CMMC-CCPのPDF問題集リアル2026最近更新された問題 [Q130-Q148]

Share

CMMC-CCPのPDF問題集リアル2026最近更新された問題

リリースCyber AB CMMC-CCP更新された問題PDF


Cyber AB CMMC-CCP 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • CMMCエコシステム:この試験セクションでは、コンサルタントとコンプライアンス専門家のスキルを評価し、CMMCエコシステム全体にわたる様々な役割と責任に焦点を当てます。受験者は、国防総省、CMMC-AB、認定取得を目指す組織、登録実務者、認定CMMCプロフェッショナルなどの組織の機能、そしてエコシステムがサイバーセキュリティの標準と認証をどのようにサポートしているかを理解する必要があります。
トピック 2
  • CMMCアセスメントプロセス(CAP):この試験セクションでは、監査および評価の専門家の計画および実行スキルを評価します。エンドツーエンドのCMMCアセスメントプロセスを網羅しています。これには、DoDおよびCMMC-AB方法論に準拠したアセスメントの計画、実行、文書化、報告、そして行動計画とマイルストーン(POA&M)の管理が含まれます。
トピック 3
  • スコープ設定:このセクションでは、サイバーセキュリティ実務者の分析スキル、特に評価範囲を適切に定義する能力が問われます。受験者は、管理対象非機密情報(CUI)資産の識別と分類、評価対象資産、評価対象資産外の資産、および特別な資産の違いの認識、そして論理的および物理的な分離手法を適用して評価の正確なスコープ設定を行う知識を実証する必要があります。
トピック 4
  • CMMCモデルの構築と実装評価:この試験セクションでは、サイバーセキュリティ評価者の評価スキルを測定します。特にCMMCモデルの適用と評価に重点を置きます。CMMCモデルのレベル、ドメイン、プラクティス、実装基準の理解に加え、エビデンスに基づく評価を用いて組織が必要なサイバーセキュリティプラクティスを満たしているかどうかを評価する方法も問われます。
トピック 5
  • CMMC-AB 職業倫理規範:この試験セクションでは、CMMC-AB 職業倫理規範の理解度を評価することで、サイバーセキュリティ専門家の誠実さを測ります。機密保持、客観性、プロフェッショナリズム、利益相反の回避、知的財産の尊重といった倫理的責任を重視し、受験者がCMMC関連の業務全体を通して倫理基準を遵守できるかどうかを確認します。

 

質問 # 130
Ethics is a shared responsibility between:

  • A. OSC and sponsors.
  • B. DoD and CMMC-AB.
  • C. CMMC-AB and members of the CMMC Ecosystem.
  • D. members of the CMMC Ecosystem and Lead Assessors.

正解:C

解説:
Understanding Ethical Responsibility in the CMMC Ecosystem
Ethics in theCMMC ecosystemis ashared responsibilitybetween theCMMC Accreditation Body (CMMC-AB) and itsmembers. TheCMMC-AB Code of Professional Conductoutlines ethical obligations forassessors, consultants, and other ecosystem participantsto ensure integrity, fairness, and professionalism.
Key Ethical Responsibilities Include:
CMMC-AB ensures the accreditation process remains fair, unbiased, and ethical.
CMMC ecosystem members (assessors, consultants, and organizations) are responsible for upholding ethical practices in assessments and implementations.
Ethical violations can result indisciplinary actions, revocation of certification, or legal consequences.
Why is the Correct Answer "CMMC-AB and Members of the CMMC Ecosystem" (C)?
A). DoD and CMMC-AB # Incorrect
TheDoD oversees CMMC implementation, butit is not responsible for the ethical conduct of CMMC assessments.
B). OSC and Sponsors # Incorrect
TheOrganization Seeking Certification (OSC)is responsible for compliance but doesnot oversee ethics in the CMMC ecosystem.
C). CMMC-AB and Members of the CMMC Ecosystem # Correct
Ethics is explicitly stated as ajoint responsibility of the CMMC-AB and its ecosystem membersin official CMMC guidance.
D). Members of the CMMC Ecosystem and Lead Assessors # Incorrect
Lead Assessors are part of theCMMC ecosystem, butCMMC-AB is the governing body responsible for ethical oversight.
CMMC 2.0 References Supporting this Answer:
CMMC-AB Code of Professional Conduct
Defines ethical responsibilities forassessors, consultants, and ecosystem members.
CMMC Ecosystem Governance Policies
Ethics isjointly managed by CMMC-AB and its accredited ecosystem members.
CMMC Assessment Process (CAP) Document
Outlines ethical expectations forassessors and consultantsduring certification assessments.


