Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Certified CMMC Professional (CCP) Exam Question and Answers

Certified CMMC Professional (CCP) Exam

Last Update May 30, 2026
Total Questions : 228

We are offering FREE CMMC-CCP Cyber AB exam questions. All you do is to just go and sign up. Give your details, prepare CMMC-CCP free exam questions and then go for complete pool of Certified CMMC Professional (CCP) Exam test questions that will help you more.

CMMC-CCP pdf

CMMC-CCP PDF

$36.75  $104.99
CMMC-CCP Engine

CMMC-CCP Testing Engine

$43.75  $124.99
CMMC-CCP PDF + Engine

CMMC-CCP PDF + Testing Engine

$57.75  $164.99
Questions 1

A program manager for a defense contractor saves all FCI data relevant to a contract on a flash drive. Why is the flash drive categorized as an FCI Asset ?

Options:

A.  

It is storing FCI.

B.  

It is testing FCI.

C.  

It is distributing FCI.

D.  

It is properly marked as FCI.

Discussion 0
Questions 2

Which principles are included in defining the CMMC-AB Code of Professional Conduct?

Options:

A.  

Objectivity, classification, and information accuracy

B.  

Objectivity, confidentiality, and information integrity

C.  

Responsibility, classification, and information accuracy

D.  

Responsibility, confidentiality, and information integrity

Discussion 0
Questions 3

Which statement is NOT a measure to determine if collected evidence is sufficient?

Options:

A.  

Evidence covers the sampled organization

B.  

Evidence is not required if the practice is ISO certified

C.  

Evidence covers the model scope of the Assessment (Target CMMC Level)

D.  

Evidence corresponds to the sampled organization in the evidence collection approach

Discussion 0
Questions 4

Companies that knowingly defraud the government by not being in compliance with cybersecurity regulations are at risk of being held liable for:

Options:

A.  

The contract value plus a penalty as stated in the Cyber Claims Act

B.  

The contract value plus a penalty as stated in the False Claims Act

C.  

Three times the contract value plus a penalty as stated in the Cyber Claims Act

D.  

Three times the contract value plus a penalty as stated in the False Claims Act

Discussion 0
Questions 5

Which phase of the CMMC Assessment Process includes the task to identify, obtain inventory, and verify evidence?

Options:

A.  

Phase 1: Plan and Prepare Assessment

B.  

Phase 2: Conduct Assessment

C.  

Phase 3: Report Recommended Assessment Results

D.  

Phase 4: Remediation of Outstanding Assessment Issues

Discussion 0
Questions 6

In the CMMC Model, how many practices are included in Level 2?

Options:

A.  

17 practices

B.  

72 practices

C.  

110 practices

D.  

180 practices

Discussion 0
Questions 7

Which NIST SP discusses protecting CUI in nonfederal systems and organizations?

Options:

A.  

NIST SP 800-37

B.  

NIST SP 800-53

C.  

NIST SP 800-88

D.  

NIST SP 800-171

Discussion 0
Questions 8

A company is about to conduct a press release. According to AC.L1-3.1.22: Control information posted or processed on publicly accessible systems, what is the MOST important factor to consider when addressing CMMC requirements?

Options:

A.  

That the information is correct

B.  

That the CEO approved the message

C.  

That the company has to safeguard the release of FCI

D.  

That so long as the information is only FCI, it can be released

Discussion 0
Questions 9

During a POA & M closeout assessment , the Lead Assessor and team members verified all evidence provided by the OSC and passed those that satisfied the requirements. Who MUST verify that every failed practice from the initial original assessment has been adequately addressed?

Options:

A.  

OSC

B.  

CCA

C.  

OSC sponsor

D.  

Lead Assessor

Discussion 0
Questions 10

An organization's sales representative is tasked with entering FCI data into various fields within a spreadsheet on a company-issued laptop. This laptop is an FCI Asset being used to:

Options:

A.  

process and transmit FCI.

B.  

process and organize FCI.

C.  

store, process, and transmit FCI.

D.  

store, process, and organize FCI.

Discussion 0
Questions 11

During the planning phase of a CMMC Level 2 Assessment, the Lead Assessor is considering what would constitute the right evidence for each practice. What is the Assessor attempting to verify?

Options:

A.  

Adequacy

B.  

Sufficiency

C.  

Process mapping

D.  

