CMMC practice MA.L2-3.7.3 - Equipment Sanitization requires organizations to sanitize equipment leaving their facilities for off-site maintenance for CUI. What standard would the OSC use to sanitize various media?
Correct Answer: B
Comprehensive and Detailed In-Depth Explanation: MA.L2-3.7.3 mandates "sanitizing equipment for CUI prior to off-site maintenance."NIST SP 800-88 - Guidelines for Media Sanitization(B) provides specific methods (e.g., clearing, purging, destroying) tailored to media types, ensuring CUI is irrecoverable-directly supporting this practice. NIST SP 800-53 (A) is a broader control framework, NIST SP 800-171 (C) defines CMMC requirements without sanitization details, and NIST SP 800-171A (D) is an assessment guide, not a sanitization standard. The CMMC guide references NIST SP 800-88 explicitly. Extract from Official CMMC Documentation: * CMMC Assessment Guide Level 2 (v2.0), MA.L2-3.7.3: "Sanitize per NIST SP 800-88 guidelines." * NIST SP 800-171A, 3.7.3: "Refer to NIST SP 800-88 for sanitization standards." Resources: * https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2. 0_FINAL_202112016_508.pdf
Question 92
Prior to starting an assessment, an OSC must develop a data flow diagram. This diagram can then be used as a tool to help establish the context and boundaries of the CMMC assessment activities. What is critical to capture while developing the data flow diagram?
Correct Answer: D
Comprehensive and Detailed in Depth Explanation: The CMMC Assessment Guide Level 2 requires data flow diagrams to map CUI flows, identifying business processes, subprocesses, and supporting systems/assets to define assessment scope. Option A (network topology) is secondary to data flow. Option B (employees) and Option C (physical layout) are unrelated to logical data mapping. Option D is critical per CMMC guidance, making it the correct answer. Reference Extract: * CMMC AG Level 2, Section 1.3:"Data flow diagrams capture processes, subprocesses, and systems handling CUI."Resources:https://dodcio.defense.gov/Portals/0/Documents/CMMC /AG_Level2_MasterV2.0_FINAL_202112016_508.pdf
Question 93
A defense contractor retains your services to assess their information systems for CMMC compliance, particularly configuration management. The contractor uses CFEngine 3 for automated configuration and maintenance of its computer systems and networks. While chatting with the network's system admins, you realize they have deployed a modern compliance checking andmonitoring tool. However, when examining their configuration management policy, you notice the contractor uses different security configurations than those recommended by product vendors. The system administrator informs you they do this to meet the minimum configuration baselines required to achieve compliance and align with organizational policy. When examining the contractor's security configuration checklists, which of the following parameters are you not likely to find?
Correct Answer: A
Comprehensive and Detailed In-Depth Explanation: CM.L2-3.4.2 involves "enforcing security configuration settings." Checklists typically include technical parameters like permissions (B), protocols (C), and network settings (D), per CMMC guidance. Assessment readiness status (A) is an administrative metric, not a config setting, and belongs in a CA-RR checklist, not security configs. Extract from Official CMMC Documentation: * CMMC Assessment Guide Level 2 (v2.0), CM.L2-3.4.2: "Checklists include permissions, protocols, network settings; readiness status separate." * NIST SP 800-171A, 3.4.2: "Examine technical config parameters." Resources: * https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2. 0_FINAL_202112016_508.pdf
Question 94
A mid-sized defense supplier has been working to achieve CMMC Level 2 certification. You are part of the Assessment Team contracted to review their documentation and assess their implementation of CMMC practices. During your review, you notice that the OSC has produced documentation for their contractor risk- managed assets. Which of the following is NOT required documentation for contractor risk-managed assets under the CMMC model?
Correct Answer: B
Comprehensive and Detailed Explanation: Contractor Risk Managed Assets (CRMAs) are assets that can but are not intended to process, store, or transmit CUI due to implemented security policies. The CMMC Assessment Scope - Level 2 requires CRMAs to be documented in the Asset Inventory, Network Diagram, and SSP todemonstrate compliance and risk management. Separation methodology, however, applies to out-of-scope assets to prove isolation from the CUI environment, not CRMAs, which are in scope and managed by the OSC's policies. Thus, B is not required for CRMAs. Reference: CMMC Assessment Scope - Level 2, Section 2.3.2 (CRMAs), p. 5: "CRMAs must be documented in the Asset Inventory, Network Diagram, and SSP." Section 2.3.5 (Out-of-Scope Assets), p. 7: "Separation methodology applies to out-of-scope assets."
Question 95
During your assessment of Defcon's (a contractor) implementation of CMMC Level 2 practices, you notice that their system for displaying security and privacy notices is insufficient. The banners currently in use lack detailed information about Controlled Unclassified Information (CUI)handling requirements and associated legal implications. Additionally, the banners are not consistently displayed across all contractor systems and workstations. Moreover, the banners on login pages disappear automatically after less than 5 seconds, providing insufficient time for users to read and acknowledge the content. Once the inconsistencies are addressed, when should the contractor's privacy and security notice be displayed?
Correct Answer: B
Comprehensive and Detailed In-Depth Explanation: AC.L2-3.1.9 requires "privacy and security notices consistent with applicable CUI rules" to be displayed at logon and when accessing CUI-related resources. Displaying notices only at logon (A) misses ongoing access points, while limiting to export-controlled data (C) is too narrow. Continuous display (D) is impractical and not required. The CMMC guide specifies initial logon and secondary notifications for CUI applications, ensuring users are reminded of obligations at key interaction points. Extract from Official CMMC Documentation: * CMMC Assessment Guide Level 2 (v2.0), AC.L2-3.1.9: "Display notices at logon and when accessing CUI-related applications." * NIST SP 800-171A, 3.1.9: "Examine notices at initial logon and secondary access points." Resources: * https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2. 0_FINAL_202112016_508.pdf