A Level 2 Assessment was conducted for an OSC, and the results are ready to be submitted. Prior to uploading the assessment results, what step MUST the C3PAO complete?
Pay an assessment submission fee.
Complete an internal review of the results.
Notify the CMMC-AB that submission is forthcoming.
Coordinate a final briefing between the Lead Assessor and the OSC.
According to the CMMC Assessment Process (CAP) and the C3PAO Authorization Requirements, every assessment conducted by a Certified Third-Party Assessment Organization (C3PAO) must undergo a formal Quality Management System (QMS) review before the results are finalized and uploaded to the eMASS (Enterprise Mission Assurance Support Service) or the SPRS (Supplier Performance Risk System).
The Quality Review Requirement: The CAP explicitly states that the C3PAO is responsible for the accuracy and integrity of the assessment findings. Before the Assessment Team Lead can formally submit the package, a person or team within the C3PAO (who was ideally not part of the active assessment team to ensure objectivity) must conduct an internal review. This review ensures that the evidence collected supports the " Met " or " Not Met " determinations and that all CMMC methodology requirements were followed.
Why other options are incorrect:
Option A: While there may be administrative costs associated with maintaining C3PAO status, paying a specific " per-submission fee " is not a mandatory procedural stepwithin the assessment lifecyclethat governs the validity of the results.
Option C: The Cyber AB (CMMC-AB) provides the platform and oversight, but a " forthcoming notification " is not a formal requirement in the CAP; the act of submission itself serves as the notification.
Option D: While a final briefing is a " best practice " and usually occurs during the " Post-Assessment " phase, the internal quality review (Option B) is the regulatory mandate that must be completed to ensure the C3PAO ' s certification of the results is valid and defensible.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section on " Phase 4: Reporting Results, " specifically the sub-section on C3PAO Quality Assurance Review.
C3PAO Quality Management System (QMS) Requirements: Outlines the necessity for internal validation of assessment packages to maintain accreditation.
For a CMMC Level 2 certification, which organization maintains a non-disclosure agreement with the OSC?
NIST
C3PAO
CMMC-AB
OUSD A & S
The Certified Third-Party Assessment Organization (C3PAO) enters into a contractual relationship with the OSC. As part of that contract, the C3PAO maintains a non-disclosure agreement (NDA) to protect sensitive and proprietary information reviewed during the assessment.
Supporting Extracts from Official Content:
CAP v2.0, Roles and Responsibilities (§2.8): “The C3PAO maintains a non-disclosure agreement with the OSC to protect all sensitive information disclosed during the assessment.â€
Why Option B is Correct:
Only the C3PAO contracts directly with the OSC and is bound to protect assessment data.
NIST, The Cyber AB (formerly CMMC-AB), and OUSD A & S do not enter NDAs directly with OSCs.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Section on OSC–C3PAO agreements.
===========
A test or demonstration is being performed for the Assessment Team during an assessment. Which environment MUST the OSC perform this test or demonstration?
Client
Production
Development
Demonstration
Understanding the Assessment Environment Requirement
During aCMMC Level 2 assessment, assessors requireobjective evidencethat security controls are implementedin the actual operating environmentwhereControlled Unclassified Information (CUI)is handled.
This means thattests or demonstrations must be conducted in the production environment, where the organization’s real systems and security controls are in use.
Why Option B (Production) is Correct
Assessment teams need to validate security controls in the actual environment where they are applied, ensuring that security measures are in effect in thereal-world operating conditions.
Option A (Client)is incorrect because " Client " is not a defined assessment environment.
Option C (Development)is incorrect because testing in a development environmentdoes not accurately represent the production security posture.
Option D (Demonstration)is incorrect becausedemonstrations in a separate test environment do not provide valid evidence for CMMC assessments—actual security implementations must be verified in production.
Official CMMC Documentation References
CMMC Assessment Process (CAP) Guide – Section 3.5 (Assessment Methods)
NIST SP 800-171 Assessment Procedures(Verification must occur in the actual system where CUI resides.)
Final Verification
SinceCMMC assessments require security controls to be validated in the actual production environment, the correct answer isOption B: Production.
When assessing SI.L1-3.14.2: Provide protection from malicious code at appropriate locations within organizational information systems, evidence shows that all of the OSC ' s workstations and servers have antivirus software installed for malicious code protection. A centralized console for the antivirus software management is in place and records show that all devices have received the most updated antivirus patterns. What is the BEST determination that the Lead Assessor should reach regarding the evidence?
It is sufficient, and the audit finding can be rated as MET.
It is insufficient, and the audit finding can be rated NOT MET.
It is sufficient, and the Lead Assessor should seek more evidence.
It is insufficient, and the Lead Assessor should seek more evidence.
Understanding SI.L1-3.14.2: Provide Protection from Malicious Code
The CMMC Level 1 practiceSI.L1-3.14.2is based onNIST SP 800-171 Requirement 3.14.2, which requires organizations to:
Implement malicious code protection(e.g., antivirus, endpoint security software).
Ensure coverage across all appropriate locations(e.g., workstations, servers, network entry points).
Keep protection mechanisms updated(e.g., regular signature updates, policy enforcement).
Assessment Criteria for a " MET " Rating:
To determine whether the practice isMET, the Lead Assessor must confirm that:
✔Antivirus or endpoint protection software is installedon all workstations and servers.
✔The solution is centrally managed, ensuring consistent policy enforcement.
✔Signature updates are current, meaning systems are protected against new threats.
✔Logs or reports demonstrate active monitoring and updates.
Why is the Correct Answer " A. It is sufficient, and the audit finding can be rated as MET " ?
The provided evidenceconfirms all necessary requirementsfor SI.L1-3.14.2:
✔All workstations and servers have antivirus installed→Meets installation requirement.
✔A centralized management console is in place→Ensures consistent enforcement.
✔Records show antivirus signatures are up to date→Confirms system protection is current.
Because the evidencemeets the requirement, the practice should berated as MET.
Why Are the Other Answers Incorrect?
B. It is insufficient, and the audit finding can be rated NOT MET → Incorrect
The evidence providedmeets all necessary requirements, so the practiceshould not be rated as NOT MET.
C. It is sufficient, and the Lead Assessor should seek more evidence → Incorrect
Ifadequate evidence already exists,additional evidence is unnecessary.
D. It is insufficient, and the Lead Assessor should seek more evidence → Incorrect
The evidence providedmeets the control requirements, making itsufficient.
CMMC 2.0 References Supporting This Answer:
CMMC Assessment Process (CAP) Document
Specifies that a practice can be marked asMET if sufficient evidence is provided.
NIST SP 800-171 (Requirement 3.14.2)
Defines the standard formalicious code protection, which ismet by antivirus with active updates.
CMMC 2.0 Level 1 (Foundational) Requirements
Clarifies that basic cybersecurity measures likeantivirus installation and updatesmeet compliance forSI.L1-3.14.2.
Final Answer:
✔A. It is sufficient, and the audit finding can be rated as MET.
When scoping a Level 2 assessment, which document is useful for understanding the process to successfully implement practices required for the various Levels of CMMC?
NISTSP 800-53
NISTSP 800-88
NISTSP 800-171
NISTSP 800-172
CMMC 2.0 Level 2 is directly aligned withNIST Special Publication (SP) 800-171, " Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations. " Organizations seeking certification (OSC) at Level 2 must demonstrate compliance with the 110 security requirements specified inNIST SP 800-171, as mandated byDFARS 252.204-7012.
Why NIST SP 800-171 is Essential for Level 2 Scoping:
Defines the Security Requirements for Protecting CUI:
NIST SP 800-171 outlines 110 security controls that contractors must implement to protectControlled Unclassified Information (CUI)in nonfederal systems.
These controls are categorized under14 families, including access control, incident response, and risk management.
Establishes the Baseline for CMMC Level 2 Compliance:
CMMC 2.0 Level 2 assessments areentirely based on NIST SP 800-171requirements.
Every practice assessed in a Level 2 certification maps directly to a requirement fromNIST SP 800-171 Rev. 2.
Provides Guidance for Implementation & Assessment:
TheNIST SP 800-171A " Assessment Guide " provides detailed assessment objectives that guide OSCs in preparing for CMMC evaluations.
It helps define the scope of an assessment by clarifying how each control should be implemented and verified.
Referenced in CMMC and DFARS Regulations:
DFARS 252.204-7012requires contractors to implementNIST SP 800-171security requirements.
TheCMMC 2.0 Level 2modeldirectly incorporates all 110 requirementsfromNIST SP 800-171, ensuring consistency with DoD cybersecurity expectations.
Explanation of Incorrect Answers:
A. NIST SP 800-53 ( " Security and Privacy Controls for Federal Information Systems and Organizations " )
This documentapplies to federal systems, not nonfederal entities handling CUI.
While it is the foundation for other security standards, it isnot the basis of CMMC Level 2assessments.
B. NIST SP 800-88 ( " Guidelines for Media Sanitization " )
This documentfocuses on secure data destructionand media sanitization techniques.
While data disposal is important, this standarddoes not define security controls for protecting CUI.
D. NIST SP 800-172 ( " Enhanced Security Requirements for Protecting CUI " )
This documentbuilds on NIST SP 800-171and applies to systems needingadvanced cybersecurity protections(e.g., targeting Advanced Persistent Threats).
It isnot required for standard CMMC Level 2 assessments, which only mandateNIST SP 800-171 compliance.
Key References for CMMC Level 2 Scoping:
NIST SP 800-171 Rev. 2(NIST Official Site)
NIST SP 800-171A (Assessment Guide)(NIST Official Site)
CMMC 2.0 Level 2 Scoping Guide(Cyber AB)
Conclusion:
SinceCMMC 2.0 Level 2 assessments are based entirely on NIST SP 800-171, this document is the most relevant resource for scoping Level 2 assessments. Therefore, the correct answer is:
✅C. NIST SP 800-171
The Assessment Team has completed the assessment and determined the preliminary practice ratings. The preliminary practice ratings must be shared with the OSC prior to being finalized for submission. Based on this information, the assessor should present the preliminary practice ratings:
During the final Daily Checkpoint
After discussing with the CMMC-AB
Via email after the final Daily Checkpoint
Over the phone after the final Daily Checkpoint
According to the CMMC Assessment Process (CAP) v2.0, assessors are required to conduct Daily Checkpoint Meetings at the end of each day to summarize progress with the OSC (Organization Seeking Certification). The final Daily Checkpoint is where preliminary practice ratings are shared, before the quality assurance review and Out-Brief. The Out-Brief is reserved for the presentation of final results. Additionally, Department of Defense regulations (32 CFR §170.17(c)(2)) provide a 10-business-day re-evaluation window for requirements marked NOT MET before the final report is delivered, which necessitates that the OSC see preliminary ratings during the assessment process itself.
Supporting Extracts from Official Content:
CAP v2.0, §2.23: “The assessment team shall host a Daily Checkpoint Meeting with the OSC at the end of each assessment day to summarize progress.â€
CAP v2.0, §3.7: “The C3PAO shall conduct the quality assurance review… prior to the conduct of the Out-Brief Meeting.â€
CAP v2.0, §3.10: “The purpose of the Out-Brief Meeting is to convey the results of the assessment to the OSC.â€
32 CFR §170.17(c)(2): “A security requirement assessed as NOT MET may be re-evaluated… for 10 business days… if the CMMC Assessment Findings Report has not been delivered.â€
Why Option A is Correct:
The CAP specifies that Daily Checkpoint Meetings are the formal, structured mechanism for assessors to communicate progress and preliminary findings to the OSC.
The final Daily Checkpoint provides the OSC with visibility into the preliminary practice ratings before they are finalized, ensuring transparency and alignment.
The Out-Brief is explicitly for conveying the final assessment results after the C3PAO has completed QA.
Federal regulation (32 CFR §170.17(c)(2)) requires the OSC to have access to preliminary results so they can provide additional evidence for re-evaluation before the report is locked, further confirming that this exchange must occur at the final Daily Checkpoint.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0: Sections 2.23 (Daily Checkpoints), 3.7–3.10 (QA and Out-Brief).
32 CFR §170.17(c)(2): Security Requirement Re-evaluation Window.
DoD CMMC Assessment Guide – Level 2 (v2.13): Guidance on MET/NOT MET determinations and findings.
The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections. How should the team score practices in which the evidence shows the deficiencies have been corrected?
MET
POA & M
NOT MET
NOT APPLICABLE
Understanding the CMMC Assessment Process (CAP) Phases
TheCMMC Assessment Process (CAP)consists ofthree primary phases:
Phase 1 - Planning(Pre-assessment activities)
Phase 2 - Conducting the Assessment(Evidence collection and analysis)
Phase 3 - Reporting and Finalizing Results
DuringPhase 3, the Assessment Teamreviews evidenceto confirm if anyLimited Practice Deficiency Correctionshave been successfully implemented.
Scoring Practices in Phase 3
The CAP document specifies that a practice can bescored as METif:
✅The deficiency identified in Phase 2 has been fully corrected before final scoring.
✅Sufficient evidence is provided to demonstrate compliance with the CMMC requirement.
✅The correction is notmerely plannedbutfully implemented and validatedby the assessors.
Since the evidence shows thatdeficiencies have been corrected, the correct score isMET.
Why the Other Answers Are Incorrect
B. POA & M (Plan of Action & Milestones)
âŒIncorrect. APOA & M (Plan of Action and Milestones)is usedonly when a deficiency remains unresolved. Since the deficiency is already corrected, this option does not apply.
C. NOT MET
âŒIncorrect. A practice is scoredNOT METonly if the deficiency hasnotbeen corrected by the end of the assessment.
D. NOT APPLICABLE
âŒIncorrect. A practice is markedNOT APPLICABLE (N/A)only if it doesnot apply to the organization’s environment, which is not the case here.
CMMC Official References
CMMC Assessment Process (CAP) Document– Defines scoring criteria for MET, NOT MET, and POA & M.
Thus,option A (MET) is the correct answer, as the deficiencies have been corrected before final scoring.
Which term describes assessing the ability of a unit equipped with a system to support its mission while withstanding cyber threat activity representative of an actual adversary?
Penetration test
Black hat testing
Red cell assessment
Adversarial assessment
The term Adversarial Assessment is formally defined in DoD cyber terminology. It describes testing that evaluates a unit or system’s ability to perform its mission while facing simulated cyber threat activity representative of a real-world adversary.
