Answers 2025/2026
1. Which statement is true?
a. FAR implements and supplements the DFARS and defines additional requirements for
safeguarding
b. DFARS implements and supplements FAR, which is the primary set of rules in the FAR
framework.
c. Far and DFARS are unified cybersecurity standards used by all nonfederal systems and
organizations that store FCI and CUI - ANSWERSB
Which document describes the procedures used to asses the maturity level of the processes
and practices of the CMMC?
a. CMMC Assessment Guide Level 3
b. CMMC Assessment Methodology
c. CMMC model - ANSWERSB
Amy is a CMMC-AB Certified professional that has participated in three ML-2 assessments this
year. During The assessment, Amy supervised one of the new Certified Assessors (CA). How do
you describe this situation?
a) Acceptable, a CP is a prerequisite for the CA credential, so supervising other CA is allowed
b) Unacceptable, a CP is neither authorized to participate in ML-2 assessments not supervise
other assessment team members.
c) Unacceptable, a CP is only authorized to participate as an assessment team member under
supervision of the of a CA - ANSWERSC
, ASO is an American Company that supplies communications, intelligence and surveillance
systems to the department of defense. They have implemented all CMMC Level 3 requirements.
Who do ASO need to contact to issue an assessment request?
a) An organization seeking certification (OSC)
b) A third part assessor (C3PAO)
c) A registered provider organization - ANSWERSB
To whom should the assessment results be submitted after conducting a CMMC level 4
Assessment?
a) Certified Quality Auditors
b) Licensed Partner Publishers
c) Certified Instructors - ANSWERSA
What is the role of Licensed Training providers LTP in the CMMC-AB ecosystem?
a) Deliver the CMMC-AB training to participants through certified instructors.
b) Develop the CMMC-AB training courses and certification exams
c) Offer consultancy services doe assessment preparation through certified assessors. -
ANSWERSA
How should GCraft Inc's processes be if the company wants to implement CMMC level 3?
a) Reviewed
b) Managed
c) Optimizing - ANSWERSB
What type of information is not addressed in CMMC levels?
a) Classified Information
b) Unclassified Information