As a part of this presentation, which document MUST include the attendee list, time/date, location/meeting link, results from all discussed topics, including any resulting actions, and due dates from the OSC or Assessment Team?

During an assessment, the Lead Assessor reviews the evidence for each CMMC in-scope practice that has been reviewed, verified, rated, and discussed with the OSC during the daily reviews. The Assessment Team records the final recommended MET or NOT MET rating and prepares to present the results to the assessment...

February 21, 2025 No Comments READ MORE +

When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?

When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?A . When under the control of the DoDB . When the document is considered secretC . When a document is being shared outside of the organizationD . When a derivative document's...

February 18, 2025 No Comments READ MORE +

Which certified individual should they approach for implementation support?

An organization that manufactures night vision cameras is looking for help to address the gaps identified in physical access control systems. Which certified individual should they approach for implementation support?A . CCA of the C3PAO performing the assessmentB . RP of an organization not part of the assessmentC . Practitioner...

February 17, 2025 No Comments READ MORE +

For this company's CMMC Level 1 Self-Assessment, how should the assets supporting the commercial services division be categorized?

A company has a government services division and a commercial services division. The government services division interacts exclusively with federal clients and regularly receives FCI. The commercial services division interacts exclusively with non-federal clients and processes only publicly available information. For this company's CMMC Level 1 Self-Assessment, how should the...

February 12, 2025 No Comments READ MORE +

Who is responsible for verifying this request?

During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?A . CCPB . C3PAOC . Lead AssessorD . Advisory BoardView AnswerAnswer: C

February 12, 2025 No Comments READ MORE +

Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse.

Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse. After a thorough review, the CCP tells the...

February 7, 2025 No Comments READ MORE +

Which function BEST describes what the printer does with the FCI?

A dedicated local printer is used to print out documents with FCI in an organization. This is considered an FCI Asset. Which function BEST describes what the printer does with the FCI?A . EncryptB . ManageC . ProcessD . DistributeView AnswerAnswer: C

February 6, 2025 No Comments READ MORE +

What is the MINIMUM number of practices that must be scored as MET to initiate this course of action?

A C3PAO has completed a Limited Practice Deficiency Correction Evaluation following an assessment of an OSC. The Lead Assessor has recommended moving deficiencies to a POA&M. but the OSC will remain on an Interim Certification. What is the MINIMUM number of practices that must be scored as MET to initiate...

February 1, 2025 No Comments READ MORE +

When assessing an OSC for CMMC: the Lead Assessor should use the information from the Discussion and Further Discussion sections in each practice because it:

When assessing an OSC for CMMC: the Lead Assessor should use the information from the Discussion and Further Discussion sections in each practice because it:A . is normative for an OSC to follow.B . contains examples that an OSC must implement.C . is mandatory and aligns with FAR Clause 52.204-21.D...

January 31, 2025 No Comments READ MORE +

What is the ESP employee considered?

In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?A . In scopeB . Out of scopeC . OSC point of contactD . Assessment Team MemberView AnswerAnswer: A

January 26, 2025 No Comments READ MORE +