質問 # 131
Which authority leads the CMMC direction, standards, best practices, and knowledge framework for how to map the controls and processes across different Levels that range from basic cyber hygiene to advanced cyber practices?

  • A. NIST
  • B. Defense Federal Acquisition Regulation Council
  • C. DoD CIO office
  • D. Federal CIO office

正解:C

解説:
Understanding the Role of the DoD CIO Office in CMMC
TheDepartment of Defense (DoD) Chief Information Officer (CIO) officeis theprimary authorityresponsible for leading the direction, standards, and best practices of theCybersecurity Maturity Model Certification (CMMC)framework.
Why "B. DoD CIO Office" is Correct?
The DoD CIO Oversees CMMC Policy and Implementation
TheDoD CIO Office is responsible for the governance and strategic direction of CMMC.
It ensures thatCMMC aligns with DoD cybersecurity policies, such asDoD Instruction 5200.48 (Controlled Unclassified Information)andNIST SP 800-171.
CMMC Development and Evolution
TheDoD CIO played a critical role in launching CMMCto improve cybersecurity across theDefense Industrial Base (DIB).
The CIO office leadspolicy development and updates to the CMMC framework, including the transition fromCMMC 1.0 to CMMC 2.0.
Alignment of CMMC with Federal Cybersecurity Strategy
The DoD CIO ensures that CMMCintegrates with federal cybersecurity policiesandNIST frameworks.
It provides oversight formapping CMMC Levels (1-2-3) to existing cybersecurity standards and controls.
Why Other Answers Are Incorrect?
A). NIST (Incorrect)
TheNational Institute of Standards and Technology (NIST)provides thetechnical framework (NIST SP 800-
171, SP 800-172), butNIST does not lead the CMMC program.
C). Federal CIO Office (Incorrect)
TheFederal CIO focuses on broader government IT policiesandnot specifically on DoD cybersecurity requirementslike CMMC.
D). Defense Federal Acquisition Regulation Council (Incorrect)
TheDFARS Counciloverseescontracting regulationsrelated to CMMC (e.g.,DFARS 252.204-7012, 7019,
7020, 7021), but it doesnot lead CMMC standards and best practices.
Conclusion
The correct answer isB. DoD CIO Office, as it isthe lead authority guiding the CMMC framework, standards, and implementation across the Defense Industrial Base (DIB).
References:
DoD CIO Website on CMMC
CMMC 2.0 Overview by DoD
DoD Instruction 5200.48 (CUI Program)
DFARS 252.204-7012 & CMMC 2.0 Policy Documents


質問 # 132
The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?

  • A. Affirmation for each practice or control
  • B. Suggested improvements for each failed practice
  • C. Documented rationale for each failed practice
  • D. Gaps or deltas due to any reciprocity model are recorded as met

