CMMC-CCA Exam Questions & Answers
Certified CMMC Assessor (CCA) Exam • Cyber AB
100% money-back guarantee
Sample CMMC-CCA Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
What should the Lead Assessor do to BEST ensure the evidence supplied effectively meets the intent of the standard for a practice?
The CAP defines evidence evaluation requirements. Evidence must not only exist but must also be:
Complete (addresses all assessment objectives for the practice)
Validated (verified by the assessor)
Mapped to the practice requirements (traceable to objectives)
Extract:
''The assessor must confirm that the evidence is complete, validated, and mapped directly to the practice requirements in order to conclude that a practice is MET.''
An OSC has a hardware and software list used to manage company assets. Which is the BEST evidence to show the OSC is managing the system baseline?
System baselines are part of Configuration Management (CM). Maintaining an inventory of hardware and software is important, but the evidence of managing baselines lies in the configuration management process, which establishes and documents standard system configurations, approved software, and change control. The CMMC practice CM.L2-3.4.1 requires the OSC to establish and maintain baseline configurations.
Exact extracts:
''Baseline configurations are documented, formally reviewed, and maintained as part of configuration management.''
''Assessment Objectives ... Determine if: baseline configurations are established; baseline configurations are maintained.''
''Potential Assessment Methods -- Examine: configuration management policy; documented baseline configuration; inventory of system components.''
Expanded explanation:
Hardware/software lists show what exists, but without baseline control they do not demonstrate effective management.
Configuration management evidence includes: CM policies, baselines for operating systems, software versions, patch levels, and configuration checklists.
This ensures that unauthorized changes or unapproved software do not deviate from the security posture.
Why the other options are incorrect:
A (Media protection): Relates to storage devices and handling, not baselines.
B (Physical protection): Relates to facility and hardware security, not configuration.
D (Identification and authentication policy): Addresses user access, not baseline configuration.
CMMC Assessment Guide -- Level 2, CM.L2-3.4.1 ''Establish and Maintain Baseline Configurations.''
NIST SP 800-171 Rev. 2, 3.4.1.
An OSC seeking Level 2 certification is reviewing the physical security of their building. Currently, the building manager unlocks and locks the doors for business operations. The OSC would like the ability to automatically unlock the door for authorized personnel, track access individually, and maintain access history for all personnel. The BEST approach is for the OSC to:
CMMC Level 2 requires the ability to control and monitor physical access to systems and facilities containing CUI. The best practice is a badge-based access control system, which provides individual accountability, access tracking, and historical audit records. Keys and keypads do not provide individual traceability. Cameras alone do not prevent unauthorized entry.
Exact Extracts (official CMMC Assessor/Study documents):
PE.L2-3.10.1: ''Limit physical access to organizational systems, equipment, and the respective operating environments to authorized individuals.''
PE.L2-3.10.3: ''Escort visitors and monitor visitor activity.''
PE.L2-3.10.5: ''Access records must be maintained.''
CMMC Assessment Guide clarifies that acceptable methods include badging systems with individual accountability for traceability.
Why the other options are not correct:
A (keys): Keys do not provide audit logs or individual accountability.
B (cameras): Monitoring alone is insufficient; prevention and control are required.
D (keypads): Shared codes do not provide unique traceability or access history per user.
CMMC Assessment Guide -- Level 2, Version 2.13: PE.L2 practices (pp. 153--159).
NIST SP 800-171A, Physical and Environmental Protection (PE) assessment objectives.
An OSC processes data in its owned data center. The data center includes a very early smoke detection apparatus (VESDA). The apparatus only captures log information from its sensors around the data center. It is not intended, nor capable of, processing CUI. The VESDA is on a separate VLAN and is in a separate locked room in the data center.
Should the assessor agree that the VESDA is out-of-scope?
The CMMC Scoping Guidance allows assets to be classified as Out-of-Scope if:
They are physically/logically isolated, and
They cannot process, store, or transmit CUI.
Extract:
''Out-of-Scope assets are those that cannot process, store, or transmit CUI and are physically or logically separated from CUI assets.''
The VESDA system only monitors environmental conditions and does not interact with CUI. Its segregation supports an out-of-scope classification.
The audit team is discussing the OSC's Risk Managed Assets. For these types of assets, the contractor need NOT:
Risk Managed Assets are not assessed against CMMC practices, but OSCs must demonstrate that they are identified and that the risk they pose to CUI is managed in accordance with organizational policies. The Scoping Guide specifies that these assets must be addressed in pre-assessment discussions and described in the scope diagram, but they are explicitly excluded from practice-by-practice assessment.
Exact extracts:
''Risk Managed Assets do not process, store, or transmit CUI but can access CUI Assets. These assets are not assessed against CMMC practices but must be discussed with the assessor.''
''Organizations must identify how these assets are managed by organizational policies.''
''Risk Managed Assets must be included in scope diagrams.''
Why the other options are incorrect:
A/B/D: Risk Managed Assets still must be documented, discussed, and managed with policies.
C: They are explicitly excluded from practice assessment.
Reference (CCA documents / Study Guide):
CMMC Assessment Scope -- Level 2 Scoping Guide (Risk Managed Assets).
Get access to all 150 verified questions with detailed answers.
Unlock All CMMC-CCA Questions