CMMC-CCP Exam Questions & Answers
Certified CMMC Professional (CCP) Exam • Cyber AB
100% money-back guarantee
Sample CMMC-CCP Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
What type of criteria is used to answer the question "Does the Assessment Team have the right evidence?"
According to the CMMC Assessment Process (CAP), specifically during the Phase 3: Conduct Assessment (Evidence Collection and Verification), the Assessment Team must evaluate all collected artifacts, interview notes, and test results against two primary dimensions: Adequacy and Sufficiency.
Adequacy (The 'Right' Evidence): This criterion focuses on the quality, relevance, and validity of the evidence. It addresses whether the evidence actually maps to the specific CMMC practice being assessed and whether it is authoritative (e.g., signed, current, and from a trusted source). If an assessor asks, 'Is this therightpiece of information to prove this practice is met?' they are testing for Adequacy.
Sufficiency (The 'Enough' Evidence): This criterion focuses on the quantity and scope of the evidence. It addresses whether the Assessment Team has collected enough data points (across the required number of assets and using the required methods of Examine, Interview, and Test) to reach a confident conclusion. If an assessor asks, 'Do I haveenoughexamples of this practice in action across the entire enclave?' they are testing for Sufficiency.
Why other options are incorrect:
B and D (Objectivity/Subjectivity): While assessors must remain objective, these are not the formal 'criteria' used to categorize the evidence collection quality within the CAP framework.
C (Sufficiency): As noted above, Sufficiency is about theamountof evidence, not whether it is thecorrect type(the 'right' evidence).
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section 3.4, 'Collect and Verify Evidence,' which explicitly defines the requirement for evidence to be both adequate and sufficient.
CMMC Level 2 Assessment Guide: Guidance on the application of the Examine, Interview, and Test (E-I-T) methods to ensure evidence quality.
NIST SP 800-171A: The foundation for CMMC assessment procedures, which emphasizes the need for relevant (adequate) evidence to support findings.
Within how many days from the Assessment Final Recommended Findings Brief should the Lead Assessor and Assessment Team Members, if necessary, review the accuracy and validity of (he OSC's updated POA&M with any accompanying evidence or scheduled collections?
In theCMMC 2.0 Assessment Process, after theAssessment Final Recommended Findings Brief, theLead Assessor and Assessment Team Membersmustreview the accuracy and validity of the Organization Seeking Certification (OSC)'s updated Plan of Action & Milestones (POA&M) and any accompanying evidence or scheduled collectionswithin180 days.
Relevant CMMC 2.0 Reference:
TheCMMC Assessment Process (CAP)outlines that organizations haveup to 180 daysto address identifieddeficienciesafter their initial assessment.
During this time, the OSC can update itsPOA&M with additional evidenceto demonstrate compliance.
Why is the Correct Answer 180 Days (B)?
A . 90 days Incorrect
The CMMC CAP does not impose a90-day limiton POA&M updates; instead,180 daysis the standard timeframe.
B . 180 days Correct
PerCMMC Assessment Process guidelines, theLead Assessor and Teammust review updateswithin 180 days.
C . 270 days Incorrect
No official CMMC documentation mentions a270-dayreview period.
D . 360 days Incorrect
The process must be completedfar sooner than 360 daysto maintain compliance.
CMMC 2.0 Reference Supporting this Answer:
CMMC Assessment Process (CAP) Document
Defines the180-day windowfor the OSC to update itsPOA&M and submit evidencefor review.
CMMC 2.0 Official Guidelines
Specifies that organizations are givenup to 180 daysto remediate deficiencies before reassessment.
Which document is the BEST source for determining the sources of evidence for a given practice?
TheCMMC Assessment Guideis the best source for determining the sources of evidence for a given practice because it provides specific guidance on how organizations should implement and demonstrate compliance with CMMC practices. Each CMMC level has its own assessment guide (e.g.,CMMC Assessment Guide -- Level 1, Level 2), detailing expected evidence and assessment procedures.
Detailed Justification:
CMMC Assessment Guide (Primary Source for Evidence)
TheCMMC Assessment Guideexplicitly outlines the evidence required to verify compliance with each practice.
It provides detailed instructions on assessment objectives, clarifying what assessors should look for when determining compliance.
The guide breaks down each practice intoassessment objectives, helping organizations prepare appropriate documentation and artifacts.
Other Documents and Why They Are Not the Best Choice:
NIST SP 800-53 (Option A)
WhileNIST SP 800-53provides a comprehensive catalog of security and privacy controls, it does not focus on CMMC-specific evidence requirements.
It serves as a foundational cybersecurity framework but does not define the specific artifacts required for CMMC assessment.
NIST SP 800-53A (Option B)
NIST SP 800-53Aprovides guidance on assessing security controls but is not tailored to the CMMC framework.
It includes general control assessment procedures, but theCMMC Assessment Guideis more precise in defining the evidence needed for CMMC compliance.
CMMC Assessment Scope (Option C)
TheCMMC Assessment Scopedocument outlines which systems, assets, and processes are subject to assessment.
While important for defining boundaries, it does not provide details on specific evidence requirements for each practice.
Reference from Official CMMC Documents:
CMMC Assessment Guide (Level 2) -- Section on 'Assessment Objectives'
This document details how evidence is collected and evaluated for each CMMC practice.
Example: ForAC.L2-3.1.1 (Access Control -- Limit System Access), the guide specifies that assessors should verify documented policies, system configurations, and audit logs.
CMMC Model Overview (Official DoD Documents)
Emphasizes thatCMMC Assessment Guidesare the official reference for determining sources of evidence.
Conclusion:
TheCMMC Assessment Guideis the most authoritative source for determining the required evidence for a given practice in CMMC assessments. It provides detailed breakdowns of assessment objectives, required artifacts, and verification steps necessary for compliance.
A contractor stores security policies, system configuration files, and audit logs in a centralized file repository for later review. According to CMMC terminology, the file repository is being used to:
Which document specifies the CMMC Level 1 practices that correspond to basic safeguarding requirements?
CMMC Level 1 practices correspond directly to the basic safeguarding requirements for Federal Contract Information (FCI), which are codified in FAR clause 48 CFR 52.204-21. These 15 requirements form the foundation for Level 1 compliance.
Supporting Extracts from Official Content:
48 CFR 52.204-21: ''Contractors shall apply the following 15 basic safeguarding requirements to protect Federal Contract Information (FCI).''
CMMC Model v2.0 Overview: ''Level 1 corresponds to the 15 basic safeguarding requirements in FAR 52.204-21.''
Why Option C is Correct:
FAR 52.204-21 is the source for Level 1 practices.
NIST SP 800-171 applies to CUI and Level 2, not Level 1.
NIST SP 800-171b is the precursor to NIST SP 800-172 (used for Level 3).
DFARS 252.204-7012 covers CUI safeguarding and incident reporting, not Level 1 FCI requirements.
Reference (Official CMMC v2.0 Content):
FAR 48 CFR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems.
CMMC Model v2.0, Level 1 Overview.
Get access to all 221 verified questions with detailed answers.
Unlock All CMMC-CCP Questions