800-171 mapping.
Reference Documents for Further Reading
CMMC 2.0 Model Overview – DoD Official Documentation
CMMC Assessment Guide, Level 1
NIST SP 800-171 Rev. 2 (Basic Security Requirements for FCI)
A Lead Assessor is ensuring all actions have been completed to conclude a Level 2 Assessment. The final Assessment Results Package has been properly reviewed and is ready to be uploaded. What other materials is the Lead Assessor responsible for maintaining and protecting?
Any additional notes and information from the Assessment
A final assessment plan, and a Quality Control report from C3PAO
A final assessment plan, and a letter from the Lead Assessor explaining the process
A final assessment plan, a letter from the Lead Assessor explaining the results, and a Quality Control report from C3PAO
The Lead Assessor is responsible for protecting and maintaining all assessment records, notes, and information gathered during the assessment process. This includes working papers and supplemental documentation that may be needed for auditability or dispute resolution.
Supporting Extracts from Official Content:
CAP v2.0, Post-Assessment Responsibilities (§3.17): “The Lead Assessor must ensure that all assessment artifacts, notes, and information are archived or disposed of in accordance with C3PAO policy.”
Why Option A is Correct:
The CAP specifies that notes and information from the assessment must be preserved or disposed of according to policy.
Options B, C, and D list items not required in the CAP. The “letter” and “quality control report” are not part of the Lead Assessor’s required maintained materials.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 3 Post-Assessment (§3.17).
===========
A Data Access Policy (DAP) document has been provided for review. It outlines the policies, procedures, and requirements for data access within the corporate area and the controlled environment. Which DAP policy statement about visitors is correct?
Visitors must not be escorted.
Visitors must be escorted in the corporate area, but not in the controlled environment.
Visitors must be escorted in the controlled environment, but not in the corporate area.
Visitors must be escorted at all times.
The correct answer is C because the CMMC physical protection requirement focuses on protecting areas where in-scope information systems, equipment, and controlled environments are located. CMMC Level 2 requirement PE.L2-3.10.3, Escort Visitors , requires the organization to “escort visitors and monitor visitor activity.” The official CMMC Level 2 Assessment Guide states that the assessment objectives include determining whether visitors are escorted, visitor activity is monitored, physical access audit logs are maintained, and physical access devices are controlled and managed. The same guide explains that individuals with permanent physical access authorization credentials are not considered visitors, and that audit logs can be used to monitor visitor activity.
For CMMC purposes, the key issue is whether the visitor could physically access organizational systems, equipment, FCI, CUI, or the respective operating environment. A general corporate area that is outside the controlled environment may not require the same escort rule unless it provides access to in-scope assets. However, the controlled environment must be protected from unauthorized physical access. Therefore, visitors should be escorted in the controlled environment, where FCI/CUI systems or related assets may be present. Option A is incorrect because CMMC requires visitor escorting. Option B reverses the protection priority. Option D is overly broad for this question because it does not distinguish between a general corporate area and the controlled environment defined in the DAP.
===========
Recording evidence as adequate is defined as the criteria needed to:
verify, based on an assessment and organizational scope.
verify, based on an assessment and organizational practice.
determine if a given artifact, interview response, demonstration, or test meets the CMMC scope.
determine if a given artifact, interview response, demonstration, or test meets the CMMC practice.
Understanding " Adequate Evidence " in the CMMC Assessment Process
In aCMMC assessment,adequate evidencerefers to the proof required to demonstrate that a specific cybersecurity practice has been implemented correctly. Evidence can come from:
Artifacts(e.g., security policies, system configurations, logs).
Interview responses(e.g., verbal confirmation from personnel about their responsibilities).
Demonstrations(e.g., showing how a security control is implemented in real time).
Testing(e.g., verifying technical security mechanisms such as multi-factor authentication).
Thegoalof evidence collection is to determinewhether a CMMC practice is met—not just whether the organization operates within the assessment scope.
Why is the Correct Answer " Determine if a given artifact, interview response, demonstration, or test meets the CMMC practice " (D)?
A. Verify, based on an assessment and organizational scope ? Incorrect
Theassessment scopedefineswhat is evaluated, but adequacy of evidence is based oncompliance with specific CMMC practices.
B. Verify, based on an assessment and organizational practice ? Incorrect
CMMC assessments focus on cybersecurity practices defined in the CMMC framework, not just general organizational practices.
C. Determine if a given artifact, interview response, demonstration, or test meets the CMMC scope ? Incorrect
Thescopedefines the assessment boundaries, but theassessment team ' s job is to confirm whether CMMC practices are satisfied.
D. Determine if a given artifact, interview response, demonstration, or test meets the CMMC practice ? Correct
TheCMMC assessment process focuses on ensuring that required practices are implemented, making this the correct answer.
CMMC 2.0 References Supporting this Answer:
CMMC Assessment Process (CAP) Document
Defines " adequate evidence " asproof that a CMMC practice has been correctly implemented.
CMMC 2.0 Assessment Criteria
Specifies that evidence must beevaluated against specific cybersecurity practices.
NIST SP 800-171A (Assessment Procedures for NIST SP 800-171)
Provides guidance on evaluating artifacts, interviews, demonstrations, and testing to confirm compliance with required practices.
Final Answer:
?D. Determine if a given artifact, interview response, demonstration, or test meets the CMMC practice.
A Lead Assessor is performing a CMMC readiness review. The Lead Assessor has already recorded the assessment risk status and the overall assessment feasibility. At MINIMUM, what remaining readiness review criteria should be verified?
Determine the practice pass/fail results.
Determine the preliminary recommended findings.
Determine the initial model practice ratings and record them.
Determine the logistics. Assessment Team, and the evidence readiness.
Understanding the CMMC Readiness Review Process
ALead Assessorconducting aCMMC Readiness Reviewevaluates whether anOrganization Seeking Certification (OSC)is prepared for a formal assessment.
After recording theassessment risk statusandoverall assessment feasibility, theminimum remaining criteriato be verified include:
Logistics Planning– Ensuring that the assessment timeline, locations, and necessary resources are in place.
Assessment Team Preparation– Confirming that assessors and required personnel are available and briefed.
Evidence Readiness– Ensuring the OSC has gathered all required artifacts and documentation for review.
Breakdown of Answer Choices
Option
Description
Correct?
A. Determine the practice pass/fail results.
Happensduringthe formal assessment, not the readiness review.
?Incorrect
B. Determine the preliminary recommended findings.
Findings are only madeafterthe full assessment.
?Incorrect
C. Determine the initial model practice ratings and record them.
Ratings are assigned during theassessment, not readiness review.
?Incorrect
D. Determine the logistics, Assessment Team, and the evidence readiness.
?Essential readiness criteria that must be confirmedbeforeassessment starts.
?Correct
Official Reference from CMMC 2.0 Documentation
TheCMMC Assessment Process Guide (CAP)states that readiness review ensureslogistics, assessment team availability, and evidence readinessare verified.
Final Verification and Conclusion
The correct answer isD. Determine the logistics, Assessment Team, and the evidence readiness.This aligns withCMMC readiness review requirements.
The facilities manager for a company has procured a Wi-Fi enabled, mobile application-controlled thermostat for the server room, citing concerns over the inability to remotely gauge and control the temperature of the room. Because the thermostat is connected to the company ' s FCI network, should it be assessed as part of the CMMC Level 1 Self-Assessment Scope?
No, because it is OT
No, because it is an loT device
Yes. because it is a restricted IS
Yes, because it is government property
Step 1: Understanding CMMC Level 1 Self-Assessment Scope
CMMC Level 1applies toFederal Contract Information (FCI)systems.
