All questions

Certified CMMC Assessor (CCA) Practice Exam

Browse all practice questions for the Certified CMMC Assessor (CCA) Practice Exam. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

Certified CMMC Assessor (CCA) Practice Exam 2026 – Your All-in-One Guide to Certification Success! course image
All questions

These questions are part of the practice quiz. Start practicing

  • Contractor Risk Managed Assets (CRMA) must be documented in all of the following EXCEPT:
  • What document confirms the compliance status and results of a CMMC assessment?
  • Which of the following describes an Enduring Exception?
  • Which method of authentication is described as insecure within AC.L2-3.1.17?
  • Which of the following best describes "Information Flow Control" in the context of OSC?
  • What is the purpose of VPN gateways in a network?
  • What should interviews conducted during an assessment demonstrate?
  • What allows VLANs to manage data flow and enhance security?
  • What key issue must be addressed during the In-Brief Meeting for assessment preparation?
  • What is the role of the organization in relation to a contract?
  • What aspect should assessors verify regarding the generated audit records according to AU.L2-3.3.1?
  • Which approach is NOT a part of reinforcing risk-aware behavior according to CMMC?
  • Which of the following best describes 'Incident Handling'?
  • What does a governing policy artifact for CMMC include?
  • What requirement does AT.L2-3.2.1 emphasize for users of organizational systems?
  • Which of the following is NOT a characteristic of an External Service Provider?
  • During an assessment, what is the purpose of inviting questions from the OSC in the In-Brief Meeting?
  • Under SI.L2-3.14.2, where must organizations provide malicious code protection?
  • What is the goal of the Non-Duplication assessment planning step?
  • What must assessors determine regarding users and nonsecurity functions according to AC.L2-3.1.6?
  • What must a legal notification inform users regarding information system usage?
  • What is the purpose of a session lock?
  • What is the purpose of a Non-Disclosure Agreement (NDA) in the CMMC assessment?
  • Which of the following is NOT a requirement for assets classified under CRMA?
  • What is the purpose of a Document Traceability Matrix?
  • What does security control inheritance refer to?
  • In terms of asset protection, what does the CMMC Level 2 practice necessitate?
  • What is the purpose of the Separation of Duties principle in CMMC?
  • Which type of account typically has the most limited access?
  • What does the principle of least privilege ensure for security functions and accounts?
  • What is the purpose of access enforcement mechanisms?
  • When developing maintenance policies, what should organizations prioritize?
  • What must organizations ensure when scheduling maintenance activities?
  • What governs the types of services outlined in a Service Level Agreement?
  • Under AC.L2-3.1.15, what is required to execute privileged commands?
  • What is the purpose of an Asset Inventory?
  • What is classified as test equipment in a CMMC context?
  • In the context of CMMC, what primarily defines 'logical access'?
  • What element is necessary to include in audit logs to meet CMMC system auditing requirements?
  • Which artifact is produced by the hashing tool in the CMMC process?
  • What must system-use notification banners display according to CMMC practice AC.L2-3.1.9?
  • What is a Practice in the context of CMMC objectives?
  • What comprises a baseline configuration according to CMMC standards?
  • What is the primary objective of security awareness training?
  • What must be included in audit records to support user activity traceability?
  • Which of the following components would NOT be considered part of a baseline configuration?
  • What does equipment sanitization aim to achieve?
  • What type of protection must be implemented for organizational systems as per SI.L2-3.14.2?
  • What type of approach is recommended for maintenance activities to avoid risks?
  • In CMMC 2.0, why are physical access controls essential at physical locations?
  • What happens after all evaluations and evidence examinations are completed in a CMMC assessment?
  • How are security policies typically structured in terms of content?
  • What characterizes out-of-scope assets in CMMC assessments?
  • Which method is NOT typically part of the sanitization process?
  • Who is responsible for affirming compliance with CMMC Program requirements within an Organization Seeking Assessment?
  • What does the Unique Entity Code (UEI) enable organizations to do?
  • What types of devices qualify as mobile devices?
  • What is an observation in the context of a CMMC assessment?
  • What function does the Artifact Hashing Tool serve in the CMMC assessment process?
  • What does the practice AC.L2-3.1.8 require organizations to define in relation to logon attempts?
  • What does a mobile device need regarding data storage?
  • What does the CMMC Assessment Scope refer to?
  • What is a fundamental practice for maintaining organizational systems?
  • What is the role of the Cyber AB in the CMMC assessment process?
  • What is the primary requirement for CUI Assets within CMMC?
  • What is the purpose of regular updates to malicious code protections described in SI.L1-3.14.4?
  • What is the role of a Lead CCA during an assessment?
  • What does an organizational chart represent in a company?
  • What does CMMC requirement AC.L2-3.1.13 mandate for OSCs regarding remote access sessions?
  • Who reviews the appeals submitted within the CMMC assessment appeals process?
  • What type of evidence is necessary to demonstrate compliance with FedRAMP Moderate standards?
  • According to IR.L2-3.6.2, how should organizations manage security incidents?
  • What is required for an artifact to be considered acceptable evidence in a CMMC assessment?
  • What is a key requirement of AC.L2-3.1.18 regarding mobile device connections?
  • What must assessors confirm about wireless access according to CMMC practice AC.L2-3.1.17?
  • What does the CMMC requirement for system baselining aim to ensure?
  • How do organizations reinforce risk-aware behavior as stated in AT.L2-3.2.1?
  • According to the assessment objectives of CMMC practice AC.L2-3.1.3, what must be defined?
  • What is a fundamental requirement for a CMMC Level 2 certification assessment to proceed?
  • What is a System Security Plan (SSP)?
  • Which type of controls are used to manage data flow within interconnected systems?
  • Which of the following best describes the Internet of Things (IoT)?
  • What distinguishes Organizations Seeking Certification (OSC) from Organizations Seeking Assessment (OSA)?
  • What does the Commercial and Government Entity (CAGE) Code signify in the CMMC assessment process?
  • Which of the following actions is essential according to the control SI.L1-3.14.4 for organizations to combat malware?
  • Within how many days must appeals concerning CMMC decisions be submitted?
  • What is the significance of having a Certificate of CMMC Status?
  • Security Protection Assets (SPA) are primarily used for what purpose?
  • What is indicated by the CMMC Status when assessing an information system?
  • Who conducts the Certification Assessment in a CMMC context?
  • According to CMMC practice AC.L2-3.1.5, what is required for privileged accounts?
  • What is required for documentation of Specialized Assets?
  • What does the term "Organization Seeking Assessment (OSA)" refer to?
  • Which term refers to the scope of the system and environment being assessed?
  • What does AC.L2-3.1.19 require for all CUI on mobile devices?
  • How should organizations approach flaw remediation as per SI.L2-3.14.1?
  • What describes the ideal implementation of privileged functions according to CMMC?
  • What does the term “facility” refer to in the context of enabling actions?
  • What defines an organization's environment according to the Network Diagram?
  • What is the purpose of the report prepared following a CMMC assessment?
  • Which of the following best describes the nature of a Process in CMMC?
  • What is the goal of the testing mandated by IR.L2-3.6.3?
  • How are logical locations defined within an information system?
  • Which of the following is NOT a requirement for privileged accounts as per CMMC?
  • What is described as a security design principle allowing only the necessary system access?
  • Which component does a Network Diagram typically include?
  • Operational Technology (OT) primarily interacts with which environment?
  • What does the CMMCAssessmentLogHash.log file contain?
  • What is the primary purpose of physical or logical separation of assets that process CUI?
  • What must organizations do associated with wireless access as indicated by AC.L2-3.1.16?
  • What is characterized by the traditional IT infrastructure within a professional environment?
  • What must assessors verify regarding security roles according to AT.L2-3.2.2?
  • What must tests or demonstrations pass to be considered acceptable evidence?
  • Which of the following best describes a physical location in system architecture?
  • Which organization produces the CMMC doctrine that guides assessment procedures?
  • What is the function of a RADIUS server in accessing wireless networks?
  • What type of technologies do boundary control devices include?
  • What is the function of Information Assurance (IA) in the context of a DMZ?
  • What defines connected systems in relation to FCI/CUI environments?
  • Which method does Physical Separation employ for data transfer?
  • Which of the following best describes a Procedure in CMMC?
  • What must assessors verify regarding the use of portable storage devices containing CUI?