Assessment scope

Discussion 0
Questions 12

When a conflict of interest is unavoidable, a CCP should NOT:

Options:

A.  

Inform their organization

B.  

Take action to minimize its impact

C.  

Disclose it to affected stakeholders

D.  

Conceal it from the Assessment Team lead

Discussion 0
Questions 13

What is the BEST document to find the objectives of the assessment of each practice?

Options:

A.  

CMMC Glossary

B.  

CMMC Appendices

C.  

CMMC Assessment Process

D.  

CMMC Assessment Guide Levels 1 and 2

Discussion 0
Questions 14

Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?

Options:

A.  

Availability

B.  

Confidentiality

C.  

Information Integrity

D.  

Respect for Intellectual Property

Discussion 0
Questions 15

An assessment is being conducted at a remote client site. For the duration of the assessment, the client has provided a designated hoteling space in their secure facility which consists of a desk with access to a shared printer. After noticing that the desk does not lock, a locked cabinet is requested but the client does not have one available. At the end of the day, the client provides a printout copy of an important network diagram. The diagram is clearly marked and contains CUI. What should be done NEXT to protect the document?

Options:

A.  

Take it with them to review in the evening.

B.  

Leave it on the desk for review the following day.

C.  

Put it in the unlocked desk drawer for review the following morning.

D.  

Take a picture with the personal phone before securely shredding it.

Discussion 0
Questions 16

The Audit and Accountability (AU) domain has practices in:

Options:

A.  

Level 1.

B.  

Level 2.

C.  

Levels 1 and 2.

D.  

Levels 1 and 3.

Discussion 0
Questions 17

Within the CMMC Ecosystem which organization ultimately will manage and oversee the training, testing, authorization, and certification of candidate assessors and instructors?

Options:

A.  

DoD OUSD

B.  

DIB Collaborative Information Sharing Environment

C.  

Committee on National Security Systems Instructions

D.  

CMMC Assessors and Instructors Certification Organization

Discussion 0
Questions 18

What type of criteria is used to answer the question "Does the Assessment Team have the right evidence?"

Options:

A.  

Adequacy criteria

B.  

Objectivity criteria

C.  

Sufficiency criteria

D.  

Subjectivity criteria

Discussion 0
Questions 19

Which CMMC Levels meet the standards of protecting FCI (Federal Contract Information) ?

Options:

A.  

Level 1

B.  

Level 2

C.  

Levels 2 and 3

D.  

Levels 1, 2, and 3

Discussion 0
Questions 20

How many domains does the CMMC Model consist of?

Options:

A.  

14 domains

B.  

43 domains

C.  

72 domains

D.  

110 domains

Discussion 0
Questions 21

Who makes the final determination of the assessment method used for each practice?

Options:

A.  

CCP

B.  

osc

C.  

Site Manager

D.  

Lead Assessor

Discussion 0
Questions 22

Which document specifies the CMMC Level 1 practices that correspond to basic safeguarding requirements?

Options:

A.  

NIST SP 800-171

B.  

NIST SP 800-171b

C.  

48 CFR 52.204-21

D.  

DFARS 252.204-7012

Discussion 0
Questions 23

Which domains are a part of a Level 1 Self-Assessment?

Options:

A.  

Access Control (AC), Risk Management < RM), and Media Protection (MP)

B.  

Risk Management (RM). Access Control (AC), and Physical Protection (PE)

C.  

Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)

D.  

Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)

Discussion 0
Questions 24

The practices in CMMC Level 2 consists of the security requirements specified in:

Options:

A.  

NISTSP 800-53.

B.  

NISTSP 800-171.

C.  

48 CFR 52.204-21.

D.  

DFARS 252.204-7012.

Discussion 0
Questions 25

The director of cybersecurity is considering which company offices and data centers store FCI to ensure an accurate scope for their CMMC Level 1 Self-Assessment . Which asset type is the director considering?

Options:

A.  

ESP

B.  

People

C.  

Facilities

D.  

Technology

Discussion 0
Questions 26

Prior to conducting a CMMC Assessment, the contractor must specify the CMMC Assessment scope by categorizing all assets. Which two asset categories are always assessed against CMMC practices?

Options:

A.  

CUI Assets and Specialized Assets

B.  

Security Protection Assets and CUI Assets

C.  

Specialized Assets and Contractor Risk Managed Assets

D.  