正解:C

解説:
Understanding the CMMC Level 2 Final Report Requirements
For aCMMC Level 2 Assessment, theFinal CMMC Assessment Results Reportmust include:
Assessment findings for each practice
Final ratings (MET or NOT MET) for each practice
A detailed rationale for each practice rated as NOT MET
Why "B. Documented rationale for each failed practice" is Correct?
The CMMC Assessment Process (CAP) Guidestates that if a practice is markedNOT MET, theassessors must provide a rationale explaining why it failed.
This rationale helps theOSC understand what needs remediationand, if applicable, whether the deficiency can be addressed via aPlan of Action & Milestones (POA&M).
TheFinal Report serves as an official recordand must be submitted as part of theresults package.
Why Other Answers Are Incorrect?
A). Affirmation for each practice or control (Incorrect)
While the report includes aMET/NOT MET ratingfor each practice,affirmation is not a required component.
C). Suggested improvements for each failed practice (Incorrect)
Assessors do not provide recommendations for improvement-they only document findings and rationale.
Providing suggestions would create aconflict of interestperCMMC-AB Code of Professional Conduct.
D). Gaps or deltas due to any reciprocity model are recorded as met (Incorrect) If an organization isleveraging reciprocity (e.g., FedRAMP, Joint Surveillance Voluntary Assessments), gapsmust still be documented-not automatically marked as "MET." Conclusion The correct answer isB. Documented rationale for each failed practice, as this is amandatory requirement in the Final CMMC Assessment Results Report.
References:
CMMC Assessment Process (CAP) Guide
DFARS 252.204-7021


質問 # 133
What is the BEST document to find the objectives of the assessment of each practice?

  • A. CMMC Appendices
  • B. CMMC Assessment Process
  • C. CMMC Glossary
  • D. CMMC Assessment Guide Levels 1 and 2

正解:D

解説:
1. Understanding the Role of Assessment Objectives in CMMC 2.0Theassessment objectivesfor each CMMC practice define thespecific criteriathat an assessor uses to evaluate whether a practice is implemented correctly. These objectives break down each control into measurable components, ensuring a structured and consistent assessment process.
To determine where these objectives are best documented, we need to consider theofficial CMMC documentation sources.
2. Why Answer Choice "D" is Correct - CMMC Assessment Guide Levels 1 and 2TheCMMC Assessment Guide (Levels 1 & 2)is theprimary documentthat provides:
#The detailedassessment objectivesfor each practice
#A breakdown of the expectedevidence and implementation details
#Step-by-stepassessment criteriafor assessors to verify compliance
Each CMMC practice in the Assessment Guide is aligned with the correspondingNIST SP 800-171 or FAR
52.204-21 control, and the guide specifies:
* How to assess compliancewith each practice
* What evidenceis required for validation
* What stepsan assessor should follow
#Reference from Official CMMC Documentation:
* CMMC Assessment Guide - Level 2 (Aligned with NIST SP 800-171)explicitly states:
"Each practice is assessed based on defined assessment objectives to determine if the practice is MET or NOT MET."
* CMMC Assessment Guide - Level 1 (Aligned with FAR 52.204-21)provides similar objectives tailored for foundational cybersecurity requirements.
Thus,CMMC Assessment Guide Levels 1 & 2 are the BEST sources for assessment objectives.
3. Why Other Answer Choices Are IncorrectOption
Reason for Elimination
A: CMMC Glossary
#The glossary only defines terminology used in CMMC but does not provide assessment objectives.
B: CMMC Appendices
#The appendices contain supplementary details, but they do not comprehensively list assessment objectives for each practice.
C: CMMC Assessment Process (CAP)
#While the CAP document describes the assessmentworkflow and methodology, it does not outline the specific objectives for each practice.
4. ConclusionTo locate thebest reference for assessment objectives, theCMMC Assessment Guide Levels 1 &
2are the most authoritative and detailed sources. They contain step-by-step assessment criteria, ensuring that practices are evaluated correctly.
#Final answer:
D: CMMC Assessment Guide Levels 1 and 2


質問 # 134
Before submitting the assessment package to the Lead Assessor for final review, a CCP decides to review the Media Protection (MP) Level 1 practice evidence to ensure that all media containing FCI are sanitized or destroyed before disposal or release for reuse. After a thorough review, the CCP tells the Lead Assessor that all supporting documents fully reflect the performance of the practice and should be accepted because the evidence is:

  • A. official.
  • B. subjective.
  • C. adequate.
  • D. compliant.

