In performing scoping, what should the assessor ensure that the scope of the assessment covers?
All assets documented in the business plan
All assets regardless if they do or do not process, store, or transmit FCI/CUI
All entities, regardless of the line of business, associated with the organization
All assets processing, storing, or transmitting FCI/CUI and security protection assets
Scoping Requirements in CMMC Assessments
TheCMMC 2.0 Scoping GuideandCMMC Assessment Process (CAP) Documentclearly define what should be included in the scope of an assessment.
The assessment scope must cover:
All assets that process, store, or transmit FCI/CUI
Security Protection Assets (ESP)– these assets help protect FCI/CUI, such as firewalls, endpoint detection systems, and encryption mechanisms.
Thus, thecorrect scope includes both:
✅FCI/CUI Assets(Data storage, processing, or transmission assets)
✅Security Protection Assets (ESP)(Firewalls, security tools, etc.)
Why the Other Answers Are Incorrect
A. All assets documented in the business plan
❌Incorrect.Business plans may include assets unrelated to FCI/CUI, making this scopetoo broad. Only assets relevant to FCI/CUI should be assessed.
B. All assets regardless if they do or do not process, store, or transmit FCI/CUI
❌Incorrect. CMMC doesnotrequire organizations to include assets thathave no connection to FCI/CUI.
C. All entities, regardless of the line of business, associated with the organization
❌Incorrect.Only the assets relevant to FCI/CUI or security protection should be assessed. Unrelated business divisions (like a non-federal commercial division) areout-of-scope.
CMMC Official References
CMMC 2.0 Scoping Guide – Level 1 & Level 2
CMMC Assessment Process (CAP) Document
Thus,option D (All assets processing, storing, or transmitting FCI/CUI and security protection assets) is the correct answeras per official CMMC assessment scoping requirements.
In scoping a CMMC Level 1 Self-Assessment, all of the computers and digital assets that handle FCI are identified. A file cabinet that contains paper FCI is also identified. What can this file cabinet BEST be determined to be?
In scope, because it is an asset that stores FCI
In scope, because it is part of the same physical location
Out of scope, because they are all only paper documents
Out of scope, because it does not process or transmit FCI
According to the CMMC Scoping Guidance, Level 1, the scope of an assessment includes all assets that process, store, or transmit Federal Contract Information (FCI). CMMC is " information-centric, " meaning the security requirements apply to the information itself, regardless of the media it resides on (digital or physical).
Asset Identification: In a Level 1 assessment, assets are categorized as either FCI Assets or Out-of-Scope Assets. Since the file cabinet is explicitly identified as containing paper FCI, it meets the definition of an asset that stores the protected information.
Basic Safeguarding (FAR 52.204-21): The 17 practices of CMMC Level 1 are derived from the FAR clause for the " Basic Safeguarding of Covered Contractor Information Systems. " However, the physical protection requirements within that set (such as PE.L1-3.10.1, which requires limiting physical access to organizational information systems and equipment) extend to the physical storage locations of that data.
Media Neutrality: CMMC documentation emphasizes that " information systems " include the physical components and the information processed by them. If FCI is printed and stored in a cabinet, that cabinet becomes a physical storage asset within the assessment boundary.
Why other options are incorrect:
Option B: Physical location alone does not bring an asset into scope. For example, a coffee machine in the same room as an FCI computer remains out of scope because it doesn ' t handle FCI. Thecontent(FCI) makes the cabinet in-scope, not its proximity.
Option C: CMMC and the underlying FAR clause do not exempt paper-based information. Protected data must be secured whether it is on a hard drive or a printed sheet.
Option D: While a file cabinet may not " process " or " transmit " data like a computer does, it absolutely stores it. The definition of the scope includes all three functions (process, store, or transmit).
Reference Documents:
CMMC Scoping Guidance, Level 1: Section 2.0 (CMMC Level 1 Asset Categories), which defines FCI Assets as those that process, store, or transmit FCI.
CMMC Assessment Guide, Level 1: Discussion on Physical Protection (PE) practices and their application to physical media.
32 CFR Part 170 (CMMC Program Rule): Definitions of FCI and the requirements for contractor self-assessments.
Which statement BEST describes a LTP?
Creates DoD-licensed training
Instructs a curriculum approved by CMMC-AB
May market itself as a CMMC-AB Licensed Provider for testing
Delivers training using some CMMC body of knowledge objectives
Understanding Licensed Training Providers (LTPs) in CMMC
ALicensed Training Provider (LTP)is an entity that is authorized by theCybersecurity Maturity Model Certification Accreditation Body (CMMC-AB)todeliver CMMC trainingbased on anapproved curriculum.
Key Responsibilities of an LTP:
Provides CMMC-AB-approved training programsfor individuals seeking CMMC certifications.
Uses an official CMMC curriculumthat aligns with theCMMC Body of Knowledge (BoK)and other CMMC-AB guidance.
Prepares students for CMMC roles, such asCertified CMMC Assessors (CCA) and Certified CMMC Professionals (CCP).
Why is the Correct Answer " Instructs a curriculum approved by CMMC-AB " (B)?
A. Creates DoD-licensed training → Incorrect
TheCMMC-AB, not the DoD, manages LTP licensing. LTPsdo not create new training contentbut mustfollow an approved curriculum.
B. Instructs a curriculum approved by CMMC-AB → Correct
LTPsteacha curriculum that has beenapproved by the CMMC-AB, ensuring consistency in CMMC training.
C. May market itself as a CMMC-AB Licensed Provider for testing → Incorrect
LTPs provide training, not testing. Testing is handled byLicensed Partner Publishers (LPPs)and exam bodies.
D. Delivers training using some CMMC body of knowledge objectives → Incorrect
LTPs mustfully adhereto theCMMC-AB-approved curriculum, not just " some " objectives.
CMMC 2.0 References Supporting This Answer:
CMMC-AB Licensed Training Provider (LTP) Program Guidelines
Defines LTPs as entities thatdeliver CMMC-AB-approved training programs.
CMMC Body of Knowledge (BoK)
Specifies that training must follow theCMMC-AB-approved curriculumto ensure standardization.
CMMC-AB Training & Certification Framework
Requires LTPs todeliver structured training that meets CMMC-AB guidelines.
Final Answer:
✔B. Instructs a curriculum approved by CMMC-AB
Prior to initiating an OSC ' s CMMC Assessment, the Lead Assessor briefed the team on the most important requirements of the assessment. The assessor also insisted that the same results of the findings summary, practice ratings, and Level recommendations must be submitted to the C3PAO for initial processes and review. After several weeks of assessment, the C3PAO completes the internal review, the recommended results are then submitted through the C3PAO for final quality review and rating approval. Which document stipulates these reporting requirements?
CMMC Assessment reporting requirements
DFARS 52.204-21 assessment reporting requirements
NISTSP 800-171 Revision 2 assessment reporting requirements
DFARS clause 252.204-7012 assessment reporting requirements
The correct answer isA. CMMC Assessment Reporting Requirementsbecause this document specifically outlines thestructured processthat Certified Third-Party Assessment Organizations (C3PAOs) must follow when conducting and reporting CMMC assessments.
Step-by-Step Breakdown:
Understanding the CMMC Assessment Process
TheLead Assessorbriefs the team on theassessment requirementsand theevaluation criteriabefore the assessment begins.
Throughout the assessment,findings summaries, practice ratings, and level recommendationsare documented and reported.
These findings are internally reviewed by theC3PAObefore they are formally submitted forquality review and final rating approval.
Key Document Stipulating Reporting Requirements: CMMC Assessment Reporting Requirements
This documentspecifically details how assessments must be reportedwithin theCMMC ecosystem.
It describes the structured process for assessment submission, internalC3PAO reviews, andquality checks by the CMMC-ABbefore an organization can receive a final certification decision.
It ensures thatresults are consistent, transparent, and aligned with DoD cybersecurity compliance expectations.
Why Other Options Are Incorrect:
B. DFARS 52.204-21 Assessment Reporting Requirements
This clause only specifiesbasic safeguardingof Federal Contract Information (FCI) but doesnotdictate the reporting process for CMMC assessments.
C. NIST SP 800-171 Revision 2 Assessment Reporting Requirements
WhileNIST SP 800-171 Rev. 2outlines security controls, it doesnotdefine how CMMC assessments must be conducted and reported.
D. DFARS Clause 252.204-7012 Assessment Reporting Requirements
This DFARS clause focuses onincident reportingandcyber incident response requirementsbut does not detail theCMMC assessment reporting process.
Official Reference:
CMMC Assessment Reporting Requirements, issued byThe Cyber ABandDoD, governs how C3PAOs must report assessment results.
CMMC Assessment Process (CAP)also outlines reporting workflows for certification.
Thus, theCMMC Assessment Reporting Requirementsdocument is the authoritative source that dictates the reporting procedures for CMMC assessments.
Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?
Availability
Confidentiality
Information Integrity
Respect for Intellectual Property
The requirement to exercise due care in protecting information gathered during an assessment aligns with the principle ofConfidentialityunder theCMMC Code of Professional Conduct (CoPC). This ensures that sensitive assessment data, findings, and any Controlled Unclassified Information (CUI) remain protected even after the engagement concludes.
Step-by-Step Breakdown:
Definition of Confidentiality in CMMC Context:
Confidentiality refers to protecting sensitive information from unauthorized disclosure.
In the context of a CMMC assessment, it includes safeguarding assessment artifacts, findings, and other sensitive data collected during the evaluation process.
CMMC Code of Professional Conduct (CoPC) References:
TheCMMC Code of Professional Conductstates that assessors and organizations must handle all collected information with discretion andensure its protection post-engagement.
Clause on " Maintaining Confidentiality " specifies that assessors must:
Not disclose sensitive information to unauthorized parties.
Secure data in storage and transmission.
Retain and dispose of data securely in accordance with federal regulations.
Alignment with NIST 800-171 & CMMC Practices:
CMMC Level 2 incorporates NIST SP 800-171 controls, which include:
Requirement 3.1.3:“Control CUI at rest and in transit” to ensure unauthorized individuals do not gain access.
Requirement 3.1.4:“Separate the duties of individuals to reduce risk” ensures that assessment findings are only shared with authorized personnel.
These requirements align with the duty toexercise due carein protecting assessment-related information.
Why the Other Options Are Incorrect:
(A) Availability:This refers to ensuring data is accessible when needed but does not directly relate to protecting gathered information post-assessment.
(C) Information Integrity:This focuses on preventing unauthorized modifications rather than restricting disclosure.
(D) Respect for Intellectual Property:While related to ethical handling of proprietary data, it does not directly cover post-engagement confidentiality requirements.
Final Validation from CMMC Documentation:
TheCMMC Code of Professional ConductandNIST SP 800-171control requirements confirm thatConfidentialityis the correct answer, as it directly pertains to protecting information post-assessment.
Thus, the correct answer isB. Confidentiality.
An OSC lead has provided company information, identified that they are seeking CMMC Level 2, stated that they handle FCI. identified stakeholders, and provided assessment logistics. The OSC has provided the company ' s cyber hygiene practices that are posted on every workstation, visitor logs, and screenshots of the configuration of their FedRAMP-approved applications. The OSC has not won any DoD government contracts yet but is working on two proposals Based on this information, which statement BEST describes the CMMC Level 2 Assessment requirements?
Ready because there is no need to certify this company until after they win a DoD contract.
Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract.
Not ready because the OSC still lacks artifacts that prove they have implemented all the CMMC Level 2 Assessment requirements.
Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification.
CMMC Level 2 Readiness and Certification Requirements
CMMCLevel 2is required forOrganizations Seeking Certification (OSCs) that handle Controlled Unclassified Information (CUI)and aligns withNIST SP 800-171 ' s 110 security controls.
Key Readiness Indicators for a Level 2 Assessment:
The OSC must have implemented all 110 security practices from NIST SP 800-171.
Documented and validated cybersecurity policies and procedures must exist.
The OSC must be prepared to provide objective evidence (artifacts) proving compliance.
Why the OSC in the Question is Not Ready:
They have not won a DoD contract yet→ This means they do not yet have a contractually definedCUI environment, which is the foundation for defining their security scope.
They have only provided FCI-related artifacts(e.g., visitor logs, workstation policies, FedRAMP configurations).
Lack of full documentation of CMMC Level 2 controls→ The assessment requiresevidence for all 110 security practices(e.g., system security plans, incident response records, security awareness training documentation).
Clarification of Incorrect Options:
A. " Ready because there is no need to certify this company until after they win a DoD contract. "
Incorrect→ Some organizationsseek certification proactivelybefore winning contracts. However, readiness depends on implementingall 110 required controls, not contract status alone.
B. " Not ready because the OSC is not on contract because they do not know the scope of FCI protection required by the contract. "
Incorrect→ CMMC Level 2focuses on CUI, not just FCI. While FCI protection is important, the assessment’s focus is onCUI security requirements, which arenot fully addressed by the provided artifacts.
D. " Ready because all DoD contractors are required to achieve CMMC Level 2; therefore, they are being proactive in seeking certification. "
Incorrect→ While it is commendable that the OSC is being proactive,readiness is based on full compliance with NIST SP 800-171, not just intent.
An organization ' s sales representative is tasked with entering FCI data into various fields within a spreadsheet on a company-issued laptop. This laptop is an FCI Asset being used to:
process and transmit FCI.
process and organize FCI.
store, process, and transmit FCI.
store, process, and organize FCI.
According to the CMMC Scoping Guidance, Level 1, the fundamental definition of an FCI Asset is any asset that performs at least one of three primary functions with Federal Contract Information (FCI). These functions are consistently defined across both Level 1 and Level 2 documentation as Processing, Storing, or Transmitting.
Process: In this scenario, the sales representative is " entering FCI data into various fields. " The act of inputting, manipulating, or editing data within an application (the spreadsheet) is the definition of processing.
Store: Because the spreadsheet is on the laptop, the data resides on the laptop ' s hard drive or memory. This constitutes storing.