Any system or device that is connected to an FCI-handling network is within the assessment scopebecause it canintroduce vulnerabilitiesinto the environment.
Step 2: Why the Thermostat is in Scope
TheWi-Fi-enabled thermostat is connected to the FCI network, meaning it haspotential accessto sensitive contract-related data.
PerCMMC Scoping Guidance, this type of device is classified as aRestricted Information System (Restricted IS)—devices that do not store, process, or transmit FCI but areconnected to networks that do.
Restricted IS must be accounted for in the self-assessment scope to ensure they do not compromise security controls.
While developing an assessment plan for an OSC. it is discovered that the certified assessor will be interviewing a former college roommate. What is the MOST correct action to take?
Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.
Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
Inform the OSC and the C3PAO of the possible conflict of interest, document the conflict and mitigation actions in the assessment plan, and if the mitigation actions are acceptable, continue with the assessment.
The Cybersecurity Maturity Model Certification (CMMC) Assessment Process (CAP) outlines strict guidelines regarding conflicts of interest (COI) to ensure the integrity and impartiality of assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs) and Certified Assessors (CAs).
The scenario presented involves a potential conflict of interest due to a prior relationship (former college roommate) between the certified assessor and an individual at the Organization Seeking Certification (OSC). While this prior relationship does not automatically disqualify the assessor, it must be disclosed, documented, and mitigated appropriately.
CMMC Conflict of Interest Handling Process
Inform the OSC and C3PAO of the Potential Conflict of Interest
The CMMC Code of Professional Conduct (CoPC) requires assessors to disclose any potential conflicts of interest.
Transparency ensures that all parties, including the OSC and C3PAO, are aware of the situation.
Document the Conflict and Mitigation Actions in the Assessment Plan
Per CMMC CAP documentation, potential conflicts should be assessed based on their material impact on the objectivity of the assessment.
The conflict and proposed mitigation strategies must be formally recorded in the assessment plan to provide an audit trail.
Determine If the Mitigation Actions Are Acceptable
If the OSC and C3PAO determine that the mitigation actions adequately eliminate or reduce the risk of bias, the assessment may proceed.
Common mitigation strategies include:
Assigning another assessor for interviews with the conflicted individual.
Ensuring that decisions regarding the OSC’s compliance are reviewed independently.
Proceed with the Assessment If Mitigation Is Acceptable
If the mitigation actions sufficiently address the conflict, the assessment may continue under strict adherence to documented procedures.
Why the Other Answers Are Incorrect
A. Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
?Incorrect. This violates CMMC’s integrity requirements and could result in disciplinary actions against the assessor or invalidation of the assessment. Transparency is mandatory.
B. Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.
?Incorrect. The CAP does not mandate immediate reassignment unless the conflict is unresolvable. Instead, mitigation strategies should be considered first.
C. Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
?Incorrect. The passage of time alone does not automatically eliminate a conflict of interest. Proper documentation and mitigation are still required.
CMMC Official References
CMMC Assessment Process (CAP) Document – Defines COI requirements and mitigation actions.
CMMC Code of Professional Conduct (CoPC) – Outlines ethical responsibilities of assessors.
CMMC Accreditation Body (Cyber-AB) Guidance – Provides rules on conflict resolution.
Thus, option D is the most correct choice, as it aligns with the official CMMC conflict of interest procedures.
Validation of findings is an iterative process usually performed during the Daily Checkpoints throughout the entire assessment process. As a validation activity, why are the preliminary findings important?
It allows the OSC to comment and provide additional evidence.
It determines whether the OSC will be rated MET or NOT MET on their assessment.
It confirms that the Assessment Team ' s findings are right and cannot be changed.
It corroborates the Assessment Team ' s understanding of the CMMC practices and controls.
1. Understanding the Validation of Findings in CMMC Assessments
Validation of findings is an essential part of theCMMC assessment process, ensuring that observations and preliminary conclusions drawn by the assessment team are accurate, fair, and based on complete evidence. This process occurs iteratively during theDaily Checkpointsand is fundamental in determining the overall compliance status of theOrganization Seeking Certification (OSC).
2. The Role of Preliminary Findings in the Assessment Process
Preliminary findings arenot finalbut rather a mechanism for ensuring transparency, accuracy, and fairness. These findings serve several key purposes:
Allows for OSC Input & Clarification: The OSC has an opportunity to review andprovide additional evidencethat may address deficiencies identified by the assessment team.
Prevents Misinterpretations: By allowing the OSC to comment, the assessment team can refine or correct their understanding of the OSC ' s implementation of CMMC practices.
Supports Fair and Informed Ratings: Before finalizing MET or NOT MET determinations, the assessment team ensures they have considered all relevant evidence.
Encourages a Collaborative Assessment Process: This validation activity fosters open communication between assessors and the OSC, reducing disputes and misunderstandings.
3. Why Answer Choice " A " is Correct
The primary purpose of preliminary findings is to allow theOSC to comment and provide additional evidencebefore final determinations are made.
This aligns withCMMC Assessment Process guidance, which emphasizes iterative validation of findings throughDaily Checkpoints and Final Outbriefdiscussions.
The validation of findings ensures thatOSC responses and supplementary evidence are considered, making the assessment process more accurate and fair.
4. Why Other Answer Choices Are Incorrect
Option
Reason for Elimination
B. It determines whether the OSC will be rated MET or NOT MET on their assessment.
Incorrect: Preliminary findings do not directly determine the final rating. The assessment team reviews all collected evidence before making a final decision.
C. It confirms that the Assessment Team ' s findings are right and cannot be changed.
Incorrect: Findings arenot finalat the preliminary stage. The OSC has the opportunity to challenge findings by providing new or clarifying evidence.
D. It corroborates the Assessment Team ' s understanding of the CMMC practices and controls.
Partially Correct but Not the Best Answer: While validation helps refine understanding, itsprimary function is to allow OSC input, making optionA the most accurate choice.
5. Official CMMC References Supporting This Answer
CMMC Assessment Process (CAP) Document:
Section 5.3 – Validation of Findings: " The OSC is given the opportunity to provide additional evidence and comments to clarify or supplement preliminary assessment results. "
Section 5.4 – Daily Checkpoints: " The assessment team discusses preliminary findings with the OSC, allowing the organization to address concerns in real time. "
CMMC 2.0 Level 2 Scoping & Assessment Guide:
Confirms that the assessment process includes continuous dialogue with the OSC before final determinations are made.
6. Conclusion
Preliminary findings are acrucial validation stepin CMMC assessments, ensuring that organizations have the opportunity toprovide additional evidence and clarify potential misunderstandings. This iterative process improves accuracy and fairness in determining compliance with CMMC requirements. Therefore, the correct answer is:
A. It allows the OSC to comment and provide additional evidence.
A test or demonstration is being performed for the Assessment Team during an assessment. Which environment MUST the OSC perform this test or demonstration?
Client
Production
Development
Demonstration
Understanding the Assessment Environment Requirement
During aCMMC Level 2 assessment, assessors requireobjective evidencethat security controls are implementedin the actual operating environmentwhereControlled Unclassified Information (CUI)is handled.
This means thattests or demonstrations must be conducted in the production environment, where the organization’s real systems and security controls are in use.
Why Option B (Production) is Correct
Assessment teams need to validate security controls in the actual environment where they are applied, ensuring that security measures are in effect in thereal-world operating conditions.
Option A (Client)is incorrect because " Client " is not a defined assessment environment.
