Summer Certification Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

CMMC-CCP Certified CMMC Professional (CCP) Exam Questions and Answers

Questions 4

While conducting a CMMC Assessment, an individual from the OSC provides documentation to the assessor for review. The documentation states an incident response capability is established and contains information on incident preparation, detection, analysis, containment, recovery, and user response activities. Which CMMC practice is this documentation attesting to?

Options:

A.

IR.L2-3.6.1: Incident Handling

B.

IR.L2-3.6.2: Incident Reporting

C.

IR.L2-3.6.3: Incident Response Testing

D.

IR.L2-3.6.4: Incident Spillage

Buy Now
Questions 5

An Assessment Team Member is conducting a CMMC Level 2 Assessment for an OSC that is in the process of inspecting Assessment Objects for AC.L1-3.1.1: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) to determine the adequacy of evidence provided by the OSC. Which Assessment Method does this activity fall under?

Options:

A.

Test

B.

Observe

C.

Examine

D.

Interview

Buy Now
Questions 6

A defense contractor needs to share FCI with a subcontractor and sends this data in an email. The email system involved in this process is being used to:

Options:

A.

manage FCI.

B.

process FCI.

C.

transmit FCI.

D.

generate FCI

Buy Now
Questions 7

Who is responsible for ensuring that subcontractors have a valid CMMC Certification?

Options:

A.

CMMC-AB

B.

OUSDA & S

C.

DoD agency or client

D.

Contractor organization

Buy Now
Questions 8

A Lead Assessor and an OSC ' s Assessment Official have agreed to have the Assessment results presented during the final Daily Checkpoint of the OSC ' s CMMC Level 2 Assessment. Which document MUST the Lead Assessor use to present assessment findings to the OSC?

Options:

A.

CMMC POA & M Brief

B.

CMMC Findings Brief

C.

CMMC Assessment Tracker Tool

D.

CMMC Recommended Findings template

Buy Now
Questions 9

When scoping the organizational system, the scope of applicability for the cybersecurity CUI practices applies to the components of:

Options:

A.

federal systems that process, store, or transmit CUI.

B.

nonfederal systems that process, store, or transmit CUI.

C.

federal systems that process, store, or transmit CUI. or that provide protection for the system components.

D.

nonfederal systems that process, store, or transmit CUI. or that provide protection for the system components.

Buy Now
Questions 10

Which government agency are DoD contractors required to report breaches of CUI to?

Options:

A.

FBI

B.

NARA

C.

DoD Cyber Crime Center

D.

Under Secretary of Defense for Intelligence and Security

Buy Now
Questions 11

A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC ' s standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?

Options:

A.

The process is running correctly.

B.

It is out of scope as this is a new acquisition.

C.

The new acquisition is considered Specialized Assets.

D.

Practice is NOT MET since the objective was not implemented.

Buy Now
Questions 12

An assessor needs to get the most accurate answers from an OSC ' s team members. What is the BEST method to ensure that the OSC ' s team members are able to describe team member responsibilities?

Options:

A.

Interview groups of people to get collective answers.

B.

Understand that testing is more important that interviews.

C.

Ensure confidentiality and non-attribution of team members.

D.

Let team members know the questions prior to the assessment.

Buy Now
Questions 13

When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?

Options:

A.

When under the control of the DoD

B.

When the document is considered secret

C.

When a document is being shared outside of the organization

D.

When a derivative document ' s original information is not CUI

Buy Now
Questions 14

SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC ' s assessment. How does this affect the assessment scope?

Options:

A.

Any existing telephone system is in scope even if it is not using VoIP technology.

B.

An error has been made and the Lead Assessor should be contacted to correct the error.

C.

VoIP technology is within scope, and it uses FlPS-validated encryption, so it does not need to be assessed.

D.

VoIP technology is not used within scope boundary, so no assessment procedures are specified for this practice.

Buy Now
Questions 15

Two assessors cannot agree if a certain practice should be rated as MET or NOT MET. Who should they consult to determine the final interpretation?

Options:

A.

C3PAO

B.

CMMC-AB

C.

Lead Assessor

D.

Quality Assurance Assessor

Buy Now
Questions 16

The Audit and Accountability (AU) domain has practices in:

Options:

A.

Level 1.

B.

Level 2.

C.

Levels 1 and 2.

D.

Levels 1 and 3.

Buy Now
Questions 17

OSCs MUST provide documentation that vulnerability scans are performed:

Options:

A.

at an OSC-defined frequency and when new vulnerabilities are identified.