Supporting Extracts from Official Content:
DoD Cybersecurity Test and Evaluation Guidebook: “Adversarial Assessment: Test conducted to evaluate a unit’s ability to support its mission while withstanding cyber threat activity representative of an actual adversary.â€
Why Option D is Correct:
A penetration test is narrower and focuses on identifying vulnerabilities.
Black hat testing is not an official DoD or CMMC term.
Red cell assessment refers more broadly to force-on-force exercises and is not the term used in CMMC/governing DoD definitions.
References (Official CMMC v2.0 Content and Source Documents):
DoD Cybersecurity Test and Evaluation Guidebook.
CMMC v2.0 Governance – Source Documents (incorporating DoD definitions).
Contractor scoping requirements for a CMMC Level 2 Assessment to document the asset in an inventory, in the SSP and on the network diagram apply to:
GUI Assets.
CUI and Security Protection Asset categories.
all asset categories except for the Out-of-scope Assets.
Contractor Risk Managed Assets and Specialized Assets.
According to the CMMC Scoping Guidance, Level 2, assets are categorized to determine the level of assessment rigor required. The requirement to document an asset in the Asset Inventory, the System Security Plan (SSP), and on the Network Diagram is a specific administrative requirement for high-priority asset classes.
CUI Assets: These are assets that process, store, or transmit Controlled Unclassified Information (CUI). They are part of the " Assessed " group and must be fully documented in the inventory, SSP, and network diagram.
Security Protection Assets (SPA): These are assets that provide security functions or capabilities to the assessment scope (e.g., firewalls, log servers, or AV management consoles), even if they do not process CUI themselves. Because they are critical to the security of CUI, they must also be documented in the inventory, SSP, and network diagram.
Why other options are incorrect:
Option A: " GUI Assets " is likely a typo or misnomer in this context (possibly meant to refer to CUI assets or a distractor).
Option C: This is incorrect because Contractor Risk Managed Assets (CRMA) and Specialized Assets have different documentation requirements. For instance, while CRMA are documented in the inventory and SSP, they are often not required to be on the network diagram in the same detail as CUI assets, depending on the specific assessment boundary. Out-of-Scope Assets are not documented at all.
Option D: Contractor Risk Managed Assets (CRMA) and Specialized Assets (like IoT, OT, or Restricted Information Systems) are required to be in the Asset Inventory and SSP, but the CMMC Scoping Guidance specifies that the most stringent documentation (Inventory + SSP + Network Diagram) is the primary mandate for those assets directly handling CUI or protecting it (SPAs).
Reference Documents:
CMMC Scoping Guidance, Level 2 (Version 2.0/2.1): Section 3.0, Table 1 (CUI Assets) and Table 2 (Security Protection Assets), which explicitly list the " Documentation Requirements " for each category.
CMMC Assessment Process (CAP): Section on Scoping Boundaries and Evidence Validation.
A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?
Performed in groups for more efficient use of resources
Recorded for inclusion in the Final Recommended Findings report
Confidential and non-attributable so interviewees can speak without fear of reprisal
Mapped to specific CMMC practices to clearly delineate which practice is being evaluated
Understanding the Role of a CCP in CMMC Assessments
ACertified CMMC Professional (CCP)is responsible for assistingCertified CMMC Assessors (CCA)in evaluating anOrganization Seeking Certification (OSC)during a CMMC assessment. One key aspect of this process isconducting interviewswith Subject Matter Experts (SMEs) to verify security practices.
Ensuring that interviewees canspeak freely without fear of retaliationiscriticalto obtainingaccurate and unbiased informationabout the implementation of security controls.
Step-by-Step Breakdown:
CMMC Assessment Process and the Role of Interviews
TheCMMC Assessment Guide (Level 2)outlines that interviews are conducted to confirm that security practices are effectively implemented.
Interviewees mustfeel comfortable sharing candid responseswithout concern that their statements will lead tonegative consequenceswithin the organization.
Ensuring Confidentiality and Non-Attribution
DoD Assessment Methodologyspecifies that interviews should be conductedconfidentiallytoprotect the identity of interviewees.
TheCMMC Code of Professional Conduct (CoPC)for assessors and professionals reinforces the requirement to maintain theconfidentialityof assessment participants.
Non-attributionensures that responses are used for evaluation purposeswithout linking statements to specific individuals.
Why the Other Answer Choices Are Incorrect:
(A) Performed in groups for more efficient use of resources:
Group interviews may prevent individuals from speaking openly.
Employees might be hesitant to contradict leadership or peers.
(B) Recorded for inclusion in the Final Recommended Findings report:
Interviews arenot directly recorded or attributedin assessment reports.
Instead, findings are documentedwithout identifying specific individuals.
(D) Mapped to specific CMMC practices to clearly delineate which practice is being evaluated:
While responsesinformwhich practices are being assessed, theprimary goalof an interview is to ensure accurate,unbiased information gathering.
Final Validation from CMMC Documentation:
According to theCMMC Assessment Guide and DoD Assessment Methodology, interview confidentiality iscrucialto gatheringaccurateandunbiasedresponses. This makesconfidentiality and non-attributionthe correct answer.
Thus, the correct answer is:
C. Confidential and non-attributable so interviewees can speak without fear of reprisal.
Which statement BEST describes an assessor ' s evidence gathering activities?
Use interviews for assessing a Level 2 practice.
Test all practices or objectives for a Level 2 practice
Test certain assessment objectives to determine findings.
Use examinations, interviews, and tests to gather sufficient evidence.
Under the CMMC Assessment Process (CAP) and CMMC 2.0 guidelines, assessors must gather objective evidence to validate that an organization meets the required security practices and processes. This evidence collection is performed through three primary assessment methods:
Examination – Reviewing documents, records, system configurations, and other artifacts.
Interviews – Speaking with personnel to verify processes, responsibilities, and understanding of security controls.
Testing – Observing system behavior, performing technical validation, and executing controls in real-time to verify effectiveness.
Why Option D is Correct
The CMMC Assessment Process (CAP) states that an assessor must use a combination of evidence-gathering methods (examinations, interviews, and tests) to determine compliance.
CMMC 2.0 Level 2 (Aligned with NIST SP 800-171) requires assessors to verify not only that policies and procedures exist but also that they are implemented and effective.
Solely relying on one method (like interviews in Option A) is insufficient.
Testing all practices or objectives (Option B) is unnecessary, as assessors follow scoping guidance to determine which objectives need deeper examination.
Testing only " certain " objectives (Option C) does not fully align with the requirement of gathering sufficient evidence from multiple methods.
CMMC 2.0 and Official Documentation References
CMMC Assessment Process (CAP) Guide, Section 3.5 – Assessment Methods explicitly defines the use of examinations, interviews, and tests as the foundation of an effective assessment.
CMMC 2.0 Level 2 Practices and NIST SP 800-171 require assessors to validate the presence, implementation, and effectiveness of security controls.
CMMC Appendix E: Assessment Procedures states that an assessor should use multiple sources of evidence to determine compliance.
Final Verification
To ensure compliance with CMMC 2.0 guidelines and official documentation, an assessor must use examinations, interviews, and tests to gather evidence effectively, making Option D the correct answer.
Two assessors cannot agree if a certain practice should be rated as MET or NOT MET. Who should they consult to determine the final interpretation?
C3PAO
CMMC-AB
Lead Assessor
Quality Assurance Assessor
The Lead Assessor has the authority to make the final determination in situations where assessors cannot agree on a rating. CAP specifies that the Lead Assessor ensures consistency, resolves disputes, and provides the authoritative interpretation during the assessment process. Escalation to the CMMC-AB or Quality Assurance would only occur in rare post-assessment review cases, not during an active assessment.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
According to the Configuration Management (CM) domain, which principle is the basis for defining essential system capabilities?
Least privilege
Essential concern
Least functionality
Separation of duties
Understanding the Principle of Least Functionality in the CM Domain
TheConfiguration Management (CM) domainin CMMC 2.0 focuses on maintaining the security and integrity of an organization’s systems through controlled configurations and restrictions on system capabilities.
The principle ofLeast Functionalityrefers to limiting a system’s features, services, and applications to only those necessary for its intended purpose. This principle reduces the attack surface by minimizing unnecessary components that could be exploited by attackers.
Justification for the Correct Answer: Least Functionality (C)
CMMC Practice CM.L2-3.4.6 (Use Least Functionality)explicitly states:
" Employ the principle of least functionality by configuring organizational systems to provide only essential capabilities. "
Thegoalis to prevent unauthorized or unnecessary applications, services, and ports from running on the system.
Examples of Implementation:
Disabling unnecessary services, such as remote desktop access if not required.
Restricting software installation to approved applications.
Blocking unused network ports and protocols.
Why Other Options Are Incorrect
A. Least Privilege
This principle (associated with Access Control) ensures that users and processes have only the minimum level of access necessary to perform their jobs.
It is relevant to CMMC PracticeAC.L2-3.1.5 (Least Privilege)but does not define system capabilities.
B. Essential Concern
There is no officially recognized cybersecurity principle called " Essential Concern " in CMMC, NIST, or related frameworks.
D. Separation of Duties
This principle (covered under CMMCAC.L2-3.1.4) ensures that no single individual has unchecked control over critical functions, reducing the risk of fraud or abuse.
While important for security, it does not define essential system capabilities.
Official CMMC and NIST References
CMMC 2.0 Level 2 Assessment Guide – Configuration Management (CM) Domain
CM.L2-3.4.6 mandatesleast functionalityto enhance security by removing unnecessary features.
NIST SP 800-171 (which CMMC is based on) – Requirement 3.4.6
States: " Limit system functionality to only the essential capabilities required for organizational missions or business functions. "
NIST SP 800-53 – Control CM-7 (Least Functionality)
Provides detailed recommendations on configuring systems to operate with only necessary features.
Conclusion
Theprinciple of Least Functionality (C)is the basis for defining essential system capabilities in theConfiguration Management (CM) domainof CMMC 2.0. By applying this principle, organizations reduce security risks by ensuring that only the necessary functions, services, and applications are enabled.
Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1, Guidelines for Media Sanitation?
Clear, purge, destroy
Clear, redact, destroy
Clear, overwrite, purge
Clear, overwrite, destroy
NIST SP 800-88 Rev. 1 is the authoritative guide for media sanitization. It defines three categories of data disposal: Clear, Purge, and Destroy.
Supporting Extracts from Official Content:
NIST SP 800-88 Rev. 1: “Media sanitization techniques are divided into three categories: Clear, Purge, and Destroy.â€
Why Option A is Correct:
“Clear, Purge, Destroy†are the exact three categories named.
Redact and Overwrite are not categories; Overwriting is a technique that may fall under Clear.
References (Official CMMC v2.0 Content and Source Documents):
NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization.
===========
A CMMC Assessment Team arrives at an OSC to begin a CMMC Level 2 Assessment. The team checks in at the front desk and lets the receptionist know that they are here to conduct the assessment. The receptionist is aware that the team is arriving today and points down a hallway where the conference room is. The receptionist tells the Lead Assessor to wait in the conference room. as someone will be there shortly. The receptionist fails to check for credentials and fails to escort the team. The receptionist ' s actions are in direct violation of which CMMC practice?
PE.L1-3.10.3: Escort visitors and monitor visitor activity
PE.L1-3.10.5: Control and manage physical access devices
PS.L2-3.9.1; Screen individuals prior to authorizing access to organizational systems containing CUI
PS.L2-3 9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
ThePhysical Protection (PE) domaininCMMC 2.0 Level 1includes the requirementPE.L1-3.10.3, which mandates that organizationsescort visitors and monitor their activity.
Breaking Down the Scenario:
TheCMMC Assessment Teamarrives at the OSC.
Thereceptionist acknowledges their arrival but does not verify credentials or escort themto the appropriate location.
Failing to verify visitor identity and failing to escort them is a violation of PE.L1-3.10.3.
Analysis of the Given Options:
A. PE.L1-3.10.3: Escort visitors and monitor visitor activity→✅Correct
This requirement ensures that visitorsdo not have unsupervised access to sensitive areas.
The receptionistshould have checked credentials and escorted the assessment team.
B. PE.L1-3.10.5: Control and manage physical access devices→âŒIncorrect
This requirement refers to managingkeys, access badges, and security devices, which isnot the issue in this scenario.
C. PS.L2-3.9.1: Screen individuals prior to authorizing access to organizational systems containing CUI→âŒIncorrect
This control applies to personnel screeningsbefore granting access to CUI systems, not physical visitor access.
D. PS.L2-3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers→âŒIncorrect
This requirement deals withoffboarding employees and ensuring they no longer have system access. It isnot relevant to visitor escorting.
Official References Supporting the Correct Answer:
CMMC 2.0 Level 1 - PE.L1-3.10.3 (Physical Protection)
Requires organizations toescort visitors and monitor visitor activityat facilities containingFCI or CUI.
NIST SP 800-171 Rev. 2, Control 3.10.3
States thatvisitors must be escorted and monitored at all timesto prevent unauthorized access.
Conclusion:
Since the receptionist failed to verify credentials and escort the visitors, this violatesPE.L1-3.10.3.
✅Correct Answer: A. PE.L1-3.10.3: Escort visitors and monitor visitor activity
Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse. After a thorough review, the CCP tells the Lead Assessor that all supporting documents fully reflect the performance of the practice and should be accepted because the evidence is:
official.
adequate.
compliant.
subjective.
CMMC Level 1 includes 17 practices derived fromFAR 52.204-21. Among them, theMedia Protection (MP) practicerequires organizations to ensure thatmedia containing FCI is sanitized or destroyed before disposal or release for reuseto prevent unauthorized access.
This requirement ensures that any storage devices, hard drives, USBs, or physical documents containingFederal Contract Information (FCI)areproperly disposed of or sanitizedto prevent data leakage.
The evidence collected for this practice should demonstrate that an organization has established and followed propermedia sanitization or destruction procedures.
Why the Correct Answer is " B. Adequate " ?
TheCMMC Assessment Process (CAP) Guideoutlines that for an assessment to be considered complete, all submitted evidence must meet the standard ofadequacybefore it is accepted by the Lead Assessor.
Definition of " Adequate " Evidence in CMMC:
Evidence isadequatewhen itfully demonstrates that a practice has been performed as requiredby CMMC guidelines.
TheLead Assessorevaluates whether the submitted documentation meets the CMMC 2.0 Level 1 requirements.