Option C (Development)is incorrect because testing in a development environmentdoes not accurately represent the production security posture.
Option D (Demonstration)is incorrect becausedemonstrations in a separate test environment do not provide valid evidence for CMMC assessments—actual security implementations must be verified in production.
Official CMMC Documentation References
CMMC Assessment Process (CAP) Guide – Section 3.5 (Assessment Methods)
NIST SP 800-171 Assessment Procedures(Verification must occur in the actual system where CUI resides.)
Final Verification
SinceCMMC assessments require security controls to be validated in the actual production environment, the correct answer isOption B: Production.
A C3PAO is near completion of a Level 2 Assessment for an OSC. The CMMC Findings Brief and CMMC Assessment Results documents have been developed. The Final Recommended Assessment Results are being generated. When generating these results, what MUST be included?
An updated Assessment Plan
Recorded and final updated Daily Checkpoint
Fully executed CMMC Assessment contract between the C3PAO and the OSC
Review documentation for the CMMC Quality Assurance Professional (CQAP)
According to the CMMC Assessment Process (CAP), specifically within the Phase 4: Reporting Results requirements, a C3PAO must ensure that every assessment package undergoes a rigorous quality review before it is finalized and submitted to the Department of Defense (DoD).
The Role of the CQAP: The CMMC Quality Assurance Professional (CQAP) is a designated role within a C3PAO responsible for verifying that the assessment was conducted in accordance with the CAP and that the evidence collected (the " Artifacts " ) supports the findings (Met/Not Met).
Mandatory Inclusion: When generating the Final Recommended Assessment Results, the package is not considered complete or valid without the formal review documentation from the CQAP. This documentation serves as the " stamp of approval " that the internal Quality Management System (QMS) of the C3PAO has validated the assessment team ' s work.
Why other options are incorrect:
Option A: While the Assessment Plan is a required document during the planning phase, it is an input to the process, not a mandatory component of theFinal Resultsgeneration in the same way quality validation is.
Option B: Daily Checkpoints are administrative tools used during the " Conduct Assessment " phase to keep the OSC informed. While they are part of the assessment record, they are not a mandatory technical component of the final results package.
Option C: The contract is a legal/business requirement handled during the " Plan and Prepare " phase; it is not included in the technical assessment results uploaded to the DoD.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 4.2 (Finalize Assessment Report) and Section 4.3 (C3PAO Quality Review).
C3PAO Authorization Requirements: Specifies the requirement for a Quality Assurance (QA) function to review all assessment outputs to ensure consistency and integrity across the ecosystem.
Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit, Supporting Organization/Unit, or enclave have been met?
OSC
Assessment Team
Authorizing official
Assessment official
Per the CMMC Assessment Process (CAP), the Assessment Team is responsible for determining the adequacy and sufficiency of evidence collected during the assessment. The team validates whether practices and components for each in-scope Host Unit, Supporting Organization, or enclave meet the target CMMC level. The OSC (Organization Seeking Certification) provides evidence, but only the Assessment Team makes the verification and scoring determination.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
What type of criteria is used to answer the question " Does the Assessment Team have the right evidence? "
Adequacy criteria
Objectivity criteria
Sufficiency criteria
Subjectivity criteria
According to the CMMC Assessment Process (CAP), specifically during the Phase 3: Conduct Assessment (Evidence Collection and Verification), the Assessment Team must evaluate all collected artifacts, interview notes, and test results against two primary dimensions: Adequacy and Sufficiency.
Adequacy (The " Right " Evidence): This criterion focuses on the quality, relevance, and validity of the evidence. It addresses whether the evidence actually maps to the specific CMMC practice being assessed and whether it is authoritative (e.g., signed, current, and from a trusted source). If an assessor asks, " Is this therightpiece of information to prove this practice is met? " they are testing for Adequacy.
Sufficiency (The " Enough " Evidence): This criterion focuses on the quantity and scope of the evidence. It addresses whether the Assessment Team has collected enough data points (across the required number of assets and using the required methods of Examine, Interview, and Test) to reach a confident conclusion. If an assessor asks, " Do I haveenoughexamples of this practice in action across the entire enclave? " they are testing for Sufficiency.
Why other options are incorrect:
B and D (Objectivity/Subjectivity): While assessors must remain objective, these are not the formal " criteria " used to categorize the evidence collection quality within the CAP framework.
C (Sufficiency): As noted above, Sufficiency is about theamountof evidence, not whether it is thecorrect type(the " right " evidence).
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4, " Collect and Verify Evidence, " which explicitly defines the requirement for evidence to be both adequate and sufficient.
CMMC Level 2 Assessment Guide: Guidance on the application of the Examine, Interview, and Test (E-I-T) methods to ensure evidence quality.
NIST SP 800-171A: The foundation for CMMC assessment procedures, which emphasizes the need for relevant (adequate) evidence to support findings.
A CMMC Level 1 Self-Assessment identified an asset in the OSC ' s facility that does not process, store, or transmit FCI. Which type of asset is this considered?
FCI Assets
Specialized Assets
Out-of-Scope Assets
Government-Issued Assets
The Cybersecurity Maturity Model Certification (CMMC) 2.0 framework categorizes assets based on their interaction with Federal Contract Information (FCI) and Controlled Unclassified Information (CUI). In a CMMC Level 1 self-assessment, assets are classified based on whether they process, store, or transmit FCI.
Asset Categories as per CMMC 2.0:
FCI Assets – These assets process, store, or transmit FCI and must meet CMMC Level 1 security requirements (17 practices from FAR 52.204-21).
CUI Assets – These assets handle Controlled Unclassified Information (CUI) and are subject to CMMC Level 2 requirements, aligned with NIST SP 800-171.
Specialized Assets – Includes IoT devices, Operational Technology (OT), Government-Furnished Equipment (GFE), and test equipment. These are often categorized separately due to their specific cybersecurity requirements.
Out-of-Scope Assets – Assets that do not process, store, or transmit FCI or CUI. These do not require compliance with CMMC practices.
Government-Issued Assets – These are assets provided by the government for contract-specific purposes, often requiring compliance based on government policies.
Why the Correct Answer is C. Out-of-Scope Assets?
The question specifies that the identified asset does not process, store, or transmit FCI.
According to CMMC 2.0 guidelines, only assets that handle FCI or CUI are subject to security controls.
Assets that are physically located within an OSC’s facility but do not interact with FCI or CUI fall into the " Out-of-Scope Assets " category.
These assets do not require CMMC-specific cybersecurity controls, as they have no impact on the security of FCI or CUI.
Relevant CMMC 2.0 References:
CMMC Scoping Guide (Nov 2021) – Defines out-of-scope assets as those that are within an OSC’s environment but have no interaction with FCI or CUI.
CMMC 2.0 Level 1 Guide – Only requires security controls on FCI assets, meaning assets that do not process, store, or transmit FCI are out of scope.
CMMC Assessment Process (CAP) Guide – Identifies the classification of assets in an OSC’s environment to determine compliance requirements.
Final Justification:
Since the asset does not process, store, or transmit FCI, it does not fall under " FCI Assets " or " Specialized Assets. " It is also not a government-issued asset. Therefore, the correct classification under CMMC 2.0 is Out-of-Scope Assets (C).
The director of cybersecurity is considering which company offices and data centers store FCI to ensure an accurate scope for their CMMC Level 1 Self-Assessment . Which asset type is the director considering?
