100% de satisfacción garantizada Inmediatamente disponible después del pago Tanto en línea como en PDF No estas atado a nada 4.2 TrustPilot
logo-home
Examen

CMMC study guide | Questions & Answers (100 %Score) Latest Updated 2024/2025 Comprehensive Questions A+ Graded Answers | 100% Pass

Puntuación
-
Vendido
-
Páginas
10
Grado
A+
Subido en
03-08-2024
Escrito en
2024/2025

CMMC study guide | Questions & Answers (100 %Score) Latest Updated 2024/2025 Comprehensive Questions A+ Graded Answers | 100% Pass

Institución
CMMC
Grado
CMMC









Ups! No podemos cargar tu documento ahora. Inténtalo de nuevo o contacta con soporte.

Escuela, estudio y materia

Institución
CMMC
Grado
CMMC

Información del documento

Subido en
3 de agosto de 2024
Número de páginas
10
Escrito en
2024/2025
Tipo
Examen
Contiene
Preguntas y respuestas

Temas

Vista previa del contenido

CMMC study guide | Questions & Answers (100 %Score) Latest Updated 2024/2025
Comprehensive Questions A+ Graded Answers | 100% Pass


What does CMMC stand for? - ✔✔Cybersecurity Maturity Model Certification



What is CMMC? - ✔✔A cybersecurity compliance mandate, required by the US DoD of orgs that serve
the DoD (prime contractors and their subcontractors)



Who mandated CMMC? What org runs the CMMC program? - ✔✔US DoD. Cyber AB runs it.



Who is subject to CMMC? - ✔✔Private sector orgs in the DIB (& higher Ed that obtain DoD research
grants with CUI)



What is the purpose of CMMC - ✔✔The DoD's goal is to strengthen the cybersecurity posture of their
suppliers and protect controlled unclassified info (CUI)



What is the acronym for the data that the DoD is seeking to protect? What does the acronym stand for?
- ✔✔CUI; Controlled unclassified information



What set of standards is CMMC based upon? - ✔✔NIST 800-171



What is the acronym for the companies that will perform CMMC audits? What does this acronym stand
for? - ✔✔C3PAO - Certified Third-party assessment organizations.



What are at least (3) major reasons that a DIB org should want to self-attest truthfully and/or be
compliant with CMMC? - ✔✔Not awarded contract work / DOJ ramifications / contract termination or
suspension / False Claims Act violations / fines and penalties.



How many domains are part of NIST 800-171 - ✔✔14



Name 6 of the domains - ✔✔Access control, awareness and training, audit and accountability,
configuration management, identification and authentication, incident response, Maintenance, media

, protection, personnel security, physical protection, risk assessment, security assessment, system and
comms protection, system and information integrity.



How many controls compromise 800-171 - ✔✔110



Each control has 2 primary components and they are ———— and ————. - ✔✔Policy & practice



NIST does not "weight" the criticality of any particular security control, but the DoD has. How does this
weighting / prioritization system work? - ✔✔Assessment methodology. Scale of 1, 3, or 5. 1 being lowest
and 5 being highest and most critical. No POAMs for 5.



What is the primary document that outlines any DIB's cyber program - ✔✔Systems and Security plan -
SSP



What are at least (3) things that would be discussed in this document - ✔✔Security policies, roles and
responsibilities, details the different security standards and guidelines that the org follows, identifies all
its hardware and the software installed on the system, include high-level diagrams that show how
connected systems talk to each other.



Provides an example of policy and practice - ✔✔Policy: user must reset password every x days and the
password must contain certain parameters.

Practice: sys admin creates the rules to remind users.



How many levels did CMMC 1.0 have - ✔✔5



How many levels are in CMMC 2? How many controls? How many objectives - ✔✔3 levels, 110 controls,
320+ objectives



What is the difference between a control and an objective - ✔✔Control = security control that must be
met to be compliant. Objectives are the criteria within a control that are auditable
$13.48
Accede al documento completo:

100% de satisfacción garantizada
Inmediatamente disponible después del pago
Tanto en línea como en PDF
No estas atado a nada


Documento también disponible en un lote

Conoce al vendedor

Seller avatar
Los indicadores de reputación están sujetos a la cantidad de artículos vendidos por una tarifa y las reseñas que ha recibido por esos documentos. Hay tres niveles: Bronce, Plata y Oro. Cuanto mayor reputación, más podrás confiar en la calidad del trabajo del vendedor.
Favorgrades Chamberlain College Of Nursing
Seguir Necesitas iniciar sesión para seguir a otros usuarios o asignaturas
Vendido
754
Miembro desde
3 año
Número de seguidores
374
Documentos
29913
Última venta
1 día hace
Favorgrades Emporium

3.7

183 reseñas

5
76
4
41
3
31
2
11
1
24

Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes