CCP Flashcards

(49 cards)

1
Q

What is the 4 phases of the CAP ?

A

Phase 1: Plan and Prepare Assessment
Phase 2: Conduct the Assessment
Phase 3: Report recommended assessment Results
Phase 4: Close-Out POA&M and Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Acronym: CUI ?

A

Control Unclassified Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Acronym: FCI ?

A

Federal Contract Information

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Acronym: DIB ?

A

Defense Industrial Base - Provides research and development services to US military such as design, manufacture, distribution and maintenance of military weapons systems and components.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Acronym: LPP ?

A

Licensed Partner Publishers - develop training courses based on the CyberAB curriculum

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Acronym: FAR ?

A

Federal Acquisition Regulation - main set of rules that all U.S. federal executive agencies must follow when they buy goods or services using government funds.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Acronym: DFARS ?

A

Defense Federal Acquisition Regulation Supplement - extension of the Federal Acquisition Regulation (FAR) that adds specific rules for Department of Defense (DoD) contracts.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How many domains are there ?

A

14

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

How many domains does level 1 have ?

A

6

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

How many domains does level 2 have ?

A

14

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Is it true or false that CCP is only authorized to analyze only level 1 practices when conducting a CMMC assessment ?

A

True

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is Phase 2 of the CAP ?

A

Phase 2: Conduct Assessment

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the 4 sub-phases of Phase 2 ?

A
  1. Convene assessment kickoff meeting
  2. Collect and examine evidence
  3. Score OSC practices and validate preliminary results.
  4. Generate and validate preliminary recommended findings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What are the 3 steps in examining practices ?

A

Examine, interview, and Test

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

When viewing evidence for a practice you must ensure ?

A

Adequacy and Sufficiency

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When a practice has not been effectively implemented but not appropriately documented, the assessment team should define it as ?

A

Limited Practice Deficiency Correction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Does the CAP provide a list of ineligible and eligible practice for LPDC ?

A

Yes (true)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

True or False: During Phase 2, the CCP can assist the assessment team in collecting and examining evidence, scoring practices, and validating preliminary results and generating final assessment results for level 2 practices.

A

False

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is Phase 3 of the CAP?

A

Phase 3: Report Recommended Assessment Results

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What are the two steps in Phase 3 of the CAP ?

A
  1. Deliver recommended assessment results(final findings)(during final findings briefing)
  2. Submit, package, and archive assessment documentation
21
Q

What template is to be using to deliver the assessment results to the OSC assessment official ?

A

Final Findings Briefing Template

22
Q

True or False: The C3PAO must use the CMMC eMASS JSON schema (detailed in the eMASS CONOPS ) for uploading the assessment results into CMMC eMASS. In how many days after the final findings briefing ?

A

True, in 20 days.

23
Q

Acronym: LPDCP ?

A

Limited Practice Deficiency Correction Program

24
Q

What happens if any practices on the LPDCP fail to result in a score of “MET” ?

A

The Lead Assessor will recommend moving the OSCs practice deficiency’s to a POA&M.

25
What percentage of the assessment score must it be to move the OSC to the POA&M close-out assessment option ?
80%
26
What document does the Lead Assessor use to present the final recommended findings ?
Assessment Findings Brief Template
27
Who verifys assessment documentation prior to eMASS upload to ensure accuracy and completeness of the assessment results package ? And how long should the final report be submitted to the CQAP after the Final Findings Briefing ?
The CMMC Quality Assurance Professional (CQAP) and no later than 10 days
28
How long does the Assessment Results package need to be retained and protected from confidentiality, non-disclosure and any other CUI ?
For three years
29
What must the lead assessor ensure the OSC has done with the assessments results package since it remains with the OSC ?
Hashed all artifacts in accordance with the CMMC Artifact hashing tool user guide and retain for 3 years
30
True or False: The CCP is allowed to take evidence or artifacts collected during the CMMC assessment ?
False
31
What is Phase 4 of the CAP ?
Phase 4: Close-out POA&Ms and Assessment
32
True or False: The C3PAO has the sole authority for validating the OSC POA&M close out results
True
33
Acronym: RPO ?
Registered Provider Organization - offers non-certified CMMC consulting services to help organizations prepare for a CMMC assessment.
34
True/False: RPOs are authorized to conduct assessments.
False
35
Acronym: LTP ?
LTP program is designed for education and training providers that are responsible for delivering the training courses developed by LPPs.
36
Acronym: FISMA ?
Federal Information Security Modernization Act - U.S. legislation that aims to improve the cybersecurity practices of the Federal Government.
37
Acronym: NISPOM ?
The National Industrial Security Program Operating Manual (NISPOM) prescribes the restrictions and safeguarding requirements for protecting classified information.
38
Acronym: FedRAMP?
The Federal Risk and Authorization Management Program (FedRAMP) is a government- wide program established to facilitate a secure transition to and use of cloud technologies.
39
SSP ?
A System Security Plan (SSP) is a formal document that describes how an organization’s systems and processes protect sensitive information (like FCI or CUI) and how the organization meets security requirements.
40
what does the FAR Clause 52.204-21 specify ?
specifies basic safeguarding requirements for all DoD contractors that process , store, or transmit FCI. (15 controls equivalent to 17 NIST SP 800-171 controls)
41
What type of info must be present for DFARS Clause 252.204-7012 to apply to contracts ?
only apply when unclassified controlled technical information is present.
42
What does DFARS Clause 252.204-7012 require ?
This clause requires all contractors and subcontractors to safeguard covered defense information that is either stored or transmitted through their information systems and networks. (CUI) (based on entire NIST SP 800-171)
43
What does DFARS Clause 252.204-7013 require ?
Rights in Technical Data (Noncommercial Items), rule explains who owns and can use technical data (like designs, drawings, or specifications) that a contractor creates under a DoD contract.
44
What is NIST SP 800-171, and why is it important?
It’s a set of 110 security requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems. It’s the foundation for CMMC Level 2 requirements.
45
What is 32 CFR Part 2002 about?
It’s managed by NARA/ISOO and sets standards for marking, safeguarding, and reviewing CUI programs.
46
Which of the following is NOT a specification under NIST SP 800-171A?
Monitoring Network Traffic
47
To become a CMMC Third Party Assessment Organization an organization must be which one of the following to qualify?
It must be 100% U.S Citizen owned
48
What is a key requirement before the Cyber AB can accredit a candidate C3PAO?
The candidate C3PAO mist achieve and maintain ISO/IEC 17020 accredidation standard.
49
When is the Contractor required to report cyber incidents to DoD according to the DFARS Clause 252.204-7012?
Within 72 hours of discovery