← All CCA Flashcard Decks

Cybersecurity Practices & Controls Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Cybersecurity Practices & Controls flashcards as text
  1. Which CMMC practice requires that system security plans (SSPs) be developed, documented, and periodically updated?

    Answer: CA.L2-3.12.4

    CA.L2-3.12.4 specifically requires development, documentation, and periodic updating of system security plans for organizational systems.

  2. What is the key distinction between a Plan of Action and Milestones (POA&M) and a System Security Plan (SSP) in the context of CMMC?

    Answer: An SSP documents the current security posture while a POA&M documents gaps and remediation timelines

    The SSP describes the current state of security controls, while the POA&M identifies gaps and establishes timelines to remediate them.

  3. A CCA assessor is evaluating an organization's use of mobile devices. Which practice requires the organization to sanitize or destroy media before disposal or reuse?

    Answer: MP.L2-3.8.3 — Sanitize or destroy system media before disposal or reuse

    MP.L2-3.8.3 requires that system media be sanitized or destroyed before disposal or reuse to prevent unauthorized disclosure of CUI.

  4. Which CMMC practice addresses the requirement to control and monitor user-installed software?

    Answer: CM.L2-3.4.8 — Apply deny-by-exception policy to prevent use of unauthorized software

    CM.L2-3.4.8 requires a deny-by-exception (blacklisting or whitelisting) policy to prevent or restrict installation of unauthorized software.

  5. Under CMMC, what does the practice IA.L2-3.5.3 specifically require?

    Answer: Employ replay-resistant authentication mechanisms for network access

    IA.L2-3.5.3 requires employing replay-resistant authentication mechanisms, such as session identifiers or one-time passwords, for network access.

  6. When assessing Configuration Management controls, a CCA assessor finds that change requests are approved verbally with no documentation. Which practice gap does this represent?

    Answer: CM.L2-3.4.3 — Track, review, approve, and log changes to organizational systems

    CM.L2-3.4.3 requires that changes be tracked, reviewed, approved, and logged; verbal-only approvals lack the required documentation.

  7. Which CMMC domain is most directly concerned with ensuring that CUI is only accessible on a need-to-know basis?

    Answer: Access Control (AC)

    The Access Control (AC) domain includes practices that enforce need-to-know access, such as AC.L1-3.1.3 (controlling the flow of CUI).