Certified CMMC Assessor (CCA) — Questions and Answers
Question 1: Which NIST publication serves as the primary framework for CMMC Level 2 (Advanced) requirements?
- NIST SP 800-137
- NIST SP 800-171 (Correct answer)
- NIST SP 800-172
- NIST SP 800-53
Correct answer: NIST SP 800-171
CMMC Level 2 maps directly to the 110 security requirements in NIST SP 800-171, which are designed to protect Controlled Unclassified Information (CUI) in non-federal systems.
Question 2: In CMMC compliance reporting, what distinguishes a 'deficiency' from a 'weakness' in assessment terminology?
- A deficiency is a practice scored NOT MET; a weakness is a partially implemented practice noted for improvement (Correct answer)
- Deficiencies require DoD notification; weaknesses are internal OSC matters only
- Deficiencies apply to Level 3 only; weaknesses apply to Levels 1 and 2
- There is no distinction; the terms are used interchangeably in all CMMC documentation
Correct answer: A deficiency is a practice scored NOT MET; a weakness is a partially implemented practice noted for improvement
In CMMC context, deficiencies are practices that fully fail assessment (NOT MET), while weaknesses may indicate partial implementation or risk areas noted for monitoring.
Question 3: When assessing the Awareness and Training (AT) domain, what is the minimum evidence a CCA assessor should expect for CMMC Level 2?
- Evidence that only IT staff receive security training
- A formal training plan with quarterly classroom sessions
- Penetration test results showing user awareness
- Annual cybersecurity training completion records for all users (Correct answer)
Correct answer: Annual cybersecurity training completion records for all users
AT.L2-3.2.1 and AT.L2-3.2.2 require that users are made aware of security risks and trained; completion records demonstrate compliance.
Question 4: Under CMMC methodology, what distinguishes a 'finding' from an 'observation' in assessment reporting?
- Observations are findings that the OSC has agreed to remediate within 30 days
- Findings require C3PAO sign-off; observations can be documented by any team member
- Findings apply to Level 3 only; observations apply to Level 2
- A finding represents a scored deficiency (NOT MET) against a specific CMMC practice, while an observation is a noteworthy item that does not affect scoring (Correct answer)
Correct answer: A finding represents a scored deficiency (NOT MET) against a specific CMMC practice, while an observation is a noteworthy item that does not affect scoring
Findings are formal scored deficiencies tied to specific practices, while observations are noteworthy items — such as best practice recommendations — that do not change a practice's MET/NOT MET score.
Question 5: Which of the following best describes the Final Assessment Report in the CMMC assessment lifecycle?
- A marketing document describing the C3PAO's assessment methodology
- An internal C3PAO quality assurance document
- The authoritative record of all findings, determinations, and the overall CMMC Level achievement submitted to the CMMC-AB (Correct answer)
- A preliminary document shared only with the OSC
Correct answer: The authoritative record of all findings, determinations, and the overall CMMC Level achievement submitted to the CMMC-AB
The Final Assessment Report is the authoritative deliverable documenting all practice determinations, findings, and the overall CMMC Level achievement that is submitted to the CMMC-AB.
Question 6: What type of assessment is required for a CMMC Level 1 certification?
- Annual self-assessment affirmed by a senior official (Correct answer)
- Biennial independent verification by a CCA
- Third-party assessment by a C3PAO
- Government-led assessment by DIBCAC
Correct answer: Annual self-assessment affirmed by a senior official
CMMC Level 1 only requires an annual self-assessment affirmed by a senior company official, not a third-party or government-led assessment.
Question 7: What action should a CCA take if they believe the lead assessor on their team is making inaccurate or biased findings?
- Contact the OSC directly to alert them of the discrepancy
- Agree with the lead assessor to maintain team cohesion
- Raise the concern through the C3PAO's quality assurance process and escalate if unresolved (Correct answer)
- Silently note the disagreement in their personal assessment notes
Correct answer: Raise the concern through the C3PAO's quality assurance process and escalate if unresolved
CCAs have a professional obligation to raise concerns about inaccurate findings through their organization's quality assurance process, as the integrity of the CMMC program depends on accurate determinations.
Question 8: An organization uses a SIEM tool to aggregate and review security logs. Which CMMC practice is best supported by this control?