正解:C


質問 # 135
Prior to conducting a CMMC Assessment, the contractor must specify the CMMC Assessment scope by categorizing all assets. Which two asset categories are always assessed against CMMC practices?

  • A. Specialized Assets and Contractor Risk Managed Assets
  • B. CUI Assets and Specialized Assets
  • C. Security Protection Assets and Contractor Risk Managed Assets
  • D. Security Protection Assets and CUI Assets

正解:B


質問 # 136
During a Level 2 Assessment, an OSC provides documentation that attests that they utilize multifactor authentication on nonlocal remote maintenance sessions. The OSC feels that they have met the controls for the Level 2 certification. What additional measures should the OSC perform to fully meet the maintenance requirement?

  • A. Connections for nonlocal maintenance sessions should be terminated when maintenance is complete.
  • B. The maintenance policy states multifactor authentication must have at least two factors applied for nonlocal maintenance sessions.
  • C. The nonlocal maintenance personnel complain that restrictions slow down their response time and should be removed.
  • D. Connections for nonlocal maintenance sessions should be unlimited to ensure maintenance is performed properly

正解:A


質問 # 137
While developing an assessment plan for an OSC. it is discovered that the certified assessor will be interviewing a former college roommate. What is the MOST correct action to take?

  • A. Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
  • B. Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.
  • C. Inform the OSC and the C3PAO of the possible conflict of interest, document the conflict and mitigation actions in the assessment plan, and if the mitigation actions are acceptable, continue with the assessment.
  • D. Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.

正解:C

解説:
TheCybersecurity Maturity Model Certification (CMMC) Assessment Process (CAP)outlines strict guidelines regardingconflicts of interest (COI)to ensure the integrity and impartiality of assessments conducted byCertified Third-Party Assessment Organizations (C3PAOs)andCertified Assessors (CAs).
The scenario presented involves apotential conflict of interestdue to a prior relationship (former college roommate) between thecertified assessorand an individual at theOrganization Seeking Certification (OSC).
While this prior relationship does not automatically disqualify the assessor, it must bedisclosed, documented, and mitigated appropriately.
Inform the OSC and C3PAO of the Potential Conflict of Interest
TheCMMC Code of Professional Conduct (CoPC)requires assessors to disclose any potential conflicts of interest.
Transparency ensures that all parties, including theOSC and C3PAO, are aware of the situation.
Document the Conflict and Mitigation Actions in the Assessment Plan
PerCMMC CAP documentation, potential conflicts should be assessed based on their material impact on the objectivity of the assessment.
The conflict and proposed mitigation strategies must beformally recorded in the assessment planto provide an audit trail.
Determine If the Mitigation Actions Are Acceptable
If theOSC and C3PAOdetermine that the mitigation actions adequatelyeliminate or reduce the risk of bias, the assessment may proceed.
Common mitigation strategies include:
Assigning another assessor forinterviews with the conflicted individual.
Ensuring thatdecisions regarding the OSC's compliance are reviewed independently.
Proceed with the Assessment If Mitigation Is Acceptable
If the mitigation actions sufficiently address the conflict, the assessment may continue understrict adherence to documented procedures.
CMMC Conflict of Interest Handling Process
A). Do not inform the OSC and the C3PAO of the possible conflict of interest, and continue as planned.
#Incorrect. This violates CMMC's integrity requirements and could result indisciplinary actions against the assessor or invalidation of the assessment. Transparency is mandatory.
B). Inform the OSC and the C3PAO of the possible conflict of interest, and start the entire process over without the conflicted team member.#Incorrect. The CAP doesnotmandate immediate reassignment unless the conflict isunresolvable. Instead, mitigation strategies should be considered first.
C). Inform the OSC and the C3PAO of the possible conflict of interest but since it has been an acceptable amount of time since college, no conflict of interest exists, and continue as planned.#Incorrect.The passage of time alone does not automatically eliminate a conflict of interest. Proper documentation and mitigation are still required.
Why the Other Answers Are Incorrect
CMMC Assessment Process (CAP) Document- Defines COI requirements and mitigation actions.
CMMC Code of Professional Conduct (CoPC)- Outlines ethical responsibilities of assessors.
CMMC Accreditation Body (Cyber-AB) Guidance- Provides rules on conflict resolution.
CMMC Official ReferencesThus,option D is the most correct choice, as it aligns with the official CMMC conflict of interest procedures.


