Cybersecurity Practices & Controls Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Practices & Controls flashcards as text
Which CMMC practice specifically requires organizations to separate user functionality from system management functionality?
Answer: SC.L2-3.13.3
SC.L2-3.13.3 requires separation of user functionality from system management functionality to reduce risk.
A CCA assessor reviews an organization's incident response plan and finds no defined roles for handling a CUI breach. Which practice gap does this represent?
Answer: IR.L2-3.6.1 — Establish an operational incident-handling capability
IR.L2-3.6.1 requires establishing an incident-handling capability that includes defined roles and responsibilities.
What does the CMMC practice PE.L1-3.10.1 require?
Answer: Limit physical access to organizational systems to authorized individuals
PE.L1-3.10.1 (Physical Protection) requires limiting physical access to systems, equipment, and the respective operating environments to authorized individuals.
Which NIST SP 800-171 control family maps to the CMMC Audit and Accountability (AU) domain?
Answer: Control Family 3.3 — Audit and Accountability
CMMC's AU domain maps directly to NIST SP 800-171 Control Family 3.3, Audit and Accountability.
An organization uses a SIEM tool to aggregate and review security logs. Which CMMC practice is best supported by this control?
Answer: AU.L2-3.3.2 — Ensure the actions of individual users can be traced
AU.L2-3.3.2 requires that individual user actions be traceable through logs, which a SIEM directly supports by aggregating and analyzing audit data.
Under CMMC, which practice requires that system components be protected from known vulnerabilities by applying patches and updates?
Answer: SI.L2-3.14.1
SI.L2-3.14.1 requires identifying, reporting, and correcting information and information system flaws in a timely manner, including applying security patches.
When assessing a subcontractor's compliance with CUI handling requirements, a CCA assessor notices that the subcontractor shares CUI with a vendor via unencrypted email. Which CMMC practice does this violate?
Answer: SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic protection of CUI during transmission; unencrypted email fails this requirement.