ESP
People
Facilities
Technology
For CMMC Level 1 scoping , the DoD’s CMMC Scoping Guide – Level 1 (v2.13) instructs an organization performing a Level 1 self-assessment to consider what is in scope for protecting Federal Contract Information (FCI) . Specifically, it states that to appropriately scope a Level 1 self-assessment, the OSA should consider the people, technology, facilities, and external service providers (ESPs) within its environment that process, store, or transmit FCI .
In this scenario, the director is evaluating company offices and data centers where FCI is stored. These are physical locations and physical environments—exactly what the scoping guidance categorizes under Facilities . Facilities in a Level 1 context include physical sites and spaces that may house systems or media containing FCI (e.g., offices, server rooms, data centers), because those locations affect physical access controls, environmental protections, and overall safeguarding of where FCI is handled and stored.
This is distinct from Technology (devices/systems), People (personnel who handle FCI), and ESPs (external providers delivering IT/cyber services). Since the question is explicitly about which offices and data centers store FCI —a physical boundary and location question—the correct asset type is Facilities .
A client uses an external cloud-based service to store, process, or transmit data that is reasonably believed to qualify as CUI. According to DFARS clause 252.204-7012. what set of established security requirements MUST that cloud provider meet?
FedRAMP Low
FedRAMP Moderate
FedRAMP High
FedRAMP Secure
UnderDFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting), if acontractoruses acloud-based serviceto store, process, or transmitControlled Unclassified Information (CUI), the cloud providermustmeet the security requirements ofFedRAMP Moderate or equivalent.
Key Requirements from DFARS 252.204-7012 (c)(1):
CUI stored in the cloud must be protected according to FedRAMP Moderate (or higher) requirements.
The cloud provider must meetFedRAMP Moderate baseline security controls, which align withNIST SP 800-53moderate impact level requirements.
The cloud provider must also ensure compliance withincident reportingandcyber incident response requirementsin DFARS 252.204-7012.
Why is the Correct Answer " FedRAMP Moderate " (B)?
A. FedRAMP Low ? Incorrect
FedRAMP Lowis intended for systems withlow confidentiality, integrity, and availability risks, making itinadequate for CUI protection.
B. FedRAMP Moderate ? Correct
FedRAMP Moderate is the minimum required level for CUIunder DFARS 252.204-7012.
It provides a security baseline for protectingsensitive but unclassified government data.
C. FedRAMP High ? Incorrect
FedRAMP Highapplies to systems handlinghighly sensitive information (e.g., classified or national security data), which is not necessarily required for CUI.
D. FedRAMP Secure ? Incorrect
There isno official FedRAMP Secure categoryin FedRAMP guidelines.
CMMC 2.0 References Supporting this Answer:
DFARS 252.204-7012(c)(1)
Specifies thatcontractors using external cloud services for CUI must meet FedRAMP Moderate or equivalent.
CMMC 2.0 Level 2 Requirements
CUI must be protected using NIST SP 800-171 security requirements, whichalign with FedRAMP Moderate controls.
FedRAMP Security Baselines
FedRAMP Moderateis designed for systems that handlesensitive government data, including CUI.
What is the MINIMUM required marking for a document containing CUI?
" CUI " must be placed in the header and footer of the document
" WCUI " must be placed in the header and footer of the document
Portion marks must be placed on all sections, parts, paragraphs, etc. known to contain CUI
A cover page must be placed to obscure content with the acronym " CUI " prominently placed
Per DoDI 5200.48, Controlled Unclassified Information (CUI), the minimum marking requirement is that the word “CUI” must appear in the header and footer of each page of a document containing CUI. Additional markings such as portion markings or cover sheets may be applied depending on the situation, but the minimum baseline requirement is header and footer placement of " CUI " .
Reference Documents:
DoDI 5200.48,Controlled Unclassified Information (CUI)
The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?
Affirmation for each practice or control
Documented rationale for each failed practice
Suggested improvements for each failed practice
Gaps or deltas due to any reciprocity model are recorded as met
Understanding the CMMC Level 2 Final Report Requirements
For aCMMC Level 2 Assessment, theFinal CMMC Assessment Results Reportmust include:
Assessment findings for each practice
Final ratings (MET or NOT MET) for each practice
A detailed rationale for each practice rated as NOT MET
Why " B. Documented rationale for each failed practice " is Correct?
The CMMC Assessment Process (CAP) Guidestates that if a practice is markedNOT MET, theassessors must provide a rationale explaining why it failed.
This rationale helps theOSC understand what needs remediationand, if applicable, whether the deficiency can be addressed via aPlan of Action & Milestones (POA & M).
TheFinal Report serves as an official recordand must be submitted as part of theresults package.
Why Other Answers Are Incorrect?
A. Affirmation for each practice or control (Incorrect)
While the report includes aMET/NOT MET ratingfor each practice,affirmation is not a required component.
C. Suggested improvements for each failed practice (Incorrect)
Assessors do not provide recommendations for improvement—they only document findings and rationale.
Providing suggestions would create aconflict of interestperCMMC-AB Code of Professional Conduct.
D. Gaps or deltas due to any reciprocity model are recorded as met (Incorrect)
If an organization isleveraging reciprocity (e.g., FedRAMP, Joint Surveillance Voluntary Assessments), gapsmust still be documented—not automatically marked as " MET. "
Conclusion
The correct answer isB. Documented rationale for each failed practice, as this is amandatory requirement in the Final CMMC Assessment Results Report.
A defense contractor needs to share FCI with a subcontractor and sends this data in an email. The email system involved in this process is being used to:
manage FCI.
process FCI.
transmit FCI.
generate FCI
Federal Contract Information (FCI) is defined in FAR 52.204-21 as information provided by or generated for the government under contract but not intended for public release. Under CMMC 2.0, organizations handling FCI must implement FAR 52.204-21 Basic Safeguarding Requirements, ensuring proper protection in processing, storing, and transmitting FCI.
Analyzing the Given Options
The question involves an email system that is used to send FCI to a subcontractor. Let’s break down the possible answers:
A. Manage FCI ? Incorrect
Managing FCI involves activities like organizing, storing, and maintaining access to FCI. Sending an email does not fall under management; it is an act of transmission.
B. Process FCI ? Incorrect
Processing refers to actively using FCI for operational or analytical purposes, such as analyzing, modifying, or computing data. Simply sending an email does not constitute processing.
C. Transmit FCI ? Correct
Transmission refers to the act of sending FCI from one entity to another. Since the contractor is sending FCI via email, this falls under transmitting the data.
Which assessment method compares actual-specified conditions with expected behavior?
Test
Examine
Compile
Interview
Understanding CMMC Assessment Methods
TheCybersecurity Maturity Model Certification (CMMC) 2.0follows theNIST SP 800-171A assessment methodology, which includesthree primary assessment methods:
Examine– Reviewing policies, procedures, system configurations, and documentation.
Interview– Engaging with personnel to validate their understanding and execution of security practices.
Test– Conducting actual technical or operational tests to determine whether security controls function as expected.
Why " Test " is the Correct Answer?
" Test " is the method that compares actual-specified conditions with expected behavior.
It involvesexecuting procedures, configurations, or automated toolsto see if thesystem behaves as required.
For example, if a policy states that multi-factor authentication (MFA) must be enforced, a test would involveattempting to log in without MFAto confirm whether access is blocked as expected.
TheNIST SP 800-171A Guide (Assessment Procedures for CUI)defines testing as an assessment method that:
Actively verifies a security control is functioning
Simulates real-world attack scenarios
Checks compliance through system actions rather than documentation
Why Other Answers Are Incorrect?