質問 # 138
The Advanced Level in CMMC will contain Access Control (AC) practices from:

  • A. Level 1
  • B. Levels 1, 2, and 3
  • C. Level 3
  • D. Levels 1 and 2

正解:D

解説:
In the CMMC 2.0 Model , the "Advanced Level" specifically refers to Level 2 . The CMMC model is designed to be cumulative , meaning each level builds upon the requirements of the levels beneath it.
* Cumulative Framework : To achieve a certification at a specific level, an Organization Seeking Certification (OSC) must demonstrate compliance with all practices at that level and all practices from the lower levels.
* Access Control (AC) Domain : The Access Control domain is one of the 14 domains in CMMC Level
2. It consists of a total of 22 practices :
* Level 1 (Foundational) : Contains 4 basic safeguarding practices (mapped to FAR 52.204-21).
* Level 2 (Advanced) : Adds 18 additional practices (mapped to NIST SP 800-171), totaling 22 practices for the AC domain at this level.
* Defining "Advanced" : The DoD defines the levels as Level 1 (Foundational), Level 2 (Advanced), and Level 3 (Expert). Therefore, the "Advanced Level" (Level 2) contains the practices from Level 1 and Level 2, but does not include the "Expert" (Level 3) practices, which are derived from NIST SP
800-172.
Why other options are incorrect :
* Option A : While it contains Level 1 practices, it also includes Level 2 practices.
* Option B : Level 3 is the "Expert" level, which is separate and higher than the "Advanced" level.
* Option D : The Advanced level does not reach the requirements of Level 3.
Reference Documents :
* CMMC Model Overview (v2.0) : Section 3.2, "Level 2: Advanced," which describes the 110 practices derived from NIST SP 800-171.
* 32 CFR Part 170 (CMMC Program Rule) : Details the structure of the levels and the requirement for cumulative compliance.
* CMMC Level 2 Assessment Guide : Lists all 22 Access Control practices required for a Level 2 assessment, clearly identifying which are carried over from Level 1.


質問 # 139
An assessor is in Phase 3 of the CMMC Assessment Process. The assessor has delivered the final findings, submitted the assessment results package, and provided feedback to the C3PAO and CMMC-AB. What must the assessor still do?

  • A. Archive or dispose of any assessment artifacts
  • B. Determine level recommendation
  • C. Archive all assessment artifacts
  • D. Determine final practice pass/fail results

正解:A

解説:
In Phase 3 (Post-Assessment), the assessor's responsibility is to archive or dispose of assessment artifacts according to the C3PAO's policies and retention requirements. By this point, final findings and results have already been delivered, so the only remaining step is ensuring proper handling of assessment materials.
Supporting Extracts from Official Content:
* CAP v2.0, Post-Assessment Activities (§3.17): "The assessor must archive or dispose of any assessment artifacts in accordance with the C3PAO's retention and destruction policy." Why Option D is Correct:
* Determining practice pass/fail results and level recommendations occurs earlier in Phases 2 and 3.
* The final step left for the assessor is the proper archiving or destruction of artifacts.
References (Official CMMC v2.0 Content):
* CMMC Assessment Process (CAP) v2.0, Phase 3: Post-Assessment (§3.17).


