โ† All CCA Flashcard Decks

CCA Risk Management & Vulnerabilities Flashcards

6 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 CCA Risk Management & Vulnerabilities flashcards as text
  1. In the context of CMMC, what is the primary goal of risk management for defense contractors?

    Answer: To identify, assess, and mitigate risks to CUI and FCI handled within the contractor environment

    The primary goal is to protect CUI and FCI by systematically identifying, assessing, and mitigating risks that could compromise the confidentiality, integrity, or availability of that data.

  2. Which NIST framework provides the foundational risk management guidance that underpins CMMC requirements?

    Answer: NIST SP 800-171

    NIST SP 800-171 provides the specific security requirements for protecting CUI that form the technical basis of CMMC Level 2 requirements.

  3. What does a Plan of Action & Milestones (POA&M) represent in a CMMC assessment context?

    Answer: A documented plan to remediate identified security weaknesses with target completion dates

    A POA&M documents known security deficiencies and outlines the remediation steps and timelines the OSC plans to follow to address those gaps.

  4. Which CMMC domain specifically addresses the requirement for organizations to identify and manage risk to operations?

    Answer: Risk Management (RM)

    The Risk Management domain includes practices that require organizations to identify, assess, and respond to organizational and system risks.

  5. A CCA assessor finds that an OSC has not conducted a periodic risk assessment. Which CMMC practice is most likely 'Not Met'?

    Answer: RM.2.141

    RM.2.141 requires organizations to periodically assess the risk to organizational operations and assets, making it the practice most directly related to conducting risk assessments.

  6. What is the relationship between vulnerability management and CMMC compliance?

    Answer: CMMC requires organizations to identify, report, and remediate vulnerabilities in organizational systems

    CMMC Level 2 includes practices requiring organizations to identify, report, and remediate vulnerabilities as part of system and information integrity requirements.