  • What characterizes a virtual assessment in the CMMC process?
  • Why is it important to have default-deny rules configured for public-facing subnetworks?
  • Which situation would indicate a too-broad scope for a CMMC assessment?
  • What does a Hybrid Assessment involve regarding evidence collection?
  • What does a Computer Security Incident Response Team (CSIRT) do?
  • Which assessment activity is overseen by the Quality Assurance Individual?
  • What is a critical measure to address when devices must be removed from the site for repair?
  • Which of the following describes Security Protection Data (SPD)?
  • What does a Data Flow Diagram illustrate?
  • What does the use of session locks ensure regarding visible information?
  • What type of data would typically fall under the category of Security Protection Data (SPD)?
  • What does a Plan in CMMC encompass?
  • What does the central hub for incident documentation and reporting enhance according to IR.L2-3.6.2?
  • What is the purpose of evidence validation in CMMC assessments?
  • What defines a Security Domain?
  • What is the purpose of the CMMC Hashing Tool Execution Policy?
  • What encryption method is utilized in WPA2-PSK?
  • What does an assessment objective express in a CMMC context?
  • What is the primary focus of CMMC Level 2 practices regarding organizational systems?
  • What aspect of maintenance does CMMC Level 2 emphasize in its practices?
  • What is necessary when confirming compliance for mobile encryption according to AC.L2-3.1.19?
  • What is the main benefit of encrypted remote access?
  • Which characteristic best defines a Demilitarized Zone (DMZ)?
  • What does the System Security Plan outline regarding security controls?
  • What is the primary role of a Firewall in networking?
  • Which of the following best defines an incident in the CMMC context?
  • Which category does NOT fall under the asset categorization required for CMMC assessment?
  • What is the main purpose of a C3PAO being listed as "authorized" or "accredited" in the CMMC Marketplace?
  • Which of the following account types does NOT categorize access privileges?
  • What is the significance of monitoring maintenance and repairs?
  • What is a primary requirement under SI.L2-3.14.3 for organizations regarding security alerts?
  • What are participants in Level 2 certification assessments called?
  • What do Restricted Information Systems support?
  • Which factor is NOT considered when testing incident response capabilities?
  • What is the primary purpose of limiting the use of portable storage devices on external systems according to CMMC practice?
  • What approach should organizations take when performing maintenance activities?
  • What is a key focus during Phase 4 of the CMMC Assessment Process?
  • How is an asset defined in relation to CMMC compliance?
  • What should assessors determine for remote access routing according to AC.L2-3.1.14?
  • What are artifacts in the context of CMMC assessments?
  • What is the purpose of a Shared Responsibility Matrix (SRM)?
  • What is the primary purpose of a Security Control Assessment?
  • In the context of industrial environments, what does the Purdue Model help establish?
  • What describes a Privileged Command as per CMMC?
  • What is the purpose of a Self-Assessment in the context of CMMC?
  • What does the DoD Assessment Methodology (DoDAM) standardize?
  • What is essential for both parties in a Non-Disclosure Agreement (NDA)?
  • What tool is used to help establish context for CMMC Assessment activities?
  • Which of the following is a responsibility of the organization’s security apparatus as outlined in CMMC?
  • What action does session termination entail?
  • What is the purpose of the final written assessment results submitted by the assessment team?
  • Which practice limits system access to authorized users and devices?
  • Security Protection Assets (SPAs) primarily provide what function?
  • Which aspect of the SHA-256 algorithm makes it suitable for integrity verification?
  • What is included in a Service Level Agreement (SLA)?
  • What is the primary function of boundary control devices in network security?
  • What defines a contractor in the context of a contract with the DoD?
  • What are Security Boundary Constraints?
  • What does "eMASS" refer to in the CMMC context?
  • In CMMC, what is essential for an activity to be classified as a Practice?
  • What common limitation might Specialized Assets face?
  • What does CMMC practice AT.L2‑3.2.3 require for mitigating insider threats?
  • What risk is associated with an insider threat?
  • What does "security relevant information" refer to?
  • What defines the assets assessed during a CMMC evaluation?
  • What is a key requirement of the practice concerning the flow of Controlled Unclassified Information (CUI)?
  • What is a key component of maintenance activities according to the CMMC requirements?
