CCA Risk Management & Vulnerabilities Flashcards
6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CCA Risk Management & Vulnerabilities flashcards as text
Which CMMC practice requires organizations to develop and implement a risk management strategy?
Answer: RM.3.144
RM.3.144 requires organizations to periodically assess the risk to organizational operations, assets, and individuals, and to develop risk management strategies to address identified risks.
What type of risk does supply chain compromise pose in the CMMC framework?
Answer: Risk that adversaries may introduce malicious components into hardware, software, or services used by contractors to compromise CUI
Supply chain risk involves adversaries compromising components before they reach the contractor, potentially enabling unauthorized access to CUI even when the contractor's own practices are sound.
What is the role of configuration baselines in CMMC vulnerability management?
Answer: They establish a known-good system state that enables detection of unauthorized changes that may introduce vulnerabilities
Configuration baselines establish the approved secure configuration state, enabling organizations to detect deviations that may introduce vulnerabilities or indicate compromise.
A CCA assessor is reviewing an OSC's vulnerability scanning program. Which finding would be most concerning from a CMMC compliance perspective?
Answer: High-severity vulnerabilities on CUI systems have remained unpatched for over 180 days
Long-standing high-severity vulnerabilities on CUI-handling systems represent a critical compliance failure, as CMMC requires timely remediation of identified vulnerabilities.
How should an OSC handle the discovery of a zero-day vulnerability affecting its CUI systems during a CMMC assessment?
Answer: Implement compensating controls immediately and document the risk treatment decision
An OSC should implement compensating controls immediately to reduce exposure and document the risk treatment decision, demonstrating an active risk management posture to the assessor.
Under CMMC, what is the purpose of conducting periodic reviews of user accounts and access privileges?
Answer: To identify and remove excessive or unauthorized access that could increase the risk of insider threat or data exposure
Periodic access reviews identify accounts with excessive or unnecessary privileges, enforcing least privilege principles that reduce insider threat risk and limit the impact of compromised accounts.