Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 30 pages
Exam (elaborations)

CMMC Review Exam 1 Questions & Answers 2025/2026

Document preview thumbnail
Preview 3 out of 30 pages

CMMC Review Exam 1 Questions & Answers 2025/2026 AC.L1-3.1.1[a] - ANSWERSauthorized users are identified. AC.L1-3.1.1[b] - ANSWERSprocesses acting on behalf of authorized users are identified. AC.L1-3.1.1[c] - ANSWERSdevices (and other systems) authorized to connect to the system are identified. AC.L1-3.1.1[d] - ANSWERSsystem access is limited to authorized users. AC.L1-3.1.1[e] - ANSWERSsystem access is limited to processes acting on behalf of authorized users. AC.L1-3.1.1[f] - ANSWERSsystem access is limited to authorized devices (including other systems). AC.L1-3.1.2[a] - ANSWERSthe types of transactions and functions that authorized users are permitted to execute are defined. AC.L1-3.1.2[b] - ANSWERSsystem access is limited to the defined types of transactions and functions for authorized users. AC.L2-3.1.3[a] - ANSWERSinformation flow control policies are defined.

Content preview

CMMC Review Exam 1 Questions &
Answers 2025/2026

AC.L1-3.1.1[a] - ANSWERSauthorized users are identified.



AC.L1-3.1.1[b] - ANSWERSprocesses acting on behalf of authorized users are identified.



AC.L1-3.1.1[c] - ANSWERSdevices (and other systems) authorized to connect to the system are
identified.



AC.L1-3.1.1[d] - ANSWERSsystem access is limited to authorized users.



AC.L1-3.1.1[e] - ANSWERSsystem access is limited to processes acting on behalf of authorized
users.



AC.L1-3.1.1[f] - ANSWERSsystem access is limited to authorized devices (including other
systems).



AC.L1-3.1.2[a] - ANSWERSthe types of transactions and functions that authorized users are
permitted to execute are defined.



AC.L1-3.1.2[b] - ANSWERSsystem access is limited to the defined types of transactions and
functions for authorized users.



AC.L2-3.1.3[a] - ANSWERSinformation flow control policies are defined.

,AC.L2-3.1.3[b] - ANSWERSmethods and enforcement mechanisms for controlling the flow of CUI
are defined.



AC.L2-3.1.3[c] - ANSWERSdesignated sources and destinations (e.g., networks, individuals, and
devices) for CUI within the system and between interconnected systems are identified.



AC.L2-3.1.3[d] - ANSWERSauthorizations for controlling the flow of CUI are defined.



AC.L2-3.1.3[e] - ANSWERSapproved authorizations for controlling the flow of CUI are enforced.



AC.L2-3.1.4[a] - ANSWERSthe duties of individuals requiring separation are defined.



AC.L2-3.1.4[b] - ANSWERSresponsibilities for duties that require separation are assigned to
separate individuals.



AC.L2-3.1.4[c] - ANSWERSaccess privileges that enable individuals to exercise the duties that
require separation are granted to separate individuals.



AC.L2-3.1.5[a] - ANSWERSprivileged accounts are identified.



AC.L2-3.1.5[b] - ANSWERSaccess to privileged accounts is authorized in accordance with the
principle of least privilege.



AC.L2-3.1.5[c] - ANSWERSsecurity functions are identified.



AC.L2-3.1.5[d] - ANSWERSaccess to security functions is authorized in accordance with the
principle of least privilege.

, AC.L2-3.1.6[a] - ANSWERSnonsecurity functions are identified.



AC.L2-3.1.6[b] - ANSWERSusers are required to use non-privileged accounts or roles when
accessing nonsecurity functions.



AC.L2-3.1.7[a] - ANSWERSprivileged functions are defined.



AC.L2-3.1.7[b] - ANSWERSnon-privileged users are defined.



AC.L2-3.1.7[c] - ANSWERSnon-privileged users are prevented from executing privileged
functions.



AC.L2-3.1.7[d] - ANSWERSthe execution of privileged functions is captured in audit logs.



AC.L2-3.1.8[a] - ANSWERSthe means of limiting unsuccessful logon attempts is defined.



AC.L2-3.1.8[b] - ANSWERSthe defined means of limiting unsuccessful logon attempts is
implemented.



AC.L2-3.1.9[a] - ANSWERSprivacy and security notices required by CUI-specified rules are
identified, consistent, and associated with the specific CUI category.



AC.L2-3.1.9[b] - ANSWERSprivacy and security notices are displayed.



AC.L2-3.1.10[a] - ANSWERSthe period of inactivity after which the system initiates a session lock
is defined.

Document information

Uploaded on
January 31, 2025
Number of pages
30
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$11.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
wanjejer1900
2.0
(1)
Sold
7
Followers
0
Items
1411
Last sold
1 month ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions