Cyber AB CCA - CMMC Certified Assessor Exam
Page: 2 / 30
Total 150 questions
Question #6 (Topic: Exam A)
The OSC POC has prepared evidence from an internal pre-assessment for the C3PAO in preparation for a third-party assessment. The OSC POC has identified that there are several ESPs involved in protecting the security of the infrastructure. While reviewing the pre-assessment documentation regarding ESPs. the Lead Assessor will be looking for items that are:
A. noted as inherited.
B. marked as requiring a waiver.
C. marked as NOT APPLICABLE.
D. noted as partially implemented.
Answer: A
Question #7 (Topic: Exam A)
A company receives data that they suspect are CUI but are not marked as such. What is an acceptable way for the company to handle unmarked potential CUI?
A. Have a procedure for proper handling of unlabeled data.
B. Have a procedure for deleting unlabeled data.
C. If data are not marked, then they are not CUI.
D. Treat all data as CUI even if not marked.
Answer: A
Question #8 (Topic: Exam A)
A CCA is conducting an interview with an OSC team member about an offering from a well-known Cloud Service Provider (CSP). The offering is known to be secure, but the OSC has not provided evidence and the person being interviewed is unsure how the offering works. Will this offering be accepted by the Assessment Team?
A. Yes, because of the process of reciprocity
B. No, because the OSC lacks adequate and sufficient evidence
C. Yes, because the CSP offering is a well-known, secure offering
D. No, because the OSC failed to train on the offering
Answer: B
Question #9 (Topic: Exam A)
An OSC seeking Level 2 certification has a fully cloud-based environment. The assessor must evaluate the fulfillment of Level 2 requirements the OSC needs to implement versus the Level 2 requirements that are handled by their cloud service provider. Which document would be the BEST to identify the Level 2 requirements handled by the organization's cloud service provider?
A. Shared responsibility matrix
B. Cloud security baseline white paper
C. Identity and access management (IAM) plan
D. Zero trust architecture
Answer: A
Question #10 (Topic: Exam A)
A cloud-native OSC uses a popular vendor’s FedRAMP MODERATE authorized cloud environment for all aspects of their business’s CUI needs (identity, email, file storage, office suite, etc.) as well as the vendor’s locally installable applications. The OSC properly configured the vendor’s cloud-based SIEM system to monitor only aspects of the cloud environment. Additionally, the OSC’s SSP details the SI.L2-3.14.7: Identify Unauthorized Use practice by defining authorized system use and references the procedures for identifying unauthorized use. How should the Certified Assessor score this practice?
A. MET because the cloud SIEM is configured to monitor all of the vendor’s cloud environment
B. NOT MET because logs from physical infrastructure are not captured by the SIEM
C. MET because being cloud-native is a great way to contain risk to a vendor’s environment
D. NOT MET because locally installable applications from a cloud-native environment are not allowed
Answer: A