Is this sufficient to pass the practice?

An Assessment Team is reviewing a practice that is documented and being checked monthly. When reviewing the logs, the practice is only being completed quarterly. During the interviews, the team members say they perform the practice monthly but only document quarterly. Is this sufficient to pass the practice?A . No,...

March 8, 2025 No Comments READ MORE +

For a Level 1 Self-Assessment, what type of asset is this?

A machining company has been awarded a contract with the DoD to build specialized parts. Testing of the parts will be done by the company using in-house staff and equipment. For a Level 1 Self-Assessment, what type of asset is this?A . CUI AssetB . In-scope AssetC . Specialized AssetD...

March 6, 2025 No Comments READ MORE +

Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?

Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?A . Level 1B . Level 2C . Level 3D . All levelsView AnswerAnswer: A

March 5, 2025 No Comments READ MORE +

Which document stipulates these reporting requirements?

Prior to initiating an OSC's CMMC Assessment, the Lead Assessor briefed the team on the most important requirements of the assessment. The assessor also insisted that the same results of the findings summary, practice ratings, and Level recommendations must be submitted to the C3PAO for initial processes and review. After...

March 4, 2025 No Comments READ MORE +

During the assessment process, who is the final interpretation authority for recommended findings?

During the assessment process, who is the final interpretation authority for recommended findings?A . C3PAOB . CMMC-ABC . OSC sponsorD . Assessment Team MembersView AnswerAnswer: D

March 4, 2025 No Comments READ MORE +

Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?

Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?A . Access Control (AC)B . Media Protection (MP)C . Asset Management (AM)D . Configuration Management (CM)View AnswerAnswer: D

March 1, 2025 No Comments READ MORE +

Which resource contains authoritative data classifications of CUI?

Which resource contains authoritative data classifications of CUI?A . NARAB . CMMC-ABC . DoD Contractors FAQD . OSC's privacy policiesView AnswerAnswer: A

February 27, 2025 No Comments READ MORE +

Which MINIMUM Level of certification must a contractor successfully achieve to receive a contract award requiring the handling of CUI?

Which MINIMUM Level of certification must a contractor successfully achieve to receive a contract award requiring the handling of CUI?A . Level 1B . Level 2C . Level 3D . Any levelView AnswerAnswer: A

February 26, 2025 No Comments READ MORE +

Which document is the BEST source for determining the sources of evidence for a given practice?

Which document is the BEST source for determining the sources of evidence for a given practice?A . NISTSP 800-53B . NISTSP 800-53AC . CMMC Assessment ScopeD . CMMC Assessment GuideView AnswerAnswer: B

February 25, 2025 No Comments READ MORE +

What can this file cabinet BEST be determined to be?

In scoping a CMMC Level 1 Self-Assessment, all of the computers and digital assets that handle FCI are identified. A file cabinet that contains paper FCI is also identified. What can this file cabinet BEST be determined to be?A . In scope, because it is an asset that stores FCIB...

February 24, 2025 No Comments READ MORE +