B.

as defined by an accredited RPO.

C.

every time a penetration test is performed.

D.

on an ad hoc basis or as directed by the security manager.

Buy Now
Questions 18

Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit, Supporting Organization/Unit, or enclave have been met?

Options:

A.

OSC

B.

Assessment Team

C.

Authorizing official

D.

Assessment official

Buy Now
Questions 19

A CCP is providing consulting services to a company who is an OSC. The CCP is preparing the OSC for a CMMC Level 2 assessment. The company has asked the CCP who is responsible for determining the CMMC Assessment Scope and who validates its CMMC Assessment Scope. How should the CCP respond?

Options:

A.

" The OSC determines the CMMC Assessment Scope, and the CCP validates the CMMC Assessment Scope. "

B.

" The OSC determines the CMMC Assessment Scope, and the C3PAO validates the CMMC Assessment Scope. "

C.

" The CMMC Lead Assessor determines the CMMC Assessment Scope, and the OSC validates the CMMC Assessment Scope. "

D.

" The CMMC C3PAO determines the CMMC Assessment Scope, and the Lead Assessor validates the CMMC Assessment Scope. "

Buy Now
Questions 20

In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?

Options:

A.

In scope

B.

Out of scope

C.

OSC point of contact

D.

Assessment Team Member

Buy Now
Questions 21

An Assessment Team is conducting interviews with team members about their roles and responsibilities. The team member responsible for maintaining the antivirus program knows that it was deployed but has very little knowledge on how it works. Is this adequate for the practice?

Options:

A.

Yes, the antivirus program is available, so it is sufficient.

B.

Yes, antivirus programs are automated to run independently.

C.

No, the team member must know how the antivirus program is deployed and maintained.

D.

No, the team member ' s interview answers about deployment and maintenance are insufficient.

Buy Now
Questions 22

An OSC has requested a C3PAO to conduct a Level 2 Assessment. The C3PAO has agreed, and the two organizations have collaborated to develop the Assessment Plan. Who agrees to and signs off on the Assessment Plan?

Options:

A.

OSC and Sponsor

B.

OSC and CMMC-AB

C.

Lead Assessor and C3PAO

D.

C3PAO and Assessment Official

Buy Now
Questions 23

When are contractors required to achieve a CMMC certificate at the Level specified in the solicitation?

Options:

A.

At the time of award

B.

Upon solicitation submission

C.

Thirty days from the award date

D.

Before the due date of submission

Buy Now
Questions 24

Which document is the BEST source for descriptions of each practice or process contained within the various CMMC domains?

Options:

A.

CMMC Glossary

B.

CMMC Appendices

C.

CMMC Assessment Process

D.

CMMC Assessment Guide Levels 1 and 2

Buy Now
Questions 25

While conducting a CMMC Level 2 Assessment, the Lead Assessor determines that the OSC has badge readers, pin code pads, and keys for various access points as well as documentation to demonstrate meeting the practice. Which CMMC practice has the OSC MET?

Options:

A.

PE.L1-3.10.5: Control and manage physical access devices

B.

MP.L2-3.8.5: Mark media with necessary CUI markings and distribution limitations

C.

SI.L2-3.14.3: Monitor system security alerts and advisories and take action in response

D.

PS.L2-3.9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers

Buy Now
Questions 26

The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?

Options:

A.

Expert

B.

Advanced

C.

Optimizing

D.

Continuously Improved

Buy Now
Questions 27

In many organizations, the protection of FCI includes devices that are used to scan physical documentation into digital form and print physical copies of digital FCI. What technical control can be used to limit multi-function device (MFD) access to only the systems authorized to access the MFD?

Options:

A.

Virtual LAN restrictions

B.

Single administrative account

C.

Documentation showing MFD configuration

D.

Access lists only known to the IT administrator

Buy Now
Questions 28

An assessor is in Phase 3 of the CMMC Assessment Process. The assessor has delivered the final findings, submitted the assessment results package, and provided feedback to the C3PAO and CMMC-AB. What must the assessor still do?

Options:

A.

Determine level recommendation

B.

Archive all assessment artifacts

C.

Determine final practice pass/fail results

D.

Archive or dispose of any assessment artifacts

Buy Now
Questions 29

Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit. Supporting Organization/Unit, or enclave has been met?

Options:

A.

OSC

B.

Assessment Team

C.

Authorizing official

D.