If the evidenceaccurately and completely demonstrates the sanitization or destruction of media containing FCI, then it meets the standard ofadequacy.
Why Not the Other Options?
A. Official– While the evidence may come from an official source, the CMMCdoes not require evidence to be " official " , only that it beadequateto confirm compliance.
C. Compliant– Compliance is the final result of an assessment, but before compliance is determined, the evidence must first beadequatefor evaluation.
D. Subjective– CMMC evidence isobjective, meaning it should be based on verifiable documents, policies, logs, and procedures—not opinions or interpretations.
Relevant CMMC 2.0 References:
CMMC 2.0 Scoping Guide (Nov 2021)– Specifies that Media Protection (MP) at Level 1 applies only to assets that process, store, or transmit FCI.
CMMC Assessment Process (CAP) Guide– Definesadequate evidenceas documentation that completely and clearly supports the implementation of a required security practice.
FAR 52.204-21– The source of the Level 1 requirements, which includessanitization and destruction of media containing FCI.
Final Justification:
The CCP’s statement that the evidence " fully reflects the performance of the practice " aligns with the definition ofadequate evidenceunder CMMC. Since adequacy is the key standard used before final compliance decisions are made, the correct answer isB. Adequate.
A Lead Assessor is preparing to conduct a Readiness Review during Phase 1 of the Assessment Process. How much evidence MUST be gathered for each practice?
A sufficient amount
At least 2 Assessment Objects
Evidence that is deemed adequate
Evidence to support at least 2 Assessment Methods
During a Readiness Review (Phase 1), the purpose is to validate whether an OSC is prepared to move forward with a formal assessment. The CAP specifies that the Lead Assessor must collect sufficient evidence for each practice to make a preliminary determination of readiness.
Supporting Extracts from Official Content:
CAP v2.0, Readiness Review (§2.14): “The Lead Assessor must collect a sufficient amount of evidence for each practice to determine the OSC’s readiness.â€
Why Option A is Correct:
The requirement is for sufficient evidence; CAP does not mandate a set number of assessment objects or methods.
Options B, C, and D incorrectly suggest minimum counts or methods that are not part of the readiness review requirements.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 1 Readiness Review.
===========
Which are guiding principles in the CMMC Code of Professional Conduct?
Objectivity, information integrity, and higher accountability
Objectivity, information integrity, and proper use of methods
Proper use of methods, higher accountability, and objectivity
Proper use of methods, higher accountability, and information integrity
The CMMC Code of Professional Conduct applies to all CMMC assessors, practitioners, and ecosystem participants. Its guiding principles are: Objectivity, Information Integrity, and Higher Accountability.
Supporting Extracts from Official Content:
CMMC Code of Professional Conduct: “Guiding principles… include Objectivity, Information Integrity, and Higher Accountability.â€
Why Option A is Correct:
These three principles are the official guiding values documented in the Code of Professional Conduct.
Options B, C, and D insert terms (“proper use of methodsâ€) that are not part of the official guiding principles.
References (Official CMMC v2.0 Content):
CMMC Code of Professional Conduct.
===========
A defense contractor needs to share FCI with a subcontractor and sends this data in an email. The email system involved in this process is being used to:
manage FCI.
process FCI.
transmit FCI.
generate FCI
Federal Contract Information (FCI) is defined in FAR 52.204-21 as information provided by or generated for the government under contract but not intended for public release. Under CMMC 2.0, organizations handling FCI must implement FAR 52.204-21 Basic Safeguarding Requirements, ensuring proper protection in processing, storing, and transmitting FCI.
Analyzing the Given Options
The question involves an email system that is used to send FCI to a subcontractor. Let’s break down the possible answers:
A. Manage FCI → Incorrect
Managing FCI involves activities like organizing, storing, and maintaining access to FCI. Sending an email does not fall under management; it is an act of transmission.
B. Process FCI → Incorrect
Processing refers to actively using FCI for operational or analytical purposes, such as analyzing, modifying, or computing data. Simply sending an email does not constitute processing.
C. Transmit FCI → Correct
Transmission refers to the act of sending FCI from one entity to another. Since the contractor is sending FCI via email, this falls under transmitting the data.
What is the BEST description of the purpose of FAR clause 52 204-21?
It directs all covered contractors to install the cyber security systems listed in that clause.
It describes all of the safeguards that contractors must take to secure covered contractor IS.
It describes the minimum standard of care that contractors must take to secure covered contractor IS.
It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.
Understanding FAR Clause 52.204-21
TheFederal Acquisition Regulation (FAR) Clause 52.204-21is titled " Basic Safeguarding of Covered Contractor Information Systems. " This clause establishesminimum cybersecurity requirementsforfederal contractorsthat handleFederal Contract Information (FCI).
Key Purpose of FAR Clause 52.204-21
Theprimary objectiveof FAR 52.204-21 is to ensure that contractors applybasic cybersecurity protectionsto theirinformation systemsthat process, store, or transmitFCI. Theseminimum safeguarding requirementsserve as abaseline security standardfor contractors doing business with theU.S. government.
Why " Minimum Standard of Care " is Correct?
FAR 52.204-21 doesnotrequire contractors to install specific cybersecurity tools (eliminating option A).
Itoutlines only the minimum safeguards, notallcybersecurity controls needed for complete security (eliminating option B).
CMMC certification isnotmandated by this clause alone (eliminating option D).
Instead, it establishesa baseline " standard of care " that all federal contractorsmust followto protectFCI(making option C correct).
Breakdown of Answer Choices
Option
Description
Correct?
A. It directs all covered contractors to install the cybersecurity systems listed in that clause.
âŒIncorrect–The clause doesnotspecify tools or require specific cybersecurity systems.
B. It describes all of the safeguards that contractors must take to secure covered contractor IS.
âŒIncorrect–It only setsminimumrequirements, notall possiblesecurity measures.
C. It describes the minimum standard of care that contractors must take to secure covered contractor IS.
✅Correct – The clause defines basic safeguards as a minimum security standard.
D. It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.
âŒIncorrect–FAR 52.204-21 doesnot mandateCMMC certification; that requirement comes from DFARS 252.204-7012 and 7021.
Minimum Safeguarding Requirements Under FAR 52.204-21
The clause defines15 basic security controls, which align withCMMC Level 1. Some examples include:
✅Access Control– Limit access to authorized users.
✅Identification & Authentication– Authenticate system users.
✅Media Protection– Sanitize media before disposal.
✅System & Communications Protection– Monitor and control network connections.
Official References from CMMC 2.0 and FAR Documentation
FAR 52.204-21– Establishes thebasic safeguarding requirementsfor FCI.
CMMC 2.0 Level 1– Directly aligns withFAR 52.204-21 controls.
Final Verification and Conclusion
The correct answer isC. It describes the minimum standard of care that contractors must take to secure covered contractor IS.This aligns withFAR 52.204-21 requirementsas abaseline security standard for FCI.
In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?
In scope
Out of scope
OSC point of contact
Assessment Team Member
Understanding Scoping in CMMC Level 1 Self-Assessments
Federal Contract Information (FCI)is any informationnot intended for public releasethat is provided or generated under aU.S. Government contracttodevelop or deliver a product or service.
Enhanced Security Personnel (ESP)refers to employees, contractors, or third parties whohave access to FCIwithin anOrganization Seeking Certification (OSC).
UnderCMMC 2.0 Scoping Guidance, anypersonnel, system, or asset with access to FCI is considered in scopefor a CMMC Level 1 assessment.
Why Option A (In scope) is Correct
Since theESP employee has access to FCI, theymustbe included in the assessment scope.
Option B (Out of scope)is incorrect because anyone with access to FCI is automatically considered part of theCMMC Level 1 boundary.
Option C (OSC point of contact)is incorrect because thepoint of contactis typically an administrative or compliance representative, not necessarily someone with FCI access.
Option D (Assessment Team Member)is incorrect because anESP employee is not part of the assessment team but rather a subject of the assessment.
Official CMMC Documentation References
CMMC Level 1 Scoping Guide, Section 2 – Defining Scope for FCI
CMMC Assessment Process (CAP) Guide – Roles and Responsibilities
Federal Acquisition Regulation (FAR) 52.204-21(Basic Safeguarding of FCI)
Final Verification
Since theESP employee has access to FCI, they are consideredin scopefor the CMMC Level 1 self-assessment, makingOption A the correct answer.
A company has a government services division and a commercial services division. The government services division interacts exclusively with federal clients and regularly receives FCI. The commercial services division interacts exclusively with non-federal clients and processes only publicly available information. For this company ' s CMMC Level 1 Self-Assessment, how should the assets supporting the commercial services division be categorized?
FCI Assets
Specialized Assets
Out-of-Scope Assets
Operational Technology Assets
Understanding CMMC Asset Categorization
TheCMMC 2.0 Scoping Guidedefines how assets are categorized based on their involvement withFederal Contract Information (FCI)andControlled Unclassified Information (CUI).
In this scenario:
Thegovernment services divisioninteracts withfederal clientsandreceives FCI, making its assetsin-scopefor CMMC Level 1.
Thecommercial services divisioninteractsonly with non-federal clientsanddoes not handle FCI—this means its assets arenot subject to CMMC Level 1 requirementsand should be classified asOut-of-Scope Assets.
CMMC 2.0 Definition of Out-of-Scope Assets
As per theCMMC Scoping Guide, assets that:
✅Do not store, process, or transmit FCI/CUI
✅Do not directly impact the security of in-scope assets
✅Are completely segregated from the FCI/CUI environment
are classified asOut-of-Scope Assets.
Since thecommercial services divisiononly processespublicly available information and has no interaction with FCI, its assets areout-of-scopefor CMMC Level 1 assessment.
Why the Other Answers Are Incorrect
A. FCI Assets
âŒIncorrect. FCI assets areonly those that store, process, or transmit FCI. The commercial services division doesnothandle FCI, so its assets donotqualify.
B. Specialized Assets
âŒIncorrect. Specialized assets refer toInternet of Things (IoT), Operational Technology (OT), and test equipment. These donot applyto a general commercial services division.
D. Operational Technology Assets
âŒIncorrect.Operational Technology (OT) Assetsinvolveindustrial control systems, SCADA, and manufacturing equipment—which are not relevant to this scenario.
CMMC Official References
CMMC 2.0 Scoping Guide – Level 1 & Level 2
CMMC Assessment Process (CAP) Document
Thus,option C (Out-of-Scope Assets) is the correct answerbased on official CMMC scoping guidance.
A Lead Assessor is presenting an assessment kickoff and opening briefing. What topic MUST be included?
Gathering evidence
Review of the OSC ' s SSP
Overview of the assessment process
Examination of the artifacts for sufficiency
What is Required in the CMMC Assessment Kickoff and Opening Briefing?
Before starting aCMMC assessment, theLead Assessormust present anopening briefingto ensure that theOrganization Seeking Certification (OSC)understands the assessment process.
Step-by-Step Breakdown:
✅1. Overview of the Assessment Process
The Lead Assessormust explain the CMMC assessment methodology, including:
Theassessment objectives and scope
How theassessment team will review security controls
What to expectduring interviews, testing, and document review
This ensurestransparency and alignmentbetween the assessors and the OSC.
✅2. Why the Other Answer Choices Are Incorrect:
(A) Gathering EvidenceâŒ
Evidence collection is part of the assessment butnot the primary topic of the opening briefing.
(B) Review of the OSC ' s SSPâŒ
While theSSP is a key document, reviewing it is part of the assessment,not the kickoff briefing.
(D) Examination of the artifacts for sufficiencyâŒ
Artifact review happens laterin the assessment process,not during the kickoff.
Final Validation from CMMC Documentation:
TheCMMC Assessment Process Guidestates that theopening briefing must include an overview of the assessment process, ensuring the OSC understands the expectations and methodology.
Thus, the correct answer is:
✅C. Overview of the assessment process.
Which MINIMUM Level of certification must a contractor successfully achieve to receive a contract award requiring the handling of CUI?
Level 1
Level 2
Level 3
Any level
1. Understanding CMMC 2.0 Levels and CUI Handling Requirements
UnderCMMC 2.0, contractors handlingControlled Unclassified Information (CUI)must meet aminimumcertification level to be eligible for contract awards involving CUI.
CMMC 2.0 Levels:
Level 1 (Foundational) – 17 Practices
Covers onlyFederal Contract Information (FCI)security.
Does NOT meet CUI handling requirements.
Level 2 (Advanced) – 110 Practices✅
REQUIRED for handling CUI.
Aligns withNIST SP 800-171, which establishes security controls for protecting CUI.
Contractorsmust achieve Level 2for contracts requiring CUI protection.
Level 3 (Expert) – 110+ Practices
Required for contracts involvinghigh-value CUIandcritical national security information.
Includesadditionalprotections fromNIST SP 800-172.
2. Official CMMC 2.0 References Confirming Level 2 for CUI
TheCMMC 2.0 Model Overviewclearly states that Level 2 is required for contractorshandling CUI.
DFARS 252.204-7012mandates that contractors protecting CUI must implementNIST SP 800-171, which is thefoundation of CMMC Level 2.
TheDoD’s CMMC Assessment Guidefor Level 2 specifies thatorganizations handling CUI must demonstrate full implementation of 110 practices from NIST SP 800-171to qualify for contract awards.
3. Why the Other Options Are Incorrect
A. Level 1âŒ
Only covers FCI, not CUI.
Does notmeet DoD requirements for protectingCUI.
C. Level 3âŒ
While Level 3 offersadditional protectionsfor high-risk CUI, it isnot the minimumrequirement.
Level 2 is the minimumneeded to handle CUI.
D. Any levelâŒ
OnlyLevel 2 and higherare eligible for contracts requiring CUI protection.
Level 1 doesnotmeet CUI security standards.
Regarding the Risk Assessment (RA) domain, what should an OSC periodically assess?
Organizational operations, business assets, and employees
Organizational operations, business processes, and employees
Organizational operations, organizational assets, and individuals
Organizational operations, organizational processes, and individuals
TheRisk Assessment (RA) domainaligns withNIST SP 800-171 control family 3.11 (Risk Assessment)and is designed to help organizationsidentify, assess, and manage cybersecurity risksthat could impact their operations.