- RA.L2-3.11.3 — Remediate vulnerabilities in accordance with risk assessments
- AU.L2-3.3.2 — Ensure the actions of individual users can be traced (Correct answer)
- SC.L2-3.13.1 — Monitor, control, and protect communications at external boundaries
- SI.L2-3.14.7 — Identify unauthorized use of organizational systems
Correct answer: AU.L2-3.3.2 — Ensure the actions of individual users can be traced
AU.L2-3.3.2 requires that individual user actions be traceable through logs, which a SIEM directly supports by aggregating and analyzing audit data.
Question 9: What is the DoD's primary objective in implementing CMMC across the Defense Industrial Base (DIB)?
- To align defense contractor cybersecurity with commercial sector practices
- To generate revenue from contractor assessment fees
- To reduce the number of small businesses eligible for DoD contracts
- To protect CUI and FCI from adversaries by verifying that DIB companies have implemented required cybersecurity practices (Correct answer)
Correct answer: To protect CUI and FCI from adversaries by verifying that DIB companies have implemented required cybersecurity practices
CMMC's primary objective is to protect sensitive defense information by verifying that DIB companies have actually implemented required cybersecurity practices, moving beyond self-attestation to third-party verification.
Question 10: How should a CCA assessor document a practice determination of 'Not Met'?
- By recommending a specific vendor solution to the OSC
- With specific evidence, the gap identified, and the practice objective that was not satisfied (Correct answer)
- By immediately halting the assessment
- With a brief note in the assessment summary only
Correct answer: With specific evidence, the gap identified, and the practice objective that was not satisfied
'Not Met' findings must be documented with the specific evidence reviewed, the identified gap, and which practice objective was not satisfied to ensure transparency and defensibility.
Question 11: Under what circumstances may a CCA share OSC assessment findings with parties outside the C3PAO and OSC?
- When sharing would benefit the broader cybersecurity community
- Only when required by law, court order, or explicitly authorized by the OSC (Correct answer)
- Whenever requested by other government contractors
- When the information is more than 90 days old
Correct answer: Only when required by law, court order, or explicitly authorized by the OSC
CCA confidentiality obligations restrict sharing of assessment findings to situations required by law, compelled by court order, or explicitly authorized by the OSC, protecting the OSC's sensitive security information.
Question 12: How does a CCA assessor determine which CMMC level to assess when the OSC's contract requirements are unclear?
- Always assess at Level 3 to ensure maximum coverage
- Use the OSC's self-assessment score to determine the level
- Consult the contract language, DFARS clauses, and the contracting officer for clarification (Correct answer)
- Default to Level 1 unless the OSC requests otherwise
Correct answer: Consult the contract language, DFARS clauses, and the contracting officer for clarification
The required CMMC level is determined by the contract requirements, relevant DFARS clauses, and if unclear, by seeking clarification from the contracting officer.
Question 13: The Cyber AB Code of Professional Conduct requires CCAs to protect the confidentiality of what type of information?
- Information the OSC designates as confidential in writing
- Only information shared during formal interviews
- All sensitive information about the OSC's systems, security posture, and assessment findings (Correct answer)
- Only information explicitly marked 'CUI' during the assessment
Correct answer: All sensitive information about the OSC's systems, security posture, and assessment findings
CCAs must protect the confidentiality of all sensitive OSC information encountered during the assessment, not just formally marked CUI, as disclosure could harm the OSC or compromise national security.
Question 14: What is the primary ethical obligation of a CCA during a CMMC assessment?
- To provide an objective, impartial, and accurate assessment of the OSC's cybersecurity practices (Correct answer)
- To help the OSC achieve the highest possible CMMC score
- To complete the assessment as quickly as possible to minimize disruption to the OSC
- To recommend specific security products that the assessor is familiar with
Correct answer: To provide an objective, impartial, and accurate assessment of the OSC's cybersecurity practices
A CCA's primary ethical obligation is objectivity and accuracy — assessments must reflect actual compliance status, not what the OSC or the C3PAO would prefer the outcome to be.
Question 15: What is the primary purpose of DFARS clause 252.204-7012 in relation to cybersecurity?
