
CMMC Certified Professional
Domain 3Objective 3
Demonstrate Understanding of the CMMC Source and Supplementary Documents CCP Practice Questions (Page 3)
Part of the CMMC Governance and Source Documents domain, which accounts for 15% of the CCP exam.
24questions here
5free pages
6concepts
15%of the exam
Questions 11–15
- 11
What should an organization do when a supplementary document like NIST SP 800-171 is revised?
Select an answer first - 12
Which supplementary document provides enhanced security requirements for protecting CUI against advanced persistent threats (APTs)?
Select an answer first - 13
A company is implementing CMMC Level 2 and is mapping its controls to the practices. The team finds that a specific practice in the CMMC Model Overview is not directly aligned with any single requirement in NIST SP 800-171. The practice appears to be a combination of multiple requirements. What is the most accurate interpretation of this situation?
Select an answer first - 14
Which of the following is a primary source document for CMMC assessments, providing guidance on how to conduct assessments?
Select an answer first - 15
An organization is implementing CMMC Level 2 and wants to understand the intent behind a specific practice related to incident response. The team finds the practice in the Model Overview but needs more context on the expected evidence and assessment methods. Which supplementary document should they consult?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CCP” is a trademark of its owner, used for identification only.