CCA Part 2 Flashcards

1
Q

Minimum practice score to pass an assessment

A

88/110 (80%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which executive order placed NARA in charge of the CUI program?

A

EO 13556

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many controls (practices) are there for CMMC L1

A

17

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many assessment objectives are there for CMMC L1

A

59

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How many domains are there in CMMC L1

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 6 domains addressed in CMMC L1

A

(AC) Access Control, (IA) Identification & Authentication, (MP) Media Protection,
(PE) Physical and Environmental, (SC) System & Communications Protection,
(SI) System & Information Integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many controls (practices) are there in CMMC L2

A

110

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many assessment objectives are there in CMMC L2

A

320

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many domains are there in CMMC L2?

A

14

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CMMC L1 controls are described as

A

Foundational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CMMC L2 controls are described as

A

Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CMMC L3 controls are described as

A

Expert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which contract clause protects FCI

A

FAR 52.204.21

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which contract clause requires 800-171 self assessment, and submission of SPRS score

A

DFARS 252.204-7019

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which contract clause allows for a DIBCAC medium or high assessment?

A

DFARS 252.204-7020

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 5 sections in the code of professional conduct?

A

Professionalism, Objectivity, Confidentiality, Proper use of Methods, and Information Integrity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Define “Affirmation”

A

a response to the interview examination method by the OSC

18
Q

Define “adequacy”

A

Does the evidence meet the objective (is it right)

19
Q

Define “sufficiency”

A

Does the evidence address the full scope of the program (is there enough)

20
Q

What markings are required on a CUI document?

A
  1. “controlled” or “CUI”
  2. the specified category if applicable
  3. designation indicator (which agency controls it)
21
Q

What are the four phases of the CAP?

A
  1. Plan and prepare assessment
  2. conduct the assessment
  3. Deliver recommended results
  4. POA&M closeout
22
Q

What are the 5 primary steps in the first phase of the CAP?

A
  1. Establish roles and responsibilities
  2. Organize and prepare
  3. Analyze assessment requirements
  4. Develop assessment plan
  5. Verify readiness to conduct the assessment
23
Q

Which ISO cert must a C3PAO obtain?

24
Q

Which ISO cert must the Cyber-AB obtain

25
Which ISO Cert must the CAICO obtain
ISO 17024
26
What are the 3 assessment methods
1. Examine 2. Interview 3. Test
27
Which org is RESPONSIBLE for CMMC training
CAICO
28
Which org PUBLISHES training content
Licensed Partner Publisher (LPP)
29
Which org ISSUES training content
Licensed Training Provider (LTP)
30
What is a CCMI
Certified CMMC Master Instructor
31
Which Code of Federal Regulations established the CUI program after Executive Order 13556?
CFR 32 Part 2002
32
Which contract clause requires a CMMC certification?
DFARS 252.204-7021
33
What is a prioritized acquisition program
A program that requires a C3PAO L2 assessment
34
What does CMMC stand for?
Cybersecurity Maturity Model Certification
35
Who oversees the CMMC-AB/CyberAB
The Department of Defense (DoD)
36
What is the official title of NIST 800-171
Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
37
How often must a CMMC certification be reassessed by a C3PAO
3 years
38
What is the subject of CFR Title 32
National Defense
39
What is the subject of CFR Title 48
Federal Aquisition Regulations System
40
How much time does an OSC have to remediate a limited practice deficiency after the completion of an assessment?
180 days
41
Which contract clause requires the implementation of NIST 800-171
DFARS 252.204-7012
42
Which contract clause allows the DoD to use an SPRS score to evaluate contract bids?
DFARS 252.204-7024