Question 36

As a CCA on a C3PAO Assessment Team, you have determined that the assessment scope provided by an OSC indicates plans to subcontract some elements of their contract to DelTech Inc. The OSC plans to bid on a DoD contract to develop guidance and targeting software. However, the software needs testing after installing a new surface-to-air defense system. Unfortunately, the OSC lacks themeans to test the software, which is where DelTech comes in. As a CCA, what must you do in this scenario?
  • Question 37

    An OSC is undergoing CMMC Assessment on an enterprise-wide basis. While walking to the conference room, the Assessor notices a printer repair technician in the hallway, unescorted, repairing a printer marked
    "Authorized for CUI printing." What is the NEXT step the Lead Assessor should take regarding PE.L2-
    3.10.3: Escort Visitors?
  • Question 38

    During scoping discussions with a Lead Assessor, the OSC mentions that there are several connected systems within the organization's network. How should an OSC consider security tools in a CMMC Assessment Scope?
  • Question 39

    The OSC has not implemented cryptographic mechanisms to prevent unauthorized disclosure of CUI during transmission, citing the use of alternative physical safeguards.
    Which of the following is NOT an alternative physical safeguard in this scenario?
  • Question 40

    An OSC can use either of the following strategies to meet the requirements of CMMC practice MP.L2-3.8.8 - Shared Media, EXCEPT?