CCA CCA Assessment Planning & Scoping 1 — Questions and Answers
Question 1: What is the first step a CCA assessor must complete before beginning a CMMC Level 2 assessment?
- Review contractor invoices
- Define the assessment scope and boundary (Correct answer)
- Install monitoring software on contractor systems
- Submit the final assessment report
Correct answer: Define the assessment scope and boundary
Defining the assessment scope and boundary is the mandatory first step to ensure all relevant systems and data are properly evaluated.
Question 2: Which document serves as the primary planning artifact for a CMMC assessment?
- System Security Plan (SSP)
- Plan of Action & Milestones (POA&M)
- Assessment Plan (AP) (Correct answer)
- Incident Response Plan (IRP)
Correct answer: Assessment Plan (AP)
The Assessment Plan (AP) is the primary planning artifact that outlines the scope, objectives, schedule, and methodology for a CMMC assessment.
Question 3: When scoping a CMMC assessment, which type of data determines what systems fall within scope?
- Personally Identifiable Information (PII)
- Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) (Correct answer)
- Classified National Security Information (CNSI)
- Export Controlled Technical Data (ECTD)
Correct answer: Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)
FCI and CUI are the data types that determine which systems, personnel, and processes fall within the CMMC assessment scope.
Question 4: What is the purpose of a pre-assessment kickoff meeting in CMMC assessment planning?
- To sign the final assessment report
- To establish ground rules, confirm scope, and align expectations between assessors and the OSC (Correct answer)
- To conduct penetration testing
- To submit findings to the CMMC-AB
Correct answer: To establish ground rules, confirm scope, and align expectations between assessors and the OSC
The kickoff meeting aligns the assessment team and the Organization Seeking Certification (OSC) on scope, logistics, and expectations before fieldwork begins.
Question 5: Which term describes the boundary within which CMMC requirements must be assessed?
- Compliance perimeter
- Assessment boundary (Correct answer)
- Security enclave
- Certification zone
Correct answer: Assessment boundary
The assessment boundary defines the people, technology, facilities, and external service providers that process, store, or transmit CUI/FCI within scope.
Question 6: How should a CCA assessor handle a situation where the OSC's scope definition appears to exclude systems that clearly handle CUI?
- Accept the OSC's scope as defined to avoid conflict
- Flag the discrepancy and require the scope to be corrected before proceeding (Correct answer)
- Proceed with the assessment and note the exclusion in a footnote
- Report the OSC immediately to the DoD
Correct answer: Flag the discrepancy and require the scope to be corrected before proceeding
An assessor must require accurate scope definition to ensure all CUI-handling systems are evaluated, as an incomplete scope would invalidate the assessment.
What is the first step a CCA assessor must complete before beginning a CMMC Level 2 assessment?