Assessment official

Buy Now
Questions 30

How many domains does the CMMC Model consist of?

Options:

A.

14 domains

B.

43 domains

C.

72 domains

D.

110 domains

Buy Now
Questions 31

Which CMMC Levels meet the standards of protecting FCI (Federal Contract Information) ?

Options:

A.

Level 1

B.

Level 2

C.

Levels 2 and 3

D.

Levels 1, 2, and 3

Buy Now
Questions 32

How many cybersecurity levels does the CMMC Model structure contain?

Options:

A.

2 Levels.

B.

3 Levels.

C.

5 Levels.

D.

4 Levels.

Buy Now
Questions 33

A C3PAO has completed a Limited Practice Deficiency Correction Evaluation following an assessment of an OSC. The Lead Assessor has recommended moving deficiencies to a POA & M. but the OSC will remain on an Interim Certification. What is the MINIMUM number of practices that must be scored as MET to initiate this course of action?

Options:

A.

80 practices

B.

88 practices

C.

100 practices

D.

110 practices

Buy Now
Questions 34

A CCP is working as an Assessment Team Member on a CMMC Level 2 Assessment. The Lead Assessor has assigned the CCP to assess the OSC ' s Configuration Management (CM) domain. The CCP ' s first interview is with a subject-matter expert for user-installed software. With respect to user-installed software, what facet should the CCP ' s interview focus on?

Options:

A.

Controlled and monitored

B.

Removed from the system

C.

Scanned for malicious code

D.

Limited to mission-essential use only

Buy Now
Questions 35

What is DFARS clause 252.204-7012 required for?

Options:

A.

All DoD solicitations and contracts

B.

Solicitations and contracts that use FAR part 12 procedures

C.

Procurements solely for the acquisition of commercial off-the-shelf

D.

Commercial off-the-shelf sold in the marketplace without modifications

Buy Now
Questions 36

What type of information is NOT intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not including information provided by the government to the public (such as on public websites) or simple transactional information, such as necessary to process payments?

Options:

A.

CDI

B.

CTI

C.

CUI

D.

FCI

Buy Now
Questions 37

An employee is the primary system administrator for an OSC. The employee will be a core part of the assessment, as they perform most of the duties in managing and maintaining the systems. What would the employee be BEST categorized as?

Options:

A.

Analyzer

B.

Inspector

C.

Applicable staff

D.

Demonstration staff

Buy Now
Questions 38

Evidence gathered from an OSC is being reviewed. Based on the assessment and organizational scope, the Lead Assessor requests the Assessment Team to verify that the coverage by domain, practice. Host Unit. Supporting Organization/Unit, and enclaves are comprehensive enough to rate against each practice. Which criteria is the assessor referring to?

Options:

A.

Adequacy

B.

Capability

C.

Sufficiency

D.

Objectivity

Buy Now
Questions 39

A Lead Assessor is planning an assessment and scheduling the test activities. Who MUST perform tests to obtain evidence?

Options:

A.

OSC personnel who normally perform that work as the CCP observes

B.

Military personnel and the CCP and/or Lead Assessor to test the adequacy of the written procedure(s)

C.

Military personnel assigned to the contractor for that contract to ensure the confidentiality of the CUI

D.

OSC personnel who do not ordinarily perform that work to evaluate the accuracy of the written procedure(s)

Buy Now
Questions 40

A dedicated local printer is used to print out documents with FCI in an organization. This is considered an FCI Asset Which function BEST describes what the printer does with the FCI?

Options:

A.

Encrypt

B.

Manage

C.

Process

D.

Distribute

Buy Now
Questions 41

In accordance with NARA directives and Chapter 33 of Title 44 (Records Management Directive), which types of data MUST have policies and procedures for disposal?

Options:

A.

All recorded digital documents

B.

All digital and recorded paper documents

C.

All digital documents and recorded media

D.

All recorded information, regardless of form or characteristics

Buy Now
Questions 42

Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse. After a thorough review, the CCP tells the Lead Assessor that all supporting documents fully reflect the performance of the practice and should be accepted because the evidence is:

Options:

A.

official.

B.

adequate.

C.

compliant.

D.

subjective.

Buy Now
Questions 43

Who has the initial responsibility for identifying and managing conflicts of interest?

Options:

A.

OSC

B.

C3PAO

C.

CMMC-AB

D.

Lead Assessor

Buy Now
Questions 44

In the CMMC Model, how many practices are included in Level 2?

