Cybersecurity Practices & Controls Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Practices & Controls flashcards as text
Which CMMC practice requires that system security plans (SSPs) be developed, documented, and periodically updated?
Answer: CA.L2-3.12.4
CA.L2-3.12.4 specifically requires development, documentation, and periodic updating of system security plans for organizational systems.
What is the key distinction between a Plan of Action and Milestones (POA&M) and a System Security Plan (SSP) in the context of CMMC?
Answer: An SSP documents the current security posture while a POA&M documents gaps and remediation timelines
The SSP describes the current state of security controls, while the POA&M identifies gaps and establishes timelines to remediate them.
A CCA assessor is evaluating an organization's use of mobile devices. Which practice requires the organization to sanitize or destroy media before disposal or reuse?
Answer: MP.L2-3.8.3 — Sanitize or destroy system media before disposal or reuse
MP.L2-3.8.3 requires that system media be sanitized or destroyed before disposal or reuse to prevent unauthorized disclosure of CUI.
Which CMMC practice addresses the requirement to control and monitor user-installed software?
Answer: CM.L2-3.4.8 — Apply deny-by-exception policy to prevent use of unauthorized software
CM.L2-3.4.8 requires a deny-by-exception (blacklisting or whitelisting) policy to prevent or restrict installation of unauthorized software.
Under CMMC, what does the practice IA.L2-3.5.3 specifically require?
Answer: Employ replay-resistant authentication mechanisms for network access
IA.L2-3.5.3 requires employing replay-resistant authentication mechanisms, such as session identifiers or one-time passwords, for network access.
When assessing Configuration Management controls, a CCA assessor finds that change requests are approved verbally with no documentation. Which practice gap does this represent?
Answer: CM.L2-3.4.3 — Track, review, approve, and log changes to organizational systems
CM.L2-3.4.3 requires that changes be tracked, reviewed, approved, and logged; verbal-only approvals lack the required documentation.
Which CMMC domain is most directly concerned with ensuring that CUI is only accessible on a need-to-know basis?
Answer: Access Control (AC)
The Access Control (AC) domain includes practices that enforce need-to-know access, such as AC.L1-3.1.3 (controlling the flow of CUI).