Prepare Smarter for the CMMC-CCA Exam
Build your exam confidence with flexible preparation resources designed around the latest CMMC-CCA exam objectives. Practice at your own pace using PDF questions, online exam simulations, or desktop practice software.
An OSC has an established password policy. The OSC wants to improve its password protection security by implementing a single change .
Which of the following is an acceptable element to add to the OSC’s password policy?
Correct Answer: D
The Identification and Authentication (IA) practices require that passwords be protected using strong methods. Storing passwords with salted one-way hashes ensures they cannot be reversed, providing strong protection.
Extract from IA.L2-3.5.10:
“Passwords must be stored and transmitted in a form that is resistant to compromise, typically using salted one-way cryptographic hashes.”
Options A and B do not align with modern password guidance, and option C (two-way cryptographic hashing) is insecure because it allows reversal.
[Reference: CMMC Assessment Guide – Level 2, IA.L2-3.5.10., ]
During a CMMC Assessment, the assessor is determining if the Escort Visitors practice is MET.
Personnel with which of the following responsibilities would be MOST appropriate to interview?
Correct Answer: C
The Escort Visitors practice falls under Physical and Environmental Protection (PE.L2-3.10.3) , which requires organizations to escort visitors and monitor visitor activity .
To validate this, the assessor should interview personnel responsible for physical access control (security guards, facility access managers) and information security
(to confirm integration with CUI protection requirements).
Exact Extracts:
PE.L2-3.10.3: “Escort visitors and monitor visitor activity.”
Assessment Guide: “Interview personnel responsible for physical access control and security monitoring to confirm escort and visitor activity tracking.”
Assessment Objectives: Require evidence of visitor escorts, visitor logs, and monitoring practices.
Why the other options are not correct:
A (Repair/maintenance): Not responsible for escort procedures.
B (Local access control only): Missing the information security link , which ensures visitors cannot access CUI assets.
D (IT management): IT is not responsible for escorting visitors in physical spaces.
[References:, CMMC Assessment Guide – Level 2, Version 2.13: PE.L2-3.10.3 (pp. 154–156)., NIST SP 800-171A: Assessment procedures for visitor escort and monitoring., , , ]
Different mechanisms can be used to protect information at rest.
Which mechanism is MOST LIKELY to afford protection for information at rest?
Correct Answer: D
Applicable Requirement: SC.L2-3.13.16 — “Protect the confidentiality of CUI at rest.”
Why D is Correct: Cryptographic mechanisms (e.g., full-disk encryption, database encryption, file encryption) provide the strongest
protection for information at rest by preventing unauthorized disclosure if systems or media are accessed.
Why Other Options Are Insufficient:
A (Patching): Protects against vulnerabilities, but not specific to data-at-rest confidentiality.
B (File share): Provides a storage method, not protection.
C (Secure offline storage): Helps physically, but not sufficient for digital confidentiality without encryption
References (CCA Official Sources):
NIST SP 800-171 Rev. 2 — SC.L2-3.13.16
NIST SP 800-171A — SC.L2-3.13.16 Assessment Objectives
CMMC Assessment Guide – Level 2, Data at Rest Protection
===========
During an assessment, the team is interviewing the IT staff to understand the ways in which the organization protects backup data.
Because the company’s backups contain CUI, the Lead Assessor asks the IT engineer which method is used to ensure that the
confidentiality of the backup data is being protected. Which implementation is LEAST LIKELY to be acceptable?
Correct Answer: A
When protecting backup data containing CUI, the requirement is to ensure confidentiality through logical or physical security controls appropriate to the sensitivity of CUI . Acceptable implementations include controlling access to CUI (AC family controls), physically securing media (MP family controls), and encrypting files or media (SC family controls) . Merely implementing alternative physical controls for site access is insufficient because site access protections do not directly ensure the confidentiality of the backup media itself.
Exact Extracts (from official CMMC Assessor/Study documents and NIST SP 800-171A references):
SC.L2-3.13.16 (Encrypt CUI): “Employ cryptographic mechanisms to prevent unauthorized disclosure of CUI during storage and transmission unless otherwise protected by alternative physical safeguards.”
MP.L2-3.8.9 (Protect backup CUI): “Protect the confidentiality of backup CUI at storage locations.”
AC.L2-3.1.3 (Access enforcement): “Limit access to CUI on the basis of need-to-know to protect confidentiality.”
Physical security references (PE family): “Physical access controls provide general site protection but are not substitutes for encryption or media protection controls when CUI confidentiality is at risk.”
Why the other options are correct (acceptable methods):
B (Managing who has access to the information): Satisfies Access Control (AC) requirements that limit exposure of CUI only to authorized individuals.
C (Physically securing devices and media): Satisfies Media Protection (MP) requirements , ensuring CUI is stored securely and protected against unauthorized access.
D (Encrypting files or media): Directly satisfies System and Communications Protection (SC) requirements for confidentiality, a highly reliable method.
Why option A is least acceptable:
Alternative physical controls for site access protect buildings or rooms, but they do not directly safeguard backup media confidentiality . If backups are removed, lost, or accessed internally, site access controls alone cannot ensure confidentiality.
References (official CCA/CMMC documents):
CMMC Assessment Guide – Level 2, Version 2.13: Practices SC.L2-3.13.16, MP.L2-3.8.9, AC.L2-3.1.3, and PE family discussion (pp. 93–96, 108–110, 125–127).
NIST SP 800-171A, Assessing Security Requirements for CUI: Related assessment objectives for protecting CUI backup confidentiality.