CMMC Model Construct & Implementation Evaluation Flashcards

1
Q

Level 1 (Foundational)
Level 2 (Advanced)
Level 3 (Expert)
A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Level 1 (Fundamental)
Level 2 (Advanced)
Level 3 (Expert)
A. True
B. False

A

B. False - Level 1 (Foundational)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are the CMMC Model Levels?

A

Level 1 (Foundational)
Level 2 (Advanced)
Level 3 (Expert)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many practices are assessed in Level 1?
A. 15
B. 16
C. 17
D. 18

A

C. 17

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How many practices are assessed in Level 2?
A. 110
B. 115
C. 120
D. 125

A

A. 110

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

How many practices are assessed in Level 1?

A

17 practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many practices are assessed in Level 2?

A

110 practices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Level 1 (Foundational) has 17 practices that are aligned with NIST SP 800-171 and FAR Clause 52.204-21.
A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Level 2 (Advanced) has 110 practices that are aligned with NIST SP 800-171.
A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

An OSC seeking CMMC Level 1 certification must reach out to a C3PAO for a third party assessment.
A. True
B. False

A

B. False - The OSC should do an annual self assessment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Level 1 certification includes 6 domains and 17 practices.
A. True
B. False

A

A. True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Level 2 certification includes 17 domains and 110 practices.
A. True
B. False

A

B. False - There are only 14 domains.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Level 1 (Foundational) encompasses the basic safeguarding requirements for FCI specified in which of the following?
A. NIST SP 800-171
B. FAR Clause 52.204-21
C. NIST SP 800-172
D.DFARS Clause 252.204-7012

A

B. FAR Clause 52.204-21

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Level 2 (Advanced) encompasses the security requirements requirements for CUI specified in which of the following?
A. NIST SP 800-171
B. FAR Clause 52.204-21
C. NIST SP 800-172
D.DFARS Clause 252.204-7012

A

D.DFARS Clause 252.204-7012

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

This image shows the steps of which of the following?
A. CMMC Assessment Process (CAP)
B. CMMC Level 1 Self-Assessment
C. CMMC Level 2 Self-Assessment
D. CMMC Level 2 Assessment

A

B. CMMC Level 1 Self-Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How often does a Level 2 certification have to be re-certified?

A

Every 3 years

17
Q

At what step of the Level 2 assessment process does the OSC contract a C3PAO to begin the formal certification process?
A. Step 7
B. Step 8
C. Step 9
D. Step 10

A

C. Step 9

18
Q

Company Alpha receives FCI from the Government as part of its contract. The only exception is information that the Government has officially designated as “For Public Release.” What level of certification must Company Alpha obtain?
A. Level 1
B. Level 2
C. Level 3

A

A. Level 1

19
Q

Company Omega decided to participate in contracts that include CUI. They have determined that CUI will be handled, processed, or stored as part of that service of the contract. What level of certification much Company Omega obtain?
A. Level 1
B. Level 2
C. Level 3

A

B. Level 2

20
Q

In the image, what information is represented in A?
A. Level
B. Domain
C. Practice
D. Security Requirement Number

A

B. Domain

21
Q

In the image, what information is represented in B?
A. Level
B. Domain
C. Practice
D. Security Requirement Number

A

A. Level

22
Q

In the image, what information is represented in C?
A. Level
B. Domain
C. Practice
D. Security Requirement Number

A

D. Security Requirement Number