Module 2 CMMC 2.0 Flashcards

1
Q

CMMC has 3 levels, what are they

A

Level 1 - foundational
Level 2 - Advanced
Level 3 - Expert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what is FCI

A

Federal Contract information - not intended for public release

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

CMMC level 2 has how many practices

A

110

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

CMMC level 2 is called what

A

advanced

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

how many domains does CMMC level 2 have

A

14

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

how many practices does CMMC level 1 have

A

17

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what is CMMC level 1 called

A

foundational

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

how many paths does CMMC level 2 have and what are they

A

2
CUI prioritized acquisition
CUI none prioritized acquisition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what is CMMC level 2 based off

A

NIST 800-171

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what will CMMC level 3 be based off

A

NIST 800-172

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what is NIST 800-171 primary purpose

A

protecting CUI in nonfederal systems and organizations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

what is NIST 800-172

A

enhanced security requirements for protecting CUI -supplement to 800-171

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

who created CMMC

A

DoD

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what is the acronym DIB

A

Defense Industrial Base

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

what is CMMC level 3 called

A

expert

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

are these the responsible parties for creating CMMC 2.0

OUSD(A&S), UARC, FFRDC and DIB

A

yes

17
Q

does CMMC encompass basic safeguarding requirements for
FCI
FAR
and the security requirements for CUI specified in NIST 800-171 per DFARS?

A

yes

18
Q

CMMC is based off what

A

NIST 800-171 rev 2

19
Q

CMMC level 1 encompasses safeguarding requirements for what

A

FCI

20
Q

when are assessments done for CMMC level 1`

A

self assessment and annually

21
Q

when are CMMC level 2 assessments done

A

triennial - third party

22
Q

CMMC levels and associated sets of practices across domains are cumulative. do you need to achieve the preceding lower level before being the next higher level certified

A

yes

23
Q

CMMC certification - what if you fail a higher level certification - what are your options

A

since you have to qualify for each level you would obtain the certification for the lower level.

24
Q

the 14 domains on CMMC level 2 (advanced) align with what

A

NIST 800-171

25
Q

what clause was CMMC level 1 specified in

A

FAR

26
Q

what clause was CMMC level 2 specified in

A

DFARS