質問 # 140
What type of information is NOT intended for public release and is provided by or generated for the government under a contract to develop or deliver a product or service to the government, but not including information provided by the government to the public (such as on public websites) or simple transactional information, such as necessary to process payments?

  • A. CUI
  • B. CTI
  • C. CDI
  • D. FCI

正解:D

解説:
Understanding Federal Contract Information (FCI)Federal Contract Information (FCI) is defined by48 CFR
52.204-21(Basic Safeguarding of Covered Contractor Information Systems). FCI refers to information that:
Is NOT intended for public release.
Is provided by or generated for the government under a contract.
Is necessary to develop or deliver a product or service to the government.
Excludes publicly available government information(such as information on public websites).
Excludes simple transactional information(e.g., necessary to process payments).
In the context ofCMMC 2.0, organizations thatprocess, store, or transmit FCImust meetCMMC Level 1 (Foundational), which requires implementing17 basic safeguarding practicesoutlined inFAR 52.204-21.
A). CDI (Controlled Defense Information)# Incorrect
This term was used inDFARS 252.204-7012but has been replaced byCUI (Controlled Unclassified Information)in CMMC discussions.
B). CTI (Cyber Threat Intelligence)# Incorrect
This refers to intelligence on cyber threats, tactics, and indicators, not contractual data.
C). CUI (Controlled Unclassified Information)# Incorrect
CUI is sensitive information requiring additional safeguarding but is a separate category from FCI.
D). FCI (Federal Contract Information)#Correct
The definition of FCI explicitly matches the description given in the question.
Why is the Correct Answer FCI (D)?
FAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems) Defines FCI and the required safeguards.
Establishes17 cybersecurity practicesfor FCI protection.
CMMC 2.0 Framework
Level 1 (Foundational)is required for contractors handlingFCI.
Ensures compliance withbasic safeguarding requirementsoutlined inFAR 52.204-21.
NIST SP 800-171 and DFARS 252.204-7012
FCI doesnotrequire compliance withNIST SP 800-171, butCUI does.
CMMC 2.0 References Supporting this Answer


質問 # 141
An assessment is being completed at a client site that is not far from the Lead Assessor's home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?

  • A. Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.
  • B. Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.
  • C. Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service.
  • D. Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.

正解:A


質問 # 142
Which phase of the CMMC Assessment Process includes developing the assessment plan?

  • A. Phase 2
  • B. Phase 1
  • C. Phase 3
  • D. Phase 4

正解:B


質問 # 143
What is a PRIMARY activity that is performed while conducting an assessment?

  • A. Develop assessment plan.
  • B. Verify readiness to conduct assessment.
  • C. Deliver recommended assessment results.
  • D. Collect and examine evidence.

正解:D

解説:
Step 1: Understand the Assessment Phases (CAP v1.0)TheCMMC Assessment Process (CAP)outlines a structured lifecycle for assessments, including:
* Plan and Prepare Phase- Develop the assessment plan (before the assessment starts).
* Conduct Assessment Phase- Execute the actual assessment activities.
* Report Results Phase- Finalize and deliver the assessment outcomes.
CAP v1.0 - Section 3.5 (Conduct Assessment):
"The assessment team collects, examines, and evaluates evidence to determine if practices are MET or NOT MET."
* During the"Conduct Assessment" phase, the main activity is to:
* Collect evidence(documentation, interviews, testing),
* Validate adequacy and sufficiency,
* Score practicesas MET/NOT MET.
#Step 2: Why "Collect and Examine Evidence" Is the Primary ActivityThis is thecore responsibilityof assessorswhile conductingan assessment.
* A. Develop assessment plan# This occurs in thePlan and Preparephasebeforeconducting the assessment.
* C. Verify readiness to conduct assessment# Readiness verification is part ofpre-assessment activities, not during the assessment itself.
* D. Deliver recommended assessment results# This is done during theReport Resultsphase after the assessment has been conducted.
#Why the Other Options Are Incorrect
Theprimary activity performed during the actual executionof a CMMC assessment iscollecting and examining evidenceto determine compliance with practices.