Transmit: While the prompt focuses on the data entry, a laptop is an endpoint designed to move data across a network (email, cloud uploads, or server saves). In the context of CMMC scoping, assets that handle protected information are categorized by their capability and role in the data lifecycle, which includes transmitting.
Why other options are incorrect:
Options B and D: These include the word " organize. " While organizing data is a task a human performs, it is not a formal technical term used in the CMMC or NIST SP 800-171/FAR 52.204-21 definitions to categorize asset functions.
Option A: This option omits " store. " Since the spreadsheet exists on the laptop, storage is a primary function being utilized.
Reference Documents:
CMMC Scoping Guidance, Level 1 (Version 2.0): Section 2.0, which defines FCI Assets as assets that " process, store, or transmit FCI. "
FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems): The regulatory source for Level 1, which applies to systems that " process, store, or transmit " federal contract information.
CMMC Assessment Guide, Level 1: Introduction and Scoping sections, reinforcing the triad of data handling functions.
Which NIST SP defines the Assessment Procedure leveraged by the CMMC?
NIST SP 800-53
NISTSP800-53a
NIST SP 800-171
NISTSP800-171a
Which NIST SP Defines the Assessment Procedures for CMMC?
CMMC Level 2 isdirectly based on NIST SP 800-171, and the assessment procedures used in CMMC assessments are derived fromNIST SP 800-171A.
Step-by-Step Breakdown:
✅1. NIST SP 800-171A Defines Assessment Procedures
NIST SP 800-171Ais titled " Assessing Security Requirements for Controlled Unclassified Information (CUI) " .
It providesdetailed assessment objectives and test proceduresfor evaluating compliance withNIST SP 800-171 security requirements, whichCMMC Level 2 is fully aligned with.
CMMC Assessors use 800-171Aas abaseline for assessing the effectiveness of security controls.
✅2. Why the Other Answer Choices Are Incorrect:
(A) NIST SP 800-53❌
800-53 defines security controlsfor federal information systems, but it doesnot provide assessment procedures specific to CMMC.
(B) NIST SP 800-53A❌
800-53A provides assessment procedures for 800-53 controls, butCMMC is based on NIST SP 800-171, not 800-53.
(C) NIST SP 800-171❌
800-171 defines security requirements, butit does not provide assessment procedures. Theassessment proceduresare in800-171A.
Final Validation from CMMC Documentation:
TheCMMC Assessment Guide (Level 2)explicitly states that assessment procedures are derived fromNIST SP 800-171A.
Thus, the correct answer is:
Who is responsible for ensuring that subcontractors have a valid CMMC Certification?
CMMC-AB
OUSDA & S
DoD agency or client
Contractor organization
Step 1: Responsibility for Subcontractor Compliance
The prime contractor (contractor organization)is responsible for ensuring thatits subcontractorshave the requiredCMMC certification levelbefore engaging them inDoD contracts that involve FCI or CUI.
This requirement is enforced throughflow-down clausesinDFARS 252.204-7021, which mandates that subcontractors handlingCUImeet the necessaryCMMC Level 2 or Level 3 requirements.
What actions should a CMMC professional take when witnessing a fellow CMMC professional behaving in an action that violates the CMMC Code of Professional Conduct?
Privately request clarification or offer to help rectify the violation.
Report the observation to the DoD contract representative.
Initiate a private investigation.
Submit a corrective action review to the CMMC-AB.
The correct answer is A because the first ethical response to observing a possible Code of Professional Conduct violation is proportionate, professional, and corrective—not punitive or investigative. A CMMC professional must preserve objectivity, professionalism, and accountability while avoiding escalation beyond the facts. Privately requesting clarification allows the professional to confirm whether the observed behavior is truly a violation rather than a misunderstanding. Offering to help rectify the violation supports remediation while maintaining professional respect and confidentiality. Option B is too aggressive because the DoD contract representative is not the first point for routine ecosystem conduct correction. Option C is inappropriate because a CMMC professional does not have authority to conduct a private investigation into another ecosystem member. Option D is also premature because a corrective action review to the CMMC-AB would normally follow unresolved, material, or reportable misconduct, not a first observation that may be clarified or corrected. The ethical principle is disciplined escalation: address the matter directly and professionally first, preserve evidence if needed, and escalate only if the conduct is confirmed, material, or unresolved. Reference/topics: CMMC-AB Code of Professional Conduct, professionalism, objectivity, accountability, ethical escalation.
Prior to conducting a CMMC Assessment, the contractor must specify the CMMC Assessment scope by categorizing all assets. Which two asset categories are always assessed against CMMC practices?
CUI Assets and Specialized Assets
Security Protection Assets and CUI Assets
Specialized Assets and Contractor Risk Managed Assets
Security Protection Assets and Contractor Risk Managed Assets
Understanding CMMC Asset Scoping Requirements
Before conducting aCMMC Level 2 Assessment, anOrganization Seeking Certification (OSC)must define theassessment scopeby categorizing all assets. This ensures that only relevant systems are assessed againstCMMC practices, reducing unnecessary compliance burdens.
According to theCMMC Scoping Guide for Level 2, there are four asset categories:
CUI Assets– Assets that process, store, or transmitControlled Unclassified Information (CUI).
Security Protection Assets (SPA)– Assets that providesecurity functions(e.g., firewalls, intrusion detection systems, identity management systems).
Contractor Risk Managed Assets (CRMA)– Assets thatdo not directly store/process CUIbut interact with CUI environments (e.g., BYOD devices, personal computers used for remote access).
Specialized Assets– Unique systems such asOperational Technology (OT), IoT, and Government Furnished Equipment (GFE), which may requirelimitedCMMC assessment.
Which Asset Categories Are Always Assessed?
✅1. CUI Assets(ALWAYS ASSESSED)
These are theprimary focusof CMMC Level 2 since they handleCUI.
All110 NIST SP 800-171 controlsapply to these assets.
✅2. Security Protection Assets (SPA)(ALWAYS ASSESSED)
Security tools that protectCUI Assetsarealways includedin the assessment.
Examples includefirewalls, antivirus, endpoint detection and response (EDR) tools, and identity management systems.
Why the Other Answer Choices Are Incorrect:
(A) CUI Assets and Specialized Assets❌
CUI Assets are assessed, butSpecialized Assets are only assessed in a limited manner, depending on their role inCUI security.
(C) Specialized Assets and Contractor Risk Managed Assets❌
Specialized Assets and CRMAsare typicallynot fully assessedagainst CMMC controls unless they directly impactCUI security.
(D) Security Protection Assets and Contractor Risk Managed Assets❌
SPAs are always assessed, butCRMAs are not necessarily assessedunless they directly impact CUI.
Final Validation from CMMC Documentation:
TheCMMC Scoping Guide (Level 2)clearly states thatCUI Assets and Security Protection Assetsarealways assessedagainst CMMC practices.
Thus, the correct answer is:
B. Security Protection Assets and CUI Assets.
An assessor is collecting affirmations. So far, the assessor has collected interviews, demonstrations, emails, messaging, and presentations. Are these appropriate approaches to collecting affirmations?
No, emails are not appropriate affirmations.
No, messaging is not an appropriate affirmation.
Yes, the affirmations collected by the assessor are all appropriate.
Yes, the affirmations collected by the assessor are all appropriate, as are screenshots.
According to the CMMC Assessment Process (CAP) and the CMMC Level 2 Assessment Guide, an assessment finding is built upon evidence collected through three primary methods: Examine, Interview, and Test. The term " affirmation " in this context refers to the verbal or written statements provided by the Organization Seeking Certification (OSC) personnel to confirm that a practice is implemented as described.
Broad Definition of Evidence: The CAP allows for a wide variety of artifacts to be used as evidence. " Affirmations " are typically captured during the Interview process or found within Examine objects.
Validity of Formats:
Interviews: Direct verbal affirmations from subject matter experts (SMEs).
Emails and Messaging (Chat/Slack/Teams): These are considered valid " Examine " objects (records/artifacts) that serve as written affirmations or evidence of an activity (e.g., an email chain approving a firewall change or a message confirming a system update).
Presentations and Demonstrations: These fall under " Examine " (the presentation slides) and " Test/Examine " (the demonstration of a mechanism).
Why Option C is correct: The CMMC framework does not disqualify digital communications like emails or messaging as evidence. In fact, these are often the primary artifacts used to prove that a process (like an approval workflow or notification) is occurring in practice. As long as the assessor can verify the authenticity and integrity of these communications, they are appropriate for collecting affirmations.
Why Option D is less accurate: While screenshots are indeed used as evidence, the core question asks if thespecificlist (interviews, demonstrations, emails, messaging, presentations) is appropriate. Option C directly validates the list provided in the prompt without introducing extraneous elements like screenshots, which—while valid—are not the focus of the " appropriate " determination for the items listed.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4 (Collect and Verify Evidence), which discusses the types of artifacts and " human evidence " (interviews) that support findings.
CMMC Level 2 Assessment Guide: " Assessment Methods " section, clarifying that evidence can include any records (electronic or physical) that demonstrate the implementation of a practice.
NIST SP 800-171A: The underlying standard for assessment procedures, which encourages the use of various evidence types to satisfy assessment objectives.
For the purpose of determining scope, what needs to be included as part of the assessment but would NOT receive a CMMC certification unless an enterprise assessment is conducted?
ESP
People
Test equipment
Government property
Per the CMMC Scoping Guidance, External Service Providers (ESPs) must be included in scope if they process, store, or transmit CUI or FCI on behalf of the OSC. However, ESPs do not themselves receive a separate CMMC certification unless they undergo their own assessment or an enterprise-level certification is conducted. Their environment is assessed only as part of the OSC’s scope.
Reference Documents:
CMMC Scoping Guidance for Level 2
CMMC Model v2.0 Overview
An Assessment Team Member is conducting a CMMC Level 2 Assessment for an OSC that is in the process of inspecting Assessment Objects for AC.L1-3.1.1: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) to determine the adequacy of evidence provided by the OSC. Which Assessment Method does this activity fall under?
Test
Observe
Examine
Interview
Understanding Assessment Methods in CMMC 2.0
According to theCMMC Assessment Process (CAP) Guide, assessors usethree primary assessment methodsto determine compliance with security practices:
Examine– Reviewing documents, policies, configurations, and system records.
Interview– Speaking with personnel to gather insights into security processes.
Test– Performing technical validation of system functions and security controls.
Why Option C (Examine) is Correct
TheAssessment Team Memberis inspectingAssessment Objects(e.g., system configurations, user access control settings, policies) to determine if the OSC ' s evidence is sufficient forAC.L1-3.1.1 (Access Control – Authorized Users).
This activity aligns directly with theExaminemethod, which involves reviewing artifacts such as:
Access control lists (ACLs)
System user authentication logs
Account management policies
Role-based access control settings
" Observe " (Option B)is incorrect because " observing " is not an official assessment method in CMMC.
" Test " (Option A)is incorrect because the assessment is not actively executing a function but ratherreviewingevidence.
" Interview " (Option D)is incorrect because no personnel are being questioned—only documentation is being reviewed.
Official CMMC Documentation References
CMMC Assessment Process (CAP) Guide, Section 3.5 – Assessment Methods
CMMC Level 2 Assessment Guide – Access Control Practices (AC.L1-3.1.1)
Final Verification
Since the activity involves reviewing documents and records to verify access control measures, it falls under theExaminemethod, makingOption C the correct answer.
Which document is the BEST source for determining the sources of evidence for a given practice?
NISTSP 800-53
NISTSP 800-53A
CMMC Assessment Scope
CMMC Assessment Guide
TheCMMC Assessment Guideis the best source for determining the sources of evidence for a given practice because it provides specific guidance on how organizations should implement and demonstrate compliance with CMMC practices. Each CMMC level has its own assessment guide (e.g.,CMMC Assessment Guide – Level 1, Level 2), detailing expected evidence and assessment procedures.
Detailed Justification:
CMMC Assessment Guide (Primary Source for Evidence)
TheCMMC Assessment Guideexplicitly outlines the evidence required to verify compliance with each practice.
It provides detailed instructions on assessment objectives, clarifying what assessors should look for when determining compliance.
The guide breaks down each practice intoassessment objectives, helping organizations prepare appropriate documentation and artifacts.
Other Documents and Why They Are Not the Best Choice:
NIST SP 800-53 (Option A)
WhileNIST SP 800-53provides a comprehensive catalog of security and privacy controls, it does not focus on CMMC-specific evidence requirements.
It serves as a foundational cybersecurity framework but does not define the specific artifacts required for CMMC assessment.
NIST SP 800-53A (Option B)
NIST SP 800-53Aprovides guidance on assessing security controls but is not tailored to the CMMC framework.
It includes general control assessment procedures, but theCMMC Assessment Guideis more precise in defining the evidence needed for CMMC compliance.
CMMC Assessment Scope (Option C)
TheCMMC Assessment Scopedocument outlines which systems, assets, and processes are subject to assessment.
While important for defining boundaries, it does not provide details on specific evidence requirements for each practice.
References from Official CMMC Documents:
CMMC Assessment Guide (Level 2) – Section on " Assessment Objectives "
This document details how evidence is collected and evaluated for each CMMC practice.
Example: ForAC.L2-3.1.1 (Access Control – Limit System Access), the guide specifies that assessors should verify documented policies, system configurations, and audit logs.
CMMC Model Overview (Official DoD Documents)
Emphasizes thatCMMC Assessment Guidesare the official reference for determining sources of evidence.
Conclusion:
TheCMMC Assessment Guideis the most authoritative source for determining the required evidence for a given practice in CMMC assessments. It provides detailed breakdowns of assessment objectives, required artifacts, and verification steps necessary for compliance.
Which document specifies the CMMC Level 1 practices that correspond to basic safeguarding requirements?
NIST SP 800-171
NIST SP 800-171b
48 CFR 52.204-21
DFARS 252.204-7012
CMMC Level 1 practices correspond directly to the basic safeguarding requirements for Federal Contract Information (FCI), which are codified in FAR clause 48 CFR 52.204-21. These 15 requirements form the foundation for Level 1 compliance.
