Certified CMMC Assessor (CCA) Exam CMMC-CCA Exam Questions
Preparing for the CMMC-CCA exam is simple with CertsPoint. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.
At CertsPoint, we keep our CMMC-CCA practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.
When assessing an environment, the CCA determines that CUI is contained within an IoT device. Which statement MUST be true?
Correct Answer: B
When an IoT device processes, stores, or transmits CUI, it is categorized as a CUI Asset (not CRMA). All in-scope assets must be documented in the System Security Plan (SSP) . The SSP must identify how the asset is managed, secured, and integrated into the OSC’s environment.
Exact Extracts:
CMMC Scoping Guide: “All CUI Assets must be identified and described in the SSP.”
“Specialized Assets (including IoT) must be documented in the SSP if they process, store, or transmit CUI.”
“Contractor Risk Managed Assets do not include assets that process, store, or transmit CUI.”
Why other options are not correct:
A: Incorrect, because an IoT device with CUI cannot be a CRMA.
C: Incorrect, IoT can process CUI if properly secured and documented.
D: While true in general (AC control applies), the mandatory requirement is accurate SSP documentation.
An OSC outsources all of its security incident and event monitoring work to a third-party SOC. Additionally, the OSC utilizes a cloud-hosted antivirus (AV) system to fulfill the requirement of having virus protection without hosting additional servers on-site.
During the scoping discussion, both the SOC and AV should be listed as what type of asset?
Correct Answer: C
The Scoping Guidance defines Security Protection Assets as systems, tools, or services that provide security functions protecting CUI assets , even if outsourced to third parties.
Extract:
“Security Protection Assets are tools, systems, or services that provide security functionality (e.g., SOC, antivirus, logging) to protect CUI assets. These must be included in scope.”
Therefore, SOC and AV must be categorized as Security Protection Assets .
During an assessment, an assessor is trying to determine if the organization provides protection from malicious code at appropriate locations within organizational information systems. The assessor has decided to use the Interview method to gather evidence. It is BEST to interview:
Correct Answer: B
Malicious code protection is typically implemented and managed by system or network administrators , who configure, deploy, and monitor anti-malware solutions. Interviews with these administrators provide direct evidence of control implementation.
Exact Extracts:
SI.L2-3.14.2: “Provide protection from malicious code at appropriate locations within organizational information systems.”
CMMC Assessment Guide: “Interviews should be conducted with administrators responsible for deployment and monitoring of malicious code protection.”
NIST SP 800-171A (SI.L2-3.14.2): “Interview system or network administrators to determine how malicious code protection is implemented.”
Why other options are not correct:
A (developers): Developers do not typically manage system-wide malicious code protections.
C (audit personnel): They review logs, not deploy/manage protections.
D (security advisory staff): They track alerts but don’t operate malicious code defenses.
During a CMMC Assessment, the assessor is determining if the Escort Visitors practice is MET. Personnel with which of the following responsibilities would be MOST appropriate to interview?
Correct Answer: C
The Escort Visitors practice falls under Physical and Environmental Protection (PE.L2-3.10.3) , which requires organizations to escort visitors and monitor visitor activity . To validate this, the assessor should interview personnel responsible for physical access control (security guards, facility access managers) and information security (to confirm integration with CUI protection requirements).
Exact Extracts:
PE.L2-3.10.3: “Escort visitors and monitor visitor activity.”
Assessment Guide: “Interview personnel responsible for physical access control and security monitoring to confirm escort and visitor activity tracking.”
Assessment Objectives: Require evidence of visitor escorts, visitor logs, and monitoring practices.
Why the other options are not correct:
A (Repair/maintenance): Not responsible for escort procedures.
B (Local access control only): Missing the information security link , which ensures visitors cannot access CUI assets.
D (IT management): IT is not responsible for escorting visitors in physical spaces.