
CMMC-CCPテスト問題練習試そう!2025年に更新された172問あります
更新された2025年05月プレミアムCMMC-CCP試験エンジンPDFで今すぐダウンロード!無料更新された172問あります
質問 # 29
A company has a government services division and a commercial services division. The government services division interacts exclusively with federal clients and regularly receives FCI. The commercial services division interacts exclusively with non-federal clients and processes only publicly available information. For this company's CMMC Level 1 Self-Assessment, how should the assets supporting the commercial services division be categorized?
- A. Specialized Assets
- B. Out-of-Scope Assets
- C. Operational Technology Assets
- D. FCI Assets
正解:C
質問 # 30
In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?
- A. In scope
- B. Out of scope
- C. Assessment Team Member
- D. OSC point of contact
正解:A
質問 # 31
An OSC receives an email with "CUI//SP-PRVCY//FED Only" in the body of the message Which organization's website should the OSC go to identify what this marking means?
- A. NARA
- B. DoD 239.7601 Definitions page
- C. DoD Contractors FAQ page
- D. CMMC-AB
正解:A
質問 # 32
When assessing SI.L1-3.14.2: Provide protection from malicious code at appropriate locations within organizational information systems, evidence shows that all of the OSC's workstations and servers have antivirus software installed for malicious code protection. A centralized console for the antivirus software management is in place and records show that all devices have received the most updated antivirus patterns.
What is the BEST determination that the Lead Assessor should reach regarding the evidence?
- A. It is insufficient, and the Lead Assessor should seek more evidence.
- B. It is sufficient, and the audit finding can be rated as MET.
- C. It is insufficient, and the audit finding can be rated NOT MET.
- D. It is sufficient, and the Lead Assessor should seek more evidence.
正解:B
質問 # 33
During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?
- A. Lead Assessor
- B. C3PAO
- C. Advisory Board
- D. CCP
正解:A
質問 # 34
Which regulation allows for whistleblowers to sue on behalf of the federal government?
- A. False Claims Act
- B. NISTSP 800-53
- C. Code of Professional Conduct
- D. NISTSP 800-171
正解:A
質問 # 35
A company is about to conduct a press release. According to AC.L1-3.1.22: Control information posted or processed on publicly accessible systems, what is the MOST important factor to consider when addressing CMMC requirements?
- A. That so long as the information is only FCI, it can be released
- B. That the CEO approved the message
- C. That the information is correct
- D. That the company has to safeguard the release of FCI
正解:D
質問 # 36
Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse. After a thorough review, the CCP tells the Lead Assessor that all supporting documents fully reflect the performance of the practice and should be accepted because the evidence is:
- A. compliant.
- B. subjective.
- C. official.
- D. adequate.
正解:D
質問 # 37
SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC's assessment. How does this affect the assessment scope?
- A. An error has been made and the Lead Assessor should be contacted to correct the error.
- B. VoIP technology is within scope, and it uses FlPS-validated encryption, so it does not need to be assessed.
- C. VoIP technology is not used within scope boundary, so no assessment procedures are specified for this practice.
- D. Any existing telephone system is in scope even if it is not using VoIP technology.
正解:C
質問 # 38
An OSC needs to be assessed on RA.L2-3.11.1: Periodically assess the risk to organizational operations (including mission, functions, image, or reputation), organizational assets, and individuals, resulting from the operation of organizational systems and the associated processing, storage, or transmission of CUI. What is in scope for a Level 2 assessment of RA.L2-3.11.1?
- A. Processes, people, physical entities, and IT systems in which CUI processed, stored, or transmitted
- B. Enterprise systems
- C. IT systems
- D. CUI Marking processes
正解:A
質問 # 39
Which document BEST determines the existence of FCI and/or CUI in scoping an assessment with an OSC?
- A. OSC POA&M
- B. OSC Contract with DoD
- C. OSC Evidence
- D. OSC SSP
正解:B
質問 # 40
A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?
- A. Confidential and non-attributable so interviewees can speak without fear of reprisal
- B. Recorded for inclusion in the Final Recommended Findings report
- C. Performed in groups for more efficient use of resources
- D. Mapped to specific CMMC practices to clearly delineate which practice is being evaluated
正解:A
質問 # 41
When planning an assessment, the Lead Assessor should work with the OSC to select personnel to be interviewed who could:
- A. have a security clearance.
- B. be a senior person in the company.
- C. demonstrate expertise on the CMMC requirements.
- D. provide clarity and understanding of their practice activities.
正解:D
質問 # 42
An assessor has been working with an OSC's point of contact to plan and prepare for their upcoming assessment. What is one of the MOST important things to remember when analyzing requirements for an assessment?
- A. Scoping an assessment is easy and worry-free.
- B. Assessors need to continuously review and update the requirements and plan for the assessment as information is gathered.
- C. The initial plan cannot be changed once agreed upon.
- D. There is a determined amount of time that the OSC's point of contact has to submit evidence and rough order-of-magnitude.
正解:B
質問 # 43
Which domains are a part of a Level 1 Self-Assessment?
- A. Risk Management (RM). Access Control (AC), and Physical Protection (PE)
- B. Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)
- C. Access Control (AC), Risk Management <RM), and Media Protection (MP)
- D. Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)
正解:C
質問 # 44
Contractor scoping requirements for a CMMC Level 2 Assessment to document the asset in an inventory, in the SSP and on the network diagram apply to:
- A. GUI Assets.
- B. all asset categories except for the Out-of-scope Assets.
- C. Contractor Risk Managed Assets and Specialized Assets.
- D. CUI and Security Protection Asset categories.
正解:B
質問 # 45
Which code or clause requires that a contractor is meeting the basic safeguarding requirements for FCI during a Level 1 Self-Assessment?
- A. DFARS 252.204-7021
- B. FAR 52.204-21
- C. DFARS 252.204-7011
- D. 22CFR 120-130
正解:B
質問 # 46
Within the CMMC Ecosystem which organization ultimately will manage and oversee the training, testing, authorization, and certification of candidate assessors and instructors?
- A. CMMC Assessors and Instructors Certification Organization
- B. DoDOUSD
- C. DIB Collaborative Information Sharing Environment
- D. Committee on National Security Systems Instructions
正解:A
質問 # 47
An assessment is being completed at a client site that is not far from the Lead Assessor's home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?
- A. Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.
- B. Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.
- C. Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.
- D. Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service.
正解:C
質問 # 48
......
正真正銘のCMMC-CCP問題集には100%合格率練習テスト問題集:https://www.passtest.jp/Cyber-AB/CMMC-CCP-shiken.html
Cyber AB CMMC-CCPリアル試験問題保証付き更新された問題集にはPassTest:https://drive.google.com/open?id=1sHHcScceFIAlJSLkPOFcHmH4hvyyIsjM