Supporting Extracts from Official Content:
48 CFR 52.204-21: “Contractors shall apply the following 15 basic safeguarding requirements to protect Federal Contract Information (FCI).”
CMMC Model v2.0 Overview: “Level 1 corresponds to the 15 basic safeguarding requirements in FAR 52.204-21.”
Why Option C is Correct:
FAR 52.204-21 is the source for Level 1 practices.
NIST SP 800-171 applies to CUI and Level 2, not Level 1.
NIST SP 800-171b is the precursor to NIST SP 800-172 (used for Level 3).
DFARS 252.204-7012 covers CUI safeguarding and incident reporting, not Level 1 FCI requirements.
References (Official CMMC v2.0 Content):
FAR 48 CFR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems.
CMMC Model v2.0, Level 1 Overview.
While developing an assessment plan for an OSC. it is discovered that the certified assessor will be interviewing a former college roommate. What is the MOST correct action to take?
Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.
Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
Inform the OSC and the C3PAO of the possible conflict of interest, document the conflict and mitigation actions in the assessment plan, and if the mitigation actions are acceptable, continue with the assessment.
The Cybersecurity Maturity Model Certification (CMMC) Assessment Process (CAP) outlines strict guidelines regarding conflicts of interest (COI) to ensure the integrity and impartiality of assessments conducted by Certified Third-Party Assessment Organizations (C3PAOs) and Certified Assessors (CAs).
The scenario presented involves a potential conflict of interest due to a prior relationship (former college roommate) between the certified assessor and an individual at the Organization Seeking Certification (OSC). While this prior relationship does not automatically disqualify the assessor, it must be disclosed, documented, and mitigated appropriately.
CMMC Conflict of Interest Handling Process
Inform the OSC and C3PAO of the Potential Conflict of Interest
The CMMC Code of Professional Conduct (CoPC) requires assessors to disclose any potential conflicts of interest.
Transparency ensures that all parties, including the OSC and C3PAO, are aware of the situation.
Document the Conflict and Mitigation Actions in the Assessment Plan
Per CMMC CAP documentation, potential conflicts should be assessed based on their material impact on the objectivity of the assessment.
The conflict and proposed mitigation strategies must be formally recorded in the assessment plan to provide an audit trail.
Determine If the Mitigation Actions Are Acceptable
If the OSC and C3PAO determine that the mitigation actions adequately eliminate or reduce the risk of bias, the assessment may proceed.
Common mitigation strategies include:
Assigning another assessor for interviews with the conflicted individual.
Ensuring that decisions regarding the OSC’s compliance are reviewed independently.
Proceed with the Assessment If Mitigation Is Acceptable
If the mitigation actions sufficiently address the conflict, the assessment may continue under strict adherence to documented procedures.
Why the Other Answers Are Incorrect
A. Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
❌Incorrect. This violates CMMC’s integrity requirements and could result in disciplinary actions against the assessor or invalidation of the assessment. Transparency is mandatory.
B. Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.
❌Incorrect. The CAP does not mandate immediate reassignment unless the conflict is unresolvable. Instead, mitigation strategies should be considered first.
C. Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
❌Incorrect. The passage of time alone does not automatically eliminate a conflict of interest. Proper documentation and mitigation are still required.
CMMC Official References
CMMC Assessment Process (CAP) Document – Defines COI requirements and mitigation actions.
CMMC Code of Professional Conduct (CoPC) – Outlines ethical responsibilities of assessors.
CMMC Accreditation Body (Cyber-AB) Guidance – Provides rules on conflict resolution.
Thus, option D is the most correct choice, as it aligns with the official CMMC conflict of interest procedures.
What is DFARS clause 252.204-7012 required for?
All DoD solicitations and contracts
Solicitations and contracts that use FAR part 12 procedures
Procurements solely for the acquisition of commercial off-the-shelf
Commercial off-the-shelf sold in the marketplace without modifications
What is the MOST common purpose of assessment procedures?
Obtain evidence.
Define level of effort.
Determine information flow.
Determine value of hardware and software.
Theprimary goal of CMMC assessment proceduresis to determine whether anOrganization Seeking Certification (OSC)complies with the cybersecurity controls required for its certification level. Themost common purpose of assessment procedures is to obtain evidencethat verifies an organization has properly implemented security practices.
Why " A. Obtain Evidence " is Correct?
CMMC Assessments Require Evidence Collection
TheCMMC Assessment Process (CAP) Guideoutlines that assessors must use three methods to verify compliance:
Examine– Reviewing documentation, policies, and system configurations.
Interview– Speaking with personnel to confirm understanding and execution.
Test– Validating controls through operational or technical tests.
All these methods involve obtaining evidenceto support whether a security requirement has been met.
Alignment with NIST SP 800-171A
CMMC Level 2 assessments follow NIST SP 800-171A, which is designed for evidence-based verification.
Assessors rely on documented artifacts, system logs, configurations, and personnel testimony as evidence of compliance.
Why Other Answers Are Incorrect?
B. Define level of effort (Incorrect)
Thelevel of effortrefers to the time and resources needed for an assessment, but this is aplanningactivity, not the primary goal of an assessment.
C. Determine information flow (Incorrect)
While understandinginformation flowis important for security controls likedata protection and access control, themain purpose of an assessment is to gather evidence—not to determine information flow itself.
D. Determine value of hardware and software (Incorrect)
Asset valuation may be part of an organization’s risk management process, but CMMC assessmentsdo not focus on determining hardware or software value.
Conclusion
The correct answer isA. Obtain evidence, as theCMMC assessment process is evidence-drivento verify compliance with security controls.
There are 15 practices that are NOT MET for an OSC ' s Level 2 Assessment. All practices are applicable to the OSC. Which determination should be reached?
The OSC may have 90 days for remediating NOT MET practices.
The OSC is not eligible for an option to remediate NOT MET practices.
The OSC may be eligible for an option to remediate NOT MET practices.
The OSC is not eligible for an option to remediate after the assessment is canceled.
According to the CMMC Model and Assessment Guides, specifically the rules governing Plan of Action and Milestones (POA & M) and the remediation period, an Organization Seeking Certification (OSC) is allowed a limited opportunity to remediate certain " Not Met " practices to achieve a " Met " status without failing the assessment entirely.
Here is the breakdown based on CMMC Ecosystem protocols:
The 180-Day POA & M Rule: CMMC Level 2 allows for the use of POA & Ms for specific practices, provided they are not high-priority items (typically 5-point values in the scoring methodology). If an OSC has " Not Met " practices that are eligible for a POA & M, they have up to 180 days to remediate them.
The Remediation Period (Assessment Closeout): During the assessment process itself, there is a " remediation period " (often referred to within the 1-90 day window depending on the specific C3PAO methodology and the CMMC assessment process) where an OSC can fix minor issues identified by the assessor before the final report is submitted.
Eligibility Criteria: The question states there are 15 practices " Not Met. " While this is a high number, the CMMC rule does not automatically disqualify an OSC based solely on thequantityof practices, but rather thetype(weight) of the practices and the resulting score. To be eligible for a conditional " Met " (via POA & M), the OSC must achieve a minimum score (often 80% of the total points) and none of the " Not Met " practices can be those designated as mandatory " Met " (no POA & M allowed) in the CMMC rule.
Why " C " is correct: Because we do not know the specific weights of the 15 " Not Met " practices or the total score, we cannot definitively say theywillbe remediated (A) or that they areineligible(B). However, under the CMMC assessment framework, the OSC may be eligible to enter a remediation phase or utilize a POA & M to bridge the gap, provided they meet the scoring threshold and the specific practices allow for it.
Reference Documents:
CMMC Assessment Process (CAP): Defines the phases of assessment including the " Remediation Period. "
32 CFR Part 170 (CMMC Program Rule): Outlines the specific requirements for POA & Ms, the 180-day timeline, and the scoring parameters required to be eligible for a Conditional Certification.
Which document BEST determines the existence of FCI and/or CUI in scoping an assessment with an OSC?
OSC SSP
OSC POA & M
OSC Evidence
OSC Contract with DoD
Understanding DFARS Clause 252.204-7012
TheDefense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012is a mandatory cybersecurity clause required inall DoD contracts and solicitationsthat involveControlled Unclassified Information (CUI).
Key Requirements of DFARS 252.204-7012
✅Implements NIST SP 800-171security controls for contractors handlingCUI.
✅Requirescyber incident reportingto theDoD Cyber Crime Center (DC3)within72 hours.
✅Mandatesadequate security measuresto protectDoD information systems.
✅Applies toall DoD contracts, except for those exclusively acquiring COTS items.
Why " All DoD Solicitations and Contracts " is Correct?
Option A (Correct):DFARS 252.204-7012must be included in all DoD contracts and solicitationswhen CUI is involved.
Option B (Incorrect):FAR Part 12 procedures apply tocommercial item acquisitions, but DFARS 7012 appliesregardless of procurement procedures.
Option C (Incorrect):Contractssolely for COTS (Commercial Off-the-Shelf) productsare exemptfrom DFARS 7012.
Option D (Incorrect):COTS itemssold without modificationsarenot requiredto include DFARS 7012.
Official References from DoD and DFARS Documentation
DFARS Clause 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
NIST SP 800-171– The required cybersecurity standard for contractors under DFARS 7012.
Final Verification and Conclusion
CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:
received and transferred.
stored, processed, and transmitted.
entered, edited, manipulated, printed, and viewed.
located on electronic media, on system component memory, and on paper.
TheCMMC Scoping Guide for Level 2outlines thatCUI assetsinclude systems, applications, and services thatstore, process, or transmitControlled Unclassified Information (CUI). These are the three core functions that defineCUI handlingwithin anOrganization Seeking Certification (OSC).
Step-by-Step Breakdown:
✅1. CUI Assets Defined in CMMC
Stored:CUI is saved on hard drives, cloud storage, or databases.
Processed:CUI is actively used, modified, or analyzed by applications and users.
Transmitted:CUI is sent between systems via email, file transfers, or network communication.
✅2. Why the Other Answer Choices Are Incorrect:
(A) Received and transferred❌
Whilereceiving and transferring CUIis part of handling CUI, it does not fully cover all CUI asset responsibilities.
(C) Entered, edited, manipulated, printed, and viewed❌
These arespecific actionswithinprocessingbut do not coverstorage or transmission, which are also required for CMMC scoping.
(D) Located on electronic media, on system component memory, and on paper❌
While CUI can exist inelectronic and physical forms, CMMC scoping focuses onhow CUI is actively managed (stored, processed, transmitted)rather than where it physically resides.
Final Validation from CMMC Documentation:
TheCMMC Level 2 Scoping Guideconfirms thatCUI Assets are categorized based on their role in storing, processing, or transmitting CUI.
NIST SP 800-171also defines these three functions as key components of CUI protection.
For a scoping a CMMC Level 1 Self-Assessment, which asset types are assessed against CMMC practices?
Any IoT or Industrial Internet of Things devices
Any restricted IS
Any test equipment hardware
Any asset transmitting FCI
The correct answer is D because CMMC Level 1 scoping is driven by whether an asset processes, stores, or transmits Federal Contract Information (FCI). The Level 1 Scoping Guide states that in-scope assets for a Level 1 self-assessment are all assets that process, store, or transmit FCI, and that these assets are part of the CMMC Assessment Scope and assessed against all Level 1 requirements. The guide also defines transmitting as FCI being transferred from one asset to another through physical or digital transport methods. The other options are attractive but incorrect because IoT, Industrial Internet of Things, Restricted Information Systems, and test equipment are treated as Specialized Assets when they can process, store, or transmit FCI but cannot be fully secured. Specialized Assets are documented and managed but are not assessed against CMMC Level 1 requirements in the same way as ordinary in-scope FCI assets. Therefore, the best answer is the general rule: any non-specialized asset transmitting FCI is assessed against CMMC Level 1 practices. Reference/topics: CMMC Level 1 Scoping, FCI assets, Specialized Assets, process/store/transmit.
An assessment procedure consists of an assessment objective, potential assessment methods, and assessment objects. Which statement is part of an assessment objective?
Specifications and mechanisms
Examination, interviews, and testing
Determination statement related to the practice
Exercising assessment objects under specified conditions
Understanding CMMC Assessment Procedures
ACMMC assessment procedureconsists of:
Assessment Objective– Defines what is being evaluated and the expected outcome.
Assessment Methods– Specifies how the evaluation is conducted (e.g.,examination, interviews, testing).
Assessment Objects– Identifies what is being evaluated, such as policies, systems, or people.
Why the Correct Answer is " C " ?
Assessment Objectivesincludedetermination statementsthat describe the expected outcome for each CMMC security practice.
These statements define whether a practice has beenadequately implementedbased ondocumented evidence and assessment findings.
TheCMMC Assessment Process (CAP) GuideandNIST SP 800-171Aspecify that each practice has a determination statement guiding assessment decisions.
Why Not the Other Options?
A. Specifications and mechanisms→Incorrect
These belong toassessment objects, which refer to the systems, policies, and mechanisms being evaluated.
B. Examination, interviews, and testing→Incorrect
These areassessment methods, which describe how assessorsverifycompliance (e.g., through interviews or testing).
D. Exercising assessment objects under specified conditions→Incorrect
This refers toassessment testing, which is a method, not an assessment objective.
Relevant CMMC 2.0 References:
CMMC Assessment Process (CAP) Guide– Describes determination statements as the core of assessment objectives.
NIST SP 800-171A– Defines determination statements as a key element of evaluating security controls.
Final Justification:
Since anassessment objectiveincludes adetermination statementthat describes whether a practice is implemented properly, the correct answer isC.
In many organizations, the protection of FCI includes devices that are used to scan physical documentation into digital form and print physical copies of digital FCI. What technical control can be used to limit multi-function device (MFD) access to only the systems authorized to access the MFD?
Virtual LAN restrictions
Single administrative account
Documentation showing MFD configuration
Access lists only known to the IT administrator
Understanding Multi-Function Device (MFD) Security in CMMC
Multi-function devices (MFDs), such asscanners, printers, and copiers,process, store, and transmit FCI, making them apotential attack surfacefor unauthorized access.