TheRA.3.144 practice(which is a CMMC Level 2 requirement) explicitly states:
" Periodically assess therisktoorganizational operations (including mission, functions, image, or reputation), organizational assets, and individualsresulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. "
This means that OSCs (Organizations Seeking Certification) should regularly evaluate risks to:
✅Organizational operations(e.g., mission, business continuity, functions)
✅Organizational assets(e.g., data, IT systems, intellectual property)
✅Individuals(e.g., employees, contractors, customers affected by security risks)
Thus, the correct answer isC. Organizational operations, organizational assets, and individuals.
Why the Other Answers Are Incorrect
A. Organizational operations, business assets, and employees
âŒIncorrect. " Business assets " is not the correct terminology used in CMMC/NIST SP 800-171. Instead, " organizational assets " is the proper term.
B. Organizational operations, business processes, and employees
âŒIncorrect. " Business processes " is not a part of the formal risk assessment requirement. The correct scope includesorganizational assetsandindividuals, not just processes.
D. Organizational operations, organizational processes, and individuals
âŒIncorrect. While processes are important,organizational assetsmust be considered in the assessment, not just processes.
CMMC Official References
CMMC 2.0 Model (Level 2 - RA.3.144)– Specifies that risk assessments must coverorganizational operations, organizational assets, and individuals.
NIST SP 800-171 (3.11.1)– Reinforces the same risk assessment scope.
Thus,option C (Organizational operations, organizational assets, and individuals) is the correct answerbased on official CMMC risk assessment requirements.
During the review of information that was published to a publicly accessible site, an OSC correctly identifies that part of the information posted should have been restricted. Which item did the OSC MOST LIKELY identify?
FCI
Change of leadership in the organization
Launching of their new business service line
Public releases identifying major deals signed with commercial entities
Understanding Federal Contract Information (FCI) and Publicly Accessible Information
Federal Contract Information (FCI)isnon-public informationprovided by or generated for the U.S. governmentunder a contractthat isnot intended for public release.
Key Characteristics of FCI:
✔FCI includesdetails related togovernment contracts, project specifics, and performance data.
✔It must be protected under FAR 52.204-21, which requiresbasic safeguarding measuresto prevent unauthorized access.
✔Posting FCI on a public site is a security violationsince it ismeant to be restrictedfrom public disclosure.
Why is the Correct Answer " A. FCI (Federal Contract Information) " ?
A. FCI → Correct
FCI must be protected from unauthorized access, and if it wasincorrectly published online, it should have been restricted.
B. Change of leadership in the organization → Incorrect
Leadership changes are typically public informationand do not require restriction unless they involve sensitive government-related security clearances.
C. Launching of their new business service line → Incorrect
Marketing and business announcementsare generallypublicly availableandnot restricted information.
D. Public releases identifying major deals signed with commercial entities → Incorrect
Commercial contracts and business deals are not considered FCIunless they involvegovernment contracts.
CMMC 2.0 References Supporting This Answer:
FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems)
DefinesFCI as sensitive but unclassified informationthat must beprotected from public disclosure.
CMMC 2.0 Level 1 Requirements
Requires contractors toprotect FCI under basic cybersecurity standardsto prevent unauthorized exposure.
DoD Guidance on FCI Protection
States thatpublishing FCI on public websites violates federal cybersecurity requirements.
An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?
Take it with them to review in the evening.
Leave it on the desk for review the following day.
Put it in the unlocked desk drawer for review the following morning.
Take a picture with the personal phone before securely shredding it.
In this scenario, the primary concern is the protection of Controlled Unclassified Information (CUI) in an environment that lacks sufficient physical security controls (specifically, a lack of a locked cabinet or drawer). According to the CMMC Assessment Process (CAP) and NIST SP 800-171 (specifically the Physical Protection (PE) family), CUI must be protected from unauthorized access at all times.
Responsibility of the Assessor: CMMC Professionals (CCPs and CCAs) are bound by the CMMC Code of Professional Conduct and the C3PAO ' s internal security protocols to ensure that any CUI provided by the Organization Seeking Certification (OSC) is handled securely.
Physical Protection (PE.L2-3.10.1 and PE.L2-3.10.2): These practices require that an organization limit physical access to systems and equipment to authorized users and protect the physical facility. If the provided " hoteling space " does not offer a locked container (like a cabinet) to secure the CUI overnight, leaving it in an unlocked drawer (Option C) or on the desk (Option B) would be a violation of CUI handling requirements and a security risk.
Why Option A is the best " Next " step: In the absence of on-site secure storage, the assessor must maintain positive control of the CUI. Taking the document to a secure location (such as the assessor ' s hotel room or person) where they can ensure it remains under their control is the only viable way to prevent unauthorized access by janitorial staff or other unauthorized personnel at the client site overnight.
Why other options are incorrect:
Option B and C: Both fail to protect the CUI from unauthorized access in a non-secure, shared environment.
Option D: Taking a picture of CUI on a personal phone is a major security violation (spillage), as personal devices are generally not authorized to store or process CUI.
Reference Documents:
CMMC Assessment Process (CAP) v1.0: Section regarding " Assessor Responsibilities for CUI and Proprietary Information. "
NIST SP 800-171 Rev 2: Physical Protection (PE) family (3.10.1, 3.10.2).
DoD Instruction 5200.48: " Controlled Unclassified Information (CUI), " which specifies that CUI must be protected by at least one physical barrier when not in the direct control of an authorized individual.
A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?
24 hours
48 hours
72 hours
96 hours
Contractors that handle Covered Defense Information (CDI) are required to report cyber incidents to the Department of Defense within 72 hours of discovery.
Supporting Extracts from Official Content:
DFARS 252.204-7012(c)(1): “When the Contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, the Contractor shall conduct a review… and rapidly report the cyber incident to DoD within 72 hours of discovery.â€
Why Option C is Correct:
The regulation explicitly specifies 72 hours.
Options A (24 hrs), B (48 hrs), and D (96 hrs) do not align with DFARS requirements.
References (Official CMMC v2.0 Content and Source Documents):
DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting.
CMMC v2.0 Governance – Source Documents list includes DFARS 252.204-7012.
===========
Which organization is the governmental authority responsible for identifying and marking CUI?
NARA
NIST
CMMC-AB
Department of Homeland Security
Step 1: Define CUI (Controlled Unclassified Information)
CUI is information thatrequires safeguarding or dissemination controlspursuant to and consistent with applicable law, regulations, and government-wide policies, butis not classifiedunder Executive Order 13526 or the Atomic Energy Act.
✅Step 2: Authority over CUI — NARA’s Role
NARA – National Archives and Records Administration, specifically theInformation Security Oversight Office (ISOO), is thegovernment-wide executive agentresponsible for implementing the CUI program.
Source:
32 CFR Part 2002 – Controlled Unclassified Information (CUI)
Executive Order 13556 – Controlled Unclassified Information
CUI Registry – https://www.archives.gov/cui
NARA:
Maintains theCUI Registry,
Issuesmarking and handling guidance,
DefinesCUI categoriesand their authority under law or regulation,
Trains and informs Federal agencies and contractors on CUI policy.
âŒWhy the Other Options Are Incorrect
B. NIST
✘NIST (National Institute of Standards and Technology) developstechnical standards(e.g., SP 800-171), but it doesnot define or mark CUI. It helps secure CUI once it’s identified.
C. CMMC-AB (now Cyber AB)
✘The Cyber AB is theCMMC ecosystem’s accreditation body, not a government agency, and hasno authority over CUI classification or marking.
D. Department of Homeland Security (DHS)
✘While DHS mayhandle and protect CUI internally, it is not the executive agent for the CUI program.
NARAis theofficial U.S. government authorityresponsible for defining, categorizing, and marking CUI via theCUI Registryand associated policies underExecutive Order 13556.
While conducting a CMMC Assessment, an individual from the OSC provides documentation to the assessor for review. The documentation states an incident response capability is established and contains information on incident preparation, detection, analysis, containment, recovery, and user response activities. Which CMMC practice is this documentation attesting to?
IR.L2-3.6.1: Incident Handling
IR.L2-3.6.2: Incident Reporting
IR.L2-3.6.3: Incident Response Testing
IR.L2-3.6.4: Incident Spillage
Understanding CMMC 2.0 Incident Response Practices
TheIncident Response (IR) domaininCMMC 2.0 Level 2aligns withNIST SP 800-171, Section 3.6, which defines requirements forestablishing and maintaining an incident response capability.
Why " A. IR.L2-3.6.1: Incident Handling " is Correct?
The documentation provideddescribes an incident response capability that includes preparation, detection, analysis, containment, recovery, and user response activities.
IR.L2-3.6.1specifically requires organizations toestablish an incident handling processcovering:
Preparation
Detection & Analysis
Containment
Eradication & Recovery
Post-Incident Response
Why Other Answers Are Incorrect?
B. IR.L2-3.6.2: Incident Reporting (Incorrect)
Incident reporting focuses on reporting incidents to external parties (e.g., DoD, DIBNet),which isnot what the provided documentation describes.
C. IR.L2-3.6.3: Incident Response Testing (Incorrect)
Incident response testing ensures that the response process is regularly tested and evaluated,which isnot the primary focus of the documentation provided.
D. IR.L2-3.6.4: Incident Spillage (Incorrect)
Incident spillage specifically refers to CUI exposure or handling unauthorized CUI incidents,which isnot the scenario described.
Conclusion
The correct answer isA. IR.L2-3.6.1: Incident Handling, as the documentationattests to the establishment of an incident response capability.
Who makes the final determination of the assessment method used for each practice?
CCP
osc
Site Manager
Lead Assessor
Who Determines the Assessment Method for Each Practice?
In aCMMC Level 2 Assessment, theLead Assessorhas thefinal authorityin determining theassessment methodused to evaluate each practice.
Key Responsibilities of the Lead Assessor
✅Ensures theCMMC Assessment Process (CAP) Guideis followed.
✅Determines whether a practice is evaluated usinginterviews, demonstrations, or document reviews.
✅Directs theCertified CMMC Professionals (CCPs)and other assessors on themethodologyfor gathering evidence.
✅Works under aCertified Third-Party Assessment Organization (C3PAO)to ensure proper assessment execution.
Why " Lead Assessor " is Correct?
CCP (Option A) assists in the assessment but does not make final decisionson methods.
OSC (Option B) is the Organization Seeking Certification, and they do not control assessment methodology.
Site Manager (Option C) may coordinate logistics but has no authority over assessment decisions.
Breakdown of Answer Choices
Option
Description
Correct?
A. CCP
âŒIncorrect–A CCPassistsbut doesnot determine assessment methods.
B. OSC
âŒIncorrect–The OSC is beingassessedand does not decide assessment methods.
C. Site Manager
âŒIncorrect–The Site Manager handles logistics butdoes not control assessment methods.
D. Lead Assessor
✅Correct – The Lead Assessor has the final say on the assessment method used.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)– Defines theLead Assessor’s rolein determining assessment methods.
Final Verification and Conclusion
The correct answer isD. Lead Assessor, as they havefinal decision-making authority over the assessment methodology.
A CMMC Assessment is being conducted at an OSC ' s HQ. which is a shared workspace in a multi-tenant building. The OSC is renting four offices on the first floor that can be locked individually. The first-floor conference room is shared with other tenants but has been reserved to conduct the assessment. The conference room has a desk with a drawer that does not lock. At the end of the day, an evidence file that had been sent by email is reviewed. What is the BEST way to handle this file?
Review it. print it, and put it in the desk drawer.
Review it, and make notes on the computer provided by the client.
Review it, print it, make notes, and then shred it in cross-cut shredder in the print room.
Review it. print it, and leave it in a folder on the table together with the other documents.
In the context of the Cybersecurity Maturity Model Certification (CMMC) 2.0, particularly at Level 2, organizations are required to implement stringent controls to protect Controlled Unclassified Information (CUI). This includes adhering to specific practices related to media protection and physical security.
Media Protection (MP):
MP.L2-3.8.1 – Media Protection: Organizations must protect (i.e., physically control and securely store) system media containing CUI, both paper and digital. This ensures that sensitive information is not accessible to unauthorized individuals.
Defense Innovation Unit
MP.L2-3.8.3 – Media Disposal: It is imperative to sanitize or destroy information system media containing CUI before disposal or release for reuse. This practice prevents potential data breaches from discarded or repurposed media.
Defense Innovation Unit
Physical Protection (PE):
PE.L2-3.10.2 – Monitor Facility: Organizations are required to protect and monitor the physical facility and support infrastructure for organizational systems. This includes ensuring that areas where CUI is processed or stored are secure and access is controlled.
Defense Innovation Unit
Application to the Scenario:
Given that the Organization Seeking Certification (OSC) operates within a shared, multi-tenant building and utilizes a common conference room for assessments, the following considerations are crucial:
Reviewing the Evidence File: The evidence file, which contains CUI, should be reviewed on a secure, authorized device to prevent unauthorized access or potential data leakage.
Printing the Evidence File: If printing is necessary, ensure that the printer is located in a secure area, and the printed documents are retrieved immediately to prevent unauthorized viewing.
Making Notes: Any notes derived from the evidence file should be treated with the same level of security as the original document, especially if they contain CUI.
Disposal of Printed Materials: After the assessment, all printed materials and notes containing CUI must be destroyed using a cross-cut shredder. Cross-cut shredding ensures that the information cannot be reconstructed, thereby maintaining confidentiality.
totem.tech
Options A and D are inadequate as they involve leaving sensitive information in unsecured locations, which violates CMMC physical security requirements. Option B, while secure in terms of digital handling, does not address the proper disposal of any physical copies that may have been made. Therefore, Option C is the best practice, aligning with CMMC 2.0 guidelines by ensuring that all physical media containing CUI are properly reviewed, securely stored during use, and thoroughly destroyed when no longer needed.
When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?
When under the control of the DoD
When the document is considered secret
When a document is being shared outside of the organization
When a derivative document ' s original information is not CUI
Background on Legacy Markings and CUI
Legacy markings refer to classification labels used before the implementation of the Controlled Unclassified Information (CUI) Program under DoD Instruction 5200.48.
Documents with legacy markings (such as “For Official Use Only†(FOUO) or “Sensitive But Unclassified†(SBU)) must be reviewed for re-marking or redaction to align with CUI requirements.
When Must Legacy Markings Be Updated?
If the document is retained internally (Answer A - Incorrect): Documents under DoD control do not require immediate re-marking unless they are being shared externally.
If the document is classified as Secret (Answer B - Incorrect): This question is about CUI, not classified information. Secret-level documents follow different marking rules under DoD Manual 5200.01.
