Skip to content
QualExam
CCA
All exams
CCP
/
Practice
CCP practice questions
20 questions, free to answer. Each one says which document it came from.
1. A contractor engages a firm to help remediate gaps ahead of a CMMC Level 2 certification assessment. Which role does that firm hold, and what does it prevent?
A Registered Provider Organization, which may not then conduct the certification assessment
A C3PAO, which may conduct the assessment because it already knows the environment
The CAICO, which certifies the contractor directly once remediation is complete
A Licensed Partner Publisher, which may assess if its practitioners hold CCP
Permalink
2. During an assessment a CCP recognises that the OSC is a direct competitor of their own employer. What does the Code require?
Report the OSC to the CAICO before proceeding
Disclose the conflict and withdraw unless it can be demonstrably managed
Continue, because the CCP is a team member rather than the Lead Assessor
Continue but exclude themselves from scoring any single practice
Permalink
3. An OSC handles FCI but no CUI. Which set of security requirements applies?
Both the 15 basic requirements and a subset of NIST SP 800-171
The 15 requirements in 48 CFR 52.204-21
The 110 requirements in NIST SP 800-171
The 17 practices defined under CMMC Level 1
Permalink
4. Which statement correctly distinguishes FCI from CUI?
FCI is not intended for public release; CUI additionally requires safeguarding or dissemination controls under law, regulation or Government-wide policy
FCI is classified at a lower level than CUI
CUI applies only to information generated by the Government, never by a contractor
FCI applies only to information marked by the contracting officer
Permalink
5. DFARS 252.204-7012 is best described as which of the following?
The NIST publication listing the Level 2 security requirements
The rule establishing the CAICO
A contract clause imposing safeguarding and cyber incident reporting obligations on the contractor
The statute that created the CMMC program
Permalink
6. How many security requirements does CMMC Level 2 incorporate?
15
17
171
110
Permalink
7. What determines which CMMC level applies to a given contract?
The dollar value of the contract
The number of employees the contractor has
Whether the contractor has previously held a certificate
The type of information involved — FCI or CUI
Permalink
8. Which source document contains the assessment objectives used to determine whether a Level 2 requirement is met?
DFARS 252.204-7012
NIST SP 800-171A
NIST SP 800-171
48 CFR 52.204-21
Permalink
9. An assessor reviews a written policy, asks the system administrator how it is applied, and observes the control operating. Which methods has the assessor used?
Examine, interview and test
Examine and interview only
Interview and test only
Test only
Permalink
10. A Level 2 requirement has five assessment objectives. Four are met and one is not. How is the requirement scored?
Partially met
Met, with a finding recorded
Not applicable
Not met
Permalink
11. An OSC offers a screenshot of one workstation’s configuration as evidence that a setting is enforced across 400 endpoints. What is the deficiency?
It is neither adequate nor sufficient, because screenshots cannot be examined
There is no deficiency if the workstation was chosen at random
It is not sufficient, because it does not cover the assessment scope
It is not adequate, because a screenshot is never acceptable evidence
Permalink
12. Which best describes the CCP’s responsibility regarding evidence during a Level 2 assessment?
Collect evidence on the OSC’s behalf to speed the assessment
Certify that the evidence satisfies the contract
Analyse its location, collection, quality and usage in support of the assessment team
Independently determine the final score for each requirement
Permalink
13. How many phases does the CMMC Assessment Process define, and what is the first?
Four; Conduct the Pre-Assessment
Three; Plan the Assessment
Four; Assess Conformity to Security Requirements
Five; Prepare the Assessment Plan
Permalink
14. In which phase is the certificate issued and any POA&M closed out?
Phase 2
Phase 1
Phase 4
Phase 3
Permalink
15. Reporting assessment results falls within which phase?
Phase 1
Phase 2
Phase 4
Phase 3
Permalink
16. Which activity is outside the CCP’s role on a Level 2 assessment team?
Analysing evidence against assessment objectives
Contributing to preparation of the assessment report
Making the final determination that a requirement is met
Assisting with preparation of the assessment plan
Permalink
17. What is a POA&M used for following a Level 2 certification assessment?
Recording the OSC’s objections to the assessment findings
Documenting the assessment team’s conflicts of interest
Listing assets excluded from the assessment scope
Tracking remaining requirements to closure within the permitted window
Permalink
18. When is assessment scope determined?
After evidence collection is complete
During the closeout of the POA&M
Only if the OSC disputes a finding
Before conformity to requirements is assessed
Permalink
19. Which document defines the asset categories used when scoping a Level 2 assessment?
CMMC Level 1 Scoping Guide
NIST SP 800-171A
DFARS 252.204-7012
CMMC Level 2 Scoping Guide
Permalink
20. An OSC handling only FCI is determining scope. Which assets are in scope?
Only assets located in Government facilities
Those that process, store or transmit FCI
Every asset the OSC owns
Only assets connected to the internet
Permalink