Thebest technical controlto limit MFD access to only authorized systems isVirtual LAN (VLAN) restrictions, whichsegment and isolate network traffic.
Why the Correct Answer is " A. Virtual LAN (VLAN) Restrictions " ?
VLAN Restrictions Provide Network Segmentation
VLANsisolate the MFDfrom unauthorized systems, ensuringonly approved devicescan communicate with it.
Prevents unauthorized network access bylimiting connectionsto specific IPs or subnets.
Meets CMMC 2.0 Network Security Controls
Aligns withCMMC System and Communications Protection (SC) Practicesfor network segmentation and access control.
Reducesthe risk of unauthorized access to scanned and printed FCI.
Why Not the Other Options?
B. Single administrative account→Incorrect
Asingle admin accountdoes not restrict accessbetween devices, only controlswho can configurethe MFD.
C. Documentation showing MFD configuration→Incorrect
Documentation helps with compliance butdoes not actively restrict access.
D. Access lists only known to the IT administrator→Incorrect
Access lists should besystem-enforced, not just " known " to the administrator.
Relevant CMMC 2.0 References:
CMMC Practice SC.3.192 (Network Segmentation)– Requires restricting access usingnetwork segmentation techniques such as VLANs.
NIST SP 800-171 (SC Family)– Supportsisolation of sensitive devicesusing VLANs and other segmentation controls.
Final Justification:
SinceVirtual LAN (VLAN) restrictions enforce access control at the network level, the correct answer isA. Virtual LAN (VLAN) restrictions.
Which term describes assessing the ability of a unit equipped with a system to support its mission while withstanding cyber threat activity representative of an actual adversary?
Penetration test
Black hat testing
Red cell assessment
Adversarial assessment
The term Adversarial Assessment is formally defined in DoD cyber terminology. It describes testing that evaluates a unit or system’s ability to perform its mission while facing simulated cyber threat activity representative of a real-world adversary.
Supporting Extracts from Official Content:
DoD Cybersecurity Test and Evaluation Guidebook: “Adversarial Assessment: Test conducted to evaluate a unit’s ability to support its mission while withstanding cyber threat activity representative of an actual adversary.”
Why Option D is Correct:
A penetration test is narrower and focuses on identifying vulnerabilities.
Black hat testing is not an official DoD or CMMC term.
Red cell assessment refers more broadly to force-on-force exercises and is not the term used in CMMC/governing DoD definitions.
References (Official CMMC v2.0 Content and Source Documents):
DoD Cybersecurity Test and Evaluation Guidebook.
CMMC v2.0 Governance – Source Documents (incorporating DoD definitions).
A contractor stores security policies, system configuration files, and audit logs in a centralized file repository for later review. According to CMMC terminology, the file repository is being used to:
protect CUI.
transmit CUI.
store CUI.
generate CUI
During the review of information that was published to a publicly accessible site, an OSC correctly identifies that part of the information posted should have been restricted. Which item did the OSC MOST LIKELY identify?
FCI
Change of leadership in the organization
Launching of their new business service line
Public releases identifying major deals signed with commercial entities
Understanding Federal Contract Information (FCI) and Publicly Accessible Information
Federal Contract Information (FCI)isnon-public informationprovided by or generated for the U.S. governmentunder a contractthat isnot intended for public release.
Key Characteristics of FCI:
✔FCI includesdetails related togovernment contracts, project specifics, and performance data.
✔It must be protected under FAR 52.204-21, which requiresbasic safeguarding measuresto prevent unauthorized access.
✔Posting FCI on a public site is a security violationsince it ismeant to be restrictedfrom public disclosure.
Why is the Correct Answer " A. FCI (Federal Contract Information) " ?
A. FCI → Correct
FCI must be protected from unauthorized access, and if it wasincorrectly published online, it should have been restricted.
B. Change of leadership in the organization → Incorrect
Leadership changes are typically public informationand do not require restriction unless they involve sensitive government-related security clearances.
C. Launching of their new business service line → Incorrect
Marketing and business announcementsare generallypublicly availableandnot restricted information.
D. Public releases identifying major deals signed with commercial entities → Incorrect
Commercial contracts and business deals are not considered FCIunless they involvegovernment contracts.
CMMC 2.0 References Supporting This Answer:
FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems)
DefinesFCI as sensitive but unclassified informationthat must beprotected from public disclosure.
CMMC 2.0 Level 1 Requirements
Requires contractors toprotect FCI under basic cybersecurity standardsto prevent unauthorized exposure.
DoD Guidance on FCI Protection
States thatpublishing FCI on public websites violates federal cybersecurity requirements.
At which CMMC Level do the Security Assessment (CA) practices begin?
Level 1
Level 2
Level 3
Level 4
Step 1: Understand the “CA” Domain – Security Assessment
TheCA (Security Assessment)domain includes practices related to:
Planning security assessments,
Performing periodic reviews,
Managing plans of action and milestones (POA & Ms).
These practices derive fromNIST SP 800-171, specifically:
CA.2.157– Develop, document, and periodically update security plans,
CA.2.158– Periodically assess security controls,
CA.2.159– Develop and implement POA & Ms.
✅Step 2: Review CMMC Levels
Level 1 (Foundational):
Implements only the17 practicesfromFAR 52.204-21
Doesnot include the CA domain
Level 2 (Advanced):
Implements110 practicesfromNIST SP 800-171, including CA.2.157–159
First levelwhereSecurity Assessment (CA)practices are required
Level 3:
Not yet finalized but intended to include selected controls fromNIST SP 800-172
❌Why the Other Options Are Incorrect
A. Level 1
✘No CA domain practices are present at Level 1.
C. Level 3 / D. Level 4
✘These levels build on CA practices but do not represent thestarting point.
TheSecurity Assessment (CA)domain practices begin atCMMC Level 2, as part of the implementation ofNIST SP 800-171.
Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?
Phase 1: Plan and Prepare Assessment
Phase 2: Conduct Assessment
Phase 3: Report Recommended Assessment Results
Phase 4: Remediation of Outstanding Assessment Issues
Understanding the CMMC Assessment Process
TheCMMC Assessment Process (CAP)consists offour phases, each with specific tasks and objectives.
Phase 1: Plan and Prepare Assessment– Planning, scheduling, and preparing for the assessment.
Phase 2: Conduct Assessment–Gathering and verifying evidence, conducting interviews, and evaluating compliance.
Phase 3: Report Recommended Assessment Results– Documenting findings and reporting results.
Phase 4: Remediation of Outstanding Assessment Issues– Allowing the organization to address any deficiencies.
Why " Phase 2: Conduct Assessment " is Correct?
DuringPhase 2: Conduct Assessment, theAssessment Teamperforms key activities, including:
✅Identifying required evidencefor compliance verification.
✅Obtaining and reviewing artifacts(e.g., security policies, configurations, logs).
✅Verifying the sufficiency of evidenceagainst CMMC practice requirements.
✅Interviewing key personneland observing cybersecurity implementations.
Since the question specifically mentions " identify, obtain inventory, and verify evidence, " this task directly falls underPhase 2: Conduct Assessment.
Breakdown of Answer Choices
Option
Description
Correct?
A. Phase 1: Plan and Prepare Assessment
❌Incorrect–This phase focuses onscheduling, logistics, and planning, not evidence collection.
B. Phase 2: Conduct Assessment
✅Correct – This phase involves gathering, verifying, and reviewing evidence.
C. Phase 3: Report Recommended Assessment Results
❌Incorrect–This phasedocumentsresults but doesnotcollect evidence.
D. Phase 4: Remediation of Outstanding Assessment Issues
❌Incorrect–This phase focuses oncorrective actions, not evidence collection.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)–Phase 2: Conduct Assessmentexplicitly includes tasks such asgathering and verifying evidence.
Final Verification and Conclusion
The correct answer isB. Phase 2: Conduct Assessment, as this phase includesidentifying, obtaining, and verifying evidence, which is critical for determining CMMC compliance.
A Data Access Policy (DAP) document has been provided for review. It outlines the policies, procedures, and requirements for data access within the corporate area and the controlled environment. Which DAP policy statement about visitors is correct?
Visitors must not be escorted.
Visitors must be escorted in the corporate area, but not in the controlled environment.
Visitors must be escorted in the controlled environment, but not in the corporate area.
Visitors must be escorted at all times.
The correct answer is C because the CMMC physical protection requirement focuses on protecting areas where in-scope information systems, equipment, and controlled environments are located. CMMC Level 2 requirement PE.L2-3.10.3, Escort Visitors , requires the organization to “escort visitors and monitor visitor activity.” The official CMMC Level 2 Assessment Guide states that the assessment objectives include determining whether visitors are escorted, visitor activity is monitored, physical access audit logs are maintained, and physical access devices are controlled and managed. The same guide explains that individuals with permanent physical access authorization credentials are not considered visitors, and that audit logs can be used to monitor visitor activity.
For CMMC purposes, the key issue is whether the visitor could physically access organizational systems, equipment, FCI, CUI, or the respective operating environment. A general corporate area that is outside the controlled environment may not require the same escort rule unless it provides access to in-scope assets. However, the controlled environment must be protected from unauthorized physical access. Therefore, visitors should be escorted in the controlled environment, where FCI/CUI systems or related assets may be present. Option A is incorrect because CMMC requires visitor escorting. Option B reverses the protection priority. Option D is overly broad for this question because it does not distinguish between a general corporate area and the controlled environment defined in the DAP.
===========
The evidence needed for each practice and/or process is weight for:
adequacy and sufficiency.
adequacy and thoroughness.
sufficiency and thoroughness.
sufficiency and appropriateness.
During aCMMC assessment, organizations must provide evidence to demonstrate compliance with requiredpractices and processes. Assessors evaluate this evidence based on two key criteria:
Adequacy– Does the evidence meet the intent of the security requirement?
Sufficiency– Is there enough evidence to reasonably conclude that the practice/process is effectively implemented?
These principles are outlined in theCMMC Assessment Process Guide, which provides a structured approach for evaluating compliance.
Step-by-Step Breakdown:
✅1. Adequacy – Does the evidence fully meet the requirement?
Adequacyrefers to whether the evidence properly demonstrates that the security practice has been implemented as required.
Example: If an organization claims to enforceMulti-Factor Authentication (MFA), an assessor would checksystem configurations, login policies, and user authentication logsto confirm that MFA is actually in use.
✅2. Sufficiency – Is there enough evidence to support the claim?
Sufficiencymeans that there isenough supporting evidenceto prove compliance.
Example: If an organization providesonly one screenshot of an MFA login screen, that alone may not besufficient—additional logs, policies, and user records would help strengthen the case.
Why the Other Answer Choices Are Incorrect:
(B) Adequacy and Thoroughness❌
Thoroughnessis not a defined metric in CMMC evidence evaluation.
The focus is onwhether the evidence meets the requirement (adequacy)and if there isenough of it (sufficiency).
(C) Sufficiency and Thoroughness❌
Thoroughnessis not a recognized term in CMMC compliance validation.
Evidence must beadequate and sufficient, not just thorough.
(D) Sufficiency and Appropriateness❌
Appropriatenessis not a CMMC-defined criterion.
Thecorrect terms used in CMMC assessmentsareAdequacy(Does it meet the requirement?) andSufficiency(Is there enough proof?).
Final Validation from CMMC Documentation:
CMMC Assessment Process Guideexplicitly states that evidence must be evaluated based onadequacyandsufficiencyto confirm compliance with security practices.
The Advanced Level in CMMC will contain Access Control (AC) practices from:
Level 1
Level 3
Levels 1 and 2
Levels 1, 2, and 3
In the CMMC 2.0 Model , the " Advanced Level " specifically refers to Level 2 . The CMMC model is designed to be cumulative , meaning each level builds upon the requirements of the levels beneath it.
Cumulative Framework : To achieve a certification at a specific level, an Organization Seeking Certification (OSC) must demonstrate compliance with all practices at that level and all practices from the lower levels.
Access Control (AC) Domain : The Access Control domain is one of the 14 domains in CMMC Level 2. It consists of a total of 22 practices :
Level 1 (Foundational) : Contains 4 basic safeguarding practices (mapped to FAR 52.204-21).
Level 2 (Advanced) : Adds 18 additional practices (mapped to NIST SP 800-171), totaling 22 practices for the AC domain at this level.
Defining " Advanced " : The DoD defines the levels as Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). Therefore, the " Advanced Level " (Level 2) contains the practices from Level 1 and Level 2, but does not include the " Expert " (Level 3) practices, which are derived from NIST SP 800-172.
Why other options are incorrect :
Option A : While it contains Level 1 practices, it also includes Level 2 practices.
Option B : Level 3 is the " Expert " level, which is separate and higher than the " Advanced " level.
Option D : The Advanced level does not reach the requirements of Level 3.
Reference Documents :
CMMC Model Overview (v2.0) : Section 3.2, " Level 2: Advanced, " which describes the 110 practices derived from NIST SP 800-171.
32 CFR Part 170 (CMMC Program Rule) : Details the structure of the levels and the requirement for cumulative compliance.
CMMC Level 2 Assessment Guide : Lists all 22 Access Control practices required for a Level 2 assessment, clearly identifying which are carried over from Level 1.
===========
Which DFARS clause considers Safeguarding CDI and Cyber Incident Reporting?
252.204-7022
252.204-7020
252.204-7012
252.204-7021
The correct answer is C because DFARS 252.204-7012 is explicitly titled “Safeguarding Covered Defense Information and Cyber Incident Reporting.” This clause is one of the core governance and source-document foundations for CMMC because it establishes contractor obligations for protecting covered defense information, including CUI/CDI, on covered contractor information systems. It defines covered contractor information systems as unclassified systems owned or operated by or for a contractor that process, store, or transmit covered defense information. It also requires contractors to provide adequate security and implement NIST SP 800-171 security requirements where applicable. In addition, it requires contractors to rapidly report cyber incidents affecting covered contractor systems or covered defense information, with “rapidly report” defined as within 72 hours of discovery. Options A, B, and D are not the clause titled for safeguarding CDI and cyber incident reporting. DFARS 252.204-7020 relates to NIST SP 800-171 DoD assessment requirements, while DFARS 252.204-7021 addresses CMMC requirements. Reference/topics: DFARS 252.204-7012, CDI/CUI safeguarding, cyber incident reporting, CMMC source documents.
Which phase of the CMMC Assessment Process includes developing the assessment plan?
Phase 1
Phase 2
Phase 3
Phase 4
Understanding the Phases of the CMMC Assessment Process
TheCMMC Assessment Process (CAP)consists of multiple phases, with each phase focusing on a different aspect of the assessment.Developing the assessment planoccurs inPhase 1, which is thePre-Assessment Phase.
Key Activities in Phase 1 – Pre-Assessment Phase
Engagement Agreement: TheOSC (Organization Seeking Certification)and theCertified Third-Party Assessment Organization (C3PAO)formalize the assessment contract.
Developing the Assessment Plan: TheLead Assessorand the assessment team create anAssessment Plan, which outlines:
Scope of the assessment
CMMC Level requirements
Assessment methodology
Timeline and logistics
Initial Data Collection: Review of system documentation, policies, and relevant security controls.
Why is the Correct Answer " Phase 1 " (A)?
A. Phase 1 → Correct
Phase 1 is where the assessment plan is developed.
It ensuresclarity on scope, methodology, and logistics before the assessment begins.
B. Phase 2 → Incorrect
Phase 2 is theAssessment Conduct Phase, where assessorsexecutethe plan by examining evidence and interviewing personnel.
C. Phase 3 → Incorrect
Phase 3 is thePost-Assessment Phase, which involvesfinalizing findings and submitting reports, not developing the plan.
D. Phase (Incomplete Answer) → Incorrect
The question requires a specific phase, and the correct one isPhase 1.
CMMC 2.0 References Supporting this Answer:
CMMC Assessment Process (CAP) Document
DefinesPhase 1as the stage where the assessment plan is developed.
CMMC Accreditation Body (CMMC-AB) Guidelines
Specifies thatplanning and pre-assessment activities occur in Phase 1.
CMMC 2.0 Certification Workflow
Outlines the assessment planning process as part of theinitial engagementbetween theC3PAO and the OSC.
Which NIST SP discusses protecting CUI in nonfederal systems and organizations?
NIST SP 800-37
NIST SP 800-53
NIST SP 800-88
NIST SP 800-171
Understanding the Role of NIST SP 800-171 in CMMC
NIST Special Publication (SP)800-171is the definitive standard for protectingControlled Unclassified Information (CUI)innonfederal systems and organizations. It provides security requirements that organizations handling CUImust implementto protect sensitive government information.
This document isthe foundationofCMMC 2.0 Level 2compliance, which aligns directly withNIST SP 800-171 Rev. 2requirements.
Breakdown of Answer Choices
NIST SP
Title
Relevance to CMMC
NIST SP 800-37
Risk Management Framework (RMF)
Focuses on risk assessment for federal agencies, not directly applicable to CUI in nonfederal systems.
NIST SP 800-53
Security and Privacy Controls for Federal Systems
Provides security controls forfederalinformation systems, not specifically tailored tononfederalorganizations handling CUI.
NIST SP 800-88
Guidelines for Media Sanitization
Covers secure data destruction and disposal, not overall CUI protection.
NIST SP 800-171
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
✅Correct Answer – Directly addresses CUI protection in contractor systems.
Key Requirements from NIST SP 800-171
The document outlines110 security controlsgrouped into14 families, including:
Access Control (AC)– Restrict access to authorized users.
Audit and Accountability (AU)– Maintain system logs and monitor activity.
Incident Response (IR)– Establish an incident response plan.
System and Communications Protection (SC)– Encrypt CUI in transit and at rest.
These controls serve as thebaseline requirementsfor organizations seekingCMMC Level 2 certificationto work withCUI.
Official Reference from CMMC 2.0 Documentation
CMMC 2.0 Level 2alignsdirectlywith NIST SP800-171 Rev. 2.
DoD contractors that handle CUImustcomply withall 110 controlsfrom NIST SP800-171.
Final Verification and Conclusion
The correct answer isD. NIST SP 800-171, as this documentexplicitly definesthe cybersecurity requirements for protectingCUI in nonfederal systems and organizations.
While conducting a CMMC Level 2 Assessment, the Lead Assessor determines that the OSC has badge readers, pin code pads, and keys for various access points as well as documentation to demonstrate meeting the practice. Which CMMC practice has the OSC MET?
PE.L1-3.10.5: Control and manage physical access devices
MP.L2-3.8.5: Mark media with necessary CUI markings and distribution limitations
SI.L2-3.14.3: Monitor system security alerts and advisories and take action in response
PS.L2-3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
The presence of badge readers, PIN code pads, and keys directly corresponds to controlling and managing physical access devices, which maps to PE.L1-3.10.5 under the Physical Protection (PE) domain. This practice ensures that only authorized individuals have access to physical areas containing information systems.
The other options address unrelated requirements:
MP.L2-3.8.5 addresses marking CUI media,
SI.L2-3.14.3 addresses monitoring security alerts,
PS.L2-3.9.2 addresses protections during personnel changes.
Reference Documents:
CMMC Model v2.0, Level 1–3 Practices
NIST SP 800-171 Rev. 2, Control PE-3
Which term describes the process of granting or denying specific requests to obtain and use information, related information processing services, and enter specific physical facilities?
Access control
Physical access control
Mandatory access control
Discretionary access control
Understanding Access Control in CMMC
Access control refers to the process ofgranting or denyingspecific requests to:
Obtain and use information
Access information processing services
Enter specific physical locations
TheAccess Control (AC) domain in CMMCis based onNIST SP 800-171 (3.1 Access Control family)and includes requirements to:
✅Implement policies for granting and revoking access.
✅Restrict access to authorized personnel only.
✅Protect physical and digital assets from unauthorized access.
Since the questionbroadly asks about the process of granting or denying access to information, services, and physical locations, the correct answer isA. Access Control.
Why the Other Answers Are Incorrect
B. Physical access control
❌Incorrect.Physical access controlis asubsetof access control that only applies tophysical locations(e.g., keycards, security guards, biometrics). The question includesinformation and services, makinggeneral access controlthe correct choice.
C. Mandatory access control (MAC)
❌Incorrect.MAC is a specific type of access controlwhere access is strictly enforced based onsecurity classifications(e.g., Top Secret, Secret, Confidential). The questiondoes not specify MAC, so this is incorrect.
D. Discretionary access control (DAC)
❌Incorrect.DAC is another specific type of access control, whereownersof data decide who can access it. The question asksgenerallyabout granting/denying access, makingaccess control (A)the best answer.
CMMC Official References
CMMC 2.0 Model - AC.L2-3.1.1 to AC.L2-3.1.22– Covers access control requirements, includingcontrolling access to information, services, and physical spaces.
NIST SP 800-171 (3.1 - Access Control Family)– Defines the general principles of access control.
Thus,option A (Access Control) is the correct answer, as it best aligns withCMMC access control requirements.
According to DFARS clause 252.204-7012, who is responsible for determining that Information in a given category should be considered CUI?
The NARA CUI Executive Agent
The contractor who generated the information
The DoD agency for whom the contractor is performing the work
The military personnel assigned to the contractor for that purpose
DFARS clause 252.204-7012 establishes the safeguarding of Covered Defense Information (CDI), which aligns with CUI categories. The clause specifies that the DoD is responsible for determining whether information is Controlled Unclassified Information (CUI) and marking it accordingly before sharing it with contractors. Contractors do not make determinations about what constitutes CUI; they are responsible for safeguarding information once it is received and marked as CUI.
Reference Documents:
DFARS 252.204-7012,Safeguarding Covered Defense Information and Cyber Incident Reporting
CMMC Model v2.0 Overview, December 2021
Which term describes a group of individuals that conduct operational network vulnerability evaluations and provide mitigation techniques to customers?
Red team
Blue team
White hat hackers
Penetration test team
The best match is Penetration test team because penetration testing is an authorized, structured security evaluation intended to find vulnerabilities in systems or networks and produce results that enable remediation/mitigation .
Authoritatively, NIST SP 800-115 (Technical Guide to Information Security Testing and Assessment) is a primary federal reference for technical security testing. It describes the purpose of technical testing as helping organizations plan and conduct tests , analyze findings , and develop mitigation strategies —which aligns directly with “vulnerability evaluations” and “providing mitigation techniques.” The DoD also points its Components to NIST SP 800-115 as guidance for penetration testing activities.
By contrast, a Red Team is typically framed as an “ethical adversary” that emulates attackers to test detection/response and overall readiness; it is often broader, scenario-driven, and focused on demonstrating what a capable adversary can accomplish rather than performing a scoped vulnerability evaluation with remediation-oriented outputs. A Blue Team is primarily defensive operations (monitoring, detection, response), not the group defined by conducting vulnerability evaluations for customers. “ White hat hackers ” is a general label for ethical hackers, but it is less specific than the established service construct of a penetration test team .
Because the question emphasizes operational network vulnerability evaluations plus mitigation techniques , the most precise and standard term is D: Penetration test team , supported by NIST’s testing-and-mitigation framing.
Which domains are a part of a Level 1 Self-Assessment?
Access Control (AC), Risk Management < RM), and Media Protection (MP)
Risk Management (RM). Access Control (AC), and Physical Protection (PE)
Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)
Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)
CMMCLevel 1focuses onbasic cyber hygieneand includes17 practicesderived fromNIST SP 800-171 Rev. 2butonly covers the protection of Federal Contract Information (FCI)—not Controlled Unclassified Information (CUI).
UnlikeLevel 2, which aligns fully withNIST SP 800-171,Level 1 does not require third-party certificationand can beself-assessedby the organization.
Domains Covered in a Level 1 Self-Assessment
CMMC Level 1 practices fall underthree specific domains:
Access Control (AC)– Ensures that only authorized individuals can access FCI.
Physical Protection (PE)– Protects physical access to systems and facilities storing FCI.
Identification and Authentication (IA)– Verifies the identity of users accessing systems containing FCI.
These domains focus on foundational security controls necessary toprotect FCI from unauthorized access.
Official CMMC 2.0 Documentation References
CMMC Model v2.0states thatLevel 1 includes only 17 practicesmapped toNIST SP 800-171requirements specific toAccess Control (AC), Physical Protection (PE), and Identification and Authentication (IA).
CMMC Assessment Guide, Level 1confirms thatRisk Management (RM) and Media Protection (MP) are not included in Level 1, as they pertain to more advanced security measures needed for handlingCUI (Level 2).
Breakdown of Answer Choices
A. Access Control (AC), Risk Management (RM), and Media Protection (MP)→ Incorrect.Risk Management (RM) and Media Protection (MP) are Level 2 domains.
B. Risk Management (RM), Access Control (AC), and Physical Protection (PE)→ Incorrect.Risk Management (RM) is not part of Level 1.
C. Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)→Correct.These are thethree domains covered in CMMC Level 1 self-assessments.
D. Risk Management (RM), Media Protection (MP), and Identification and Authentication (IA)→ Incorrect.Risk Management (RM) and Media Protection (MP) are Level 2 domains.
Conclusion
Thecorrect answer is C. Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA), as these are theonly three domains included in a CMMC Level 1 Self-Assessmentaccording toCMMC 2.0 documentation and NIST SP 800-171 mapping.
Reference Documents for Further Reading
CMMC 2.0 Model Overview – DoD Official Documentation
CMMC Assessment Guide, Level 1
NIST SP 800-171 Rev. 2 (Basic Security Requirements for FCI)
A CCP is consulting with an OSC. In the course of an interview, the OSC representative asks the CCP what basic safeguarding requirements must be met with respect to CMMC Level 1. The CCP tells the representative that this publication contains all the requirements from:
NIST SP 800-171.
DFARS Clause 252.202-7014.
DFARS Clause 252.204-7012.
FAR Clause 52.204-21.
The correct answer is D because CMMC Level 1 is based on the basic safeguarding requirements in FAR Clause 52.204-21 , not on the full NIST SP 800-171 or DFARS 252.204-7012 requirements. The official CMMC Model Overview states that Level 1 focuses on protecting Federal Contract Information (FCI) and consists of security requirements that correspond to the basic safeguarding requirements specified in 48 CFR 52.204-21 , commonly referred to as the FAR Clause. It also states that Level 2 is the level that incorporates the 110 security requirements from NIST SP 800-171 Rev. 2 for protection of Controlled Unclassified Information (CUI) .
FAR 52.204-21 applies to covered contractor information systems that process, store, or transmit Federal Contract Information. The clause requires contractors to apply basic safeguarding requirements and procedures, including limiting system access to authorized users, controlling external connections, protecting information on publicly accessible systems, identifying and authenticating users, and sanitizing or destroying media containing FCI before disposal or reuse.
Option A is incorrect because NIST SP 800-171 is associated with CMMC Level 2, not Level 1. Option B is incorrect because the cited DFARS clause number is not the CMMC Level 1 source. Option C is incorrect because DFARS 252.204-7012 is tied to safeguarding covered defense information and implementing NIST SP 800-171 for CUI, not the Level 1 basic safeguarding baseline.
An assessment is being completed at a client site that is not far from the Lead Assessor ' s home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?
Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.
Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.
Log into the client VPN from the assessor ' s laptop and retrieve the documents from the secure cloud storage service.
Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.
Best Practices for Handling Sensitive Assessment Information
CMMC assessments involve handlingsensitive and potentially CUI-related documents. Assessors must follow strictsecurity policiesto avoid unauthorized access, data leaks, or non-compliance withCMMC 2.0 and NIST SP 800-171 requirements.
Why Logging into the Client VPN on the Client Laptop is the Best Approach:
Ensures Data Protection:The client laptop is likely configured to meet security controls required for handling assessment-related materials.
Prevents Data Spillage:Keeping all assessment-related activities within the client’s secured environment reduces the risk ofdata leakage or unauthorized storage.
Maintains Compliance with CMMC/NIST Guidelines:Using aproperly configured client laptop and secured connectionensures compliance withNIST SP 800-171 controls on secure remote access(Requirement3.13.12).
Clarification of Incorrect Options:
A. " Log into the secure cloud storage service to save copies of the documents on both the work and client laptops. "
Incorrect→Sensitive data should not be duplicated across multiple systems, especially a non-client-approved laptop. Storing it on an unauthorized systemviolates data handling best practices.
C. " Log into the client VPN from the assessor ' s laptop and retrieve the documents from the secure cloud storage service. "
Incorrect→ Theassessor’s laptop may not be authorizedorsecuredto handle client data. CMMC guidelines emphasizeusing approved, secured systemsfor assessment-related information.
D. " Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick. "
Incorrect→
Transferring sensitive documents via USBintroduces security risks, including unauthorized data storage and potential malware contamination.
Home office workstationsare unlikely to be authorized for handling CMMC-sensitive data.
Which method facilitates understanding by analyzing gathered artifacts as evidence?
Test
Examine
Behavior
Interview
The CMMC Assessment Process uses three methods: Examine, Interview, and Test. The method that involves analyzing artifacts (documents, system configurations, records, logs, etc.) is Examine.
Supporting Extracts from Official Content:
CMMC Assessment Guide: “Examine consists of reviewing, inspecting, or analyzing assessment objects such as documents, system configurations, or other artifacts to evaluate compliance.”
Why Option B is Correct:
Examine = analyzing artifacts.
Interview = discussions with personnel.
Test = executing technical checks.
Behavior is not an assessment method.
References (Official CMMC v2.0 Content):
CMMC Assessment Guide, Levels 1 and 2 — Assessment Methods (Examine, Interview, Test).
===========
The practices in CMMC Level 2 consist of the security requirements specified in:
NIST SP 800-53
NIST SP 800-171
48 CFR 52.204-21
DFARS 252.204-7012
CMMC Level 2 requires full implementation of the 110 security requirements specified in NIST SP 800-171 Rev. 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations. These practices form the foundation for safeguarding CUI across defense contractor systems.
NIST SP 800-53 is a broader catalog of security controls for federal systems, not specific to CUI in the defense contractor environment.
48 CFR 52.204-21 establishes basic safeguarding requirements for Federal Contract Information (FCI) and corresponds to CMMC Level 1.
DFARS 252.204-7012 defines safeguarding and incident reporting obligations but does not enumerate the specific security practices required.
Thus, Level 2 practices are aligned to NIST SP 800-171.
Reference Documents:
CMMC Model v2.0 Overview, December 2021
NIST SP 800-171 Rev. 2
What activities are conducted while developing an assessment plan?
The C3PAO decides the Assessment Team members and notifies the Lead Assessor.
The Lead Assessor and the OSC’s sponsor determine the assessment resources and schedule.
The C3PAO’s project manager is responsible for handling potential conflicts of interest.
The evidence collection approach can be finalized when the Lead Assessor conducts an onsite assessment.
In the CAP v2.0 “preliminary proceedings,” the assessment is “framed” before Phase 1/Phase 2 execution. CAP states the C3PAO works with the OSC’s leadership point(s) of contact (the Affirming Official and/or OSC POC ) “to determine the purview and planning details of the assessment,” explicitly including schedule , personnel , logistics , relevant contractual requirements, and the prospective CMMC Assessment Scope .
Although the question uses the term “OSC sponsor,” the CAP’s official role language is Affirming Official / OSC POC , and the Lead CCA (Lead Assessor) is the assessor counterpart. CAP further explains that the In-Brief Meeting establishes a common understanding of objectives, roles/responsibilities, and the schedule , and the Lead CCA must (at minimum) review the schedule and confirm assessment scope with the OSC.
Option A is incomplete because team assignment is a C3PAO responsibility, but CAP’s “plan” emphasis here is broader framing: availability of personnel/evidence, documentation readiness, timing, and logistics. Option C is incorrect because CAP states C3PAOs are ultimately responsible for managing conflicts of interest and this responsibility cannot be delegated to the assessment team or the OSC. Option D is incorrect because CAP requires evaluation methods and evidence planning activities to be established during Phase 1 planning, not deferred until onsite work.
===========
What is the BEST description of the purpose of FAR clause 52 204-21?
It directs all covered contractors to install the cyber security systems listed in that clause.
It describes all of the safeguards that contractors must take to secure covered contractor IS.
It describes the minimum standard of care that contractors must take to secure covered contractor IS.
It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.
Understanding FAR Clause 52.204-21
TheFederal Acquisition Regulation (FAR) Clause 52.204-21is titled " Basic Safeguarding of Covered Contractor Information Systems. " This clause establishesminimum cybersecurity requirementsforfederal contractorsthat handleFederal Contract Information (FCI).
Key Purpose of FAR Clause 52.204-21
Theprimary objectiveof FAR 52.204-21 is to ensure that contractors applybasic cybersecurity protectionsto theirinformation systemsthat process, store, or transmitFCI. Theseminimum safeguarding requirementsserve as abaseline security standardfor contractors doing business with theU.S. government.
Why " Minimum Standard of Care " is Correct?
FAR 52.204-21 doesnotrequire contractors to install specific cybersecurity tools (eliminating option A).
Itoutlines only the minimum safeguards, notallcybersecurity controls needed for complete security (eliminating option B).
CMMC certification isnotmandated by this clause alone (eliminating option D).
Instead, it establishesa baseline " standard of care " that all federal contractorsmust followto protectFCI(making option C correct).
Breakdown of Answer Choices
Option
Description
Correct?
A. It directs all covered contractors to install the cybersecurity systems listed in that clause.
❌Incorrect–The clause doesnotspecify tools or require specific cybersecurity systems.
B. It describes all of the safeguards that contractors must take to secure covered contractor IS.
❌Incorrect–It only setsminimumrequirements, notall possiblesecurity measures.
C. It describes the minimum standard of care that contractors must take to secure covered contractor IS.
✅Correct – The clause defines basic safeguards as a minimum security standard.
D. It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.
❌Incorrect–FAR 52.204-21 doesnot mandateCMMC certification; that requirement comes from DFARS 252.204-7012 and 7021.
Minimum Safeguarding Requirements Under FAR 52.204-21
The clause defines15 basic security controls, which align withCMMC Level 1. Some examples include:
✅Access Control– Limit access to authorized users.
✅Identification & Authentication– Authenticate system users.
✅Media Protection– Sanitize media before disposal.
✅System & Communications Protection– Monitor and control network connections.
Official References from CMMC 2.0 and FAR Documentation
FAR 52.204-21– Establishes thebasic safeguarding requirementsfor FCI.
CMMC 2.0 Level 1– Directly aligns withFAR 52.204-21 controls.
Final Verification and Conclusion
The correct answer isC. It describes the minimum standard of care that contractors must take to secure covered contractor IS.This aligns withFAR 52.204-21 requirementsas abaseline security standard for FCI.
What banner markings MUST a document that contains CUI include?
A highest level of CUI contained within the document marking on each page
All CUI Category and Subcategory markings contained within the document on each page
A special Category or Subcategory marking on the cover page only
A special Category or Subcategory marking on only the page(s) that include the CUI
The correct answer is B because the CUI banner marking is a document-level marking and must reflect the CUI contained in the document, not merely the CUI on one page or only the cover. The CUI marking rule states that CUI banner markings may include the CUI control marking, category or subcategory markings, and limited dissemination controls. It also states that CUI Specified category or subcategory markings that pertain to the information in the document must be included in the banner marking. Most importantly, the content of the CUI banner marking must apply to the whole document, inclusive of all CUI within the document, and must be the same on each page of the document that includes CUI. Option A uses “highest level” language, which is more characteristic of classified-information marking logic and is not the cleanest CUI rule. Options C and D are wrong because they confine special category/subcategory marking to the cover page or only selected pages, while the CUI banner marking operates at the document level. Reference/topics: CUI Registry, CUI banner marking, CUI category/subcategory markings, CUI Specified.
In accordance with NARA directives and Chapter 33 of Title 44 (Records Management Directive), which types of data MUST have policies and procedures for disposal?
All recorded digital documents
All digital and recorded paper documents
All digital documents and recorded media
All recorded information, regardless of form or characteristics
Under Title 44 U.S.C. Chapter 33 (Records Management) and NARA directives, agencies and organizations must establish policies and procedures for the disposal of all recorded information, regardless of form or characteristics. This includes paper records, electronic documents, digital media, audiovisual files, and any other information format. The requirement ensures consistent handling, retention, and lawful disposal of both federal records and CUI.
Reference Documents:
Title 44, U.S. Code, Chapter 33: Records Management
NARA Records Management Directive
How many cybersecurity levels does the CMMC Model structure contain?
2 Levels.
3 Levels.
5 Levels.
4 Levels.
The correct answer is B , 3 Levels. The official CMMC 2.0 Model Overview states that there are three levels within CMMC: Level 1, Level 2, and Level 3 . It explains that the model measures implementation of cybersecurity requirements at three levels, with each level containing a defined set of CMMC practices. Level 1 is focused on basic safeguarding of Federal Contract Information, Level 2 is focused on protection of Controlled Unclassified Information using requirements aligned to NIST SP 800-171, and Level 3 is intended for higher-risk programs requiring enhanced protection.
This is a major difference between CMMC 2.0 and the earlier CMMC 1.0 structure. CMMC 1.0 used five maturity levels, but CMMC 2.0 simplified the model to three cybersecurity levels. Therefore, option C , 5 Levels, reflects the older CMMC 1.0 structure and is not correct for CMMC 2.0. Option A , 2 Levels, is incorrect because it omits one of the three official levels. Option D , 4 Levels, is also incorrect because the official CMMC 2.0 model does not contain four levels. The bottom line is that CMMC 2.0 contains three cybersecurity levels: Level 1 Foundational, Level 2 Advanced, and Level 3 Expert .
Which term describes " the protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to. or modification of information " ?
Adopted security
Adaptive security
Adequate security
Advanced security
Understanding the Concept of Security in CMMC 2.0
CMMC 2.0 aligns with federal cybersecurity standards, particularlyFISMA (Federal Information Security Modernization Act), NIST SP 800-171, and FAR 52.204-21. One key principle in these frameworks is the implementation of security measures that are appropriate for the risk level associated with the data being protected.
The question describes security measures that are proportionate to therisk of loss, misuse, unauthorized access, or modificationof information. This matches the definition of " Adequate Security. "
Analyzing the Given Options
A. Adopted security→ Incorrect
The term " adopted security " is not officially recognized in CMMC, NIST, or FISMA. Organizations adopt security policies, but the concept does not directly align with the question’s definition.
B. Adaptive security→ Incorrect
Adaptive securityrefers to adynamic cybersecurity modelwhere security measures continuously evolve based on real-time threats. While important, it does not directly match the definition in the question.
C. Adequate security→Correct
The term " adequate security " is defined inNIST SP 800-171, DFARS 252.204-7012, and FISMAas the level of protection that isproportional to the consequences and likelihood of a security incident.
This aligns perfectly with the definition in the question.
D. Advanced security→ Incorrect
Advanced securitytypically refers tohighly sophisticated cybersecurity mechanisms, such as AI-driven threat detection. However, the term does not explicitly relate to the concept of risk-based proportional security.
Official References Supporting the Correct Answer
FISMA (44 U.S.C. § 3552(b)(3))
Definesadequate securityas " protective measures commensurate with the risk and potential impact of unauthorized access, use, disclosure, disruption, modification, or destruction of information. "
This directly matches the question ' s wording.
DFARS 252.204-7012 (Safeguarding Covered Defense Information and Cyber Incident Reporting)
Mandates that contractors apply " adequate security " to protect Controlled Unclassified Information (CUI).
NIST SP 800-171 Rev. 2, Requirement 3.1.1
States that organizations must " limit system access to authorized users and implement adequate security protections to prevent unauthorized disclosure. "
CMMC 2.0 Documentation (Level 1 and Level 2 Requirements)
Requires that organizationsapply adequate security measures in accordance with NIST SP 800-171to meet compliance standards.
Conclusion
The term " adequate security " is the correct answer because it is explicitly defined in federal cybersecurity frameworks asprotection proportional to risk and potential consequences. Thus, the verified answer is:
Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?
Level 1
Level 2
Level 3
All levels
Understanding Training Requirements in CMMC
The requirement for ensuring thatpersonnel are trained to carry out their assigned information security-related duties and responsibilitiesfirst appears inCMMC Level 2as part ofNIST SP 800-171 control AT.L2-3.2.1.
Key Details on the Training Requirement:
✔AT.L2-3.2.1: " Ensure that personnel are trained to carry out their assigned information security-related duties and responsibilities. "
✔This control is derived fromNIST SP 800-171and applies toCMMC Level 2 (Advanced).
✔It ensures that employees handlingControlled Unclassified Information (CUI)understand theircybersecurity responsibilities.
Why is the Correct Answer " B. Level 2 " ?
A. Level 1 → Incorrect
CMMC Level 1 does not include this training requirement.Level 1 focuses on basic safeguarding ofFederal Contract Information (FCI)but doesnot require formal cybersecurity training.
B. Level 2 → Correct
The training requirement (AT.L2-3.2.1) first appears in CMMC Level 2, which aligns withNIST SP 800-171.
C. Level 3 → Incorrect
The training requirementalready exists in Level 2. Level 3 builds on Level 2 with additionalrisk management and advanced cybersecurity controls, but training is introduced at Level 2.
D. All levels → Incorrect
CMMC Level 1 does not include this requirement—it is first introduced in Level 2.
CMMC 2.0 References Supporting This Answer:
NIST SP 800-171 (Requirement 3.2.1)
Defines themandatory training requirementfor personnel handling CUI.
CMMC Assessment Guide for Level 2
ListsAT.L2-3.2.1as a required practice under Level 2.
CMMC 2.0 Model Overview
Confirms thatCMMC Level 2 aligns with NIST SP 800-171, which includes security training requirements.
What is the legal entity under a contract that has agreed to deliver products or services?
Supporting Organization/Unit
Commercial and Government Entity Code
Host Unit
HQ Organization
The correct answer is D because the HQ Organization represents the legal entity associated with the contract obligation to deliver products or services. In assessment scoping, it is critical to separate the overall legal contracting entity from the specific Host Unit or operational segment that processes, stores, or transmits FCI or CUI. A Host Unit is the assessed operational environment or business unit within the organization where the relevant contract work and information handling occur. A Supporting Organization/Unit provides people, processes, or technology that support the Host Unit but is not the prime legal entity delivering the contractual product or service. A Commercial and Government Entity Code, or CAGE code, is an identifier associated with the entity; it is not itself the legal entity. CAP guidance requires the C3PAO to confirm the specific corporate legal entity being assessed and to solicit the associated CAGE code or codes. That distinction points to the HQ Organization as the contractual legal entity, while the CAGE code is only the identifier used to associate the entity with DoD systems. Reference/topics: CAP scoping, HQ Organization, Host Unit, CAGE code, legal entity confirmation.
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
Have a security clearance
Be a senior person in the company
Demonstrate expertise on the CMMC requirements
Provide clarity and understanding of their practice activities
Per the CMMC Assessment Process (CAP), when planning an assessment, the Lead Assessor must coordinate with the Organization Seeking Certification (OSC) to select interview participants who can provide clarity and understanding of their practice activities. The intent is to interview individuals directly involved with and knowledgeable about the processes and practices under review, rather than selecting personnel based solely on rank, clearance, or formal expertise in CMMC.
This ensures the assessment is evidence-based and grounded in how practices are actually performed within the OSC.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
A CMMC Assessment Team arrives at an OSC to begin a CMMC Level 2 Assessment. The team checks in at the front desk and lets the receptionist know that they are here to conduct the assessment. The receptionist is aware that the team is arriving today and points down a hallway where the conference room is. The receptionist tells the Lead Assessor to wait in the conference room. as someone will be there shortly. The receptionist fails to check for credentials and fails to escort the team. The receptionist ' s actions are in direct violation of which CMMC practice?
PE.L1-3.10.3: Escort visitors and monitor visitor activity
PE.L1-3.10.5: Control and manage physical access devices
PS.L2-3.9.1; Screen individuals prior to authorizing access to organizational systems containing CUI
PS.L2-3 9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
ThePhysical Protection (PE) domaininCMMC 2.0 Level 1includes the requirementPE.L1-3.10.3, which mandates that organizationsescort visitors and monitor their activity.
Breaking Down the Scenario:
TheCMMC Assessment Teamarrives at the OSC.
Thereceptionist acknowledges their arrival but does not verify credentials or escort themto the appropriate location.
Failing to verify visitor identity and failing to escort them is a violation of PE.L1-3.10.3.
Analysis of the Given Options:
A. PE.L1-3.10.3: Escort visitors and monitor visitor activity→✅Correct
This requirement ensures that visitorsdo not have unsupervised access to sensitive areas.
The receptionistshould have checked credentials and escorted the assessment team.
B. PE.L1-3.10.5: Control and manage physical access devices→❌Incorrect
This requirement refers to managingkeys, access badges, and security devices, which isnot the issue in this scenario.
C. PS.L2-3.9.1: Screen individuals prior to authorizing access to organizational systems containing CUI→❌Incorrect
This control applies to personnel screeningsbefore granting access to CUI systems, not physical visitor access.
D. PS.L2-3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers→❌Incorrect
This requirement deals withoffboarding employees and ensuring they no longer have system access. It isnot relevant to visitor escorting.
Official References Supporting the Correct Answer:
CMMC 2.0 Level 1 - PE.L1-3.10.3 (Physical Protection)
Requires organizations toescort visitors and monitor visitor activityat facilities containingFCI or CUI.
NIST SP 800-171 Rev. 2, Control 3.10.3
States thatvisitors must be escorted and monitored at all timesto prevent unauthorized access.
Conclusion:
Since the receptionist failed to verify credentials and escort the visitors, this violatesPE.L1-3.10.3.
✅Correct Answer: A. PE.L1-3.10.3: Escort visitors and monitor visitor activity
A CCP is on their first assessment for CMMC Level 2 with an Assessment Team and is reviewing the CMMC Assessment Process to understand their responsibilities. Which method gathers information from the subject matter experts to facilitate understanding and achieve clarification?
Test
Examine
Interview
Assessment
Understanding CMMC Assessment Methods
TheCMMC Assessment Process (CAP)definesthree primary assessment methodsused to verify compliance with cybersecurity practices:
Examine– Reviewing documents, policies, configurations, and logs.
Interview– Engaging with subject matter experts (SMEs) to clarify processes and verify implementation.
Test– Observing technical implementations, such as system configurations and security measures.
Since the question asks for a method thatgathers information from SMEs to facilitate understanding and achieve clarification, the correct method isInterview.
Why " Interview " is Correct?
✅Interviewsare specifically designed togather information from SMEsto confirm understanding and clarify security processes.
✅TheCMMC Assessment Guiderequires assessors tointerview key personnelresponsible for cybersecurity practices.
✅Examine (Option B)andTest (Option A)are also valid assessment methods, but they donot focus on gathering insights directly from SMEs.
Breakdown of Answer Choices
Option
Description
Correct?
A. Test
❌Incorrect–This method involvestechnical verification, not gathering SME insights.
B. Examine
❌Incorrect–This method focuses ondocument review, not SME interaction.
C. Interview
✅Correct – The method used to gather information from SMEs and achieve clarification.
D. Assessment
❌Incorrect–This is a general term,not a specific assessment method.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)– DefinesInterviewas the method for obtaining information from SMEs.
Final Verification and Conclusion
The correct answer isC. Interview, as this methodgathers insights from subject matter expertsto verify cybersecurity implementations.
Which resource could BEST help a CEO determine how to identify the category of CUI ?
NARA
CMMC-AB
DoD DFARS Part 252
CMMC Assessment Guide
The best resource for identifying the category of Controlled Unclassified Information (CUI) is NARA , because NARA is the CUI Executive Agent for the federal CUI Program and maintains the authoritative CUI Registry . The Registry is specifically where the government publishes the approved CUI categories (and related markings and handling guidance) used across the Executive Branch.
NARA’s own CUI FAQs explicitly point users to the CUI Registry as the place that “lists all authorized CUI Categories (basic and specified).” Likewise, NIST’s CUI-related FAQ page also points to the NARA CUI Registry for CUI categories, reinforcing that the Registry is the correct source for determining which category applies to a given type of information.
By contrast, DFARS Part 252 (including clauses like 252.204-7012) addresses contractual safeguarding and cyber reporting requirements, not the authoritative categorization list itself. The CMMC Assessment Guide is about how to assess controls for CMMC levels, not how to determine CUI categories. And the Cyber AB (formerly CMMC-AB) administers the ecosystem and assessment processes, not the federal CUI category taxonomy. Therefore, NARA is the best answer.
An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?
Take it with them to review in the evening.
Leave it on the desk for review the following day.
Put it in the unlocked desk drawer for review the following morning.
Take a picture with the personal phone before securely shredding it.
In this scenario, the primary concern is the protection of Controlled Unclassified Information (CUI) in an environment that lacks sufficient physical security controls (specifically, a lack of a locked cabinet or drawer). According to the CMMC Assessment Process (CAP) and NIST SP 800-171 (specifically the Physical Protection (PE) family), CUI must be protected from unauthorized access at all times.
Responsibility of the Assessor: CMMC Professionals (CCPs and CCAs) are bound by the CMMC Code of Professional Conduct and the C3PAO ' s internal security protocols to ensure that any CUI provided by the Organization Seeking Certification (OSC) is handled securely.
Physical Protection (PE.L2-3.10.1 and PE.L2-3.10.2): These practices require that an organization limit physical access to systems and equipment to authorized users and protect the physical facility. If the provided " hoteling space " does not offer a locked container (like a cabinet) to secure the CUI overnight, leaving it in an unlocked drawer (Option C) or on the desk (Option B) would be a violation of CUI handling requirements and a security risk.
Why Option A is the best " Next " step: In the absence of on-site secure storage, the assessor must maintain positive control of the CUI. Taking the document to a secure location (such as the assessor ' s hotel room or person) where they can ensure it remains under their control is the only viable way to prevent unauthorized access by janitorial staff or other unauthorized personnel at the client site overnight.
Why other options are incorrect:
Option B and C: Both fail to protect the CUI from unauthorized access in a non-secure, shared environment.
Option D: Taking a picture of CUI on a personal phone is a major security violation (spillage), as personal devices are generally not authorized to store or process CUI.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section regarding " Assessor Responsibilities for CUI and Proprietary Information. "
NIST SP 800-171 Rev 2: Physical Protection (PE) family (3.10.1, 3.10.2).
DoD Instruction 5200.48: " Controlled Unclassified Information (CUI), " which specifies that CUI must be protected by at least one physical barrier when not in the direct control of an authorized individual.
For CMMC Assessments, during Phase 1 of the CMMC Assessment Process, which are responsible for identifying potential conflicts of information?
C3PAO and OSC
OSC and CMMC-AB
CMMC-AB and C3PAO
Lead Assessor and Assessment Team Members
In Phase 1 (Planning) of the CMMC Assessment Process, the Lead Assessor is responsible for managing the team and identifying conflicts of interest. Assessment team members must also disclose potential conflicts.
Supporting Extracts from Official Content:
CAP v2.0, Planning (§2.5–2.8): “The Lead Assessor and Assessment Team Members must identify and disclose any conflicts of interest prior to conducting the assessment.”
Why Option D is Correct:
Only the Lead Assessor and assessment team are responsible for identifying conflicts of interest during Phase 1.
Options A, B, and C incorrectly assign this role to organizations that do not hold the responsibility.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 1 Planning responsibilities.
===========
When assessing SI.L2-3.14.6: Monitor communications for attack, the CCA interviews the person responsible for the intrusion detection system and examines relevant policies and procedures for monitoring organizational systems. What would be a possible next step the CCA could conduct to gather sufficient evidence?
Conduct a penetration test
Interview the intrusion detection system ' s supplier.
Upload known malicious code and observe the system response.
Review an artifact to check key references for the configuration of the IDS or IPS practice for additional guidance on intrusion detection and prevention systems.
Understanding SI.L2-3.14.6: Monitor Communications for Attacks
The practiceSI.L2-3.14.6fromNIST SP 800-171(aligned with CMMC Level 2) requires an organization tomonitor organizational communications for indicators of attack. This typically includes:
✅Intrusion Detection Systems (IDS)andIntrusion Prevention Systems (IPS)
✅Log analysis and network monitoring
✅Incident response planningfor detected threats
As part of aCMMC Level 2 assessment, theCertified CMMC Assessor (CCA)must ensure that theOSC (Organization Seeking Certification)hasproperly implemented and documenteditsmonitoring capabilities.
Why " Review an artifact to check key references for the configuration of the IDS or IPS " is Correct?
TheCCA must collect sufficient objective evidenceto determine compliance.
Reviewing anartifact(such as system configurations, IDS/IPS logs, or security policies)helps validatethat intrusion detection is properly implemented.
Configuration settings providedirect evidenceof whethermonitoring for attacksis effectively applied.
Breakdown of Answer Choices
Option
Description
Correct?
A. Conduct a penetration test
❌Incorrect–Penetration testing isnot requiredfor CMMC Level 2 assessments and falls outside an assessor ' s responsibilities.
B. Interview the intrusion detection system ' s supplier.
❌Incorrect–Thesupplier does not determine compliance; the assessor needs evidence from theOSC’s implementation.
C. Upload known malicious code and observe the system response.
❌Incorrect–This would beinvasive testing, which isnot part of a CMMC assessment.
D. Review an artifact to check key references for the configuration of the IDS or IPS practice for additional guidance on intrusion detection and prevention systems.
✅Correct – Reviewing system artifacts provides direct evidence of compliance with SI.L2-3.14.6.
Official References from CMMC 2.0 and NIST SP 800-171 Documentation
NIST SP 800-171 SI.L2-3.14.6– Requires monitoring communications for attack indicators.
CMMC Assessment Process Guide (CAP)– Describesartifact reviewas an essential assessment method.
Final Verification and Conclusion
The correct answer isD. Review an artifact to check key references for the configuration of the IDS or IPS practice for additional guidance on intrusion detection and prevention systems.
This aligns withCMMC 2.0 Level 2 assessment requirementsandSI.L2-3.14.6 compliance verification.
For a CMMC Level 2 certification, which organization maintains a non-disclosure agreement with the OSC?
NIST
C3PAO
CMMC-AB
OUSD A & S
The Certified Third-Party Assessment Organization (C3PAO) enters into a contractual relationship with the OSC. As part of that contract, the C3PAO maintains a non-disclosure agreement (NDA) to protect sensitive and proprietary information reviewed during the assessment.
Supporting Extracts from Official Content:
CAP v2.0, Roles and Responsibilities (§2.8): “The C3PAO maintains a non-disclosure agreement with the OSC to protect all sensitive information disclosed during the assessment.”
Why Option B is Correct:
Only the C3PAO contracts directly with the OSC and is bound to protect assessment data.
NIST, The Cyber AB (formerly CMMC-AB), and OUSD A & S do not enter NDAs directly with OSCs.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Section on OSC–C3PAO agreements.
===========
Which are guiding principles in the CMMC Code of Professional Conduct?
Objectivity, information integrity, and higher accountability
Objectivity, information integrity, and proper use of methods
Proper use of methods, higher accountability, and objectivity
Proper use of methods, higher accountability, and information integrity
The CMMC Code of Professional Conduct applies to all CMMC assessors, practitioners, and ecosystem participants. Its guiding principles are: Objectivity, Information Integrity, and Higher Accountability.
Supporting Extracts from Official Content:
CMMC Code of Professional Conduct: “Guiding principles… include Objectivity, Information Integrity, and Higher Accountability.”
