Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which example represents a Specialized Asset?
According to the CMMC Scoping Guidance, Level 2, assets are categorized into specific groups to determine how they are treated during an assessment. One of these categories is Specialized Assets.
The CMMC Scoping Guidance defines Specialized Assets as a specific group that includes:
Government Property: Any property owned or leased by the government and provided to the contractor (Government Furnished Equipment or GFE).
Internet of Things (IoT): Physical objects that are embedded with sensors, software, and other technologies for the purpose of connecting and exchanging data.
Operational Technology (OT): Programmable systems or devices that interact with the physical environment (e.g., Industrial Control Systems).
Restricted Information Systems: Systems that have specific configurations or constraints that prevent standard security controls from being applied (e.g., legacy systems).
Test Equipment: Specialized equipment used for testing, such as oscilloscopes or signal generators.
Why other options are incorrect:
Option A (SOCs): A Security Operations Center is typically considered a Security Protection Asset (SPA) because it provides security functions (monitoring/response) for the assessment scope.
Option B (Hosted VPN services): These are generally categorized as External Service Providers (ESPs) or part of the Security Protection Assets, depending on how they are managed and their role in protecting CUI.
Option C (Consultants): These are External Service Providers (ESP) (personnel/organizations), not specialized hardware/software assets.
Treatment of Specialized Assets: Under CMMC Level 2 scoping rules, Specialized Assets must be identified in the Asset Inventory and documented in the System Security Plan (SSP), but they are generally not managed against the CMMC practices unless they process, store, or transmit CUI in a way that falls outside their specialized function.
Reference Documents:
CMMC Scoping Guidance, Level 2 (Version 2.0/2.1): Section 3.1, 'Specialized Assets' and Table 3.
32 CFR Part 170 (CMMC Program Rule): Definitions of asset categories and their associated assessment requirements.
A dedicated local printer is used to print out documents with FCI in an organization. This is considered an FCI Asset Which function BEST describes what the printer does with the FCI?
Understanding the Role of an FCI Asset in CMMC
Adedicated local printer used to print Federal Contract Information (FCI)is considered anFCI Asset. UnderCMMC Level 1, FCI assets are required to meetbasic cybersecurity controlsto ensure that FCI is properlyprotected from unauthorized access.
Step-by-Step Breakdown:
1. Why 'Process' is the Best Answer
The printerreceives digital FCI, converts it into a physical format (paper), and outputs the document.
This aligns with thedefinition of 'processing' in CMMC, which includes:
Transforming or modifying data
Generating output (e.g., printed documents)
Using systems to interpret or manipulate information
2. Why the Other Answer Choices Are Incorrect:
(A) Encrypt
Aprinter does not encryptFCI---it simply prints it. Encryption applies todigital storage and transmission, not printing.
(B) Manage
Managing FCI typically refers togovernance, access control, and oversight, which is not the function of a printer.
(D) Distribute
While a printed documentcould be distributed, theprinter itself is not responsible for distributing FCI---it only processes the data for output.
Final Validation from CMMC Documentation:
CMMC Assessment Guide (Level 1)confirms thatprocessing FCI includes using systems that convert or transform information, such as printers.
NIST SP 800-171definesprocessingas an action thatchanges or manipulates information, which applies to printing.
What activities are conducted while developing an assessment plan?
In the CAP v2.0 ''preliminary proceedings,'' the assessment is ''framed'' before Phase 1/Phase 2 execution. CAP states the C3PAO works with the OSC's leadership point(s) of contact (the Affirming Official and/or OSC POC) ''to determine the purview and planning details of the assessment,'' explicitly including schedule, personnel, logistics, relevant contractual requirements, and the prospective CMMC Assessment Scope.
Although the question uses the term ''OSC sponsor,'' the CAP's official role language is Affirming Official / OSC POC, and the Lead CCA (Lead Assessor) is the assessor counterpart. CAP further explains that the In-Brief Meeting establishes a common understanding of objectives, roles/responsibilities, and the schedule, and the Lead CCA must (at minimum) review the schedule and confirm assessment scope with the OSC.
Option A is incomplete because team assignment is a C3PAO responsibility, but CAP's ''plan'' emphasis here is broader framing: availability of personnel/evidence, documentation readiness, timing, and logistics. Option C is incorrect because CAP states C3PAOs are ultimately responsible for managing conflicts of interest and this responsibility cannot be delegated to the assessment team or the OSC. Option D is incorrect because CAP requires evaluation methods and evidence planning activities to be established during Phase 1 planning, not deferred until onsite work.
There are 15 practices that are NOT MET for an OSC's Level 2 Assessment. All practices are applicable to the OSC. Which determination should be reached?
According to the CMMC Model and Assessment Guides, specifically the rules governing Plan of Action and Milestones (POA&M) and the remediation period, an Organization Seeking Certification (OSC) is allowed a limited opportunity to remediate certain 'Not Met' practices to achieve a 'Met' status without failing the assessment entirely.
Here is the breakdown based on CMMC Ecosystem protocols:
The 180-Day POA&M Rule: CMMC Level 2 allows for the use of POA&Ms for specific practices, provided they are not high-priority items (typically 5-point values in the scoring methodology). If an OSC has 'Not Met' practices that are eligible for a POA&M, they have up to 180 days to remediate them.