If a document is being shared externally (Answer C - Correct):
According to DoD Instruction 5200.48, Section 3.6(a), organizations must review legacy markings before sharing documents outside the organization.
The document must be re-marked in compliance with the CUI Program before dissemination.
If the original document does not contain CUI (Answer D - Incorrect): The original source document ' s status does not affect the requirement to re-mark a derivative document if it contains CUI.
Conclusion
The correct answer is C: Documents with legacy markings must be re-marked or redacted when being shared outside the organization to comply with DoD CUI guidelines.
The Lead Assessor is presenting the Final Findings Presentation to the OSC. During the presentation, the Assessment Sponsor and OSC staff inform the assessor that they do not agree with the assessment results. Who has the final authority for the assessment results?
C3PAO
CMMC-AB
Assessment Team
Assessment Sponsor
Who Has the Final Authority Over Assessment Results?
During aCMMC Level 2 assessment, theCertified Third-Party Assessment Organization (C3PAO)is responsible for conducting and finalizing the assessment results.
Key Responsibilities of a C3PAO
✅Leads the assessmentand ensures it follows the CMMC Assessment Process (CAP).
✅Validates compliancewith CMMC Level 2 requirements based onNIST SP 800-171controls.
✅Finalizes the assessment resultsand submits them to theCMMC-ABand theDoD.
✅Handles disagreementsfrom the OSC but hasfinal decision-making authorityon results.
Why " C3PAO " is Correct?
The C3PAO has final authority over the assessment resultsafter considering all evidence and findings.
TheCMMC-AB (Option B) does not finalize assessments—it accredits C3PAOs and manages the certification ecosystem.
TheAssessment Team (Option C) supports the C3PAO but does not have final decision authority.
TheAssessment Sponsor (Option D) is a representative from the OSC and does not control the results.
Breakdown of Answer Choices
Option
Description
Correct?
A. C3PAO
✅Correct – C3PAOs finalize and submit assessment results.
B. CMMC-AB
âŒIncorrect–The CMMC-AB accredits C3PAOs but doesnot finalize results.
C. Assessment Team
âŒIncorrect–They conduct the assessment, but the C3PAO makes final decisions.
D. Assessment Sponsor
âŒIncorrect–This is arepresentative of the OSC, not the assessment authority.
Official References from CMMC 2.0 Documentation
CMMC Assessment Process Guide (CAP)– DefinesC3PAO authorityover final assessment results.
Final Verification and Conclusion
The correct answer isA. C3PAO, as theC3PAO has final decision-making authority over CMMC assessment results.
What is the MOST common purpose of assessment procedures?
Obtain evidence.
Define level of effort.
Determine information flow.
Determine value of hardware and software.
Theprimary goal of CMMC assessment proceduresis to determine whether anOrganization Seeking Certification (OSC)complies with the cybersecurity controls required for its certification level. Themost common purpose of assessment procedures is to obtain evidencethat verifies an organization has properly implemented security practices.
Why " A. Obtain Evidence " is Correct?
CMMC Assessments Require Evidence Collection
TheCMMC Assessment Process (CAP) Guideoutlines that assessors must use three methods to verify compliance:
Examine– Reviewing documentation, policies, and system configurations.
Interview– Speaking with personnel to confirm understanding and execution.
Test– Validating controls through operational or technical tests.
All these methods involve obtaining evidenceto support whether a security requirement has been met.
Alignment with NIST SP 800-171A
CMMC Level 2 assessments follow NIST SP 800-171A, which is designed for evidence-based verification.
Assessors rely on documented artifacts, system logs, configurations, and personnel testimony as evidence of compliance.
Why Other Answers Are Incorrect?
B. Define level of effort (Incorrect)
Thelevel of effortrefers to the time and resources needed for an assessment, but this is aplanningactivity, not the primary goal of an assessment.
C. Determine information flow (Incorrect)
While understandinginformation flowis important for security controls likedata protection and access control, themain purpose of an assessment is to gather evidence—not to determine information flow itself.
D. Determine value of hardware and software (Incorrect)
Asset valuation may be part of an organization’s risk management process, but CMMC assessmentsdo not focus on determining hardware or software value.
Conclusion
The correct answer isA. Obtain evidence, as theCMMC assessment process is evidence-drivento verify compliance with security controls.
An employee is the primary system administrator for an OSC. The employee will be a core part of the assessment, as they perform most of the duties in managing and maintaining the systems. What would the employee be BEST categorized as?
Analyzer
Inspector
Applicable staff
Demonstration staff
In the context of a Cybersecurity Maturity Model Certification (CMMC) assessment, the roles and responsibilities of individuals involved are clearly delineated to ensure a structured and effective evaluation process. The term " applicable staff " refers to personnel within the Organization Seeking Certification (OSC) who possess specific knowledge or expertise pertinent to the assessment. These individuals are integral to the assessment process as they provide essential information, demonstrate the implementation of security practices, and facilitate the assessment team ' s understanding of the organization ' s cybersecurity posture.
In this scenario, the employee serving as the primary system administrator is responsible for managing and maintaining the organization ' s systems. Given their comprehensive understanding of the system configurations, security controls, and operational procedures, this individual is best categorized as " applicable staff. " Their involvement is crucial during the assessment, as they can provide detailed insights, demonstrate compliance measures, and address technical inquiries from the assessment team.
The other options can be delineated as follows:
Analyzer:Typically refers to individuals who analyze data or security incidents, often as part of a security operations center. This role is not specifically defined within the CMMC assessment context.
Inspector:Generally denotes a person who examines or inspects systems and processes, possibly as part of an internal audit or compliance check. This term is not a standard designation within the CMMC assessment framework.
Demonstration staff:While this could imply personnel responsible for demonstrating systems or processes, it is not a recognized role within the CMMC assessment process.
Therefore, the primary system administrator, by virtue of their role and responsibilities, aligns with the " applicable staff " category, playing a pivotal role in facilitating a successful CMMC assessment.
How many domains does the CMMC Model consist of?
14 domains
43 domains
72 domains
110 domains
Step 1: Understanding CMMC Domains
TheCMMC Model consists of 14 domains, which are based on theNIST SP 800-171 control familieswith additional cybersecurity practices.
Eachdomaincontainspractices and processesthat define cybersecurity requirements for organizations seeking CMMC certification.
Validation of findings is an iterative process usually performed during the Daily Checkpoints throughout the entire assessment process. As a validation activity, why are the preliminary findings important?
It allows the OSC to comment and provide additional evidence.
It determines whether the OSC will be rated MET or NOT MET on their assessment.
It confirms that the Assessment Team ' s findings are right and cannot be changed.
It corroborates the Assessment Team ' s understanding of the CMMC practices and controls.
1. Understanding the Validation of Findings in CMMC Assessments
Validation of findings is an essential part of theCMMC assessment process, ensuring that observations and preliminary conclusions drawn by the assessment team are accurate, fair, and based on complete evidence. This process occurs iteratively during theDaily Checkpointsand is fundamental in determining the overall compliance status of theOrganization Seeking Certification (OSC).
2. The Role of Preliminary Findings in the Assessment Process
Preliminary findings arenot finalbut rather a mechanism for ensuring transparency, accuracy, and fairness. These findings serve several key purposes:
Allows for OSC Input & Clarification: The OSC has an opportunity to review andprovide additional evidencethat may address deficiencies identified by the assessment team.
Prevents Misinterpretations: By allowing the OSC to comment, the assessment team can refine or correct their understanding of the OSC ' s implementation of CMMC practices.
Supports Fair and Informed Ratings: Before finalizing MET or NOT MET determinations, the assessment team ensures they have considered all relevant evidence.
Encourages a Collaborative Assessment Process: This validation activity fosters open communication between assessors and the OSC, reducing disputes and misunderstandings.
3. Why Answer Choice " A " is Correct
The primary purpose of preliminary findings is to allow theOSC to comment and provide additional evidencebefore final determinations are made.
This aligns withCMMC Assessment Process guidance, which emphasizes iterative validation of findings throughDaily Checkpoints and Final Outbriefdiscussions.
The validation of findings ensures thatOSC responses and supplementary evidence are considered, making the assessment process more accurate and fair.
4. Why Other Answer Choices Are Incorrect
Option
Reason for Elimination
B. It determines whether the OSC will be rated MET or NOT MET on their assessment.
Incorrect: Preliminary findings do not directly determine the final rating. The assessment team reviews all collected evidence before making a final decision.
C. It confirms that the Assessment Team ' s findings are right and cannot be changed.
Incorrect: Findings arenot finalat the preliminary stage. The OSC has the opportunity to challenge findings by providing new or clarifying evidence.
D. It corroborates the Assessment Team ' s understanding of the CMMC practices and controls.
Partially Correct but Not the Best Answer: While validation helps refine understanding, itsprimary function is to allow OSC input, making optionA the most accurate choice.
5. Official CMMC References Supporting This Answer
CMMC Assessment Process (CAP) Document:
Section 5.3 – Validation of Findings: " The OSC is given the opportunity to provide additional evidence and comments to clarify or supplement preliminary assessment results. "
Section 5.4 – Daily Checkpoints: " The assessment team discusses preliminary findings with the OSC, allowing the organization to address concerns in real time. "
CMMC 2.0 Level 2 Scoping & Assessment Guide:
Confirms that the assessment process includes continuous dialogue with the OSC before final determinations are made.
6. Conclusion
Preliminary findings are acrucial validation stepin CMMC assessments, ensuring that organizations have the opportunity toprovide additional evidence and clarify potential misunderstandings. This iterative process improves accuracy and fairness in determining compliance with CMMC requirements. Therefore, the correct answer is:
A. It allows the OSC to comment and provide additional evidence.
When assessing an OSC for CMMC: the Lead Assessor should use the information from the Discussion and Further Discussion sections in each practice because it:
is normative for an OSC to follow.
contains examples that an OSC must implement.
is mandatory and aligns with FAR Clause 52.204-21.
provides additional information to facilitate the assessment of the practice.
Understanding the Role of " Discussion " and " Further Discussion " Sections in CMMC Assessments
When assessing anOrganization Seeking Certification (OSC)forCMMC compliance, theLead Assessorrelies on various sources of guidance.
Eachpracticein the CMMC model includes:
The Practice Statement– The official requirement the OSC must meet.
Discussion Section– Providesclarifications, interpretations, and guidancefor implementation.
Further Discussion Section– Expands on the practice,offering additional details, best practices, and examples.
These sections arenot mandatory, but they help assessorsinterpret and evaluatewhether an OSC has met the practice requirements.
Why " Provides Additional Information to Facilitate the Assessment " is Correct?
TheDiscussion and Further Discussion sectionsprovidecontext, explanations, and examplesto assist theLead Assessorin understanding how an OSC might demonstrate compliance.
Theyhelp guide the assessment processbut arenot prescriptiveormandatoryfor an OSC.
Theassessor uses these sectionsto verify whether theOSC ' s implementation meets the intent of the requirement.
Breakdown of Answer Choices
Option
Description
Correct?
A. Is normative for an OSC to follow.
âŒIncorrect–The sections areguidance, notnormative (mandatory)requirements.
B. Contains examples that an OSC must implement.
âŒIncorrect–Examples aresuggestions, notmandatory implementations.
C. Is mandatory and aligns with FAR Clause 52.204-21.
âŒIncorrect–The " Discussion " sections arenot mandatoryand arenot tied directlyto FAR 52.204-21.
D. Provides additional information to facilitate the assessment of the practice.
✅Correct – These sections help the assessor evaluate compliance but do not mandate specific implementations.
Official References from CMMC 2.0 Documentation
TheCMMC Assessment Guidestates that theDiscussion and Further Discussion sections provide clarificationsto help both assessors and OSCs.
These sections arenot bindingbut serve asinterpretive guidanceto assist in assessments.
Final Verification and Conclusion
The correct answer isD. Provides additional information to facilitate the assessment of the practice.This aligns withCMMC 2.0 documentation and assessment guidelines.
SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC ' s assessment. How does this affect the assessment scope?
Any existing telephone system is in scope even if it is not using VoIP technology.
An error has been made and the Lead Assessor should be contacted to correct the error.
VoIP technology is within scope, and it uses FlPS-validated encryption, so it does not need to be assessed.
VoIP technology is not used within scope boundary, so no assessment procedures are specified for this practice.
Understanding SC.L2-3.13.14 – Control and Monitor the Use of VoIP Technologies
TheCMMC 2.0 Level 2requirementSC.L2-3.13.14comes fromNIST SP 800-171, Security Requirement 3.13.14, which mandates that organizations mustcontrol and monitor the use of VoIP (Voice over Internet Protocol) technologiesif used within their system boundary.
If a systemdoes not use VoIP technology, then this control isNot Applicable (N/A)because there is nothing to assess.
Why Option D is Correct
When a requirement is marked as Not Applicable (N/A), it means the OSC does not use the technology or process covered by that controlwithin its assessment boundary.
No assessment procedures are neededsince there is no VoIP system to evaluate.
Option A (Existing telephone system in scope)is incorrect becausetraditional (non-VoIP) telephone systems are not covered by SC.L2-3.13.14—only VoIP is within scope.
Option B (Error, contact the Lead Assessor)is incorrect because markingSC.L2-3.13.14 as N/A is valid if VoIP is not used. This is not an error.
Option C (VoIP in scope but using FIPS-validated encryption, so it doesn’t need to be assessed)is incorrect becauseeven if VoIP uses FIPS-validated encryption, the control would still need to be assessed to ensure monitoring and usage control are in place.
Official CMMC Documentation References
CMMC 2.0 Level 2 Assessment Guide – SC.L2-3.13.14
NIST SP 800-171, Security Requirement 3.13.14
CMMC Scoping Guidance – Determining Not Applicable (N/A) Practices
Final Verification
IfVoIP is not used within the OSC’s system boundary, the control does not require assessment, making Option D the correct answer.
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
Have a security clearance
Be a senior person in the company
Demonstrate expertise on the CMMC requirements
Provide clarity and understanding of their practice activities
Per the CMMC Assessment Process (CAP), when planning an assessment, the Lead Assessor must coordinate with the Organization Seeking Certification (OSC) to select interview participants who can provide clarity and understanding of their practice activities. The intent is to interview individuals directly involved with and knowledgeable about the processes and practices under review, rather than selecting personnel based solely on rank, clearance, or formal expertise in CMMC.
This ensures the assessment is evidence-based and grounded in how practices are actually performed within the OSC.