B. Examine (Incorrect)
Examining only involvesreviewing policies, procedures, or configurationsbut does not actively test system behavior.
C. Compile (Incorrect)
" Compile " is not an assessment method in CMMC 2.0 or NIST SP 800-171A.
D. Interview (Incorrect)
Interviews are used to gather insights from personnel, but they do not compare actual conditions with expected behavior.
Conclusion
The correct answer isA. Testbecause itactively verifies system performance against expected security conditions.
In the CMMC Model, how many practices are included in Level 1?
15 practices
17 practices
72 practices
110 practices
CMMC (Cybersecurity Maturity Model Certification) 2.0 Level 1 is designed to protectFederal Contract Information (FCI)and consists of17 foundational cybersecurity practices. These practices are directly derived fromFAR 52.204-21(Basic Safeguarding of Covered Contractor Information Systems), which outlines minimum security requirements for contractors handling FCI.
Breakdown of CMMC Level 1 Practices
The17 practicesin Level 1 focus on basic cybersecurity hygiene and fall under the following6 domains:
Access Control (AC)– 4 practices
AC.L1-3.1.1: Limit system access to authorized users
AC.L1-3.1.2: Limit user access to authorized transactions and functions
AC.L1-3.1.20: Verify and control connections to external systems
AC.L1-3.1.22: Control information posted or processed on publicly accessible systems
Identification and Authentication (IA)– 2 practices
IA.L1-3.5.1: Identify and authenticate system users
IA.L1-3.5.2: Use multifactor authentication for local and network access
Media Protection (MP)– 1 practice
MP.L1-3.8.3: Sanitize media before disposal or reuse
Physical Protection (PE)– 4 practices
PE.L1-3.10.1: Limit physical access to systems containing FCI
PE.L1-3.10.3: Escort visitors and monitor visitor activity
PE.L1-3.10.4: Maintain audit logs of physical access
PE.L1-3.10.5: Control and manage physical access devices
System and Communications Protection (SC)– 2 practices
SC.L1-3.13.1: Monitor and control communications at system boundaries
SC.L1-3.13.5: Implement subnetworks for publicly accessible system components
System and Information Integrity (SI)– 4 practices
SI.L1-3.14.1: Identify, report, and correct system flaws in a timely manner
SI.L1-3.14.2: Provide protection from malicious code at designated locations
SI.L1-3.14.4: Update malicious code protection mechanisms periodically
SI.L1-3.14.5: Perform scans of system components and real-time file scans
Official Reference from CMMC 2.0 Documentation
The 17 practices forCMMC Level 1are explicitly listed in theCMMC 2.0 Appendices and Assessment Guide for Level 1, as well as in theFAR 52.204-21 requirements. These practices representbasic safeguarding measuresthat all DoD contractors handlingFCImust implement.
???? CMMC 2.0 Level 1 Summary:
Focus:Basic safeguarding of FCI
Total Practices:17
Derived From:FAR 52.204-21
Assessment Type:Self-assessment (annual)
Final Verification and Conclusion
The correct answer isB. 17 practicesas verified from theCMMC 2.0 official documentsandFAR 52.204-21 requirements.
A contractor provides services and data to the DoD. The transactions that occur to handle FCI take place over the contractor ' s business network, but the work is performed on contractor-owned systems, which must be configured based on government requirements and are used to support a contract. What type of Specialized Asset are these systems?
loT
Restricted IS
Test equipment
Government property
Understanding Restricted Information Systems (IS) in CMMC Scoping
InCMMC 2.0,Specialized Assetsrefer to assets that do not fit traditional IT system categories but still play a role inprocessing, storing, or transmitting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The four categories ofSpecialized Assetsin theCMMC Scoping Guideinclude:
Internet of Things (IoT) Devices– Smart or network-connected devices.
Restricted Information Systems (Restricted IS)– Systems that arecontractually requiredto beconfigured to government specifications.
Test Equipment– Devices used for specialized testing or measurement.
Government Property– Equipment owned by theU.S. Governmentbut used by contractors.
Why " B. Restricted IS " is Correct?
The contractor-owned systems in question areconfigured based on government requirementsandused to support a DoD contract.
Restricted ISassets arecontractually requiredto meet government security requirements andhandle DoD-related information.
These systemsdo not fall under general IT assets but instead require special handling, making them a Restricted ISper theCMMC Scoping Guide.
Why Other Answers Are Incorrect?
A. IoT (Incorrect)
IoT devices includesmart devices, sensors, and embedded systems, but the contractor ' s business systems are not classified as IoT.
C. Test Equipment (Incorrect)
The contractor’s systems areused for handling FCI, not for testing or measurement.
D. Government Property (Incorrect)
The systems arecontractor-owned, not owned by theU.S. Government, so they do not qualify asGovernment Property.
Conclusion
The correct answer isB. Restricted IS, as the systems arecontractor-owned but must follow DoD security requirements.
A machining company has been awarded a contract with the DoD to build specialized parts. Testing of the parts will be done by the company using in-house staff and equipment. For a Level 1 Self-Assessment, what type of asset is this?
CUI Asset
In-scope Asset
Specialized Asset
Contractor Risk Managed Asset
According to the CMMC Scoping Guidance, Level 1, the categorization of assets is much simpler than at Level 2. At Level 1, there are only two primary categories for assets within the Organization Seeking Certification (OSC): In-Scope Assets (FCI Assets) and Out-of-Scope Assets.
FCI Asset Definition: An asset is considered " In-Scope " for Level 1 if it processes, stores, or transmits Federal Contract Information (FCI). Since the company is building specialized parts under a DoD contract and using in-house staff and equipment for testing, the information related to that contract (the specifications, schedules, and test results) constitutes FCI.
The Level 1 Universe:
Level 1 does not use the complex sub-categories found in Level 2 scoping, such as " Specialized Assets " (OT/IoT/Test Equipment) or " Contractor Risk Managed Assets. " Those distinctions are specific to CMMC Level 2 Scoping.
In a Level 1 environment, any piece of equipment or software that handles the contract ' s information is simply termed an FCI Asset, which falls under the broader umbrella of In-Scope Assets.
Why other options are incorrect:
Option A (CUI Asset): Level 1 is focused exclusively on FCI. CUI (Controlled Unclassified Information) is the focus of Level 2 and Level 3.
Option C (Specialized Asset) and Option D (Contractor Risk Managed Asset): These are specific scoping categories defined in the CMMC Level 2 Scoping Guidance. In Level 1, these categories do not exist; an asset either handles FCI (In-Scope) or it does not (Out-of-Scope).
Reference Documents:
CMMC Scoping Guidance, Level 1 (Version 2.0): Section 2.0 (CMMC Level 1 Asset Categories), which defines FCI Assets and Out-of-Scope Assets.
32 CFR Part 170 (CMMC Program Rule): Establishes the simplified scoping requirements for Level 1 self-assessments.
CMMC Level 1 Assessment Guide: Clarifies that the scope includes all " information systems " (including test equipment) used by the contractor to process, store, or transmit FCI.
When are contractors required to achieve a CMMC certificate at the Level specified in the solicitation?
At the time of award
Upon solicitation submission
Thirty days from the award date
Before the due date of submission
PerDFARS 252.204-7021, contractors must achieve the requiredCMMC certification levelbefore contract awardif the solicitation specifies it.
Key Requirements:
?Contractorsmust be certified at the required CMMC levelprior to contract award.
?Thecertification must be conducted by a C3PAO(for Level 2) orthrough self-assessment(for Level 1).
