An assessor is examining an organization's system maintenance program. While reviewing the system maintenance policy and the OSC's maintenance records for the CUI network, the assessor notices there is no mention of printers. The assessor asks the IT manager if the company has any printers. Why is the assessor concerned if the OSC has printers?
Correct Answer: D
Printers are a concern because they can produce hard copies of CUI, which must be safeguarded like digital CUI. CUI handling requirements extend to both electronic and printed media. Extract from MP.L2-3.8.4: "Protect the confidentiality of CUI at rest and in use, including hardcopy outputs such as printed material." Thus, the concern is that printed CUI must be protected, making printers relevant to maintenance and safeguarding practices. Reference: CMMC Assessment Guide - Level 2, MP Domain.
Question 37
The OSC has assembled its documentation relating to how it controls remote access for assessment. The Lead Assessor compared this documentation to the provided topology map and noted several indications of external connections with External Service Providers (ESPs). Which document is MOST LIKELY to show acceptable evidence of the security controls related to the interface between the OSC and the ESP?
Correct Answer: B
* Applicable Requirement (CMMC/NIST): Multiple practices may apply (e.g., AC.L2-3.1.14 "Control remote access sessions" and CA.L2-3.12.4 "Develop, document, and periodically update system security plans"). However, when an OSC uses an External Service Provider (ESP), the key control is the documented agreement defining the terms, conditions, and responsibilities between the OSC and the ESP. * Why Interconnection Agreement is Correct (supports B): * According to the CMMC Assessment Guide (Level 2), acceptable evidence for external connections with ESPs includes "interconnection security agreements, memoranda of understanding, or contracts that define the security requirements governing the connection." * These agreements document controls at the interface boundary and ensure both parties understand their responsibilities for protecting CUI. * Why Other Options Are Insufficient: * A. OSC's access control policy - An internal policy outlines organizational expectations, but it does not constitute binding evidence of controls at the boundary with an ESP. * C. Technical design of VPN security - Technical configurations demonstrate how connections are secured, but they do not formally document agreed security requirements between OSC and ESP. * D. Instructions from ESP - ESP-provided setup instructions are not evidence of the OSC's validated control implementation or responsibility-sharing agreement. * Assessment Process Alignment: * The CMMC Assessment Process (CAP) requires assessors to confirm not only technical implementations but also documented agreements that establish accountability for safeguarding CUI. * Evidence such as interconnection agreements is specifically highlighted as objective evidence that the OSC has verified and controlled external system interfaces. References (CCA Official Sources): * CMMC Assessment Guide - Level 2, Version 2.13 - External Service Providers and Evidence Requirements for External Connections * NIST SP 800-171 Rev. 2 - §3.1.20 and §3.13.6 (discussions on external system connections and interconnection agreements) * NIST SP 800-171A - Assessment Methods for verifying security of external system interfaces
Question 38
In order to assess whether an OSC meets AC.L2-3.1.5: Least Privilege, what should be examined by the Assessor?
Correct Answer: C
The requirement of least privilege mandates that users be granted only the access necessary to perform their duties. Assessors confirm compliance by reviewing user access lists, ensuring privileged access is limited, documented, and assigned only where required. Exact Extracts: * AC.L2-3.1.5: "Employ the principle of least privilege, including for specific security functions and privileged accounts." * Assessment Guide: "Evidence includes user access lists, role-based access assignments, and documentation of privileged accounts." * NIST SP 800-171A Objective: "Examine system access lists, rights, and permissions for least privilege." Why other options are not correct: * A (Authentication policy): Pertains to verifying identity, not enforcing least privilege. * B (System configurations): Provide technical settings, but access lists are the primary evidence for least privilege. * D (Terminated employees list): Tied to AC.L2-3.1.2 (Access enforcement) and AC.L2-3.1.7 (Account management), not least privilege. References: CMMC Assessment Guide - Level 2, Version 2.13: AC.L2-3.1.5 (pp. 17-19). NIST SP 800-171A: Assessment procedures for least privilege.
Question 39
As a Lead Assessor, you are in contact with the OSC Assessment Official. The Assessment Official has submitted a document that outlines the scope of your assessment engagement. You expect to find all the following elements on the Assessment Scope document, EXCEPT?
Correct Answer: C
Comprehensive and Detailed Explanation: The CMMC Assessment Scope - Level 2 requires the scope document to detail boundaries (Option A), storage locations (Option B), and network/enclave specifics (Option D) to define the assessment environment. The CEO's name (Option C) is not required unless they have a direct CUI protection role, which is not typical. C is the exception. Reference: CMMC Assessment Scope - Level 2, Section 2.2 (Scope Documentation), p. 4: "Scope includes boundaries, storage, and networks, not personal identifiers unless relevant."
Question 40
A CCA is conducting a CMMC assessment and discovers that the OSC's evidence includes a policy that contradicts a practice's objectives (e.g., allowing unrestricted access when restricted access is required). The OSC claims it's a typo and the practice is followed correctly. How should the CCA proceed?
Correct Answer: B
Comprehensive and Detailed in Depth Explanation: The CAP requires documenting contradictions as gaps and assessing all evidence (Option B). Option A lacks verification, Option C is premature, and Option D is consulting. Extract from Official Document (CAP v1.0): * Section 2.2 - Conduct Assessment (pg. 25):"Document contradictions between policy and practice as evidence gaps and assess based on implementation." References: CMMC Assessment Process (CAP) v1.0, Section 2.2.