CMMC Framework & Domains Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 CMMC Framework & Domains flashcards as text
Which CMMC domain specifically addresses the ability to recover from a cybersecurity incident by restoring systems?
Answer: Recovery (RE)
The Recovery domain focuses on maintaining data backups and restoring capabilities to ensure resilience after a cybersecurity event.
Under CMMC, which practice area is concerned with limiting system access to authorized users and the minimum necessary permissions?
Answer: Least privilege and need-to-know, under Access Control (AC)
The Access Control domain enforces least privilege and need-to-know principles to restrict what users can access and do.
A defense subcontractor receives CUI from a prime contractor. Under CMMC 2.0, the subcontractor is required to:
Answer: Obtain the same CMMC level certification as required by the prime contractor's contract
CMMC requirements flow down the supply chain; subcontractors handling CUI must obtain the same level of CMMC certification required by the prime contractor.
Which CMMC domain governs how organizations perform maintenance on their IT systems and controls who can conduct that maintenance?
Answer: Maintenance (MA)
The Maintenance domain covers performing, controlling, monitoring, and documenting system maintenance activities and personnel.
In CMMC assessments, what is a 'Contractor Risk Managed Asset' (CRA)?
Answer: An asset that can reach CUI but is managed with compensating controls outside the assessment scope
A CRA is an asset that can reach CUI-scoped assets but is separated and managed by the contractor with mitigating controls, placing it outside the full assessment scope.
The 'Risk Assessment (RA)' domain under CMMC requires organizations to:
Answer: Periodically assess risk to operations, assets, and individuals from system operations
The RA domain requires organizations to conduct periodic risk assessments and use findings to inform security decisions and remediation efforts.
Which CMMC 2.0 level allows self-attestation annually as the ONLY assessment method for ALL contractors at that level?
Answer: Level 1
CMMC Level 1 contractors protecting only FCI may self-attest annually without a third-party assessment.