CCA Contractor & Supplier Requirements Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCA Contractor & Supplier Requirements flashcards as text
What is a 'covered contractor information system' under DFARS 252.204-7012?
Answer: An unclassified information system owned or operated by a contractor that processes, stores, or transmits covered defense information
A covered contractor information system is an unclassified system that processes, stores, or transmits covered defense information (CUI) as required or authorized by the DoD contract.
Under CMMC, what is the contractor's obligation regarding media containing CUI that is sent off-site for maintenance?
Answer: CUI must be sanitized or encrypted on media prior to removal, and the chain of custody must be documented
CMMC media protection practices require that CUI be sanitized or appropriately encrypted when media is sent for maintenance, and the chain of custody must be maintained to protect against unauthorized disclosure.
Which practice requires contractors to limit the use of portable storage devices on organizational systems?
Answer: MP.2.120
MP.2.120 requires organizations to control and limit the use of removable media on system components to reduce the risk of data exfiltration or introduction of malicious code.
What is the significance of the CMMC Ecosystem in contractor compliance?
Answer: It encompasses the network of C3PAOs, CCAs, RPOs, RPs, and the Cyber AB that support contractor CMMC certification
The CMMC Ecosystem includes all the accredited organizations and individuals (C3PAOs, CCAs, RPOs, RPs) that support contractors in achieving and maintaining CMMC compliance under the Cyber AB's oversight.
When a contractor uses a cloud service provider (CSP) to store CUI, which federal authorization standard must the CSP meet?
Answer: FedRAMP authorization at the appropriate impact level
CSPs that store, process, or transmit CUI for defense contractors must meet FedRAMP authorization requirements at the appropriate impact level (typically Moderate or High for CUI).
What does CMMC require regarding the protection of CUI in transit across external networks?
Answer: CUI must be encrypted using FIPS 140-2 validated cryptography when transmitted over external networks
CMMC requires that CUI transmitted over external networks be protected using FIPS 140-2 validated cryptographic mechanisms to prevent unauthorized interception or disclosure.