Why Option A is Correct:
These three principles are the official guiding values documented in the Code of Professional Conduct.
Options B, C, and D insert terms (“proper use of methods”) that are not part of the official guiding principles.
References (Official CMMC v2.0 Content):
CMMC Code of Professional Conduct.
===========
Which term describes the prevention of damage to. protection of, and restoration of computers and electronic communications systems/services, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation?
Cybersecurity
Data security
Network security
Information security
The term that describes " the prevention of damage to, protection of, and restoration of computers and electronic communication systems/services, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and non-repudiation " isCybersecurity.
Step-by-Step Breakdown:
✅1. Cybersecurity Defined
Cybersecurityfocuses onprotecting networks, systems, and datafrom cyber threats.
It includes measures to ensure:
Availability(data is accessible when needed).
Integrity(data is accurate and unaltered).
Authentication(verifying users ' identities).
Confidentiality(ensuring only authorized access).
Non-repudiation(preventing denial of actions).
The definition in the questionaligns directly with cybersecurity principles, making it the best answer.
✅2. Why the Other Answer Choices Are Incorrect:
(B) Data Security❌
Data securityfocusesspecificallyon protectingstored information(e.g., encryption, access controls), but cybersecurity is broader—it includesnetworks, systems, and communication services.
(C) Network Security❌
Network securityis asubset of cybersecuritythat focuses on protectingnetwork infrastructure(e.g., firewalls, intrusion detection systems).
The definition in the question includesmore than just networks, so cybersecurity is the better choice.
(D) Information Security❌
Information security (InfoSec)is related but broader than cybersecurity.
InfoSeccoversphysical and organizational security(e.g., policies, procedures) in addition todigital protections.
Final Validation from CMMC Documentation:
CMMC and NIST SP 800-171 define cybersecurityas the protection ofsystems, networks, and data from cyber threats.
DoD Cybersecurity Definitions(aligned with NIST) confirm that cybersecurity is the term thatbest fits the definition in the question.
A CCP is providing consulting services to a company who is an OSC. The CCP is preparing the OSC for a CMMC Level 2 assessment. The company has asked the CCP who is responsible for determining the CMMC Assessment Scope and who validates its CMMC Assessment Scope. How should the CCP respond?
" The OSC determines the CMMC Assessment Scope, and the CCP validates the CMMC Assessment Scope. "
" The OSC determines the CMMC Assessment Scope, and the C3PAO validates the CMMC Assessment Scope. "
" The CMMC Lead Assessor determines the CMMC Assessment Scope, and the OSC validates the CMMC Assessment Scope. "
" The CMMC C3PAO determines the CMMC Assessment Scope, and the Lead Assessor validates the CMMC Assessment Scope. "
Step 1: Understanding CMMC Assessment Scope Determination
In a CMMC Level 2 assessment, the Organization Seeking Certification (OSC) is responsible for identifying the assessment scope based on the CMMC Scoping Guidance provided by the Cyber AB (Cyber Accreditation Body) and DoD.
The OSC must determine which assets and systems handle Controlled Unclassified Information (CUI) and categorize them accordingly.
Who is responsible for ensuring that subcontractors have a valid CMMC Certification?
CMMC-AB
OUSD A & S
DoD agency or client
Contractor organization
Under DFARS and CMMC requirements, the prime contractor is responsible for ensuring its subcontractors meet the required CMMC level. Neither the DoD, The Cyber AB, nor OUSD A & S directly manages subcontractor certification.
Supporting Extracts from Official Content:
DFARS 252.204-7021: “The contractor shall ensure that its subcontractors have the appropriate CMMC level certification for the information they will handle.”
Why Option D is Correct:
Compliance responsibility flows through the contractor supply chain.
CMMC-AB (The Cyber AB) accredits assessors but does not police subcontractors.
OUSD A & S sets policy, not enforcement at contract level.
DoD agencies only require compliance at award/contract oversight level.
References (Official CMMC v2.0 Content):
DFARS 252.204-7021.
CMMC Model v2.0 governance guidance.
===========
Which authority leads the CMMC direction, standards, best practices, and knowledge framework for how to map the controls and processes across different Levels that range from basic cyber hygiene to advanced cyber practices?
NIST
DoD CIO office
Federal CIO office
Defense Federal Acquisition Regulation Council
Understanding the Role of the DoD CIO Office in CMMC
TheDepartment of Defense (DoD) Chief Information Officer (CIO) officeis theprimary authorityresponsible for leading the direction, standards, and best practices of theCybersecurity Maturity Model Certification (CMMC)framework.
Why " B. DoD CIO Office " is Correct?
The DoD CIO Oversees CMMC Policy and Implementation
TheDoD CIO Office is responsible for the governance and strategic direction of CMMC.
It ensures thatCMMC aligns with DoD cybersecurity policies, such asDoD Instruction 5200.48 (Controlled Unclassified Information)andNIST SP 800-171.
CMMC Development and Evolution
TheDoD CIO played a critical role in launching CMMCto improve cybersecurity across theDefense Industrial Base (DIB).
The CIO office leadspolicy development and updates to the CMMC framework, including the transition fromCMMC 1.0 to CMMC 2.0.
Alignment of CMMC with Federal Cybersecurity Strategy
The DoD CIO ensures that CMMCintegrates with federal cybersecurity policiesandNIST frameworks.
It provides oversight formapping CMMC Levels (1-2-3) to existing cybersecurity standards and controls.
Why Other Answers Are Incorrect?
A. NIST (Incorrect)
TheNational Institute of Standards and Technology (NIST)provides thetechnical framework (NIST SP 800-171, SP 800-172), butNIST does not lead the CMMC program.
C. Federal CIO Office (Incorrect)
TheFederal CIO focuses on broader government IT policiesandnot specifically on DoD cybersecurity requirementslike CMMC.
D. Defense Federal Acquisition Regulation Council (Incorrect)
TheDFARS Counciloverseescontracting regulationsrelated to CMMC (e.g.,DFARS 252.204-7012, 7019, 7020, 7021), but it doesnot lead CMMC standards and best practices.
Conclusion
The correct answer isB. DoD CIO Office, as it isthe lead authority guiding the CMMC framework, standards, and implementation across the Defense Industrial Base (DIB).
Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?
DOD OUSD
Authorized holder
Information Disclosure Official
Presidentially authorized Original Classification Authority
DoDI 5200.48 specifies that Authorized Holders of CUI are responsible for applying appropriate CUI markings. An authorized holder is an individual who has lawful government purpose access to the information. This ensures that responsibility for correctly marking information rests with those who create or handle the material, not only with original classification authorities (which apply to classified information, not CUI).
Reference Documents:
DoDI 5200.48,Controlled Unclassified Information (CUI)
Which code or clause requires that a contractor is meeting the basic safeguarding requirements for FCI during a Level 1 Self-Assessment?
FAR 52.204-21
22CFR 120-130
DFARS 252.204-7011
DFARS 252.204-7021
1. Understanding Basic Safeguarding Requirements for FCI in CMMC Level 1
Federal Contract Information (FCI) is defined as information provided by or generated for the government under a contract that isnot intended for public release.
CMMCLevel 1is designed to ensurebasic safeguardingof FCI, aligning with15 security requirementsfound inFAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems).
Contractors handlingonly FCImust meetCMMC Level 1, which alignsdirectlywith the safeguarding requirements set inFAR 52.204-21.
2. FAR 52.204-21 and Its Role in CMMC Level 1 Compliance
FAR 52.204-21establishes the baseline cybersecurity controls that contractors must implement to protectFCI.
The15 basic safeguarding requirementsinclude:
Limiting information accessto authorized users.
Identifying and authenticating usersbefore allowing system access.
Protecting transmitted FCIfrom unauthorized disclosure.
Monitoring and controlling connectionsto external systems.
Applying boundary protectionand cybersecurity measures.
Sanitizing mediabefore disposal.
Updating security configurationsto reduce vulnerabilities.
Providing physical securityprotections.
Controlling physical accessto systems that process FCI.
Enforcing multi-factor authentication (MFA) where applicable.
Patching vulnerabilitiesin software and hardware.
Limiting the use of removable media.
Creating and retaining system audit logs.
Performing risk-based security assessments.
Developing an incident response plan.
These 15 practices form thefoundationof CMMCLevel 1 Self-Assessment, ensuring contractorsmeet minimum cybersecurity expectationsfor handling FCI.
3. Why the Other Options Are Incorrect
B. 22 CFR 120-130:
This refers toInternational Traffic in Arms Regulations (ITAR), which controls the export of defense-related articles and services,notFCI safeguarding requirements.
C. DFARS 252.204-7011:
This clause refers toalternative line item structuresand does not pertain to cybersecurity or safeguarding FCI.
D. DFARS 252.204-7021:
This clause enforcesCMMC requirementsbut doesnot definebasic safeguarding controls. It requires compliance with CMMC but does not specify the foundational requirements (which come fromFAR 52.204-21for Level 1).
4. Official CMMC 2.0 Reference & Study Guide Alignment
TheCMMC 2.0 model documentationconfirms that Level 1 is focused on the15 practices from FAR 52.204-21.
TheDoD’s official CMMC Assessment Guidefor Level 1 explicitly states that meeting FAR 52.204-21 is therequirement for passing a Level 1 Self-Assessment.
TheCMMC 2.0 Scoping Guideclarifies that contractors handling onlyFCIand seekingLevel 1 certificationmust implementonly FAR 52.204-21security controls.
Final Confirmation:
The correct answer isA. FAR 52.204-21, as it directly governs the basic safeguarding ofFCIand is the foundational requirement for aLevel 1 Self-Assessmentin CMMC 2.0.
A CMMC Assessment is being conducted at an OSC ' s HQ. which is a shared workspace in a multi-tenant building. The OSC is renting four offices on the first floor that can be locked individually. The first-floor conference room is shared with other tenants but has been reserved to conduct the assessment. The conference room has a desk with a drawer that does not lock. At the end of the day, an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?
Review it. print it, and put it in the desk drawer.
Review it, and make notes on the computer provided by the client.
Review it, print it, make notes, and then shred it in cross-cut shredder in the print room.
Review it. print it, and leave it in a folder on the table together with the other documents.
In the context of the Cybersecurity Maturity Model Certification (CMMC) 2.0, particularly at Level 2, organizations are required to implement stringent controls to protect Controlled Unclassified Information (CUI). This includes adhering to specific practices related to media protection and physical security.
Media Protection (MP):
MP.L2-3.8.1 – Media Protection: Organizations must protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. This ensures that sensitive information is not accessible to unauthorized individuals.
Defense Innovation Unit
MP.L2-3.8.3 – Media Disposal: It is imperative to sanitize or destroy information system media containing CUI before disposal or release for reuse. This practice prevents potential data breaches from discarded or repurposed media.
Defense Innovation Unit
Physical Protection (PE):
PE.L2-3.10.2 – Monitor Facility: Organizations are required to protect and monitor the physical facility and support infrastructure for organizational systems. This includes ensuring that areas where CUI is processed or stored are secure and access is controlled.
Defense Innovation Unit
Application to the Scenario:
Given that the Organization Seeking Certification (OSC) operates within a shared, multi-tenant building and utilizes a common conference room for assessments, the following considerations are crucial:
Reviewing the Evidence File: The evidence file, which contains CUI, should be reviewed on a secure, authorized device to prevent unauthorized access or potential data leakage.
Printing the Evidence File: If printing is necessary, ensure that the printer is located in a secure area, and the printed documents are retrieved immediately to prevent unauthorized viewing.
Making Notes: Any notes derived from the evidence file should be treated with the same level of security as the original document, especially if they contain CUI.
Disposal of Printed Materials: After the assessment, all printed materials and notes containing CUI must be destroyed using a cross-cut shredder. Cross-cut shredding ensures that the information cannot be reconstructed, thereby maintaining confidentiality.
totem.tech
Options A and D are inadequate as they involve leaving sensitive information in unsecured locations, which violates CMMC physical security requirements. Option B, while secure in terms of digital handling, does not address the proper disposal of any physical copies that may have been made. Therefore, Option C is the best practice, aligning with CMMC 2.0 guidelines by ensuring that all physical media containing CUI are properly reviewed, securely stored during use, and thoroughly destroyed when no longer needed.
The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections. How should the team score practices in which the evidence shows the deficiencies have been corrected?
MET
POA & M
NOT MET
NOT APPLICABLE
Understanding the CMMC Assessment Process (CAP) Phases
TheCMMC Assessment Process (CAP)consists ofthree primary phases:
Phase 1 - Planning(Pre-assessment activities)
Phase 2 - Conducting the Assessment(Evidence collection and analysis)
Phase 3 - Reporting and Finalizing Results
DuringPhase 3, the Assessment Teamreviews evidenceto confirm if anyLimited Practice Deficiency Correctionshave been successfully implemented.
Scoring Practices in Phase 3
The CAP document specifies that a practice can bescored as METif:
✅The deficiency identified in Phase 2 has been fully corrected before final scoring.
✅Sufficient evidence is provided to demonstrate compliance with the CMMC requirement.
✅The correction is notmerely plannedbutfully implemented and validatedby the assessors.
Since the evidence shows thatdeficiencies have been corrected, the correct score isMET.
Why the Other Answers Are Incorrect
B. POA & M (Plan of Action & Milestones)
❌Incorrect. APOA & M (Plan of Action and Milestones)is usedonly when a deficiency remains unresolved. Since the deficiency is already corrected, this option does not apply.
C. NOT MET
❌Incorrect. A practice is scoredNOT METonly if the deficiency hasnotbeen corrected by the end of the assessment.
D. NOT APPLICABLE
❌Incorrect. A practice is markedNOT APPLICABLE (N/A)only if it doesnot apply to the organization’s environment, which is not the case here.
CMMC Official References
CMMC Assessment Process (CAP) Document– Defines scoring criteria for MET, NOT MET, and POA & M.
Thus,option A (MET) is the correct answer, as the deficiencies have been corrected before final scoring.
Copyright © 2014-2026 Certensure. All Rights Reserved