質問 # 144
In the CMMC Model, how many practices are included in Level 1?

  • A. 17 practices
  • B. 72 practices
  • C. 110 practices
  • D. 15 practices

正解:D

解説:
CMMC (Cybersecurity Maturity Model Certification) 2.0 Level 1 is designed to protectFederal Contract Information (FCI)and consists of17 foundational cybersecurity practices. These practices are directly derived fromFAR 52.204-21(Basic Safeguarding of Covered Contractor Information Systems), which outlines minimum security requirements for contractors handling FCI.
Breakdown of CMMC Level 1 PracticesThe17 practicesin Level 1 focus on basic cybersecurity hygiene and fall under the following6 domains:
Access Control (AC)- 4 practices
AC.L1-3.1.1: Limit system access to authorized users
AC.L1-3.1.2: Limit user access to authorized transactions and functions AC.L1-3.1.20: Verify and control connections to external systems AC.L1-3.1.22: Control information posted or processed on publicly accessible systems Identification and Authentication (IA)- 2 practices IA.L1-3.5.1: Identify and authenticate system users IA.L1-3.5.2: Use multifactor authentication for local and network access Media Protection (MP)- 1 practice MP.L1-3.8.3: Sanitize media before disposal or reuse Physical Protection (PE)- 4 practices PE.L1-3.10.1: Limit physical access to systems containing FCI PE.L1-3.10.3: Escort visitors and monitor visitor activity PE.L1-3.10.4: Maintain audit logs of physical access PE.L1-3.10.5: Control and manage physical access devices System and Communications Protection (SC)- 2 practices SC.L1-3.13.1: Monitor and control communications at system boundaries SC.L1-3.13.5: Implement subnetworks for publicly accessible system components System and Information Integrity (SI)- 4 practices SI.L1-3.14.1: Identify, report, and correct system flaws in a timely manner SI.L1-3.14.2: Provide protection from malicious code at designated locations SI.L1-3.14.4: Update malicious code protection mechanisms periodically SI.L1-3.14.5: Perform scans of system components and real-time file scans Official Reference from CMMC 2.0 DocumentationThe 17 practices forCMMC Level 1are explicitly listed in theCMMC 2.0 Appendices and Assessment Guide for Level 1, as well as in theFAR 52.204-21 requirements.
These practices representbasic safeguarding measuresthat all DoD contractors handlingFCImust implement.
#CMMC 2.0 Level 1 Summary:
Focus:Basic safeguarding of FCI
Total Practices:17
Derived From:FAR 52.204-21
Assessment Type:Self-assessment (annual)
Final Verification and ConclusionThe correct answer isB. 17 practicesas verified from theCMMC 2.0 official documentsandFAR 52.204-21 requirements.


質問 # 145
Which code or clause requires that a contractor is meeting the basic safeguarding requirements for FCI during a Level 1 Self-Assessment?

