CCA Assessment Planning & Scoping Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCA Assessment Planning & Scoping flashcards as text
Which CMMC assessment guide provides the authoritative criteria used by C3PAOs and CCAs during assessments?
Answer: CMMC Assessment Guide Level 2
The CMMC Assessment Guide Level 2 provides the specific assessment objectives and methods that CCAs must use when evaluating OSC implementations.
What does the term 'OSC' refer to in the context of CMMC assessments?
Answer: Organization Seeking Certification
OSC stands for Organization Seeking Certification, referring to the defense contractor undergoing the CMMC assessment.
During assessment scoping, what role does the System Security Plan (SSP) play?
Answer: It provides a description of the system boundary, components, and implemented security controls
The SSP describes the system boundary and how security controls are implemented, serving as a critical reference document for scoping and evaluating the assessment.
What is the minimum number of assessors required for a CMMC Level 2 certification assessment conducted by a C3PAO?
Answer: A team of at least two CCAs
CMMC Level 2 certification assessments require a team of at least two CCAs to ensure objectivity and thoroughness.
What is a 'gap analysis' in the context of CMMC assessment planning?
Answer: A pre-assessment review identifying where an OSC does not yet meet CMMC requirements
A gap analysis is a pre-assessment activity that identifies where the OSC's current security posture falls short of CMMC requirements, allowing remediation before the formal assessment.
Which factor is most important when determining if a cloud service provider falls within an OSC's CMMC assessment scope?
Answer: Whether CUI is stored, processed, or transmitted within the CSP environment
A cloud service provider is in scope if CUI is stored, processed, or transmitted within its environment, regardless of FedRAMP status.