CCA Cheat Sheet 2026
The 30 highest-yield CCA facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
150 questions
240 min time limit
70.00% to pass
- Which CMMC domain deals with identifying and responding to cybersecurity threats? → Incident Response (IR)
- What does the CMMC practice PE.L1-3.10.1 require? → Limit physical access to organizational systems to authorized individuals
- What evidence types are used in CMMC assessments? → Objective evidence from multiple sources
- What is required of assessors before performing evaluations? → Hold certification and adhere to standards
- What standard governs the professional competency expected of CCA assessors in performing their assessments? → The CMMC Assessment Guide, Cyber AB standards, and applicable NIST guidance
- What does the term 'OSC' refer to in the context of CMMC assessments? → Organization Seeking Certification
- Under CMMC 2.0, Level 3 is based primarily on requirements from which source beyond NIST SP 800-171? → NIST SP 800-172
- An OSC's self-assessment SPRS score of -203 indicates what about their current compliance posture? → No practices are implemented; maximum negative score reflecting all requirements unmet
- Which CMMC compliance artifact describes how security requirements are implemented across an organization's system boundary? → System Security Plan (SSP)
- Which NIST publication provides the assessment procedures that directly underpin the CMMC Level 2 evaluation methodology? → NIST SP 800-171A
- The 'Risk Assessment (RA)' domain under CMMC requires organizations to: → Periodically assess risk to operations, assets, and individuals from system operations
- What is the standard CMMC term for a contractor or subcontractor that undergoes a CMMC assessment to achieve certification? → Organization Seeking Certification (OSC)
- What is the purpose of CMMC compliance? → To protect sensitive government information
- What is the primary purpose of the Media Protection (MP) domain in CMMC? → To protect system media containing CUI, both paper and digital
- Under CMMC, which practice area is concerned with limiting system access to authorized users and the minimum necessary permissions? → Least privilege and need-to-know, under Access Control (AC)
- Which DoD contract clause requires contractors to implement basic safeguarding requirements specifically for Federal Contract Information (FCI)? → FAR 52.204-21
- Which of the following would constitute a finding of 'NOT MET' for the CMMC practice requiring media sanitization (MP.L2-3.8.3)? → Reformatting a drive and returning it to service without verification of data removal
- How many cybersecurity practices are required for CMMC Level 1 (Foundational)? → 17
- What type of sensitive information does CMMC Level 2 specifically aim to protect? → Controlled Unclassified Information (CUI)
- Which CMMC domain addresses the protection of audit logs and monitoring of system activity? → Audit and Accountability (AU)
- What type of assessment is required for a CMMC Level 1 certification? → Annual self-assessment affirmed by a senior official
- Which CMMC domain addresses the need to establish and maintain baseline configurations for information technology systems? → Configuration Management (CM)
- Which statement BEST describes a Plan of Action and Milestones (POA&M) in the CMMC context? → A roadmap identifying deficiencies and scheduled remediation actions
- How is a practice marked during a CMMC assessment? → MET/NOT MET/NOT APPLICABLE
- Under CMMC 2.0, how long is a Level 2 certification issued by a C3PAO valid before reassessment is required? → 3 years
- Which CMMC level specifically addresses protecting CUI against Advanced Persistent Threats (APTs)? → Level 3
- Which factor is most important when determining if a cloud service provider falls within an OSC's CMMC assessment scope? → Whether CUI is stored, processed, or transmitted within the CSP environment
- A defense subcontractor receives CUI from a prime contractor. Under CMMC 2.0, the subcontractor is required to: → Obtain the same CMMC level certification as required by the prime contractor's contract
- Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents? → DFARS 252.204-7012
- What is the first step a CCA assessor must complete before beginning a CMMC Level 2 assessment? → Define the assessment scope and boundary
Turn these facts into recall:
Was this helpful?