Options:

A.

17 practices

B.

72 practices

C.

110 practices

D.

180 practices

Buy Now
Questions 45

A C3PAO Assessment Plan document captures the names of the interviewees, the facilities that will utilized, along with estimated costs and schedule of the assessment. What part of the assessment plan is this?

Options:

A.

Identify resources and schedule.

B.

Select Assessment Team members.

C.

Identify and manage assessment risks.

D.

Select and develop the evidence collection approach.

Buy Now
Questions 46

In scoping a CMMC Level 1 Self-Assessment, all of the computers and digital assets that handle FCI are identified. A file cabinet that contains paper FCI is also identified. What can this file cabinet BEST be determined to be?

Options:

A.

In scope, because it is an asset that stores FCI

B.

In scope, because it is part of the same physical location

C.

Out of scope, because they are all only paper documents

D.

Out of scope, because it does not process or transmit FCI

Buy Now
Questions 47

A cyber incident is discovered that affects a covered contractor IS and the CDI residing therein. How long does the contractor have to inform the DoD?

Options:

A.

24 hours

B.

48 hours

C.

72 hours

D.

96 hours

Buy Now
Questions 48

Which entity specifies the required CMMC Level in Requests for Information and Requests for Proposals?

Options:

A.

DoD

B.

NARA

C.

NIST

D.

Department of Homeland Security

Buy Now
Questions 49

Which organization is the governmental authority responsible for identifying and marking CUI?

Options:

A.

NARA

B.

NIST

C.

CMMC-AB

D.

Department of Homeland Security

Buy Now
Questions 50

There are 15 practices that are NOT MET for an OSC ' s Level 2 Assessment. All practices are applicable to the OSC. Which determination should be reached?

Options:

A.

The OSC may have 90 days for remediating NOT MET practices.

B.

The OSC is not eligible for an option to remediate NOT MET practices.

C.

The OSC may be eligible for an option to remediate NOT MET practices.

D.

The OSC is not eligible for an option to remediate after the assessment is canceled.

Buy Now
Questions 51

Which are guiding principles in the CMMC Code of Professional Conduct?

Options:

A.

Objectivity, information integrity, and higher accountability

B.

Objectivity, information integrity, and proper use of methods

C.

Proper use of methods, higher accountability, and objectivity

D.

Proper use of methods, higher accountability, and information integrity

Buy Now
Questions 52

Who is responsible for ensuring that subcontractors have a valid CMMC Certification?

Options:

A.

CMMC-AB

B.

OUSD A & S

C.

DoD agency or client

D.

Contractor organization

Buy Now
Questions 53

A Lead Assessor is presenting an assessment kickoff and opening briefing. What topic MUST be included?

Options:

A.

Gathering evidence

B.

Review of the OSC ' s SSP

C.

Overview of the assessment process

D.

Examination of the artifacts for sufficiency

Buy Now
Questions 54

After a CMMC Level 2 certification assessment, the Lead Assessor (Lead CCA) is preparing to present the Final Recommended Findings to the OSC . Which statement BEST describes the Lead Assessor’s responsibility for delivering the assessment findings to the OSC?

Options:

A.

Summary recommendations presented using the CMMC Assessment Findings Brief are sufficient.

B.

Detailed findings must be presented to the OSC along with clear evidence of how the ratings map to the assessor’s findings.

C.

The initial report delivered to the OSC will only include an overall assessment MET or NOT MET score along with a score for each practice.

D.

The Lead Assessor is required to submit their initial assessment findings to the C3PAO for review before they can be shared with the OSC.

Buy Now
Questions 55

While conducting a CMMC Level 2 Assessment, a CCP is reviewing an OSC ' s personnel security process. They have a policy that describes screening individuals prior to authorizing access to CUI, but it does not mention what organizations should be looking for in an individual. There is no link to a process or procedural document. What should the OSC evaluate when screening individuals prior to accessing CUI?

Options:

A.

They are trusted and well liked

B.

They are a hard and loyal worker

C.

Their conduct, integrity, and loyalty

D.

Their functionality, reliability, and ability to adapt

Buy Now
Questions 56

A machining company has been awarded a contract with the DoD to build specialized parts. Testing of the parts will be done by the company using in-house staff and equipment. For a Level 1 Self-Assessment, what type of asset is this?

Options:

A.

CUI Asset

B.

In-scope Asset

C.

Specialized Asset

D.

