Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

Certified CMMC Assessor (CCA) Exam

Last Update 9 hours ago Total Questions : 150

The Certified CMMC Assessor (CCA) Exam content is now fully updated, with all current exam questions added 9 hours ago. Deciding to include CMMC-CCA practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our CMMC-CCA exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these CMMC-CCA sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any Certified CMMC Assessor (CCA) Exam practice test comfortably within the allotted time.

Question # 1

An OSC has a headquarters (HQ) site and satellite offices A and B. The two satellite offices are connected to the HQ through a VPN. CUI is stored within the HQ LAN room and used by staff at HQ and Site A. When categorizing assets for this assessment, assets at the HQ:

A.

and Site A contain CUI assets and Site B is out of scope.

B.

and Site A and Site B contain CUI assets since all have access to CUI.

C.

contain CUI assets and Site A and Site B contain only Certification in Risk Management Assurance.

D.

and Site A contain CUI assets and Site B contains only Certification in Risk Assurance.

Question # 2

A Lead Assessor is conducting an assessment for an OSC. The OSC is currently using doors and badge access to limit access to private areas of their campus to only authorized personnel. Which item is another means of controlling physical access to areas that contain CUI?

A.

Guards

B.

Cameras

C.

Firewalls

D.

Partition walls

Question # 3

What is NOT required for the Lead Assessor to confirm when verifying readiness to conduct an assessment?

A.

That risks have been identified

B.

That necessary logistics have been arranged

C.

Whether the OSC can better meet the targeted CMMC Level

D.

That evidence is available and accessible for the targeted CMMC Level

Question # 4

The Lead Assessor is reviewing the Assessment Plan to identify people for interviews regarding a specific Level 2 practice. Some OSC personnel previously interviewed provided only brief answers without meaningful verification. What can the Lead Assessor do to improve this situation going forward?

A.

Ensure the people from the training matrix are made available

B.

Ensure and verify confidentiality and non-attribution of responses

C.

Ensure the respondents sign a non-disclosure agreement for the OSC

D.

Ensure and verify the responses map to the documented artifacts

Question # 5

An OSC is preparing for an assessment and wants to gather evidence that will be used by the Lead Assessor to determine the scope of the assessment. The OSC currently operates a hybrid network, with part of their infrastructure at their physical location and part of their infrastructure in a cloud environment.

What evidence should the OSC collect that would assist the Lead Assessor in determining cloud and hybrid environment constraints?

A.

Subnetworks list

B.

System inventory

C.

Company-owned hardware list

D.

Cloud Service Provider’s Customer Responsibility Matrix

Question # 6

During a CMMC Level 2 Assessment, a CCA interviewed a system administrator on the OSC’s procedures around configuration management and endpoint security. The system administrator described how they build and deploy new systems, and noted that some users require specialized applications for their jobs. Users have been asked to email IT when they install and run an additional application so IT can add it to their list of allowed software.

What must the CCA conclude?

A.

The OSC has properly implemented application deny listing.

B.

The OSC has not properly implemented application allow listing.

C.

IT must deploy an application to report newly installed software.

D.

IT does not have a policy that users notify IT when they install new applications.

Question # 7

The Lead Assessor is conducting an assessment for an OSC. The Lead Assessor has finished collecting and examining evidence from the assessment.

Based on this information, what is the NEXT logical step?

A.

Develop an assessment plan.

B.

Deliver recommended assessment results.

C.

Generate final recommended assessment results.

D.

Determine and record initial practice scores.

Question # 8

In completing the assessment of practices in the Access Control (AC) domain, a CCA scored AC.L2-3.1.15: Privileged Remote Access as NOT MET. The OSC was notified of this deficiency at the end of day two of the assessment. On day five of the assessment, the OSC’s Assessment Official contacted the CCA to provide evidence that the deficiencies have been corrected.

What is the CCA’s NEXT step?

A.

This practice is not eligible for deficiency correction and should be scored as NOT MET.

B.

This practice is not eligible for deficiency correction, should be scored as NOT MET, and reevaluated during a POA & M Close-Out Assessment.

C.

This practice is eligible for deficiency correction and should be scored as MET but must be reevaluated during a POA & M Close-Out Assessment.

D.

This practice is eligible for deficiency correction, should be scored as NOT MET, and evaluated during the Limited Deficiency Correction evaluation.

Question # 9

To meet AC.L2-3.1.5: Least Privilege , the following procedure is established:

    All employees are given a basic (non-privileged) user account.

    System Administrators are given a separate System Administrator account.

    Database Administrators are given a separate Database Administrator account.

Which steps should be added to BEST meet all of the standards for least privilege?

A.

4. Database Administrators use their Database Administrator accounts to perform privileged functions.

  5. All users use their basic account for non-privileged functions.

B.

4. Database Administrators use their Database Administrator accounts to perform privileged functions.

  5. Non-privileged users use their basic account for non-privileged functions.

C.

4. Database Administrators use the System Administrator accounts to perform privileged functions.

  5. All other users use their basic account for all authorized functions.

D.

4. Database Administrators use the System Administrator accounts to perform privileged functions.

  5. Non-privileged users use their basic account for all authorized functions.

Question # 10

An OSC seeking Level 2 certification wants to develop and launch a website for customers to purchase items online and submit contact forms. The OSC plans to host the web server in their own data center while also maintaining the security of their internal IT environment. Based on this information, what would be the BEST approach?

A.

Relocate the server to a different office location to protect the OSC’s LAN

B.

Configure a DMZ for an additional layer of security to the OSC’s LAN to host the publicly accessible server

C.

Configure a firewall rule to only allow internal traffic to communicate with the server for an additional layer of security to the OSC’s LAN

D.

Configure the server to protect against object reuse and residual information via shared system resources for an additional layer of security to the OSC’s LAN

Go to page: