CCA Risk Management & Vulnerabilities Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCA Risk Management & Vulnerabilities flashcards as text
During a CMMC assessment, an assessor discovers an OSC has unpatched critical vulnerabilities on servers that store CUI. What is the appropriate assessor action?
Answer: Document the finding as 'Not Met' for the relevant patching/vulnerability management practices
Unpatched critical vulnerabilities on CUI-storing systems directly evidence failure of patch and vulnerability management practices, which must be documented as 'Not Met'.
What is the primary purpose of threat intelligence in CMMC risk management?
Answer: To inform risk assessments and security decisions with current knowledge of threats facing defense contractors
Threat intelligence provides current information about adversarial tactics, techniques, and procedures relevant to defense contractors, helping organizations make informed risk management decisions.
Which practice requires OSCs to monitor system security alerts and advisories under CMMC Level 2?
Answer: SI.2.214
SI.2.214 requires organizations to monitor system security alerts and advisories and take appropriate actions in response, supporting proactive vulnerability awareness.
In CMMC risk management, what is meant by 'residual risk'?
Answer: The remaining risk after security controls have been applied
Residual risk is the level of risk that remains after security controls have been implemented, which organizations must decide to accept, transfer, or further mitigate.
How does CMMC address the risk posed by insider threats?
Answer: Through practices such as least privilege, separation of duties, and personnel screening
CMMC addresses insider threat risk through access control practices (least privilege), personnel security practices, and audit/accountability requirements that collectively reduce and detect insider threats.
What is the significance of FIPS 140-2 validation in CMMC risk management?
Answer: It ensures cryptographic modules meet federal standards, reducing risk of encryption failures protecting CUI
FIPS 140-2 validated cryptography is required by CMMC to ensure that encryption protecting CUI meets federal security standards and reduces the risk of cryptographic failure.