Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
An OSC seeking Level 2 certification has recently configured system auditing capabilities for all systems within the assessment scope. The audit logs are generated based on the required events and contain the correct content that the organization has defined.
Which of the following BEST describes the next system auditing objective that the organization should define?
The next step after configuring audit logs and ensuring event content is correct is to periodically review and update the logged events to maintain alignment with evolving security requirements and risks.
Extract from AU.L2-3.3.2 & AU.L2-3.3.7:
''Organizations must review and update audit log events periodically to ensure they continue to support accountability and monitoring objectives.''
While centralized collection and retention are important, the next required objective per progression is review and update of logged events.
A company describes its organization as having two systems. One system, System Org, covers the entire organization and allows instant messaging, email, and Internet activity. The other system, System CUI, is used for processing, storing, and transmitting CUI dat
a. System CUI interfaces with System Org through security mechanisms and a firewall.
The CMMC Assessment is being done on System CUI only.
What is the BEST way to describe System CUI?
Per the CMMC Scoping Guidance, CUI Assets are those that process, store, or transmit CUI. Since System CUI is the system handling CUI data, it must be categorized as CUI Assets.
Extract:
''CUI Assets are any assets that process, store, or transmit CUI. These assets are in-scope for assessment and must meet CMMC practice requirements.''
Thus, the best classification for System CUI is CUI Assets.
Different mechanisms can be used to protect information at rest. Which mechanism is MOST LIKELY to afford protection for information at rest?
Applicable Requirement: SC.L2-3.13.16 --- ''Protect the confidentiality of CUI at rest.''
Why D is Correct: Cryptographic mechanisms (e.g., full-disk encryption, database encryption, file encryption) provide the strongest protection for information at rest by preventing unauthorized disclosure if systems or media are accessed.
Why Other Options Are Insufficient:
A (Patching): Protects against vulnerabilities, but not specific to data-at-rest confidentiality.
B (File share): Provides a storage method, not protection.
C (Secure offline storage): Helps physically, but not sufficient for digital confidentiality without encryption.
Reference (CCA Official Sources):
NIST SP 800-171 Rev. 2 --- SC.L2-3.13.16
NIST SP 800-171A --- SC.L2-3.13.16 Assessment Objectives
CMMC Assessment Guide -- Level 2, Data at Rest Protection
During a CMMC Assessment, the assessor is determining if the Escort Visitors practice is MET. Personnel with which of the following responsibilities would be MOST appropriate to interview?
The Escort Visitors practice falls under Physical and Environmental Protection (PE.L2-3.10.3), which requires organizations to escort visitors and monitor visitor activity. To validate this, the assessor should interview personnel responsible for physical access control (security guards, facility access managers) and information security (to confirm integration with CUI protection requirements).
Exact Extracts:
PE.L2-3.10.3: ''Escort visitors and monitor visitor activity.''
Assessment Guide: ''Interview personnel responsible for physical access control and security monitoring to confirm escort and visitor activity tracking.''
Assessment Objectives: Require evidence of visitor escorts, visitor logs, and monitoring practices.
Why the other options are not correct:
A (Repair/maintenance): Not responsible for escort procedures.
B (Local access control only): Missing the information security link, which ensures visitors cannot access CUI assets.
D (IT management): IT is not responsible for escorting visitors in physical spaces.
CMMC Assessment Guide -- Level 2, Version 2.13: PE.L2-3.10.3 (pp. 154--156).
NIST SP 800-171A: Assessment procedures for visitor escort and monitoring.
While examining evidence, a CCA is trying to confirm the claim that the OSC has identified all information system users, processes acting on behalf of users, and all devices.
Which of the following provides the STRONGEST evidence of this practice?
For IA.L2-3.5.1 (Identify system users, processes, and devices), the strongest evidence is direct lists of accounts, devices, and supporting audit logs/records that show users and devices are actively identified and managed. Policies and procedures are supporting evidence but not as strong as system-generated, real evidence.
Extract:
''Strong evidence includes account listings, device inventories, and audit logs demonstrating that all users, processes, and devices are identified and uniquely associated.''
150 questions covering all exam domains, starting from $20
Exam domains verified against: Official Cyber AB CMMC-CCA exam guide, last checked September 2026.
Learn the structure and roles within the CMMC ecosystem including the Office of the Undersecretary of Defense, CMMC-AB, assessors, and Licensed Training Providers. Recognize how these organizations function together and understand the responsibilities of each authority within the defense industrial base.
Understand the guiding principles of professional conduct, including professionalism, objectivity, and confidentiality requirements. Learn how to maintain high ethical standards when handling FCI and CUI, and apply ISO/IEC and DoD requirements to your assessor role.
Study the rules and regulations governing FCI and CUI transmission and receipt within the CMMC framework. Identify Foundational Level 1 and Level 2 assessment requirements, understand the CMMC v2.0 program structure, and recognize consequences of non-compliance.
Sample question from this domain above: Q1
Apply CMMC Source Documents to evaluate implementation and review of practices across all model levels and domains. Develop competency in using evidence in different assessment scenarios and understand the architecture and structure of the CMMC model.
Learn the appropriate roles and responsibilities of CCA team members throughout the assessment lifecycle. Master the phases and steps for conducting CMMC Level 2 assessments, preparing assessment reports, and evaluating outstanding assessment issues.
Common questions about the exam itself