Reference Documents:
CMMC Assessment Process (CAP), v1.0
At which CMMC Level do the Security Assessment (CA) practices begin?
Level 1
Level 2
Level 3
Level 4
Step 1: Understand the “CA†Domain – Security Assessment
TheCA (Security Assessment)domain includes practices related to:
Planning security assessments,
Performing periodic reviews,
Managing plans of action and milestones (POA & Ms).
These practices derive fromNIST SP 800-171, specifically:
CA.2.157– Develop, document, and periodically update security plans,
CA.2.158– Periodically assess security controls,
CA.2.159– Develop and implement POA & Ms.
✅Step 2: Review CMMC Levels
Level 1 (Foundational):
Implements only the17 practicesfromFAR 52.204-21
Doesnot include the CA domain
Level 2 (Advanced):
Implements110 practicesfromNIST SP 800-171, including CA.2.157–159
First levelwhereSecurity Assessment (CA)practices are required
Level 3:
Not yet finalized but intended to include selected controls fromNIST SP 800-172
âŒWhy the Other Options Are Incorrect
A. Level 1
✘No CA domain practices are present at Level 1.
C. Level 3 / D. Level 4
✘These levels build on CA practices but do not represent thestarting point.
TheSecurity Assessment (CA)domain practices begin atCMMC Level 2, as part of the implementation ofNIST SP 800-171.
An Assessment Team is conducting interviews with team members about their roles and responsibilities. The team member responsible for maintaining the antivirus program knows that it was deployed but has very little knowledge on how it works. Is this adequate for the practice?
Yes, the antivirus program is available, so it is sufficient.
Yes, antivirus programs are automated to run independently.
No, the team member must know how the antivirus program is deployed and maintained.
No, the team member ' s interview answers about deployment and maintenance are insufficient.
For a practice to beadequately implementedin aCMMC Level 2 assessment, theresponsible personnel must demonstrate knowledge of deployment, maintenance, and operationof security tools such asantivirus programs. Simply having the tool in place isnot sufficient—there must be evidence that it isproperly configured, updated, and monitoredto protect against threats.
Step-by-Step Breakdown:
✅1. Relevant CMMC and NIST SP 800-171 Requirements
CMMC Level 2 aligns with NIST SP 800-171, which includes:
Requirement 3.14.5 (System and Information Integrity - SI-3):
" Employautomatedmechanisms toidentify, report, and correctsystem flaws in a timely manner. "
Requirement 3.14.6 (SI-3(2)):
" Employautomated toolsto detect and prevent malware execution. "
These requirements imply that theperson responsible for antivirus must understand how it is deployed and maintainedto ensure compliance.
✅2. Why the Team Member’s Knowledge is Insufficient
Antivirus tools requireregular updates,configuration adjustments, andmonitoringto function properly.
The responsible team member must:
Knowhow the antivirus was deployedacross systems.
Be able toconfirm updates, logs, and alerts are monitored.
Understand how torespond to malware detectionsand failures.
If the team member lacks this knowledge, assessors maydetermine the practice is not fully implemented.
✅3. Why the Other Answer Choices Are Incorrect:
(A) Yes, the antivirus program is available, so it is sufficient.âŒ
Incorrect:Just having antivirus softwareinstalleddoes not prove compliance. It must bemanaged and maintained.
(B) Yes, antivirus programs are automated to run independently.âŒ
Incorrect:While automation helps, security toolsrequire oversight, updates, and configuration.
(D) No, the team member ' s interview answers about deployment and maintenance are insufficient.âŒ
Partially correct but incomplete:Themain issueis that the team membermust have sufficient knowledge, not just that their answers are weak.
Final Validation from CMMC Documentation:
TheCMMC Assessment Guide for SI-3 and SI-3(2)states that personnel mustunderstand the function, deployment, and maintenance of security toolsto ensure proper implementation.
Thus, the correct answer is:
Which domain references the requirements needed to handle physical or digital assets containing CUI?
Media Protection (MP)
Physical Protection (PE)
System and Information Integrity (SI)
System and Communications Protection (SC)
Understanding the Media Protection (MP) Domain
TheMedia Protection (MP) domaininCMMC 2.0focuses on the security requirements needed to handlephysical or digital mediacontainingControlled Unclassified Information (CUI).
This domain includes controls for:
Protecting digital and physical mediathat store CUI.
Sanitizing and destroying mediabefore disposal or reuse.
Restricting access to CUI mediato authorized personnel only.
Why the Correct Answer is " A. Media Protection (MP) " ?
TheMP domaindirectly addresses the requirements for handlingCUI media, includingencryption, access control, storage, and disposal.
CMMC 2.0Level 2aligns withNIST SP 800-171, which includesMP controlsfor managing media containing CUI.
Why Not the Other Options?
B. Physical Protection (PE)→Incorrect
PEfocuses onphysical security(e.g., facility access, visitor logs, physical barriers),not the handling of CUI on media.
C. System and Information Integrity (SI)→Incorrect
SIdeals withsystem monitoring, vulnerability management, and incident response, not media protection.
D. System and Communications Protection (SC)→Incorrect
SCcoversnetwork security, encryption, and secure communications, but does not specifically focus on media handling.
Relevant CMMC 2.0 References:
CMMC Level 2 Practice MP.3.125– Protects CUI by ensuring proper handling ofmedia containing CUI.
NIST SP 800-171 (MP Family)– Establishes security requirements for handlingdigital and physical mediacontaining CUI.
CMMC Scoping Guide (Nov 2021)– ConfirmsMP controls apply to all media that store, process, or transmit CUI.
Final Justification:
SinceMedia Protection (MP) directly addresses the handling of assets containing CUI, the correct answer isA. Media Protection (MP).
A member of the Assessment Team has been assigned the responsibility of maintaining and protecting information from the OSC. The Assessment Results Package, PCI, CUI, and any notes must be retained and protected from disclosure. To protect the OSC ' s information, which principle should be used, and for how long?
Cryptography and hashing for 1 year
Confidentiality and non-disclosure for 3 years
Availability, confidentiality, and integrity for 1 year
Authentication, authorization, and accounting for 3 years
The core protection principle for OSC-provided assessment information (including PCI/CUI, assessment workpapers/notes, and the assessment results package ) is confidentiality / non-disclosure . The CMMC rules require assessors not to disclose OSC information outside the assessment participants, except as required by law. For example, CMMC assessor requirements include not sharing information about an OSC obtained during pre-assessment and assessment activities with anyone not involved in that specific assessment .
For retention, the authoritative requirement in the CMMC Program rule (32 CFR Part 170) is that assessment-related records are maintained for six (6) years , unless disposition is otherwise authorized by the CMMC PMO. This record set includes assessment materials and working papers generated during Level 2 certification assessments, and it also includes contractual agreements.
Important correction to the multiple-choice options: none of the answers list the official six-year retention period. The best available option is therefore B because it correctly captures the required confidentiality/non-disclosure principle—but the “ 3 years †duration in the option does not match the official CMMC v2.0 retention requirement (which is 6 years ).
===========
Evidence gathered from an OSC is being reviewed. Based on the assessment and organizational scope, the Lead Assessor requests the Assessment Team to verify that the coverage by domain, practice. Host Unit. Supporting Organization/Unit, and enclaves are comprehensive enough to rate against each practice. Which criteria is the assessor referring to?
Adequacy
Capability
Sufficiency
Objectivity
Step 1: Understand the Definitions of Evidence Evaluation Criteria
TheCMMC Assessment Process (CAP)introduces two key criteria for evaluating evidence:
Adequacy– Does the evidencealign with the practice?
Sufficiency– Is the evidencecomprehensive enoughin terms ofcoverage across systems, users, and scope?
CAP v1.0 – Section 3.5.4:
“Evidence must be evaluated for bothadequacy(is it the right evidence?) andsufficiency(is there enough of it across all in-scope assets and areas?) to score a practice as MET.â€
✅Step 2: Applying to the Scenario
In the question, the Lead Assessor is asking the team toverify that evidence is sufficient across:
Domains
Practices
Host Units
Supporting Organizations
Enclaves
âž¡ï¸This is adirect reference to sufficiency, which evaluates whether thebreadth and depthof evidence is enough to make an informed judgment that the control is truly implemented across theentire assessed environment.
âŒWhy the Other Options Are Incorrect
A. Adequacy
✘Adequacy refers to therelevanceof the evidence to the specific practice — not itscoverageacross scope.
B. Capability
✘Not a term used in evidence validation within CMMC CAP documentation.
D. Objectivity
✘While objectivity is important, it refers to theunbiased nature of assessment activities, not to theextent of evidence coverage.
When an assessor evaluates whether the evidence is broad enough across all necessary systems, units, and enclaves to score a practice as MET, they are evaluatingsufficiency— one of the two core criteria for evidence validity in a CMMC assessment.
Which statement BEST describes the key references a Lead Assessor should refer to and use the:
DoD adequate security checklist for covered defense information.
CMMC Model Overview as it provides assessment methods and objects.
safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment.
published CMMC Assessment Guide practice descriptions for the desired certification level.
Key References for a Lead Assessor in a CMMC Assessment
ALead Assessorconducting aCMMC assessmentmust rely onofficial CMMC guidance documentsto evaluate whether anOrganization Seeking Certification (OSC)meets the required cybersecurity practices.
Most Relevant Reference: CMMC Assessment Guide
TheCMMC Assessment Guideprovidesdetailed descriptionsof eachpractice and processat the specificCMMC level being assessed.
It defines:
✔Theassessment objectivesfor each practice.
✔Therequired evidencefor compliance.
✔Thescoring criteriato determine if a practice isMET or NOT MET.
Why is the Correct Answer " D. Published CMMC Assessment Guide practice descriptions for the desired certification level " ?
A. DoD adequate security checklist for covered defense information → Incorrect
TheDoD adequate security checklistis related toDFARS 252.204-7012 compliance, butCMMC assessmentsfollow theCMMC Assessment Guide.
B. CMMC Model Overview as it provides assessment methods and objects → Incorrect
TheCMMC Model Overviewprovideshigh-level guidance, butdoes not contain specific assessment criteria.
C. Safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment → Incorrect
FAR 52.204-21is relevant toCMMC Level 1 (FCI protection), butCMMC Level 2 follows NIST SP 800-171and requiresCMMC Assessment Guidesfor validation.
D. Published CMMC Assessment Guide practice descriptions for the desired certification level → Correct
TheCMMC Assessment Guideis theofficial documentused to determine if anOSC meets the required security practices for certification.
CMMC 2.0 References Supporting This Answer:
CMMC Assessment Process (CAP) Document
Specifies thatLead Assessors must use the CMMC Assessment Guidefor official scoring.
CMMC Assessment Guide for Level 1 & Level 2
Providesdetailed descriptions, assessment methods, and scoring criteriafor each practice.
CMMC-AB Guidance for Certified Third-Party Assessment Organizations (C3PAOs)
Confirms thatCMMC assessments must follow the Assessment Guide, not general DoD security policies.
Final Answer:
✔D. Published CMMC Assessment Guide practice descriptions for the desired certification level.
A Lead Assessor is performing a CMMC readiness review. The Lead Assessor has already recorded the assessment risk status and the overall assessment feasibility. At MINIMUM, what remaining readiness review criteria should be verified?
Determine the practice pass/fail results.
Determine the preliminary recommended findings.
Determine the initial model practice ratings and record them.
Determine the logistics. Assessment Team, and the evidence readiness.
Understanding the CMMC Readiness Review Process
ALead Assessorconducting aCMMC Readiness Reviewevaluates whether anOrganization Seeking Certification (OSC)is prepared for a formal assessment.
After recording theassessment risk statusandoverall assessment feasibility, theminimum remaining criteriato be verified include:
Logistics Planning– Ensuring that the assessment timeline, locations, and necessary resources are in place.
Assessment Team Preparation– Confirming that assessors and required personnel are available and briefed.
Evidence Readiness– Ensuring the OSC has gathered all required artifacts and documentation for review.
Breakdown of Answer Choices
Option
Description
Correct?
A. Determine the practice pass/fail results.
Happensduringthe formal assessment, not the readiness review.
âŒIncorrect
B. Determine the preliminary recommended findings.
Findings are only madeafterthe full assessment.
âŒIncorrect
C. Determine the initial model practice ratings and record them.
Ratings are assigned during theassessment, not readiness review.
âŒIncorrect
D. Determine the logistics, Assessment Team, and the evidence readiness.
✅Essential readiness criteria that must be confirmedbeforeassessment starts.
✅Correct
Official Reference from CMMC 2.0 Documentation
TheCMMC Assessment Process Guide (CAP)states that readiness review ensureslogistics, assessment team availability, and evidence readinessare verified.
Final Verification and Conclusion
The correct answer isD. Determine the logistics, Assessment Team, and the evidence readiness.This aligns withCMMC readiness review requirements.
Which phase of the CMMC Assessment Process includes developing the assessment plan?
Phase 1
Phase 2
Phase 3
Phase 4
Understanding the Phases of the CMMC Assessment Process
TheCMMC Assessment Process (CAP)consists of multiple phases, with each phase focusing on a different aspect of the assessment.Developing the assessment planoccurs inPhase 1, which is thePre-Assessment Phase.
Key Activities in Phase 1 – Pre-Assessment Phase
Engagement Agreement: TheOSC (Organization Seeking Certification)and theCertified Third-Party Assessment Organization (C3PAO)formalize the assessment contract.
Developing the Assessment Plan: TheLead Assessorand the assessment team create anAssessment Plan, which outlines:
Scope of the assessment
CMMC Level requirements
Assessment methodology
Timeline and logistics
Initial Data Collection: Review of system documentation, policies, and relevant security controls.
Why is the Correct Answer " Phase 1 " (A)?
A. Phase 1 → Correct
Phase 1 is where the assessment plan is developed.
It ensuresclarity on scope, methodology, and logistics before the assessment begins.
B. Phase 2 → Incorrect
Phase 2 is theAssessment Conduct Phase, where assessorsexecutethe plan by examining evidence and interviewing personnel.
C. Phase 3 → Incorrect
Phase 3 is thePost-Assessment Phase, which involvesfinalizing findings and submitting reports, not developing the plan.
D. Phase (Incomplete Answer) → Incorrect
The question requires a specific phase, and the correct one isPhase 1.
