/
om
CMMC-CCP
.c
fy
Certified CMMC Professional (CCP) Exam
rti v15.2
ce
ct
DEMO QUESTIONS
ire
Sample Q&A Preview
.d
w
Preview content before purchase
w
w
Get Full Version & Premium Features
www.directcertify.com/exam/cmmc-ccp
Premium Benefits Included
Free Updates Money Back
90 days of exam updates 30-day guarantee policy
Instant Access 24/7 Support
Download immediately Expert assistance anytime
www.directcertify.com/exams/cmmc-ccp Page 1 of 9
, Question 1. (Single Select)
Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a part of a
plan of action?
A: Completion dates
/
om
B: Milestones to measure progress
C: Ownership of who is accountable for ensuring plan performance
.c
D: Budget requirements to implement the plan's remediation actions
fy
rti Answer: D
ce
ct
Explanation:
ire
Under the Cybersecurity Maturity Model Certification (CMMC) 2.0, a Plan of Action (POA) is a critical
document that outlines the specific actions a contractor needs to take to remediate cybersecurity
.d
deficiencies. While POAs serve as a roadmap for achieving compliance with required controls, the inclusion
w
of certain elements is standardized.
w
Key Elements of a Plan of Action (POA)
w
According to the CMMC guidelines and NIST SP 800-171, which underpins many CMMC requirements, a
POA typically includes:
Completion Dates: Identifies target deadlines for resolving deficiencies.
Milestones to Measure Progress: Includes interim steps or markers to ensure progress is monitored over
time.
Ownership or Accountability: Clearly assigns responsibility for each action item to specific personnel or
teams.
What is Generally NOT Part of a POA?
Budget requirements to implement the plan's remediation actions (Option D) are generally not included in a
POA. While budgeting is critical for ensuring the plan's success, it is considered a part of the broaderproject
management or resource planning process, not the POA itself. This distinction is intentional to keep the
POA focused on actionable items rather than resource allocation.
Supporting Reference
NIST SP 800-171A, Appendix D: Provides an overview of POA components, emphasizing the prioritization
of corrective actions, responsibility, and measurable outcomes.
CMMC Level 2 Practices (Aligned with NIST SP 800-171): Specifically, the focus is on actions, timelines,
and accountability rather than financial planning.
www.directcertify.com/exams/cmmc-ccp Page 2 of 9