Cyber AB CCA - CMMC Certified Assessor Exam

Question #1 (Topic: Exam A)
The assessor begins the assessment by meeting with the client's stakeholders and learns that multiple subsidiaries exist. In order to perform a complete assessment, the assessor must review documents from multiple entities as multiple, corresponding Commercial and Government Entities codes were provided. Which of the following entities may receive certification as a result of this assessment?
A. HQ Organization B. Host Unit and Supporting Organizations/Units C. HQ Organization and Host Unit D. HQ Organization, Host Unit, and Supporting Organizations/Units
Answer: A
Question #2 (Topic: Exam A)
ESPs are exceptionally common today, given that many organizations are turning to secure cloud offerings to establish and maintain compliance. Integral to these relationships is a responsibility matrix, which defines who is responsible for specific items such as security. This can be a very complex assortment of taskings associated with cybersecurity and federal compliance, but what is the MOST important thing to remember?
A. The relationship of an OSC with an ESP is a partnership and the CMMC Assessment will evaluate the ESP at the same time as the OSC. B. Only the OSC is being assessed for compliance, and while the ESP may have a number of responsibilities in the matrix, the OSC is ultimately responsible for meeting the requirements as specified by government mandates. C. The CMMC Assessment Team will factor in any documentation provided by the ESP when evaluating the OSC for compliance. D. The ESP is technically not part of the DIB and has no responsibility to be CMMC compliant in its own right.
Answer: B
Question #3 (Topic: Exam A)
Does CMMC Level 2 require that a Cloud Service Provider (CSP) hold a FedRAMP HIGH authorization hosted in a government community cloud (GCC)?
A. No. The CSP can obtain a FedRAMP MODERATE equivalency. B. Yes. FedRAMP HIGH authorization demonstrates the CSP compliance with NIST SP 800-53 and SP 800-171 control requirements. C. Yes. FedRAMP HIGH is required for CUI data controls due to the sensitive nature of the Defense Industrial Base systems. D. No. The CSP must hold a FedRAMP MODERATE authorization.
Answer: A
Question #4 (Topic: Exam A)
An OSC seeking Level 2 certification is looking to migrate to a fully cloud-based environment. The organization would like to select a Cloud Service Provider (CSP) that can share responsibilities for CMMC Level 2 requirements. Assume that both CSPs can equally provide the technical capabilities and business value required by the business process.
CSP A has SOC 2 certification and is California Consumer Privacy Act and Health Insurance Portability and Accountability Act (HIPAA) compliant.
CSP B has SOC 2 and FedRAMP MODERATE certifications.
Based on this information, which CSP is MOST LIKELY to be acceptable?
A. Both CSP A and B B. CSP B C. Neither CSP A nor B D. CSP A
Answer: B
Question #5 (Topic: Exam A)
An OSC uses an ESP to provide components of the OSC's CUI processing scope. The OSC has chosen an accredited ESP that is FedRAMP MODERATE authorized. The OSC has a contract with the ESP that requires them to provide security that meets the OSC security requirements. The ESP has given the OSC a copy of its shared responsibility matrix that coincides with the contract terms. When assessing the assets within the assessment scope, which should the assessor MOST carefully review?
A. The ESP's FedRAMP MODERATE authorization to ensure that the OSC's CMMC Level 2 requirements are MET, and the shared responsibility matrix to ensure that the shared responsibilities are well defined B. The ESP's FedRAMP MODERATE authorization to ensure that the OSC's CMMC Level 2 requirements are MET, and the shared responsibility matrix to ensure that the ESP’s responsibilities are well defined C. The contract terms to ensure that the OSC's CMMC Level 2 requirements are in the contract, and the shared responsibility matrix to ensure that the shared responsibilities are well defined D. The contract terms to ensure that the OSC's CMMC Level 2 requirements are in the contract, and the shared responsibility matrix to ensure that the ESP's responsibilities are well defined
Answer: A
Download Exam
Page: 1 / 30
Total 150 questions