CCA Part 2 Flashcards
Minimum practice score to pass an assessment
88/110 (80%)
Which executive order placed NARA in charge of the CUI program?
EO 13556
How many controls (practices) are there for CMMC L1
17
How many assessment objectives are there for CMMC L1
59
How many domains are there in CMMC L1
6
What are the 6 domains addressed in CMMC L1
(AC) Access Control, (IA) Identification & Authentication, (MP) Media Protection,
(PE) Physical and Environmental, (SC) System & Communications Protection,
(SI) System & Information Integrity.
How many controls (practices) are there in CMMC L2
110
How many assessment objectives are there in CMMC L2
320
How many domains are there in CMMC L2?
14
CMMC L1 controls are described as
Foundational
CMMC L2 controls are described as
Advanced
CMMC L3 controls are described as
Expert
Which contract clause protects FCI
FAR 52.204.21
Which contract clause requires 800-171 self assessment, and submission of SPRS score
DFARS 252.204-7019
Which contract clause allows for a DIBCAC medium or high assessment?
DFARS 252.204-7020
What are the 5 sections in the code of professional conduct?
Professionalism, Objectivity, Confidentiality, Proper use of Methods, and Information Integrity
Define “Affirmation”
a response to the interview examination method by the OSC
Define “adequacy”
Does the evidence meet the objective (is it right)
Define “sufficiency”
Does the evidence address the full scope of the program (is there enough)
What markings are required on a CUI document?
- “controlled” or “CUI”
- the specified category if applicable
- designation indicator (which agency controls it)
What are the four phases of the CAP?
- Plan and prepare assessment
- conduct the assessment
- Deliver recommended results
- POA&M closeout
What are the 5 primary steps in the first phase of the CAP?
- Establish roles and responsibilities
- Organize and prepare
- Analyze assessment requirements
- Develop assessment plan
- Verify readiness to conduct the assessment
Which ISO cert must a C3PAO obtain?
ISO 17020
Which ISO cert must the Cyber-AB obtain
ISO 17011