Question 81

An OSC undergoing a CMMC Level 2 assessment has provided a detailed System Security Plan (SSP) and supporting evidence. During the assessment, you notice that the SSP references a practice as being fully implemented, but interviews with staff reveal that the practice is not consistently followed. How should the Lead Assessor proceed?
  • Question 82

    A company mirrors its FCI/CUI data storage in a cloud environment. Data is managed across multiple virtual machines (VMs). To satisfy requirements for data security of the LOCAL copy using physical controls, what should the OSC do?
  • Question 83

    CMMC practice SC.L2-3.13.6 assessment objectives [a] and [b] require contractors' systems to deny network communications traffic by default [a] and allow network communications traffic by exception [b] respectively. As a CCA, you assess whether an OSC has segmented its network into different zones. The OSC has implemented Access Control Lists (ACLs) on its network devices to permit or deny traffic based on source and destination IP addresses and ports. Additionally, the OSC uses a Fortinet Next-Generation Firewall (NGFW). To monitor their computing environment, theOSC uses a state-of-the-art SIEM. Which of the following assessment methods is NOT a method you would use to assess whether the OSC has met assessment objectives [a] and [b]?
  • Question 84

    To meet AC.L2-3.1.5: Least Privilege, the following procedure is established:
    * All employees are given a basic (non-privileged) user account.
    * System Administrators are given a separate System Administrator account.
    * Database Administrators are given a separate Database Administrator account.
    Which steps should be added to BEST meet all of the standards for least privilege?
  • Question 85

    A Lead Assessor is preparing to conduct a Level 2 Assessment for an OSC. During the planning phase, the Lead Assessor and OSC have:
    * Developed evidence collection approach;
    * Identified the team members, resources, schedules, and logistics;
    * Identified and managed conflicts of interest;
    * Gained access to the OSC's relevant documentation.
    Based on the information provided, which would be an additional element to be discussed during the planning phase of the assessment?