PRACTICE TEST QUESTIONS AND DETAILED
MATURITY LEVEL BREAKDOWN FULL REVIEW
◉ What version of the CMMC Assessment Process is referenced in
this document? Answer: Version 2.0
◉ When is the effective date of CMMC 2.0? Answer: December 2024
◉ What should be adhered to in case of contradictions in CMMC
documentation? Answer: The Department of Defense (DoD) and/or
National Institute of Standards and Technology (NIST)
documentation.
◉ What is the disclaimer regarding the content of the CAP? Answer:
The material is provided on an 'AS-IS' basis with no warranties of
any kind.
◉ What is the initial step in the CMMC Assessment Process? Answer:
Receive CMMC Assessment Request from the Organization Seeking
Certification (OSC).
,◉ What is involved in the preliminary proceedings of the CAP?
Answer: Confirming the entity/entities to be assessed and framing
the assessment.
◉ What is the focus of Phase 1 in the CMMC Assessment Process?
Answer: Conducting the Pre-Assessment.
◉ What document is reviewed during Phase 1 of the CAP? Answer:
The System Security Plan (SSP).
◉ What is the goal of Phase 2 in the CMMC Assessment Process?
Answer: Assess conformity to security requirements.
◉ What is conducted during Phase 3 of the CAP? Answer:
Completing and reporting assessment results.
◉ What is the outcome of Phase 4 in the CMMC Assessment Process?
Answer: Issuing the Certificate of CMMC Status and closing out the
Plan of Action and Milestones (POA&M).
◉ What is the role of the Assessment Team in the CAP? Answer: To
conduct the assessment and ensure compliance with security
requirements.
, ◉ What should be done if an organization is not ready for
assessment? Answer: An adverse determination of assessment
readiness should be made.
◉ What is the purpose of the Quality Assurance Review in the
assessment process? Answer: To ensure the accuracy and reliability
of the assessment results.
◉ What are the daily checkpoint meetings for during the
assessment? Answer: To discuss progress and address any issues
that arise during the assessment.
◉ What is the significance of the feedback requested on the draft
CAP? Answer: To improve the document and inform future editions
of the CAP.
◉ What does the acronym CMMC stand for? Answer: Cybersecurity
Maturity Model Certification.
◉ What is the role of external service providers in the assessment?
Answer: To be addressed during the assessment to ensure
compliance with security requirements.
◉ What is the purpose of the Out-Brief Meeting? Answer: To discuss
the assessment results with the assessed organization.