The Remediation Period (Assessment Closeout): During the assessment process itself, there is a 'remediation period' (often referred to within the 1-90 day window depending on the specific C3PAO methodology and the CMMC assessment process) where an OSC can fix minor issues identified by the assessor before the final report is submitted.
Eligibility Criteria: The question states there are 15 practices 'Not Met.' While this is a high number, the CMMC rule does not automatically disqualify an OSC based solely on thequantityof practices, but rather thetype(weight) of the practices and the resulting score. To be eligible for a conditional 'Met' (via POA&M), the OSC must achieve a minimum score (often 80% of the total points) and none of the 'Not Met' practices can be those designated as mandatory 'Met' (no POA&M allowed) in the CMMC rule.
Why 'C' is correct: Because we do not know the specific weights of the 15 'Not Met' practices or the total score, we cannot definitively say theywillbe remediated (A) or that they areineligible(B). However, under the CMMC assessment framework, the OSC may be eligible to enter a remediation phase or utilize a POA&M to bridge the gap, provided they meet the scoring threshold and the specific practices allow for it.
Reference Documents:
CMMC Assessment Process (CAP): Defines the phases of assessment including the 'Remediation Period.'
32 CFR Part 170 (CMMC Program Rule): Outlines the specific requirements for POA&Ms, the 180-day timeline, and the scoring parameters required to be eligible for a Conditional Certification.
Which statement BEST describes the requirements for a C3PA0?
Understanding C3PAO Requirements
ACertified Third-Party Assessment Organization (C3PAO)is an entityauthorized by the CMMC Accreditation Body (CMMC-AB)to conductCMMC Level 2 Assessmentsfor organizations handlingControlled Unclassified Information (CUI).
Key Requirements for a C3PAO to Conduct Assessments:
Must be authorized by CMMC-AB before conducting assessments.
Must meet CMMC-AB and DoD cybersecurity and process requirements.
Must comply with ISO/IEC 17020 standards for inspection bodies.
Must undergo a rigorous vetting process, including cybersecurity verification.
Why is the Correct Answer 'D' (A C3PAO must be authorized by CMMC-AB before being able to conduct assessments)?
A . An authorized C3PAO must meet some DoD and all ISO/IEC 17020 requirements Incorrect
C3PAOs must comply with CMMC-AB authorization requirementsbefore performing assessments.
While they must align withISO/IEC 17020, they donotnecessarily meet all requirements upfront.
B . An accredited C3PAO must meet all DoD and some ISO/IEC 17020 requirements Incorrect
C3PAOs are not accredited by DoD; they areauthorized by CMMC-ABto perform assessments.
Accreditation follows full compliance with CMMC-AB and ISO/IEC 17020 requirements.
C . A C3PAO must be accredited by DoD before being able to conduct assessments Incorrect
The DoD does not directly accredit C3PAOs---CMMC-AB is responsible forauthorization and oversight.
D . A C3PAO must be authorized by CMMC-AB before being able to conduct assessments Correct
CMMC-AB grants authorization to C3PAOs, allowing them to perform assessmentsonly after meeting specific requirements.
CMMC 2.0 Reference Supporting This Answer:
CMMC-AB Certified Third-Party Assessment Organization (C3PAO) Guidelines
States thatC3PAOs must receive CMMC-AB authorization before conducting assessments.
CMMC 2.0 Assessment Process (CAP) Document
Specifies that onlyC3PAOs authorized by CMMC-AB can conduct official CMMC assessments.
ISO/IEC 17020 Compliance for C3PAOs
Defines theinspection body requirements for C3PAOs, which must be met for accreditation.
221 questions covering all exam domains, starting from $20
Exam domains verified against: Official Cyber AB CMMC-CCP exam guide, last checked September 2026.
Understand the CMMC program authorities including the Office of the Undersecretary of Defense, DFARS 252.204-7012, and the regulatory framework. Learn the roles of Organizations Seeking Certification (OSC), CMMC Third-Party Assessment Organizations (C3PAO), Registered Practitioner Organizations (RPO), Licensed Training Providers (LTP), and certification paths for CCPs, CCAs, and CCIs within the CMMC ecosystem.
Apply the CMMC-AB Code of Professional Conduct, ISO/IEC standards, and DoD requirements including professionalism, objectivity, confidentiality, conflicts of interest, and respect for intellectual property. Understand lawful and ethical practices relevant to CMMC professionals.
Demonstrate knowledge of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) handling, DFARS clauses, NIST SP 800-171, and the CMMC v2.0 framework with its three assessment levels. Understand compliance consequences including contract failure, contractual liability, and the False Claims Act.
Sample question from this domain above: Q4
Apply CMMC source documents to evaluate the implementation of practices across 14 security domains including Access Control, Identification and Authentication, Incident Response, and System and Information Integrity. Analyze evidence adequacy and sufficiency using assessment methods of Examine, Interview, and Test.
Execute CCP responsibilities across the three phases of CMMC assessments: developing assessment plans during Phase 1, supporting assessment teams during Phase 2 by using the three assessment methods and scoring evidence, and preparing assessment reports during Phase 3 including final findings and documentation.
Define organizational scoping including the organization, host unit, and supporting units. Analyze scenarios to identify FCI assets that process, store, or transmit sensitive data, and determine specialized assets such as government property, IoT/IIoT systems, operational technology, and external service providers.
Common questions about the exam itself