CMMC 2.0 References Supporting this Answer:
CMMC Assessment Process (CAP) Document
DefinesPhase 1as the stage where the assessment plan is developed.
CMMC Accreditation Body (CMMC-AB) Guidelines
Specifies thatplanning and pre-assessment activities occur in Phase 1.
CMMC 2.0 Certification Workflow
Outlines the assessment planning process as part of theinitial engagementbetween theC3PAO and the OSC.
Which document is used to protect sensitive and confidential information from being made available by the recipient of that information?
Legal agreement
CMMC agreement
Assessment agreement
Non-disclosure agreement
The correct document is a Non-Disclosure Agreement (NDA) , because its specific purpose is to restrict a receiving party from disclosing sensitive or confidential information to unauthorized parties. In the official CMMC Assessment Process (CAP) v2.0 , NDAs are called out directly as a required element of the contracting relationship for a Level 2 certification assessment.
CAP v2.0 states that the C3PAO and the OSC must execute a written contractual agreement for the assessment and then specifies that “A mutual non-disclosure agreement (NDA) between the parties shall be incorporated into the contractual agreement or negotiated and executed in a separate document (e.g., stand-alone NDA, master services agreement, etc.).â€
This is important because CMMC assessments can involve access to highly sensitive organizational information, including details about system architectures, security implementations, and potentially CUI handling processes. The CAP’s NDA requirement supports controlling dissemination of that information and reinforces the broader confidentiality expectations placed on assessment participants.
While an “assessment agreement†or generic “legal agreement†might contain confidentiality clauses, CAP v2.0 explicitly identifies the NDA instrument (either embedded or standalone) as the mechanism to protect information exchanged during the assessment engagement. Therefore, the best answer—consistent with CMMC v2.0 official process documentation—is D (Non-disclosure agreement) .
How many cybersecurity levels does the CMMC Model structure contain?
2 Levels.
3 Levels.
5 Levels.
4 Levels.
The correct answer is B , 3 Levels. The official CMMC 2.0 Model Overview states that there are three levels within CMMC: Level 1, Level 2, and Level 3 . It explains that the model measures implementation of cybersecurity requirements at three levels, with each level containing a defined set of CMMC practices. Level 1 is focused on basic safeguarding of Federal Contract Information, Level 2 is focused on protection of Controlled Unclassified Information using requirements aligned to NIST SP 800-171, and Level 3 is intended for higher-risk programs requiring enhanced protection.
This is a major difference between CMMC 2.0 and the earlier CMMC 1.0 structure. CMMC 1.0 used five maturity levels, but CMMC 2.0 simplified the model to three cybersecurity levels. Therefore, option C , 5 Levels, reflects the older CMMC 1.0 structure and is not correct for CMMC 2.0. Option A , 2 Levels, is incorrect because it omits one of the three official levels. Option D , 4 Levels, is also incorrect because the official CMMC 2.0 model does not contain four levels. The bottom line is that CMMC 2.0 contains three cybersecurity levels: Level 1 Foundational, Level 2 Advanced, and Level 3 Expert .
After completing a Level 2 Assessment, a C3PAO is preparing to upload the Assessment Results Package to Enterprise Mission Assurance Support Service. Which document MUST be included as part of the final assessment results package?
Final Report
Certification rating
Summary-level findings
All Daily Checkpoint logs
Understanding the Assessment Results Package Submission
After completing aCMMC Level 2 Assessment, theCertified Third-Party Assessment Organization (C3PAO)mustsubmit the final assessment results packageto theEnterprise Mission Assurance Support Service (eMASS)system.
Key Required Document: Final Report
TheFinal Reportis themandatory documentthatcontains all assessment details, findings, and scoring.
It serves as theofficial record of the assessmentanddetermines certification eligibility.
Why is the Correct Answer " Final Report " (A)?
A. Final Report → Correct
TheFinal Report is requiredin the submission package todocument assessment results officially.
It includes asummary of findings, scoring, and recommendations.
B. Certification rating → Incorrect
The C3PAO does not issue certification ratings—theDoDandCMMC-ABdetermine certification status after reviewing the Final Report.
C. Summary-level findings → Incorrect
While the Final Reportincludessummary findings, astandalone summary-level findings document is not a required upload.
D. All Daily Checkpoint logs → Incorrect
Checkpoint logsare part of the internal assessment process butare not required in the final eMASS submission.
CMMC 2.0 References Supporting This Answer:
CMMC Assessment Process (CAP) Document
Specifies that theFinal Report must be submitted to eMASSafter a Level 2 assessment.
CMMC-AB Guidelines for C3PAOs
States that theFinal Report is the key document used to determine certification status.
DFARS 252.204-7021 (CMMC Requirements Clause)
Requires the assessment results to be documented in an official report and submitted via eMASS.
Final Answer:
✔A. Final Report
Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1. Guidelines for Media Sanitation?
Clear, purge, destroy
Clear redact, destroy
Clear, overwrite, purge
Clear, overwrite, destroy
Understanding NIST SP 800-88 Rev. 1 and Media Sanitization
TheNIST Special Publication (SP) 800-88 Revision 1, Guidelines for Media Sanitization, provides guidance onsecure disposalof data from various types of storage media to prevent unauthorized access or recovery.
Three Categories of Data Disposal in NIST SP 800-88 Rev. 1
Clear
Useslogical techniquesto remove data from media, making it difficult to recover usingstandard system functions.
Example:Overwriting all datawith binary zeros or ones on a hard drive.
Applies to:Magnetic media, solid-state drives (SSD), and non-volatile memorywhen the media isreused within the same security environment.
Purge
Usesadvanced techniquesto make data recoveryinfeasible, even with forensic tools.
Example:Degaussinga magnetic hard drive orcryptographic erasure(deleting encryption keys).
Applies to:Media that is leaving organizational control or requires a higher level of assurance than " Clear " .
Destroy
Physicallydamages the mediaso that data recovery isimpossible.
Example:Shredding, incinerating, pulverizing, or disintegratingstorage devices.
Applies to:Highly sensitive data that must be permanently eliminated.
Why " A. Clear, Purge, Destroy " is Correct?
B. Clear, Redact, Destroy (Incorrect)– " Redact " is a term used for document sanitization,notdata disposal.
C. Clear, Overwrite, Purge (Incorrect)– " Overwrite " is a method within " Clear, " but it isnot a top-level categoryin NIST SP 800-88.
D. Clear, Overwrite, Destroy (Incorrect)– " Overwrite " is a sub-method of " Clear, " but " Purge " is missing, making this incorrect.
Conclusion
The correct answer isA. Clear, Purge, Destroy, as these are thethree official categoriesof data disposal inNIST SP 800-88 Revision 1.
The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?
Expert
Advanced
Optimizing
Continuously Improved
Understanding CMMC 2.0 Levels and Their Descriptions
TheCybersecurity Maturity Model Certification (CMMC) 2.0consists ofthree levels, each representing increasing cybersecurity maturity:
Level 1 – Foundational
Focuses onbasic cyber hygiene
Implements17 practicesaligned withFAR 52.204-21
Primarily protectsFederal Contract Information (FCI)
Level 2 – Advanced(Correct Answer)
Focuses onprotecting Controlled Unclassified Information (CUI)
Implements110 practicesaligned withNIST SP 800-171
Requirestriennial third-party assessments for critical programs
Level 3 – Expert
Focuses onadvanced cybersecurityagainstAPT (Advanced Persistent Threats)
ImplementsNIST SP 800-171 and additional NIST SP 800-172 controls
Requirestriennial government-led assessments
Why " B. Advanced " is Correct?
TheCMMC 2.0 framework explicitly describes Level 2 as " Advanced. "
Italigns with NIST SP 800-171to ensure robustCUI protection.
Why Other Answers Are Incorrect?
A. Expert (Incorrect)– This describesLevel 3, not Level 2.
C. Optimizing (Incorrect)– Not a defined CMMC level description.
D. Continuously Improved (Incorrect)– CMMC does not use this terminology.
Conclusion
The correct answer isB. Advanced, which accurately describesCMMC Level 2.
A CCP is consulting with an OSC. In the course of an interview, the OSC representative asks the CCP what basic safeguarding requirements must be met with respect to CMMC Level 1. The CCP tells the representative that this publication contains all the requirements from:
NIST SP 800-171.
DFARS Clause 252.202-7014.
DFARS Clause 252.204-7012.
FAR Clause 52.204-21.
The correct answer is D because CMMC Level 1 is based on the basic safeguarding requirements in FAR Clause 52.204-21 , not on the full NIST SP 800-171 or DFARS 252.204-7012 requirements. The official CMMC Model Overview states that Level 1 focuses on protecting Federal Contract Information (FCI) and consists of security requirements that correspond to the basic safeguarding requirements specified in 48 CFR 52.204-21 , commonly referred to as the FAR Clause. It also states that Level 2 is the level that incorporates the 110 security requirements from NIST SP 800-171 Rev. 2 for protection of Controlled Unclassified Information (CUI) .
FAR 52.204-21 applies to covered contractor information systems that process, store, or transmit Federal Contract Information. The clause requires contractors to apply basic safeguarding requirements and procedures, including limiting system access to authorized users, controlling external connections, protecting information on publicly accessible systems, identifying and authenticating users, and sanitizing or destroying media containing FCI before disposal or reuse.
Option A is incorrect because NIST SP 800-171 is associated with CMMC Level 2, not Level 1. Option B is incorrect because the cited DFARS clause number is not the CMMC Level 1 source. Option C is incorrect because DFARS 252.204-7012 is tied to safeguarding covered defense information and implementing NIST SP 800-171 for CUI, not the Level 1 basic safeguarding baseline.
A contractor provides services and data to the DoD. The transactions that occur to handle FCI take place over the contractor ' s business network, but the work is performed on contractor-owned systems, which must be configured based on government requirements and are used to support a contract. What type of Specialized Asset are these systems?
loT
Restricted IS
Test equipment
Government property
Understanding Restricted Information Systems (IS) in CMMC Scoping
InCMMC 2.0,Specialized Assetsrefer to assets that do not fit traditional IT system categories but still play a role inprocessing, storing, or transmitting Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The four categories ofSpecialized Assetsin theCMMC Scoping Guideinclude:
Internet of Things (IoT) Devices– Smart or network-connected devices.
Restricted Information Systems (Restricted IS)– Systems that arecontractually requiredto beconfigured to government specifications.
Test Equipment– Devices used for specialized testing or measurement.
Government Property– Equipment owned by theU.S. Governmentbut used by contractors.
Why " B. Restricted IS " is Correct?
The contractor-owned systems in question areconfigured based on government requirementsandused to support a DoD contract.
Restricted ISassets arecontractually requiredto meet government security requirements andhandle DoD-related information.
These systemsdo not fall under general IT assets but instead require special handling, making them a Restricted ISper theCMMC Scoping Guide.
Why Other Answers Are Incorrect?
A. IoT (Incorrect)
IoT devices includesmart devices, sensors, and embedded systems, but the contractor ' s business systems are not classified as IoT.
C. Test Equipment (Incorrect)
The contractor’s systems areused for handling FCI, not for testing or measurement.
D. Government Property (Incorrect)
The systems arecontractor-owned, not owned by theU.S. Government, so they do not qualify asGovernment Property.
Conclusion
The correct answer isB. Restricted IS, as the systems arecontractor-owned but must follow DoD security requirements.
Which document is the BEST source for determining the sources of evidence for a given practice?
NISTSP 800-53
NISTSP 800-53A
CMMC Assessment Scope
CMMC Assessment Guide
TheCMMC Assessment Guideis the best source for determining the sources of evidence for a given practice because it provides specific guidance on how organizations should implement and demonstrate compliance with CMMC practices. Each CMMC level has its own assessment guide (e.g.,CMMC Assessment Guide – Level 1, Level 2), detailing expected evidence and assessment procedures.
Detailed Justification:
CMMC Assessment Guide (Primary Source for Evidence)
TheCMMC Assessment Guideexplicitly outlines the evidence required to verify compliance with each practice.
It provides detailed instructions on assessment objectives, clarifying what assessors should look for when determining compliance.
The guide breaks down each practice intoassessment objectives, helping organizations prepare appropriate documentation and artifacts.
Other Documents and Why They Are Not the Best Choice:
NIST SP 800-53 (Option A)
WhileNIST SP 800-53provides a comprehensive catalog of security and privacy controls, it does not focus on CMMC-specific evidence requirements.
It serves as a foundational cybersecurity framework but does not define the specific artifacts required for CMMC assessment.
NIST SP 800-53A (Option B)
NIST SP 800-53Aprovides guidance on assessing security controls but is not tailored to the CMMC framework.
It includes general control assessment procedures, but theCMMC Assessment Guideis more precise in defining the evidence needed for CMMC compliance.
CMMC Assessment Scope (Option C)
TheCMMC Assessment Scopedocument outlines which systems, assets, and processes are subject to assessment.
While important for defining boundaries, it does not provide details on specific evidence requirements for each practice.
References from Official CMMC Documents:
CMMC Assessment Guide (Level 2) – Section on " Assessment Objectives "
This document details how evidence is collected and evaluated for each CMMC practice.
Example: ForAC.L2-3.1.1 (Access Control – Limit System Access), the guide specifies that assessors should verify documented policies, system configurations, and audit logs.
CMMC Model Overview (Official DoD Documents)
Emphasizes thatCMMC Assessment Guidesare the official reference for determining sources of evidence.
Conclusion:
TheCMMC Assessment Guideis the most authoritative source for determining the required evidence for a given practice in CMMC assessments. It provides detailed breakdowns of assessment objectives, required artifacts, and verification steps necessary for compliance.
A company is about to conduct a press release. According to AC.L1-3.1.22: Control information posted or processed on publicly accessible systems, what is the MOST important factor to consider when addressing CMMC requirements?
That the information is correct
That the CEO approved the message
That the company has to safeguard the release of FCI
That so long as the information is only FCI, it can be released
Step 1: Understanding AC.L1-3.1.22
AC.L1-3.1.22states: " Control information posted or processed on publicly accessible systems. "
This control requires organizations toensure that FCI (Federal Contract Information) is not publicly postedor made accessible in an uncontrolled manner.
FCI must beprotected from unauthorized disclosure, even if it is not classified or CUI.
The practices in CMMC Level 2 consists of the security requirements specified in:
NISTSP 800-53.
NISTSP 800-171.
48 CFR 52.204-21.
DFARS 252.204-7012.