Security Protection Assets and Contractor Risk Managed Assets

Discussion 0
Questions 27

An assessment is being completed at a client site that is not far from the Lead Assessor's home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?

Options:

A.  

Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.

B.  

Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.

C.  

Log into the client VPN from the assessor's laptop and retrieve the documents from the secure cloud storage service.

D.  

Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.

Discussion 0
Questions 28

A defense contractor needs to share FCI with a subcontractor and sends this data in an email. The email system involved in this process is being used to:

Options:

A.  

manage FCI.

B.  

process FCI.

C.  

transmit FCI.

D.  

generate FCI

Discussion 0
Questions 29

Which government agency are DoD contractors required to report breaches of CUI to?

Options:

A.  

FBI

B.  

NARA

C.  

DoD Cyber Crime Center

D.  

Under Secretary of Defense for Intelligence and Security

Discussion 0
Questions 30

Which term describes the prevention of damage to. protection of, and restoration of computers and electronic communications systems/services, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation?

Options:

A.  

Cybersecurity

B.  

Data security

C.  

Network security

D.  

Information security

Discussion 0
Questions 31

The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections. How should the team score practices in which the evidence shows the deficiencies have been corrected?

Options:

A.  

MET

B.  

POA & M

C.  

NOT MET

D.  

NOT APPLICABLE

Discussion 0
Questions 32

Two network administrators are working together to determine a network configuration in preparation for CMMC. The administrators find that they disagree on a couple of small items. Which solution is the BEST way to ensure compliance with CMMC?

Options:

A.  

Consult with the CEO of the company.

B.  

Consult the CMMC Assessment Guides and NIST SP 800-171.

C.  

Go with the network administrator's ideas with the least stringent controls.

D.  

Go with the network administrator's ideas with the most stringent controls.

Discussion 0
Questions 33

Which statement BEST describes an assessor's evidence gathering activities?

Options:

A.  

Use interviews for assessing a Level 2 practice.

B.  

Test all practices or objectives for a Level 2 practice

C.  

Test certain assessment objectives to determine findings.

D.  

Use examinations, interviews, and tests to gather sufficient evidence.

Discussion 0
Questions 34

Which standard and regulation requirements are the CMMC Model 2.0 based on?

Options:

A.  

NIST SP 800-171 and NIST SP 800-172

B.  

DFARS, FIPS 100, and NIST SP 800-171

C.  

DFARS, NIST, and Carnegie Mellon University

D.  

DFARS, FIPS 100, NIST SP 800-171, and Carnegie Mellon University

Discussion 0
Questions 35

A contractor has implemented IA.L2-3.5.3: Multifactor Authentication practice for their privileged users, however, during the assessment it was discovered that the OSC's standard users do not require MFA to access their endpoints and network resources. What would be the BEST finding?

Options:

A.  

The process is running correctly.

B.  

It is out of scope as this is a new acquisition.

C.  

The new acquisition is considered Specialized Assets.

D.  

Practice is NOT MET since the objective was not implemented.

Discussion 0
Questions 36

Which regulation allows for whistleblowers to sue on behalf of the federal government?

Options:

A.  

NISTSP 800-53

B.  

NISTSP 800-171

C.  

False Claims Act

D.  

Code of Professional Conduct

Discussion 0
Questions 37

Which entity specifies the required CMMC Level in Requests for Information and Requests for Proposals?

Options:

A.  

DoD

B.  

NARA

C.  

NIST

D.  

Department of Homeland Security

Discussion 0
Questions 38

Which statement BEST describes the key references a Lead Assessor should refer to and use the:

Options:

A.  

DoD adequate security checklist for covered defense information.

B.  

CMMC Model Overview as it provides assessment methods and objects.

C.  

safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment.

D.  

published CMMC Assessment Guide practice descriptions for the desired certification level.

Discussion 0
Questions 39

What is objectivity as it applies to activities with the CMMC-AB?

Options:

A.  

Ensuring full disclosure

B.  

Reporting results of CMMC services completely

C.  

Avoiding the appearance of or actual, conflicts of interest

D.  