  • A. DFARS 252.204-7021
  • B. FAR 52.204-21
  • C. DFARS 252.204-7011
  • D. 22CFR 120-130

正解:B

解説:
1. Understanding Basic Safeguarding Requirements for FCI in CMMC Level 1
* Federal Contract Information (FCI) is defined as information provided by or generated for the government under a contract that isnot intended for public release.
* CMMCLevel 1is designed to ensurebasic safeguardingof FCI, aligning with15 security requirementsfound inFAR 52.204-21 (Basic Safeguarding of Covered Contractor Information Systems).
* Contractors handlingonly FCImust meetCMMC Level 1, which alignsdirectlywith the safeguarding requirements set inFAR 52.204-21.
2. FAR 52.204-21 and Its Role in CMMC Level 1 Compliance
* FAR 52.204-21establishes the baseline cybersecurity controls that contractors must implement to protectFCI.
* The15 basic safeguarding requirementsinclude:
* Limiting information accessto authorized users.
* Identifying and authenticating usersbefore allowing system access.
* Protecting transmitted FCIfrom unauthorized disclosure.
* Monitoring and controlling connectionsto external systems.
* Applying boundary protectionand cybersecurity measures.
* Sanitizing mediabefore disposal.
* Updating security configurationsto reduce vulnerabilities.
* Providing physical securityprotections.
* Controlling physical accessto systems that process FCI.
* Enforcing multi-factor authentication (MFA) where applicable.
* Patching vulnerabilitiesin software and hardware.
* Limiting the use of removable media.
* Creating and retaining system audit logs.
* Performing risk-based security assessments.
* Developing an incident response plan.
These 15 practices form thefoundationof CMMCLevel 1 Self-Assessment, ensuring contractorsmeet minimum cybersecurity expectationsfor handling FCI.
3. Why the Other Options Are Incorrect
* B. 22 CFR 120-130:
* This refers toInternational Traffic in Arms Regulations (ITAR), which controls the export of defense-related articles and services,notFCI safeguarding requirements.
* C. DFARS 252.204-7011:
* This clause refers toalternative line item structuresand does not pertain to cybersecurity or safeguarding FCI.
* D. DFARS 252.204-7021:
* This clause enforcesCMMC requirementsbut doesnot definebasic safeguarding controls. It requires compliance with CMMC but does not specify the foundational requirements (which come fromFAR 52.204-21for Level 1).
4. Official CMMC 2.0 Reference & Study Guide Alignment
* TheCMMC 2.0 model documentationconfirms that Level 1 is focused on the15 practices from FAR
52.204-21.
* TheDoD's official CMMC Assessment Guidefor Level 1 explicitly states that meeting FAR 52.204-21 is therequirement for passing a Level 1 Self-Assessment.
* TheCMMC 2.0 Scoping Guideclarifies that contractors handling onlyFCIand seekingLevel 1 certificationmust implementonly FAR 52.204-21security controls.
Final Confirmation:The correct answer isA. FAR 52.204-21, as it directly governs the basic safeguarding ofFCIand is the foundational requirement for aLevel 1 Self-Assessmentin CMMC 2.0.


質問 # 146
The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections. How should the team score practices in which the evidence shows the deficiencies have been corrected?

  • A. NOT APPLICABLE
  • B. POA&M
  • C. MET
  • D. NOT MET

正解:C


質問 # 147
A CMMC Assessment Team arrives at an OSC to begin a CMMC Level 2 Assessment. The team checks in at the front desk and lets the receptionist know that they are here to conduct the assessment. The receptionist is aware that the team is arriving today and points down a hallway where the conference room is. The receptionist tells the Lead Assessor to wait in the conference room. as someone will be there shortly. The receptionist fails to check for credentials and fails to escort the team. The receptionist's actions are in direct violation of which CMMC practice?

  • A. PE.L1-3.10.3: Escort visitors and monitor visitor activity
  • B. PS.L2-3.9.1; Screen individuals prior to authorizing access to organizational systems containing CUI
  • C. PS.L2-3 9.2: Ensure that organizational systems containing CUI are protected during and after personnel actions such as terminations and transfers
  • D. PE.L1-3.10.5: Control and manage physical access devices

正解:A


質問 # 148
......

CMMC-CCP問題集と練習テスト(238試験問題):https://jp.fast2test.com/CMMC-CCP-premium-file.html

ガイド(2026年最新)実際のCyber AB CMMC-CCP試験問題:https://drive.google.com/open?id=1BjtHzWFeLF8d4XkaTtgD3CNt6Q49U8r7


弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

我々の働いている時間: ( GMT 0:00-15:00 )
月曜日から土曜日まで

サポート: 現在連絡 

English Deutsch 繁体中文 한국어