- To define CMMC certification levels and timelines
- To require annual self-assessments for all DoD contractors
- To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI (Correct answer)
- To authorize C3PAOs to conduct CMMC assessments
Correct answer: To establish adequate security safeguards and mandate 72-hour cyber incident reporting for CUI
DFARS 252.204-7012 requires contractors to implement adequate security to protect covered defense information (CUI) and mandates reporting of cyber incidents to DoD within 72 hours.
Question 16: What is the significance of External Service Providers (ESPs) in CMMC scoping?
- They must be included in scope if they process, store, or transmit CUI (Correct answer)
- They only need to be scoped if they hold a DoD contract
- They are only in scope for CMMC Level 3 assessments
- They are automatically excluded from scope
Correct answer: They must be included in scope if they process, store, or transmit CUI
External Service Providers that handle CUI on behalf of the OSC must be included in the assessment scope to ensure comprehensive coverage.
Question 17: What is the minimum number of assessors required for a CMMC Level 2 certification assessment conducted by a C3PAO?
- A team of at least two CCAs (Correct answer)
- Three CCAs plus a Certified CMMC Professional
- One CCA acting independently
- One CCA and one CMMC Registered Practitioner
Correct answer: A team of at least two CCAs
CMMC Level 2 certification assessments require a team of at least two CCAs to ensure objectivity and thoroughness.
Question 18: Which practice requires contractors to limit the use of portable storage devices on organizational systems?
- CM.3.068
- MP.2.120 (Correct answer)
- AC.2.007
- SI.1.210
Correct answer: MP.2.120
MP.2.120 requires organizations to control and limit the use of removable media on system components to reduce the risk of data exfiltration or introduction of malicious code.
Question 19: In the context of CMMC, what is the primary goal of risk management for defense contractors?
- To transfer all cybersecurity risk to the DoD
- To eliminate all cybersecurity tools to reduce attack surface
- To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment (Correct answer)
- To maximize profit margins on defense contracts
Correct answer: To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment
The primary goal is to protect CUI and FCI by systematically identifying, assessing, and mitigating risks that could compromise the confidentiality, integrity, or availability of that data.
Question 20: Which document serves as the primary planning artifact for a CMMC assessment?
- Assessment Plan (AP) (Correct answer)
- Plan of Action & Milestones (POA&M)
- System Security Plan (SSP)
- Incident Response Plan (IRP)
Correct answer: Assessment Plan (AP)
The Assessment Plan (AP) is the primary planning artifact that outlines the scope, objectives, schedule, and methodology for a CMMC assessment.
Question 21: Which of the following scenarios represents a conflict of interest for a CCA assessor?
- Assessing an OSC in an industry the assessor is unfamiliar with
- Assessing an OSC for which the assessor previously provided CMMC consulting or implementation support (Correct answer)
- Assessing an OSC that is a competitor of a former employer
- Assessing an OSC in a different state than where the assessor is located
Correct answer: Assessing an OSC for which the assessor previously provided CMMC consulting or implementation support
A CCA who previously provided consulting or implementation help to an OSC has a conflict of interest because they would effectively be assessing their own prior work, compromising objectivity.
Question 22: Under CMMC, what is the contractor's obligation regarding media containing CUI that is sent off-site for maintenance?
- CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented (Correct answer)
- No special precautions are required if the vendor has signed an NDA
- Only media containing classified information requires special handling during maintenance
- Media can be sent to any certified repair vendor without restriction
Correct answer: CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented
CMMC media protection practices require that CUI be sanitized or appropriately encrypted when media is sent for maintenance, and the chain of custody must be maintained to protect against unauthorized disclosure.
Question 23: What continuing education requirement must CCAs fulfill to maintain their certification?
- No continuing education is required once certified
- CCAs must complete Cyber AB-required continuing professional education (CPE) credits each year (Correct answer)
- CCAs must retake the full CCA exam every two years
- CCAs must conduct a minimum of 10 assessments per year
Correct answer: CCAs must complete Cyber AB-required continuing professional education (CPE) credits each year
CCAs must complete continuing professional education credits as required by the Cyber AB to maintain current knowledge of CMMC requirements, assessment methodologies, and cybersecurity developments.
Question 24: Which domain ensures users are only granted necessary access?
- Identification and Authentication (IA)
- System and Communications Protection (SC)
- Access Control (AC) (Correct answer)
- Security Assessment (CA)
Correct answer: Access Control (AC)
The Access Control (AC) domain requires limiting system access to authorized users and processes based on the principle of least privilege.
Question 25: What should a CCA do if an OSC refuses to provide access to required systems during the assessment?
- Request the CMMC-AB to intervene immediately
- Proceed with available evidence and assume compliance
- Extend the assessment deadline indefinitely
- Document the lack of access, which may result in a 'Not Met' finding for affected practices (Correct answer)
Correct answer: Document the lack of access, which may result in a 'Not Met' finding for affected practices
If an OSC withholds access to required systems, the assessor must document this and assign a 'Not Met' finding, as evidence cannot be gathered without access.
Question 26: Which DFARS clause requires defense contractors to implement NIST SP 800-171 and report cyber incidents?
- DFARS 252.204-7012 (Correct answer)
- DFARS 252.204-7000
- DFARS 252.239-7010
- DFARS 252.204-7020
Correct answer: DFARS 252.204-7012
DFARS 252.204-7012 requires defense contractors to implement NIST SP 800-171 security requirements and report cyber incidents involving covered contractor information systems within 72 hours.
Question 27: Which of the following best describes 'assessment scope creep' in CMMC assessments?
- Updating the assessment plan after the kickoff meeting
- Expanding the assessment boundary beyond what was originally agreed upon without formal change control (Correct answer)
- Requesting additional evidence from the OSC
- Adding additional assessors mid-assessment
Correct answer: Expanding the assessment boundary beyond what was originally agreed upon without formal change control
Scope creep occurs when the assessment boundary expands informally beyond its agreed limits, potentially causing delays and resource issues without proper change management.
Question 28: Which NIST SP 800-171 control family maps to the CMMC Audit and Accountability (AU) domain?
- Control Family 3.1 — Access Control
- Control Family 3.12 — Security Assessment
- Control Family 3.5 — Identification and Authentication
- Control Family 3.3 — Audit and Accountability (Correct answer)
Correct answer: Control Family 3.3 — Audit and Accountability
CMMC's AU domain maps directly to NIST SP 800-171 Control Family 3.3, Audit and Accountability.
Question 29: When assessing Configuration Management controls, a CCA assessor finds that change requests are approved verbally with no documentation. Which practice gap does this represent?
- CM.L2-3.4.3 — Track, review, approve, and log changes to organizational systems (Correct answer)
- CM.L2-3.4.9 — Control and monitor user-installed software
- CM.L2-3.4.5 — Define, document, and implement a system component inventory
- CM.L2-3.4.1 — Establish and maintain baseline configurations
Correct answer: CM.L2-3.4.3 — Track, review, approve, and log changes to organizational systems
CM.L2-3.4.3 requires that changes be tracked, reviewed, approved, and logged; verbal-only approvals lack the required documentation.
Question 30: How does CMMC handle a scenario where an OSC uses an external IT managed service provider (MSP) that accesses CUI-handling systems?
- MSPs are automatically exempt from CMMC requirements
- MSPs only need to sign a CMMC compliance attestation form
- MSPs are regulated separately under FISMA, not CMMC
- The MSP must be included in the assessment scope or have its own CMMC certification, depending on the nature of its access (Correct answer)
Correct answer: The MSP must be included in the assessment scope or have its own CMMC certification, depending on the nature of its access
MSPs with privileged access to CUI-handling systems must be scoped into the assessment or demonstrate their own CMMC compliance, as their access creates direct risk to the CUI environment.
Question 31: Which CMMC domain specifically addresses the ability to recover from a cybersecurity incident by restoring systems?
- System and Information Integrity (SI)
- Incident Response (IR)
- Recovery (RE) (Correct answer)
- Risk Assessment (RA)
Correct answer: Recovery (RE)
The Recovery domain focuses on maintaining data backups and restoring capabilities to ensure resilience after a cybersecurity event.
Certified CMMC Assessor (CCA)
The CCA certification validates an assessor's ability to evaluate organizations seeking CMMC certification, covering assessment scoping, evidence collection, and evaluating Level 2 cybersecurity practices against NIST SP 800-171 controls. It is administered by Cyber AB and required for individuals conducting official CMMC assessments on behalf of C3PAOs.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds