← All CCA Flashcard Decks

Evaluation Methodology Flashcards

7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Evaluation Methodology flashcards as text
  1. Under CMMC methodology, which condition allows an assessor to use sampling when evaluating a practice across multiple similar assets?

    Answer: Sampling is permitted when assets are homogeneous, consistently configured, and managed identically

    Assessors may use sampling when assets are demonstrably homogeneous — same configuration, management, and purpose — making a full review of every asset redundant.

  2. During the Execute phase, an assessor discovers a critical control gap not identified during scoping. What is the correct course of action?

    Answer: Document the finding, notify the Lead Assessor, and assess it as part of the current engagement

    Newly discovered findings must be documented and assessed; the Lead Assessor coordinates with the OSC to ensure all relevant scope items are evaluated.

  3. A CMMC assessor is reviewing access control practices. An employee states they share credentials with a colleague when that colleague is out of the office. How should this be scored?

    Answer: NOT MET, because shared credentials violate individual accountability requirements

    Credential sharing violates the individual accountability principle required by access control practices, making the relevant practice NOT MET regardless of technical configurations.

  4. What is the significance of a System Security Plan (SSP) in the context of a CMMC evaluation?

    Answer: It is the OSC's primary artifact describing how each CMMC practice is implemented and provides the starting point for assessor review

    The SSP is the OSC's foundational document describing control implementations, and assessors use it as the primary starting point to plan and focus their evidence review.

  5. Which of the following BEST describes 'objective evidence' as used in CMMC assessment methodology?

    Answer: Factual information based on observation, measurement, test, or other means that can be verified and does not depend on personal opinion

    Objective evidence is verifiable, factual information obtained through examination, testing, or observation — it does not rely on subjective assessor opinion or unverified OSC assertions.

  6. An OSC's subcontractor processes CUI on behalf of the prime contractor. Under CMMC evaluation methodology, how does this affect the assessment scope?

    Answer: The subcontractor's handling of CUI may extend the scope boundary and require its systems to be assessed

    When a subcontractor processes, stores, or transmits CUI for the OSC, those systems may fall within the CUI boundary and must be included in the assessment scope.

  7. During an assessment, the 'test' method is most appropriate for evaluating which type of control?

    Answer: A technical control such as an access control mechanism or audit logging function that can be exercised to verify operation

    The 'test' method involves exercising or operating a mechanism to verify it functions as intended, making it most appropriate for technical controls that can be activated or triggered.

Evaluation Methodology Flashcards — CCA Study Cards with Answers