← All CCA Flashcard Decks

Cybersecurity Practices & Controls Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cybersecurity Practices & Controls flashcards as text
  1. Which CMMC practice specifically requires organizations to separate user functionality from system management functionality?

    Answer: SC.L2-3.13.3

    SC.L2-3.13.3 requires separation of user functionality from system management functionality to reduce risk.

  2. A CCA assessor reviews an organization's incident response plan and finds no defined roles for handling a CUI breach. Which practice gap does this represent?

    Answer: IR.L2-3.6.1 — Establish an operational incident-handling capability

    IR.L2-3.6.1 requires establishing an incident-handling capability that includes defined roles and responsibilities.

  3. What does the CMMC practice PE.L1-3.10.1 require?

    Answer: Limit physical access to organizational systems to authorized individuals

    PE.L1-3.10.1 (Physical Protection) requires limiting physical access to systems, equipment, and the respective operating environments to authorized individuals.

  4. Which NIST SP 800-171 control family maps to the CMMC Audit and Accountability (AU) domain?

    Answer: Control Family 3.3 — Audit and Accountability

    CMMC's AU domain maps directly to NIST SP 800-171 Control Family 3.3, Audit and Accountability.

  5. An organization uses a SIEM tool to aggregate and review security logs. Which CMMC practice is best supported by this control?

    Answer: AU.L2-3.3.2 — Ensure the actions of individual users can be traced

    AU.L2-3.3.2 requires that individual user actions be traceable through logs, which a SIEM directly supports by aggregating and analyzing audit data.

  6. Under CMMC, which practice requires that system components be protected from known vulnerabilities by applying patches and updates?

    Answer: SI.L2-3.14.1

    SI.L2-3.14.1 requires identifying, reporting, and correcting information and information system flaws in a timely manner, including applying security patches.

  7. When assessing a subcontractor's compliance with CUI handling requirements, a CCA assessor notices that the subcontractor shares CUI with a vendor via unencrypted email. Which CMMC practice does this violate?

    Answer: SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission

    SC.L2-3.13.8 requires cryptographic protection of CUI during transmission; unencrypted email fails this requirement.

Cybersecurity Practices & Controls Flashcards — CCA Study Cards with Answers