Contractor Risk Managed Asset

Buy Now
Questions 57

Which CMMC Levels focus on protecting CUI from exfiltration?

Options:

A.

Levels 1 and 2

B.

Levels 1 and 3

C.

Levels 2 and 3

D.

Levels 1, 2, and 3

Buy Now
Questions 58

Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?

Options:

A.

Access Control (AC)

B.

Media Protection (MP)

C.

Asset Management (AM)

D.

Configuration Management (CM)

Buy Now
Questions 59

During Phase 4 of the Assessment process, what MUST the Lead Assessor determine and recommend to the C3PAO concerning the OSC?

Options:

A.

Ability

B.

Eligibility

C.

Capability

D.

Suitability

Buy Now
Questions 60

A CCP is part of a CMMC Assessment Team interviewing a subject-matter expert on Access Control (AC) within an OSC. During the interview process, what will the CCP ensure about the information exchanged during the interview?

Options:

A.

Performed in groups for more efficient use of resources

B.

Recorded for inclusion in the Final Recommended Findings report

C.

Confidential and non-attributable so interviewees can speak without fear of reprisal

D.

Mapped to specific CMMC practices to clearly delineate which practice is being evaluated

Buy Now
Questions 61

During the planning phase of a CMMC Level 2 Assessment, the Lead Assessor is considering what would constitute the right evidence for each practice. What is the Assessor attempting to verify?

Options:

A.

Adequacy

B.

Sufficiency

C.

Process mapping

D.

Assessment scope

Buy Now
Questions 62

Per DoDI 5200.48: Controlled Unclassified Information (CUI), CUI is marked by whom?

Options:

A.

DOD OUSD

B.

Authorized holder

C.

Information Disclosure Official

D.

Presidentially authorized Original Classification Authority

Buy Now
Questions 63

While determining the scope for a company ' s CMMC Level 1 Self-Assessment, the contract administrator includes the hosting providers that manage their IT infrastructure. Which asset type BEST describes the third-party organization?

Options:

A.

ESPs

B.

People

C.

Facilities

D.

Technology

Buy Now
Questions 64

Which statement BEST describes a LTP?

Options:

A.

Creates DoD-licensed training

B.

Instructs a curriculum approved by CMMC-AB

C.

May market itself as a CMMC-AB Licensed Provider for testing

D.

Delivers training using some CMMC body of knowledge objectives

Buy Now
Questions 65

An assessment procedure consists of an assessment objective, potential assessment methods, and assessment objects. Which statement is part of an assessment objective?

Options:

A.

Specifications and mechanisms

B.

Examination, interviews, and testing

C.

Determination statement related to the practice

D.

Exercising assessment objects under specified conditions

Buy Now
Questions 66

During the review of information that was published to a publicly accessible site, an OSC correctly identifies that part of the information posted should have been restricted. Which item did the OSC MOST LIKELY identify?

Options:

A.

FCI

B.

Change of leadership in the organization

C.

Launching of their new business service line

D.

Public releases identifying major deals signed with commercial entities

Buy Now
Questions 67

What are CUI protection responsibilities?

Options:

A.

Shielding

B.

Governing

C.

Correcting

D.

Safeguarding

Buy Now
Questions 68

During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?

Options:

A.

CCP

B.

C3PAO

C.

Lead Assessor

D.

Advisory Board

Buy Now
Questions 69

Which activities are involved in ALL assessment methods?

Options:

A.

Exercising one or more assessment objects under specified conditions to compare actual with expected behavior

B.

Conducting discussions with individuals or groups of individuals in an organization to facilitate understanding, achieve clarification, or lead to the location of evidence

C.

Checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment objects or artifacts to facilitate understanding, achieve clarification, or obtain additional evidence

D.

Determining security safeguard existence, functionality, correctness, completeness, and potential for improvement over time

Buy Now
Questions 70

What is the legal entity under a contract that has agreed to deliver products or services?

Options:

A.

Supporting Organization/Unit

B.

Commercial and Government Entity Code

C.

Host Unit

D.

HQ Organization

Buy Now
Exam Code: CMMC-CCP
Exam Name: Certified CMMC Professional (CCP) Exam
Last Update: Aug 19, 2026
Questions: 236
CMMC-CCP pdf

CMMC-CCP PDF

$25.5  $84.99
CMMC-CCP Engine

CMMC-CCP Testing Engine

$30  $99.99
CMMC-CCP PDF + Engine

CMMC-CCP PDF + Testing Engine

$40.5  $134.99