EXAM PREPARATION PACK KEY SECURITY
CONTROLS AND SAMPLE QUESTIONS WITH
EXPLANATIONS
◉ What is the role of feedback in the CMMC Assessment Process?
Answer: To improve the document and inform future editions of the
CAP.
◉ What is meant by 'conducting assessment scoring'? Answer:
Evaluating the organization's compliance with the CMMC security
requirements.
◉ What should be done after compiling assessment results? Answer:
Conduct a Quality Assurance Review.
◉ What is the purpose of the CMMC eMASS system? Answer: To
manage and store assessment results and documentation.
◉ What is the significance of the 'Adverse Determination of
Assessment Readiness'? Answer: It indicates that the organization is
not prepared for the assessment.
,◉ What is the initial step in managing conflicts of interest (COI)?
Answer: Identify and manage initial conflicts of interest.
◉ What is the role of the CMMC Ecosystem? Answer: To provide
input and feedback on the CMMC Assessment Process.
◉ What is the purpose of the Cybersecurity Maturity Model
Certification (CMMC) Program? Answer: To assess and certify
conformance to security requirements for companies within the
Defense Industrial Base (DIB).
◉ What type of information does the CMMC aim to protect? Answer:
Controlled Unclassified Information (CUI) and Federal Contract
Information (FCI).
◉ Which office oversees the CMMC Program? Answer: The Office of
the DoD Chief Information Officer (ODCIO).
◉ What is the role of the Cyber AB in the CMMC Program? Answer: It
is the designated sole Accreditation Body for the CMMC Program.
◉ Where can the official CMMC doctrine and documentation be
found? Answer: In the Code of Federal Regulations (CFR) and
documents from DoD and NIST.
, ◉ What is the CMMC Assessment Process (CAP)? Answer: The
official procedural guide for conducting CMMC Level 2 certification
assessments.
◉ What is the main goal of the CAP? Answer: To ensure consistency
and integrity in CMMC Level 2 certification assessments.
◉ How many phases are in the CMMC Assessment Process? Answer:
Four phases.
◉ What is the first phase of the CMMC Assessment Process? Answer:
Conduct the Pre-Assessment.
◉ What is the second phase of the CMMC Assessment Process?
Answer: Assess Conformity to Security Requirements.
◉ What is the third phase of the CMMC Assessment Process?
Answer: Complete and Report Assessment Results.
◉ What is the fourth phase of the CMMC Assessment Process?
Answer: Issue Certificate and Closeout POA&M.