?The certification must bevalid and registered in the Supplier Performance Risk System (SPRS)before award.
Why is the Correct Answer " At the Time of Award " (A)?
A. At the time of award ? Correct
DFARS 252.204-7021requires CMMC certification before a contract can be awardedif the solicitation includes CMMC requirements.
B. Upon solicitation submission ? Incorrect
Contractorsdo notneed to be CMMC-certified at thetime of bid submission, only by the time of award.
C. Thirty days from the award date ? Incorrect
Contractorsmust already be certified before the award is granted. There isno grace period.
D. Before the due date of submission ? Incorrect
While compliance planning is important,CMMC certification is only required before contract award, not before bid submission.
CMMC 2.0 References Supporting This Answer:
DFARS 252.204-7021 (CMMC Requirement Clause)
CMMC certification is required prior to contract awardif specified in the solicitation.
CMMC 2.0 Program Overview
States that certificationis not needed at bid submission but is required before award.
DoD Interim Rule & SPRS Guidance
Contractors must havea valid CMMC certification recorded in SPRSbefore award.
Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?
Level 1
Level 2
Level 3
All levels
Understanding Training Requirements in CMMC
The requirement for ensuring thatpersonnel are trained to carry out their assigned information security-related duties and responsibilitiesfirst appears inCMMC Level 2as part ofNIST SP 800-171 control AT.L2-3.2.1.
Key Details on the Training Requirement:
?AT.L2-3.2.1: " Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. "
?This control is derived fromNIST SP 800-171and applies toCMMC Level 2 (Advanced).
?It ensures that employees handlingControlled Unclassified Information (CUI)understand theircybersecurity responsibilities.
Why is the Correct Answer " B. Level 2 " ?
A. Level 1 ? Incorrect
CMMC Level 1 does not include this training requirement.Level 1 focuses on basic safeguarding ofFederal Contract Information (FCI)but doesnot require formal cybersecurity training.
B. Level 2 ? Correct
The training requirement (AT.L2-3.2.1) first appears in CMMC Level 2, which aligns withNIST SP 800-171.
C. Level 3 ? Incorrect
The training requirementalready exists in Level 2. Level 3 builds on Level 2 with additionalrisk management and advanced cybersecurity controls, but training is introduced at Level 2.
D. All levels ? Incorrect
CMMC Level 1 does not include this requirement—it is first introduced in Level 2.
CMMC 2.0 References Supporting This Answer:
NIST SP 800-171 (Requirement 3.2.1)
Defines themandatory training requirementfor personnel handling CUI.
CMMC Assessment Guide for Level 2
ListsAT.L2-3.2.1as a required practice under Level 2.
CMMC 2.0 Model Overview
Confirms thatCMMC Level 2 aligns with NIST SP 800-171, which includes security training requirements.
A company is about to conduct a press release. According to AC.L1-3.1.22: Control information posted or processed on publicly accessible systems, what is the MOST important factor to consider when addressing CMMC requirements?
That the information is correct
That the CEO approved the message
That the company has to safeguard the release of FCI
That so long as the information is only FCI, it can be released
Step 1: Understanding AC.L1-3.1.22
AC.L1-3.1.22states: " Control information posted or processed on publicly accessible systems. "
This control requires organizations toensure that FCI (Federal Contract Information) is not publicly postedor made accessible in an uncontrolled manner.
FCI must beprotected from unauthorized disclosure, even if it is not classified or CUI.
What is the legal entity under a contract that has agreed to deliver products or services?
Supporting Organization/Unit
Commercial and Government Entity Code
Host Unit
HQ Organization
The correct answer is D because the HQ Organization represents the legal entity associated with the contract obligation to deliver products or services. In assessment scoping, it is critical to separate the overall legal contracting entity from the specific Host Unit or operational segment that processes, stores, or transmits FCI or CUI. A Host Unit is the assessed operational environment or business unit within the organization where the relevant contract work and information handling occur. A Supporting Organization/Unit provides people, processes, or technology that support the Host Unit but is not the prime legal entity delivering the contractual product or service. A Commercial and Government Entity Code, or CAGE code, is an identifier associated with the entity; it is not itself the legal entity. CAP guidance requires the C3PAO to confirm the specific corporate legal entity being assessed and to solicit the associated CAGE code or codes. That distinction points to the HQ Organization as the contractual legal entity, while the CAGE code is only the identifier used to associate the entity with DoD systems. Reference/topics: CAP scoping, HQ Organization, Host Unit, CAGE code, legal entity confirmation.
The IT manager is scoping the company ' s CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?
ESP
People
Facilities
Technology
Understanding Asset Types in CMMC 2.0
In CMMC 2.0, assets are categorized based on their role in handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The Cybersecurity Maturity Model Certification (CMMC) Scoping Guidance for Level 1 and Level 2 provides asset definitions to help organizations identify what needs protection.
According to CMMC Scoping Guidance, there are five primary asset types:
Security Protection Assets (ESP - External Service Providers & Security Systems)
People (Personnel who interact with FCI/CUI)
Facilities (Physical locations housing FCI/CUI)
Technology (Hardware, software, and networks that store, process, or transmit FCI/CUI)
CUI Assets (For Level 2 assessments, assets specifically storing CUI)
Why " Technology " Is the Correct Answer
The IT manager is evaluating servers, laptops, databases, and applications—all of which are technology assets used to store, process, or transmit FCI.
According to CMMC Scoping Guidance, Technology assets include:
?Endpoints (Laptops, Workstations, Mobile Devices)
?Servers (On-premise or cloud-based)
?Networking Devices (Routers, Firewalls, Switches)
?Applications (Software, Cloud-based tools)
?Databases (Storage of FCI or CUI)
Since the IT manager is focusing on these components, the correct asset category is Technology (Option D).
Why the Other Answers Are Incorrect
A. ESP (Security Protection Assets)
?Incorrect. ESPs refer to security-related assets (e.g., firewalls, monitoring tools, managed security services) that help protect FCI/CUI but do not store, process, or transmit it directly.
B. People
?Incorrect. While employees play a role in handling FCI, the question focuses on hardware and software—which falls under Technology, not People.
C. Facilities
?Incorrect. Facilities refer to physical buildings or secured areas where FCI/CUI is stored or processed. The question explicitly mentions servers, laptops, and applications, which are not physical facilities.
CMMC Official References
CMMC Level 1 Scoping Guide (CMMC-AB) – Defines asset categories, including Technology.
CMMC 2.0 Scoping Guidance for Assessors – Provides clarification on FCI assets.
Thus, option D (Technology) is the most correct choice as per official CMMC 2.0 guidance.
A Lead Assessor is preparing to conduct a Readiness Review during Phase 1 of the Assessment Process. How much evidence MUST be gathered for each practice?
A sufficient amount
At least 2 Assessment Objects
Evidence that is deemed adequate
Evidence to support at least 2 Assessment Methods
During a Readiness Review (Phase 1), the purpose is to validate whether an OSC is prepared to move forward with a formal assessment. The CAP specifies that the Lead Assessor must collect sufficient evidence for each practice to make a preliminary determination of readiness.
Supporting Extracts from Official Content:
CAP v2.0, Readiness Review (§2.14): “The Lead Assessor must collect a sufficient amount of evidence for each practice to determine the OSC’s readiness.”
Why Option A is Correct:
The requirement is for sufficient evidence; CAP does not mandate a set number of assessment objects or methods.
Options B, C, and D incorrectly suggest minimum counts or methods that are not part of the readiness review requirements.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 1 Readiness Review.