Demonstrating integrity in the use of materials as described in policy

Discussion 0
Questions 40

Prior to initiating an OSC's CMMC Assessment, the Lead Assessor briefed the team on the most important requirements of the assessment. The assessor also insisted that the same results of the findings summary, practice ratings, and Level recommendations must be submitted to the C3PAO for initial processes and review. After several weeks of assessment, the C3PAO completes the internal review, the recommended results are then submitted through the C3PAO for final quality review and rating approval. Which document stipulates these reporting requirements?

Options:

A.  

CMMC Assessment reporting requirements

B.  

DFARS 52.204-21 assessment reporting requirements

C.  

NISTSP 800-171 Revision 2 assessment reporting requirements

D.  

DFARS clause 252.204-7012 assessment reporting requirements

Discussion 0
Questions 41

According to DFARS clause 252.204-7012, who is responsible for determining that Information in a given category should be considered CUI?

Options:

A.  

The NARA CUI Executive Agent

B.  

The contractor who generated the information

C.  

The DoD agency for whom the contractor is performing the work

D.  

The military personnel assigned to the contractor for that purpose

Discussion 0
Questions 42

An assessor is collecting affirmations. So far, the assessor has collected interviews, demonstrations, emails, messaging, and presentations. Are these appropriate approaches to collecting affirmations?

Options:

A.  

No, emails are not appropriate affirmations.

B.  

No, messaging is not an appropriate affirmation.

C.  

Yes, the affirmations collected by the assessor are all appropriate.

D.  

Yes, the affirmations collected by the assessor are all appropriate, as are screenshots.

Discussion 0
Questions 43

During the planning phase of the Assessment Process. C3PAO staff are reviewing the various entities associated with an OSC that has requested a CMMC Level 2 Assessment. Which term describes the people, processes, and technology external to the HQ Organization that participate in the assessment but will not receive a CMMC Level unless an enterprise Assessment is conducted?

Options:

A.  

Host Unit

B.  

Organization

C.  

Coordinating Unit

D.  

Supporting Organization/Unit

Discussion 0
Questions 44

When assessing SI.L2-3.14.6: Monitor communications for attack, the CCA interviews the person responsible for the intrusion detection system and examines relevant policies and procedures for monitoring organizational systems. What would be a possible next step the CCA could conduct to gather sufficient evidence?

Options:

A.  

Conduct a penetration test

B.  

Interview the intrusion detection system's supplier.

C.  

Upload known malicious code and observe the system response.

D.  

Review an artifact to check key references for the configuration of the IDS or IPS practice for additional guidance on intrusion detection and prevention systems.

Discussion 0
Questions 45

When scoping a Level 2 assessment, which document is useful for understanding the process to successfully implement practices required for the various Levels of CMMC?

Options:

A.  

NISTSP 800-53

B.  

NISTSP 800-88

C.  

NISTSP 800-171

D.  

NISTSP 800-172

Discussion 0
Questions 46

The director of sales, in a meeting, stated that the sales team received feedback on some emails that were sent, stating that the emails were not marked correctly. Which training should the director of sales refer the sales team to regarding information as to how to mark emails?

Options:

A.  

FBI CUI Introduction to Marking

B.  

NARA CUI Introduction to Marking

C.  

C3PAO CUI Introduction to Marking

D.  

CMMC-AB CUI Introduction to Marking

Discussion 0
Questions 47

Which term describes a group of individuals that conduct operational network vulnerability evaluations and provide mitigation techniques to customers?

Options:

A.  

Red team

B.  

Blue team

C.  

White hat hackers

D.  

Penetration test team

Discussion 0
Questions 48

When scoping the organizational system, the scope of applicability for the cybersecurity CUI practices applies to the components of:

Options:

A.  

federal systems that process, store, or transmit CUI.

B.  

nonfederal systems that process, store, or transmit CUI.

C.  

federal systems that process, store, or transmit CUI. or that provide protection for the system components.

D.  

nonfederal systems that process, store, or transmit CUI. or that provide protection for the system components.

Discussion 0
Questions 49

During an assessment, the Lead Assessor reviews the evidence for each CMMC in-scope practice that has been reviewed, verified, rated, and discussed with the OSC during the daily reviews. The Assessment Team records the final recommended MET or NOT MET rating and prepares to present the results to the assessment participants during the final review with the OSC and sponsor. As a part of this presentation, which document MUST include the attendee list, time/date, location/meeting link, results from all discussed topics, including any resulting actions, and due dates from the OSC or Assessment Team?

Options:

A.  

