
CMMC Certified Assessor
Domain 4Objective 1
Identify Evidence Verification/validation Methods and Objects for Practices Based on the CMMC Level 2 Assessment Guide and CMMC Assessment Process (CAP) Documentation CCA Practice Questions (Page 1)
Part of the Domain 4: Assessing CMMC Level 2 Practices (40%) domain, which accounts for 40% of the CCA exam.
28questions here
6free pages
7concepts
40%of the exam
Questions 1–5
- 1
Which of the following is an example of an evidence object that could be used to verify a CMMC Level 2 practice?
Select an answer first - 2
An assessor is collecting evidence for the risk assessment practice. The organization has a risk register with 500 risks and a risk assessment report. The assessor must collect evidence efficiently while maintaining chain of custody. What is the most appropriate procedure?
Select an answer first - 3
An assessor is verifying the access control practice. The organization has 500 user accounts, and the assessor selects a random sample of 50. In the sample, 5 accounts are found to be inactive but still enabled. What is the most appropriate conclusion?
Select an answer first - 4
An assessor has collected the following evidence: a network diagram, a firewall configuration export, and a vulnerability scan report. Which CMMC Level 2 practice is this evidence most directly mapped to?
Select an answer first - 5
What is the primary purpose of maintaining a chain of custody for evidence during a CMMC assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCA” is a trademark of its owner, used for identification only.