The Cybersecurity Maturity Model Certification (CMMC) Level 2 is designed to ensure that organizations can adequately protect Controlled Unclassified Information (CUI). To achieve this, CMMC Level 2 incorporates specific security requirements.
Step-by-Step Explanation:
Alignment with NIST SP 800-171:
CMMC Level 2 aligns directly with the security requirements outlined in the National Institute of Standards and Technology Special Publication 800-171 (NIST SP 800-171). This publication, titled " Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, " provides a comprehensive framework for safeguarding CUI.
Incorporation of Security Requirements:
The practices required for CMMC Level 2 certification encompass all 110 security requirements specified in NIST SP 800-171. These requirements are organized into 14 families, each addressing different aspects of cybersecurity, such as access control, incident response, and risk assessment.
Purpose of Alignment:
By integrating the NIST SP 800-171 requirements, CMMC Level 2 aims to standardize the implementation of cybersecurity practices across organizations handling CUI, ensuring a consistent and robust approach to protecting sensitive information.
A Data Access Policy (DAP) document has been provided for review. It outlines the policies, procedures, and requirements for data access within the corporate area and the controlled environment. Which DAP policy statement about visitors is correct?
Visitors must not be escorted.
Visitors must be escorted in the corporate area, but not in the controlled environment.
Visitors must be escorted in the controlled environment, but not in the corporate area.
Visitors must be escorted at all times.
The correct answer is C because the CMMC physical protection requirement focuses on protecting areas where in-scope information systems, equipment, and controlled environments are located. CMMC Level 2 requirement PE.L2-3.10.3, Escort Visitors , requires the organization to “escort visitors and monitor visitor activity.†The official CMMC Level 2 Assessment Guide states that the assessment objectives include determining whether visitors are escorted, visitor activity is monitored, physical access audit logs are maintained, and physical access devices are controlled and managed. The same guide explains that individuals with permanent physical access authorization credentials are not considered visitors, and that audit logs can be used to monitor visitor activity.
For CMMC purposes, the key issue is whether the visitor could physically access organizational systems, equipment, FCI, CUI, or the respective operating environment. A general corporate area that is outside the controlled environment may not require the same escort rule unless it provides access to in-scope assets. However, the controlled environment must be protected from unauthorized physical access. Therefore, visitors should be escorted in the controlled environment, where FCI/CUI systems or related assets may be present. Option A is incorrect because CMMC requires visitor escorting. Option B reverses the protection priority. Option D is overly broad for this question because it does not distinguish between a general corporate area and the controlled environment defined in the DAP.
===========
A C3PAO Assessment Plan document captures the names of the interviewees, the facilities that will utilized, along with estimated costs and schedule of the assessment. What part of the assessment plan is this?
Identify resources and schedule.
Select Assessment Team members.
Identify and manage assessment risks.
Select and develop the evidence collection approach.
ACertified Third-Party Assessor Organization (C3PAO)is responsible for conductingCMMC Level 2 Assessments. Before the assessment begins, the C3PAO must develop anAssessment Plan, which includes several key elements.
The part of the plan that captures:
✅Names of interviewees
✅Facilities to be utilized
✅Estimated costs
✅Assessment schedule
falls under the " Identify Resources and Schedule " section of the plan.
Step-by-Step Breakdown:
✅1. Identify Resources and Schedule
This section of theCMMC Assessment Planoutlines:
Thepersonnelinvolved (e.g., interviewees, assessors).
Thelocationswhere the assessment will take place.
Thetimeline and scheduling details.
Theestimated costsassociated with the assessment.
This ensures that all necessaryresourcesare allocated and that the assessment proceeds as planned.
✅2. Why the Other Answer Choices Are Incorrect:
(B) Select Assessment Team MembersâŒ
This section focuses onchoosing the assessorswho will conduct the evaluation, not listing interviewees and facilities.
(C) Identify and Manage Assessment RisksâŒ
This part of the plandocuments risks(e.g., scheduling conflicts, data access issues), but it doesnot outline names, facilities, or costs.
(D) Select and Develop the Evidence Collection ApproachâŒ
This step defineshowevidence will be gathered (e.g., document reviews, interviews, system testing) but doesnot focus on logistics.
Final Validation from CMMC Documentation:
TheCMMC Assessment Process Guidestates thatresource identification and schedulingare essential for organizing the assessment. Since this sectioncaptures interviewees, facilities, costs, and the schedule, the correct answer is:
✅A. Identify resources and schedule.
Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?
Access Control (AC)
Media Protection (MP)
Asset Management (AM)
Configuration Management (CM)
Understanding the Role of Configuration Management (CM) in CMMC 2.0
TheConfiguration Management (CM) domainin CMMC 2.0 ensures that systems aresecurely configured and maintainedto prevent unauthorized or unnecessary changes that could introduce vulnerabilities. One key requirement in CM is torestrict, disable, or prevent the use of nonessential programsto reduce security risks.
Relevant CMMC 2.0 Practice:
CM.L2-3.4.1 – Establish and enforce security configuration settings for information technology products employed in organizational systems.
This practicerequires organizations to control system configurations, including the removal or restriction ofnonessential programs, functions, ports, and servicestoreduce attack surfaces.
The goal is tominimize exposure to cyber threatsby ensuring only necessary and approved software is running on the system.
Why is the Correct Answer CM (D)?
A. Access Control (AC) → Incorrect
Access Control (AC) focuses onmanaging user permissions and accessto systems and data, not restricting programs.
B. Media Protection (MP) → Incorrect
Media Protection (MP) deals withprotecting and controlling removable media(e.g., USBs, hard drives) rather than software or system configurations.
C. Asset Management (AM) → Incorrect
Asset Management (AM) is aboutidentifying and tracking IT assets, not configuring or restricting software.
D. Configuration Management (CM) → Correct
CM explicitly coverssecuring system configurationsbyrestricting nonessential programs, ports, services, and functions, making it the correct answer.
CMMC 2.0 References Supporting this Answer:
CMMC 2.0 Practice CM.L2-3.4.1(Security Configuration Management)
Requires organizations toenforce security configuration settingsandremove unnecessary programsto protect systems.
NIST SP 800-171 Requirement 3.4.1
Supportssecure configuration settingsandrestricting unauthorized applicationsto prevent security risks.
CMMC 2.0 Level 2 Requirement
This practice is aLevel 2 (Advanced) requirement, meaningorganizations handling Controlled Unclassified Information (CUI)must comply with it.
Who has the initial responsibility for identifying and managing conflicts of interest?
OSC
C3PAO
CMMC-AB
Lead Assessor
Under the CMMC Assessment Process (CAP) v2.0 , the C3PAO holds the initial (and ultimate) responsibility to identify and manage conflicts of interest (COI) related to a CMMC Level 2 certification assessment. CAP v2.0 includes an explicit pre-assessment activity titled “Identify and Manage Initial Conflicts of Interest (COI)†and states that C3PAOs are ultimately responsible for managing impartiality and identifying conflicts of interest for the assessment.
CAP v2.0 further clarifies that this responsibility cannot be delegated to the assessment team (including the Lead Assessor/Lead CCA) or to the OSC. In other words, while the Lead Assessor participates in executing the process and the OSC must cooperate (e.g., disclose relationships or prior services that could create COI), CAP places the duty to run the COI identification/mitigation process squarely on the C3PAO as the assessment organization.
This aligns with the intent of impartiality controls in certification programs: the certification body (here, the C3PAO) must ensure objective assessments by identifying conflicts early, applying mitigation (or avoidance), and documenting the resolution before the assessment proceeds. Since the question asks who has the initial responsibility , the CAP’s direct assignment of COI management to the C3PAO makes B the correct answer.
===========
Which standard and regulation requirements are the CMMC Model 2.0 based on?
NIST SP 800-171 and NIST SP 800-172
DFARS, FIPS 100, and NIST SP 800-171
DFARS, NIST, and Carnegie Mellon University
DFARS, FIPS 100, NIST SP 800-171, and Carnegie Mellon University
TheCybersecurity Maturity Model Certification (CMMC) 2.0is primarily based on two key National Institute of Standards and Technology (NIST) Special Publications:
NIST SP 800-171– " Protecting Controlled Unclassified Information (CUI) in Nonfederal Systems and Organizations "
NIST SP 800-172– " Enhanced Security Requirements for Protecting Controlled Unclassified Information: A Supplement to NIST Special Publication 800-171 "
Reference and Breakdown:
NIST SP 800-171
This document is thecore foundationof CMMC 2.0 and establishes the security requirements for protectingControlled Unclassified Information (CUI)in non-federal systems.
The 110 security controls fromNIST SP 800-171 Rev. 2are mapped directly toCMMC Level 2.
NIST SP 800-172
This supplement includesenhanced security requirementsfor organizations handlinghigh-value CUIthat faces advanced persistent threats (APTs).
These enhanced requirements apply toCMMC Level 3under the 2.0 model.
Eliminating Incorrect Answer Choices:
B. DFARS, FIPS 100, and NIST SP 800-171→Incorrect
WhileDFARS 252.204-7012mandates compliance withNIST SP 800-171,FIPS 100 does not existas a relevant cybersecurity standard.
C. DFARS, NIST, and Carnegie Mellon University→Incorrect
CMMC is aligned with DFARS and NIST but isnot developed or directly influenced by Carnegie Mellon University.
D. DFARS, FIPS 100, NIST SP 800-171, and Carnegie Mellon University→Incorrect
Again,FIPS 100 is not relevant, andCarnegie Mellon Universityis not a defining entity in the CMMC framework.
Official CMMC 2.0 References Supporting the Answer:
CMMC 2.0 Scoping Guide (2023)confirms thatCMMC Level 2 is entirely based on NIST SP 800-171.
CMMC 2.0 Level 3 Draft Documentationexplicitly referencesNIST SP 800-172for enhanced security requirements.
DoD Interim Rule (DFARS 252.204-7021)mandates that organizations meetNIST SP 800-171 for CUI protection.
Final Conclusion:
The CMMC 2.0 model is derivedsolely from NIST SP 800-171 and NIST SP 800-172, makingAnswer A the only correct choice.
The IT manager is scoping the company ' s CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?
ESP
People
Facilities
Technology
Understanding Asset Types in CMMC 2.0
In CMMC 2.0, assets are categorized based on their role in handling Federal Contract Information (FCI) or Controlled Unclassified Information (CUI). The Cybersecurity Maturity Model Certification (CMMC) Scoping Guidance for Level 1 and Level 2 provides asset definitions to help organizations identify what needs protection.
According to CMMC Scoping Guidance, there are five primary asset types:
Security Protection Assets (ESP - External Service Providers & Security Systems)
People (Personnel who interact with FCI/CUI)
Facilities (Physical locations housing FCI/CUI)
Technology (Hardware, software, and networks that store, process, or transmit FCI/CUI)
CUI Assets (For Level 2 assessments, assets specifically storing CUI)
Why " Technology " Is the Correct Answer
The IT manager is evaluating servers, laptops, databases, and applications—all of which are technology assets used to store, process, or transmit FCI.
According to CMMC Scoping Guidance, Technology assets include:
✅Endpoints (Laptops, Workstations, Mobile Devices)
✅Servers (On-premise or cloud-based)
✅Networking Devices (Routers, Firewalls, Switches)
✅Applications (Software, Cloud-based tools)
✅Databases (Storage of FCI or CUI)
Since the IT manager is focusing on these components, the correct asset category is Technology (Option D).
Why the Other Answers Are Incorrect
A. ESP (Security Protection Assets)
âŒIncorrect. ESPs refer to security-related assets (e.g., firewalls, monitoring tools, managed security services) that help protect FCI/CUI but do not store, process, or transmit it directly.
B. People
âŒIncorrect. While employees play a role in handling FCI, the question focuses on hardware and software—which falls under Technology, not People.
C. Facilities
âŒIncorrect. Facilities refer to physical buildings or secured areas where FCI/CUI is stored or processed. The question explicitly mentions servers, laptops, and applications, which are not physical facilities.
CMMC Official References
CMMC Level 1 Scoping Guide (CMMC-AB) – Defines asset categories, including Technology.
CMMC 2.0 Scoping Guidance for Assessors – Provides clarification on FCI assets.
Thus, option D (Technology) is the most correct choice as per official CMMC 2.0 guidance.
A Lead Assessor is ensuring all actions have been completed to conclude a Level 2 Assessment. The final Assessment Results Package has been properly reviewed and is ready to be uploaded. What other materials is the Lead Assessor responsible for maintaining and protecting?
Any additional notes and information from the Assessment
A final assessment plan, and a Quality Control report from C3PAO
A final assessment plan, and a letter from the Lead Assessor explaining the process
A final assessment plan, a letter from the Lead Assessor explaining the results, and a Quality Control report from C3PAO
The Lead Assessor is responsible for protecting and maintaining all assessment records, notes, and information gathered during the assessment process. This includes working papers and supplemental documentation that may be needed for auditability or dispute resolution.
Supporting Extracts from Official Content:
CAP v2.0, Post-Assessment Responsibilities (§3.17): “The Lead Assessor must ensure that all assessment artifacts, notes, and information are archived or disposed of in accordance with C3PAO policy.â€
Why Option A is Correct:
The CAP specifies that notes and information from the assessment must be preserved or disposed of according to policy.
Options B, C, and D list items not required in the CAP. The “letter†and “quality control report†are not part of the Lead Assessor’s required maintained materials.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 3 Post-Assessment (§3.17).
===========
For CMMC Assessments, during Phase 1 of the CMMC Assessment Process, which are responsible for identifying potential conflicts of information?
C3PAO and OSC
OSC and CMMC-AB
CMMC-AB and C3PAO
Lead Assessor and Assessment Team Members
In Phase 1 (Planning) of the CMMC Assessment Process, the Lead Assessor is responsible for managing the team and identifying conflicts of interest. Assessment team members must also disclose potential conflicts.
Supporting Extracts from Official Content:
CAP v2.0, Planning (§2.5–2.8): “The Lead Assessor and Assessment Team Members must identify and disclose any conflicts of interest prior to conducting the assessment.â€
Why Option D is Correct:
Only the Lead Assessor and assessment team are responsible for identifying conflicts of interest during Phase 1.
Options A, B, and C incorrectly assign this role to organizations that do not hold the responsibility.
References (Official CMMC v2.0 Content):
CMMC Assessment Process (CAP) v2.0, Phase 1 Planning responsibilities.
===========
TESTED 18 Jul 2026