Cybersecurity Practices & Controls Flashcards
7 cards from real CCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Cybersecurity Practices & Controls flashcards as text
Under CMMC 2.0, which practice requires organizations to limit system access to authorized users, processes acting on behalf of authorized users, and devices?
Answer: AC.L1-3.1.1
AC.L1-3.1.1 (Authorized Access Control) is a Level 1 practice that limits system access to authorized users, processes, and devices.
Which CMMC domain addresses the need to establish and maintain baseline configurations for information technology systems?
Answer: Configuration Management (CM)
The Configuration Management (CM) domain includes practices for establishing and maintaining baseline configurations for IT systems.
A CCA assessor finds that an organization uses shared accounts for multiple administrators. Which CMMC practice is most directly violated?
Answer: IA.L2-3.5.5 — Employ identifier management
IA.L2-3.5.5 requires identifier management, including ensuring individual identifiability, which shared accounts violate.
What is the primary purpose of the Media Protection (MP) domain in CMMC?
Answer: To protect system media containing CUI, both paper and digital
The Media Protection domain focuses on protecting system media containing CUI, whether in physical (paper) or digital form.
Which practice requires that CMMC Level 2 organizations scan for vulnerabilities in organizational systems and applications periodically?
Answer: RA.L2-3.11.2
RA.L2-3.11.2 requires periodic vulnerability scanning of organizational systems and hosted applications.
When assessing the Awareness and Training (AT) domain, what is the minimum evidence a CCA assessor should expect for CMMC Level 2?
Answer: Annual cybersecurity training completion records for all users
AT.L2-3.2.1 and AT.L2-3.2.2 require that users are made aware of security risks and trained; completion records demonstrate compliance.
An organization encrypts CUI data at rest on laptops but transmits it in plaintext internally. Which CMMC practice is not being met?
Answer: SC.L2-3.13.8 — Implement cryptographic mechanisms to protect CUI during transmission
SC.L2-3.13.8 requires cryptographic protection of CUI during transmission, which is not satisfied by plaintext internal transfers.