===========
Which document is the BEST source for determining the sources of evidence for a given practice?
NISTSP 800-53
NISTSP 800-53A
CMMC Assessment Scope
CMMC Assessment Guide
TheCMMC Assessment Guideis the best source for determining the sources of evidence for a given practice because it provides specific guidance on how organizations should implement and demonstrate compliance with CMMC practices. Each CMMC level has its own assessment guide (e.g.,CMMC Assessment Guide – Level 1, Level 2), detailing expected evidence and assessment procedures.
Detailed Justification:
CMMC Assessment Guide (Primary Source for Evidence)
TheCMMC Assessment Guideexplicitly outlines the evidence required to verify compliance with each practice.
It provides detailed instructions on assessment objectives, clarifying what assessors should look for when determining compliance.
The guide breaks down each practice intoassessment objectives, helping organizations prepare appropriate documentation and artifacts.
Other Documents and Why They Are Not the Best Choice:
NIST SP 800-53 (Option A)
WhileNIST SP 800-53provides a comprehensive catalog of security and privacy controls, it does not focus on CMMC-specific evidence requirements.
It serves as a foundational cybersecurity framework but does not define the specific artifacts required for CMMC assessment.
NIST SP 800-53A (Option B)
NIST SP 800-53Aprovides guidance on assessing security controls but is not tailored to the CMMC framework.
It includes general control assessment procedures, but theCMMC Assessment Guideis more precise in defining the evidence needed for CMMC compliance.
CMMC Assessment Scope (Option C)
TheCMMC Assessment Scopedocument outlines which systems, assets, and processes are subject to assessment.
While important for defining boundaries, it does not provide details on specific evidence requirements for each practice.
References from Official CMMC Documents:
CMMC Assessment Guide (Level 2) – Section on " Assessment Objectives "
This document details how evidence is collected and evaluated for each CMMC practice.
Example: ForAC.L2-3.1.1 (Access Control – Limit System Access), the guide specifies that assessors should verify documented policies, system configurations, and audit logs.
CMMC Model Overview (Official DoD Documents)
Emphasizes thatCMMC Assessment Guidesare the official reference for determining sources of evidence.
Conclusion:
TheCMMC Assessment Guideis the most authoritative source for determining the required evidence for a given practice in CMMC assessments. It provides detailed breakdowns of assessment objectives, required artifacts, and verification steps necessary for compliance.
Which term describes " the protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to. or modification of information " ?
Adopted security
Adaptive security
Adequate security
Advanced security
Understanding the Concept of Security in CMMC 2.0
CMMC 2.0 aligns with federal cybersecurity standards, particularlyFISMA (Federal Information Security Modernization Act), NIST SP 800-171, and FAR 52.204-21. One key principle in these frameworks is the implementation of security measures that are appropriate for the risk level associated with the data being protected.
The question describes security measures that are proportionate to therisk of loss, misuse, unauthorized access, or modificationof information. This matches the definition of " Adequate Security. "
Analyzing the Given Options
A. Adopted security? Incorrect
The term " adopted security " is not officially recognized in CMMC, NIST, or FISMA. Organizations adopt security policies, but the concept does not directly align with the question’s definition.
B. Adaptive security? Incorrect
Adaptive securityrefers to adynamic cybersecurity modelwhere security measures continuously evolve based on real-time threats. While important, it does not directly match the definition in the question.
C. Adequate security?Correct
The term " adequate security " is defined inNIST SP 800-171, DFARS 252.204-7012, and FISMAas the level of protection that isproportional to the consequences and likelihood of a security incident.
This aligns perfectly with the definition in the question.
D. Advanced security? Incorrect
Advanced securitytypically refers tohighly sophisticated cybersecurity mechanisms, such as AI-driven threat detection. However, the term does not explicitly relate to the concept of risk-based proportional security.
Official References Supporting the Correct Answer
FISMA (44 U.S.C. § 3552(b)(3))
Definesadequate securityas " protective measures commensurate with the risk and potential impact of unauthorized access, use, disclosure, disruption, modification, or destruction of information. "
This directly matches the question ' s wording.
DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
Mandates that contractors apply " adequate security " to protect Controlled Unclassified Information (CUI).
NIST SP 800-171 Rev. 2, Requirement 3.1.1
States that organizations must " limit system access to authorized users and implement adequate security protections to prevent unauthorized disclosure. "
CMMC 2.0 Documentation (Level 1 and Level 2 Requirements)
Requires that organizationsapply adequate security measures in accordance with NIST SP 800-171to meet compliance standards.
Conclusion
The term " adequate security " is the correct answer because it is explicitly defined in federal cybersecurity frameworks asprotection proportional to risk and potential consequences. Thus, the verified answer is:
CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:
received and transferred.
stored, processed, and transmitted.
entered, edited, manipulated, printed, and viewed.
located on electronic media, on system component memory, and on paper.
TheCMMC Scoping Guide for Level 2outlines thatCUI assetsinclude systems, applications, and services thatstore, process, or transmitControlled Unclassified Information (CUI). These are the three core functions that defineCUI handlingwithin anOrganization Seeking Certification (OSC).
Step-by-Step Breakdown:
?1. CUI Assets Defined in CMMC
Stored:CUI is saved on hard drives, cloud storage, or databases.
Processed:CUI is actively used, modified, or analyzed by applications and users.
Transmitted:CUI is sent between systems via email, file transfers, or network communication.
?2. Why the Other Answer Choices Are Incorrect:
(A) Received and transferred?
Whilereceiving and transferring CUIis part of handling CUI, it does not fully cover all CUI asset responsibilities.
(C) Entered, edited, manipulated, printed, and viewed?
These arespecific actionswithinprocessingbut do not coverstorage or transmission, which are also required for CMMC scoping.
(D) Located on electronic media, on system component memory, and on paper?
While CUI can exist inelectronic and physical forms, CMMC scoping focuses onhow CUI is actively managed (stored, processed, transmitted)rather than where it physically resides.
Final Validation from CMMC Documentation:
TheCMMC Level 2 Scoping Guideconfirms thatCUI Assets are categorized based on their role in storing, processing, or transmitting CUI.
NIST SP 800-171also defines these three functions as key components of CUI protection.
The Lead Assessor is presenting the Final Findings Presentation to the OSC. During the presentation, the Assessment Sponsor and OSC staff inform the assessor that they do not agree with the assessment results. Who has the final authority for the assessment results?
C3PAO
CMMC-AB
Assessment Team
Assessment Sponsor
Who Has the Final Authority Over Assessment Results?
During aCMMC Level 2 assessment, theCertified Third-Party Assessment Organization (C3PAO)is responsible for conducting and finalizing the assessment results.
Key Responsibilities of a C3PAO
?Leads the assessmentand ensures it follows the CMMC Assessment Process (CAP).
?Validates compliancewith CMMC Level 2 requirements based onNIST SP 800-171controls.
?Finalizes the assessment resultsand submits them to theCMMC-ABand theDoD.
?Handles disagreementsfrom the OSC but hasfinal decision-making authorityon results.
Why " C3PAO " is Correct?
The C3PAO has final authority over the assessment resultsafter considering all evidence and findings.
TheCMMC-AB (Option B) does not finalize assessments—it accredits C3PAOs and manages the certification ecosystem.
TheAssessment Team (Option C) supports the C3PAO but does not have final decision authority.
TheAssessment Sponsor (Option D) is a representative from the OSC and does not control the results.
Breakdown of Answer Choices
Option
Description
Correct?
A. C3PAO
?Correct – C3PAOs finalize and submit assessment results.