  • What does Evidence Acceptability refer to in CMMC assessments?
  • What does the document detailing Procedures need to provide?
  • Which of the following best describes Acquisitions in the context of federal government?
  • What characteristic describes emergency accounts?
  • What is the main purpose of a CUI Enclave?
  • Who convenes the In-Brief Meeting before assessment activities begin?
  • What does the term External Service Provider (ESP) refer to?
  • Why is timely repair and maintenance of systems essential for organizations?
  • According to AC.L2-3.1.18, what is required for mobile device connections in OSCs?
  • What is the primary goal of an Assessment in the CMMC context?
  • What is prohibited in terms of information system use according to legal notifications?
  • What characterizes a Temporary Deficiency in CMMC compliance?
  • Under CMMC practice AC.L2-3.1.5, what must organizations implement?
  • What is the primary objective of the scoping process in CMMC compliance?
  • What is a key requirement of the role-based security training outlined in AT.L2-3.2.2?
  • Why is it essential to maintain baseline configurations?
  • Which of the following best describes a CMMC Third-Party Assessment Organization (C3PAO)?
  • What must an organization define regarding session termination conditions?
  • What is the consequence of failing to enforce system security policy?
  • What is a key benefit of non-duplication in CMMC assessments?
  • How should reviews of maintenance activities be conducted according to CMMC standards?
  • How are portable storage devices defined in the context of information systems?
  • What is included in the effective incident handling process defined by IR.L2-3.6.1?
  • What does the term "one-way function" refer to in the context of SHA-256?
  • What does SI.L2-3.14.5 emphasize about scanning systems and files?
  • What characterizes Physical Separation in asset management?
  • Under MA.L2-3.7.2, what is the focus of CMMC practice regarding system maintenance?
  • What action should organizations take regarding remote access information?
  • Which action is part of the Process in CMMC?
  • What role do firewalls and proxies play in Information Flow Enforcement Mechanisms?
  • What is a key requirement of remote access under CMMC practice AC.L2-3.1.12?
  • Which of the following systems is not typically categorized as Operational Technology?
  • What is the purpose of the FedRAMP Moderate Equivalency documentation?
  • What is a key aspect of the CMMC Level 2 practice for System Auditing per AU.L2-3.3.1?
  • Which of the following best describes the significance of strategic goals in a CMMC Plan?
  • What does SI.L2-3.14.1 require organizations to do regarding system flaws?
  • According to AU.L2-3.3.2, what must be uniquely traced for accountability?
  • What is the required length of the Artifact Retention Period for CMMC assessment artifacts?
  • What is a Virtual Local Area Network (VLAN) primarily used for?
  • What does a Government Furnished Equipment (GFE) asset include?
  • What documentation is essential for effective maintenance according to CMMC?
  • What does CUI stand for?
  • What activities are involved in Phase 3 of the CMMC Assessment Process?
  • What components should maintenance documentation include according to CMMC Level 2 practices?
  • Who initiates the certification engagement for a CMMC assessment?
  • What type of output does the SHA-256 algorithm produce from input data?
  • What does effective identification of wireless access points help to prevent?
  • What must be done by the OSA regarding Security Protection Assets (SPAs)?
  • Subnetworks in a network architecture are primarily used for what purpose?
  • What defines a portable storage device?
  • Which term describes the location defined by software and network configurations, such as VLANs?
  • Why is regular security awareness training necessary?
  • What type of assets are classified as Specialized Assets?
  • What does the Lead CCA need to explain during the In-Brief Meeting?
  • What role does the Quality Assurance Individual play during the CMMC assessment?
  • Which of the following represents a network device that requires isolation from internal systems when providing remote access?
  • What is one of the main objectives of security policies within an organization?
  • What aspect does the Shared Responsibility Matrix aim to clarify?
  • What must the OSC enforce according to CMMC practice AC.L2-3.1.3 regarding separation of duties?
  • What kind of information must the OSC define for audit record content according to AU.L2-3.3.2?
  • Which component in CMMC assessments ensures compliance with cybersecurity practices?
  • What role does the Affirming Official play in an organization?
  • Logical separation in a system is achieved through what means?
  • What function does access control policies serve?
  • Which document outlines the CMMC Security Requirements Level 2?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy