CertsPoint
See all results for ""
Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
About Us
Sign In Get Started

Certified CMMC Assessor (CCA) Exam CMMC-CCA Exam Questions

Preparing for the CMMC-CCA exam is simple with CertsPoint. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.

At CertsPoint, we keep our CMMC-CCA practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.

Download Exam View Entire Exam
Page: 2 / 2
Question #6 (Topic: Demo Questions)

When assessing an environment, the CCA determines that CUI is contained within an IoT device. Which statement MUST be true?

A.

The IoT device is a Contractor Risk Managed Asset.

B.

The IoT device must be accurately documented within the SSP.

C.

An IoT device may not be utilized to process, store, or transmit CUI.

D.

Access provisioned to the IoT device must be done in accordance with AC.L2-3.1.1: Limit System Access.

Correct Answer: B
Explanation:

When an IoT device processes, stores, or transmits CUI, it is categorized as a CUI Asset (not CRMA). All in-scope assets must be documented in the System Security Plan (SSP) . The SSP must identify how the asset is managed, secured, and integrated into the OSC’s environment.

Exact Extracts:

    CMMC Scoping Guide: “All CUI Assets must be identified and described in the SSP.”

    “Specialized Assets (including IoT) must be documented in the SSP if they process, store, or transmit CUI.”

    “Contractor Risk Managed Assets do not include assets that process, store, or transmit CUI.”

Why other options are not correct:

    A: Incorrect, because an IoT device with CUI cannot be a CRMA.

    C: Incorrect, IoT can process CUI if properly secured and documented.

    D: While true in general (AC control applies), the mandatory requirement is accurate SSP documentation.

[References:, CMMC Assessment Scope – Level 2, Version 2.13: Asset categories (pp. 5–10)., CMMC Assessment Guide – Level 2: SSP documentation requirements., ]
Question #7 (Topic: Demo Questions)

An OSC outsources all of its security incident and event monitoring work to a third-party SOC. Additionally, the OSC utilizes a cloud-hosted antivirus (AV) system to fulfill the requirement of having virus protection without hosting additional servers on-site.

During the scoping discussion, both the SOC and AV should be listed as what type of asset?

A.

They are CUI Assets due to their operation within a CUI network.

B.

They are Out-of-Scope Assets due to being fully hosted/operated by third parties.

C.

They are Security Protection Assets due to their performance of security functions.

D.

They are Contractor Risk Managed Assets because they are not physically or logically isolated from CUI assets.

Correct Answer: C
Explanation:

The Scoping Guidance defines Security Protection Assets as systems, tools, or services that provide security functions protecting CUI assets , even if outsourced to third parties.

Extract:

“Security Protection Assets are tools, systems, or services that provide security functionality (e.g., SOC, antivirus, logging) to protect CUI assets. These must be included in scope.”

Therefore, SOC and AV must be categorized as Security Protection Assets .

[Reference: CMMC Scoping Guidance – Security Protection Assets., ]
Question #8 (Topic: Demo Questions)

During an assessment, an assessor is trying to determine if the organization provides protection from malicious code at appropriate locations within organizational information systems. The assessor has decided to use the Interview method to gather evidence. It is BEST to interview:

A.

System developers

B.

System or network administrators

C.

Personnel with audit and accountability responsibilities

D.

Personnel with security alert and advisory responsibilities

Correct Answer: B
Explanation:

Malicious code protection is typically implemented and managed by system or network administrators , who configure, deploy, and monitor anti-malware solutions. Interviews with these administrators provide direct evidence of control implementation.

Exact Extracts:

    SI.L2-3.14.2: “Provide protection from malicious code at appropriate locations within organizational information systems.”

    CMMC Assessment Guide: “Interviews should be conducted with administrators responsible for deployment and monitoring of malicious code protection.”

    NIST SP 800-171A (SI.L2-3.14.2): “Interview system or network administrators to determine how malicious code protection is implemented.”

Why other options are not correct:

    A (developers): Developers do not typically manage system-wide malicious code protections.

    C (audit personnel): They review logs, not deploy/manage protections.

    D (security advisory staff): They track alerts but don’t operate malicious code defenses.

[References:, CMMC Assessment Guide – Level 2, Version 2.13: SI.L2-3.14.2 (pp. 142–144)., NIST SP 800-171A: Assessment procedures for malicious code protection., ]
Question #9 (Topic: Demo Questions)

During a CMMC Assessment, the assessor is determining if the Escort Visitors practice is MET. Personnel with which of the following responsibilities would be MOST appropriate to interview?

A.

Repair and facilities maintenance

B.

Local access control and information security

C.

Physical access control and information security

D.

Information technology management and operations

Correct Answer: C
Explanation:

The Escort Visitors practice falls under Physical and Environmental Protection (PE.L2-3.10.3) , which requires organizations to escort visitors and monitor visitor activity . To validate this, the assessor should interview personnel responsible for physical access control (security guards, facility access managers) and information security (to confirm integration with CUI protection requirements).

Exact Extracts:

    PE.L2-3.10.3: “Escort visitors and monitor visitor activity.”

    Assessment Guide: “Interview personnel responsible for physical access control and security monitoring to confirm escort and visitor activity tracking.”

    Assessment Objectives: Require evidence of visitor escorts, visitor logs, and monitoring practices.

Why the other options are not correct:

    A (Repair/maintenance): Not responsible for escort procedures.

    B (Local access control only): Missing the information security link , which ensures visitors cannot access CUI assets.

    D (IT management): IT is not responsible for escorting visitors in physical spaces.

[References:, CMMC Assessment Guide – Level 2, Version 2.13: PE.L2-3.10.3 (pp. 154–156)., NIST SP 800-171A: Assessment procedures for visitor escort and monitoring., , , ]
Download Exam
« Prev Page: 2 / 2
Next Page