CCA Part 2 Flashcards

1
Q

Minimum practice score to pass an assessment

A

88/110 (80%)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which executive order placed NARA in charge of the CUI program?

A

EO 13556

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How many controls (practices) are there for CMMC L1

A

17

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How many assessment objectives are there for CMMC L1

A

59

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

How many domains are there in CMMC L1

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the 6 domains addressed in CMMC L1

A

(AC) Access Control, (IA) Identification & Authentication, (MP) Media Protection,
(PE) Physical and Environmental, (SC) System & Communications Protection,
(SI) System & Information Integrity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How many controls (practices) are there in CMMC L2

A

110

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many assessment objectives are there in CMMC L2

A

320

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many domains are there in CMMC L2?

A

14

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

CMMC L1 controls are described as

A

Foundational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

CMMC L2 controls are described as

A

Advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

CMMC L3 controls are described as

A

Expert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Which contract clause protects FCI

A

FAR 52.204.21

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Which contract clause requires 800-171 self assessment, and submission of SPRS score

A

DFARS 252.204-7019

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Which contract clause allows for a DIBCAC medium or high assessment?

A

DFARS 252.204-7020

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 5 sections in the code of professional conduct?

A

Professionalism, Objectivity, Confidentiality, Proper use of Methods, and Information Integrity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Define “Affirmation”

A

a response to the interview examination method by the OSC

18
Q

Define “adequacy”

A

Does the evidence meet the objective (is it right)

19
Q

Define “sufficiency”

A

Does the evidence address the full scope of the program (is there enough)

20
Q

What markings are required on a CUI document?

A
  1. “controlled” or “CUI”
  2. the specified category if applicable
  3. designation indicator (which agency controls it)
21
Q

What are the four phases of the CAP?

A
  1. Plan and prepare assessment
  2. conduct the assessment
  3. Deliver recommended results
  4. POA&M closeout
22
Q

What are the 5 primary steps in the first phase of the CAP?

A
  1. Establish roles and responsibilities
  2. Organize and prepare
  3. Analyze assessment requirements
  4. Develop assessment plan
  5. Verify readiness to conduct the assessment
23
Q

Which ISO cert must a C3PAO obtain?

A

ISO 17020

24
Q

Which ISO cert must the Cyber-AB obtain

A

ISO 17011

25
Q

Which ISO Cert must the CAICO obtain

A

ISO 17024

26
Q

What are the 3 assessment methods

A
  1. Examine
  2. Interview
  3. Test
27
Q

Which org is RESPONSIBLE for CMMC training

A

CAICO

28
Q

Which org PUBLISHES training content

A

Licensed Partner Publisher (LPP)

29
Q

Which org ISSUES training content

A

Licensed Training Provider (LTP)

30
Q

What is a CCMI

A

Certified CMMC Master Instructor

31
Q

Which Code of Federal Regulations established the CUI program after Executive Order 13556?

A

CFR 32 Part 2002

32
Q

Which contract clause requires a CMMC certification?

A

DFARS 252.204-7021

33
Q

What is a prioritized acquisition program

A

A program that requires a C3PAO L2 assessment

34
Q

What does CMMC stand for?

A

Cybersecurity Maturity Model Certification

35
Q

Who oversees the CMMC-AB/CyberAB

A

The Department of Defense (DoD)

36
Q

What is the official title of NIST 800-171

A

Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

37
Q

How often must a CMMC certification be reassessed by a C3PAO

A

3 years

38
Q

What is the subject of CFR Title 32

A

National Defense

39
Q

What is the subject of CFR Title 48

A

Federal Aquisition Regulations System

40
Q

How much time does an OSC have to remediate a limited practice deficiency after the completion of an assessment?

A

180 days

41
Q

Which contract clause requires the implementation of NIST 800-171

A

DFARS 252.204-7012

42
Q

Which contract clause allows the DoD to use an SPRS score to evaluate contract bids?

A

DFARS 252.204-7024