B. CMMC-AB
?Incorrect–The CMMC-AB accredits C3PAOs but doesnot finalize results.
C. Assessment Team
?Incorrect–They conduct the assessment, but the C3PAO makes final decisions.
D. Assessment Sponsor
?Incorrect–This is arepresentative of the OSC, not the assessment authority.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)– DefinesC3PAO authorityover final assessment results.
Final Verification and Conclusion
The correct answer isA. C3PAO, as theC3PAO has final decision-making authority over CMMC assessment results.
An assessment is being completed at a client site that is not far from the Lead Assessor ' s home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?
Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.
Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.
Log into the client VPN from the assessor ' s laptop and retrieve the documents from the secure cloud storage service.
Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.
Best Practices for Handling Sensitive Assessment Information
CMMC assessments involve handlingsensitive and potentially CUI-related documents. Assessors must follow strictsecurity policiesto avoid unauthorized access, data leaks, or non-compliance withCMMC 2.0 and NIST SP 800-171 requirements.
Why Logging into the Client VPN on the Client Laptop is the Best Approach:
Ensures Data Protection:The client laptop is likely configured to meet security controls required for handling assessment-related materials.
Prevents Data Spillage:Keeping all assessment-related activities within the client’s secured environment reduces the risk ofdata leakage or unauthorized storage.
Maintains Compliance with CMMC/NIST Guidelines:Using aproperly configured client laptop and secured connectionensures compliance withNIST SP 800-171 controls on secure remote access(Requirement3.13.12).
Clarification of Incorrect Options:
A. " Log into the secure cloud storage service to save copies of the documents on both the work and client laptops. "
Incorrect?Sensitive data should not be duplicated across multiple systems, especially a non-client-approved laptop. Storing it on an unauthorized systemviolates data handling best practices.
C. " Log into the client VPN from the assessor ' s laptop and retrieve the documents from the secure cloud storage service. "
Incorrect? Theassessor’s laptop may not be authorizedorsecuredto handle client data. CMMC guidelines emphasizeusing approved, secured systemsfor assessment-related information.
D. " Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick. "
Incorrect?
Transferring sensitive documents via USBintroduces security risks, including unauthorized data storage and potential malware contamination.
Home office workstationsare unlikely to be authorized for handling CMMC-sensitive data.
During the planning phase of a CMMC Level 2 Assessment, the Lead Assessor is considering what would constitute the right evidence for each practice. What is the Assessor attempting to verify?
Adequacy
Sufficiency
Process mapping
Assessment scope
Understanding Evidence Sufficiency in CMMC Level 2 Assessments
During aCMMC Level 2 Assessment, theLead Assessormust determine whether the evidence collected for each practice issufficientto support an assessment finding. This aligns with theCMMC Assessment Process (CAP) Guide, which requires assessors to evaluate:
Examinations– Reviewing documents, configurations, and system records.
Interviews– Speaking with personnel to confirm implementation and understanding.
Testing– Observing security controls in action to validate effectiveness.
To determine whether evidence issufficient, the assessor ensures that it:
Directly supports the assessment objective.
Demonstrates that the practice is consistently implemented.
Can be independently verified.
Why Option B (Sufficiency) is Correct
Sufficiencyrefers to whetherenoughevidence has been collected to make an accurate determination about compliance.
Option A (Adequacy)is incorrect because adequacy relates tothe qualityof evidence, while sufficiency focuses on whetherenoughevidence exists.
Option C (Process Mapping)is incorrect because process mapping is used for understanding workflows but is not an assessment verification method.
Option D (Assessment Scope)is incorrect because defining the scope happensbeforeevidence collection, during the planning phase.
Official CMMC Documentation References
CMMC Assessment Process (CAP) Guide – Section 3.6 (Determining Sufficiency of Evidence)
CMMC Level 2 Assessment Guide – Evidence Collection and Evaluation
Final Verification
Since theLead Assessor is ensuring enough evidence is available to verify compliance, the correct answer isOption B: Sufficiency.
An assessor is in Phase 3 of the CMMC Assessment Process. The assessor has delivered the final findings, submitted the assessment results package, and provided feedback to the C3PAO and CMMC-AB. What must the assessor still do?
Determine level recommendation
Archive all assessment artifacts
Determine final practice pass/fail results
Archive or dispose of any assessment artifacts
In Phase 3 (Post-Assessment), the assessor’s responsibility is to archive or dispose of assessment artifacts according to the C3PAO’s policies and retention requirements. By this point, final findings and results have already been delivered, so the only remaining step is ensuring proper handling of assessment materials.
Supporting Extracts from Official Content:
CAP v2.0, Post-Assessment Activities (§3.17): “The assessor must archive or dispose of any assessment artifacts in accordance with the C3PAO’s retention and destruction policy.”
Why Option D is Correct:
Determining practice pass/fail results and level recommendations occurs earlier in Phases 2 and 3.
The final step left for the assessor is the proper archiving or destruction of artifacts.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 3: Post-Assessment (§3.17).
===========
The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections. How should the team score practices in which the evidence shows the deficiencies have been corrected?
MET
POA & M
NOT MET
NOT APPLICABLE
Understanding the CMMC Assessment Process (CAP) Phases
TheCMMC Assessment Process (CAP)consists ofthree primary phases:
Phase 1 - Planning(Pre-assessment activities)
Phase 2 - Conducting the Assessment(Evidence collection and analysis)
Phase 3 - Reporting and Finalizing Results
DuringPhase 3, the Assessment Teamreviews evidenceto confirm if anyLimited Practice Deficiency Correctionshave been successfully implemented.
Scoring Practices in Phase 3
The CAP document specifies that a practice can bescored as METif:
?The deficiency identified in Phase 2 has been fully corrected before final scoring.
?Sufficient evidence is provided to demonstrate compliance with the CMMC requirement.
?The correction is notmerely plannedbutfully implemented and validatedby the assessors.
Since the evidence shows thatdeficiencies have been corrected, the correct score isMET.
Why the Other Answers Are Incorrect
B. POA & M (Plan of Action & Milestones)
?Incorrect. APOA & M (Plan of Action and Milestones)is usedonly when a deficiency remains unresolved. Since the deficiency is already corrected, this option does not apply.
C. NOT MET
?Incorrect. A practice is scoredNOT METonly if the deficiency hasnotbeen corrected by the end of the assessment.
D. NOT APPLICABLE
?Incorrect. A practice is markedNOT APPLICABLE (N/A)only if it doesnot apply to the organization’s environment, which is not the case here.
CMMC Official References
CMMC Assessment Process (CAP) Document– Defines scoring criteria for MET, NOT MET, and POA & M.
Thus,option A (MET) is the correct answer, as the deficiencies have been corrected before final scoring.
In accordance with NARA directives and Chapter 33 of Title 44 (Records Management Directive), which types of data MUST have policies and procedures for disposal?
All recorded digital documents
All digital and recorded paper documents
All digital documents and recorded media
All recorded information, regardless of form or characteristics
Under Title 44 U.S.C. Chapter 33 (Records Management) and NARA directives, agencies and organizations must establish policies and procedures for the disposal of all recorded information, regardless of form or characteristics. This includes paper records, electronic documents, digital media, audiovisual files, and any other information format. The requirement ensures consistent handling, retention, and lawful disposal of both federal records and CUI.
Reference Documents:
Title 44, U.S. Code, Chapter 33: Records Management
NARA Records Management Directive
3 Months Free Update
3 Months Free Update
3 Months Free Update
TESTED 23 Aug 2026