
CMMC Certified Assessor
Domain 1Objective 1
Assess the Various Environmental Considerations of Organizations Seeking Certification (OSCs) Against CMMC Level 2 Practices CCA Practice Questions (Page 3)
Part of the Domain 1: Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 (15%) domain, which accounts for 15% of the CCA exam.
28questions here
6free pages
6concepts
15%of the exam
Questions 11–15
- 11
An OSC's IT team has configured all workstations with full disk encryption and enabled firewalls. However, they have not implemented any form of network segmentation, and all users can access the file server containing CUI. Which logical environment control is most lacking?
Select an answer first - 12
A small defense contractor operates from a leased office suite in a multi-tenant commercial building. The suite has a locked entrance, but shared hallways and a common lobby are accessible to other tenants. The contractor's server room door is unlocked during business hours, and the room also serves as a storage closet. During a CMMC Level 2 assessment, which physical security control should the assessor most likely identify as a gap?
Select an answer first - 13
An OSC uses a third-party cloud provider to host its CUI. The provider's data centers are located in a foreign country. The OSC's contract with the provider does not specify where data is stored or processed. Which external environment consideration is most critical for the assessor to evaluate?
Select an answer first - 14
An assessor is reviewing the OSC's system configurations. Which of the following is an example of a logical environment factor that could affect CMMC Level 2 compliance?
Select an answer first - 15
Which of the following is an example of an external environmental factor that can affect an OSC's CMMC Level 2 compliance?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCA” is a trademark of its owner, used for identification only.