Final log report

B.  

Final CMMC report

C.  

Final and recorded OSC CMMC report

D.  

Final and recorded Daily Checkpoint log

Discussion 0
Questions 50

In scoping a CMMC Level 1 Self-Assessment, it is determined that an ESP employee has access to FCI. What is the ESP employee considered?

Options:

A.  

In scope

B.  

Out of scope

C.  

OSC point of contact

D.  

Assessment Team Member

Discussion 0
Questions 51

Which words summarize categories of data disposal described in the NIST SP 800-88 Revision 1, Guidelines for Media Sanitation?

Options:

A.  

Clear, purge, destroy

B.  

Clear, redact, destroy

C.  

Clear, overwrite, purge

D.  

Clear, overwrite, destroy

Discussion 0
Questions 52

When an OSC requests an assessment by a C3PAO, who selects the Lead Assessor for the assessment?

Options:

A.  

OSC

B.  

C3PAO

C.  

C3PAO and OSC

D.  

OSC and Lead Assessor

Discussion 0
Questions 53

While determining the scope for a company's CMMC Level 1 Self-Assessment, the contract administrator includes the hosting providers that manage their IT infrastructure. Which asset type BEST describes the third-party organization?

Options:

A.  

ESPs

B.  

People

C.  

Facilities

D.  

Technology

Discussion 0
Questions 54

When are contractors required to achieve a CMMC certificate at the Level specified in the solicitation?

Options:

A.  

At the time of award

B.  

Upon solicitation submission

C.  

Thirty days from the award date

D.  

Before the due date of submission

Discussion 0
Questions 55

Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit. Supporting Organization/Unit, or enclave has been met?

Options:

A.  

OSC

B.  

Assessment Team

C.  

Authorizing official

D.  

Assessment official

Discussion 0
Questions 56

Which resource contains authoritative data classifications of CUI?

Options:

A.  

NARA

B.  

CMMC-AB

C.  

DoD Contractors FAQ

D.  

OSC's privacy policies

Discussion 0
Questions 57

When executing a remediation review, the Lead Assessor should:

Options:

A.  

help OSC to complete planned remediation activities.

B.  

plan two consecutive remediation reviews for an OSC.

C.  

submit a delta assessment remediation package for C3PAO's internal quality review.

D.  

validate that practices previously listed on the POA & M have been removed on an updated Risk Assessment.

Discussion 0
Questions 58

During a CMMC readiness review, the OSC proposes that an associated enclave should not be applicable in the scope. Who is responsible for verifying this request?

Options:

A.  

CCP

B.  

C3PAO

C.  

Lead Assessor

D.  

Advisory Board

Discussion 0
Questions 59

Which method facilitates understanding by analyzing gathered artifacts as evidence?

Options:

A.  

Test

B.  

Examine

C.  

Behavior

D.  

Interview

Discussion 0
Questions 60

Plan of Action defines the clear goal or objective for the plan. What information is generally NOT a part of a plan of action?

Options:

A.  

Completion dates

B.  

Milestones to measure progress

C.  

Ownership of who is accountable for ensuring plan performance

D.  

Budget requirements to implement the plan's remediation actions

Discussion 0
Questions 61

The Lead Assessor interviews a network security specialist of an OSC. The incident monitoring report for the month shows that no security incidents were reported from OSC's external SOC service provider. This is provided as evidence for RA.L2-3.11.2: Scan for vulnerabilities in organizational systems and applications periodically and when new vulnerabilities affecting those systems and applications are identified. Based on this information, the Lead Assessor should conclude that the evidence is:

Options:

A.  

inadequate because it is irrelevant to the practice.

B.  

adequate because it fits well for expected artifacts.

C.  

adequate because no security incidents were reported.

D.  

inadequate because the OSC's service provider should be interviewed.

Discussion 0
Questions 62

During Phase 4 of the Assessment process, what MUST the Lead Assessor determine and recommend to the C3PAO concerning the OSC?

Options:

A.  

Ability

B.  

Eligibility

C.  

Capability

D.  

Suitability

Discussion 0
Questions 63

In performing scoping, what should the assessor ensure that the scope of the assessment covers?

Options:

A.  

All assets documented in the business plan

B.  

All assets regardless if they do or do not process, store, or transmit FCI/CUI

C.  

All entities, regardless of the line of business, associated with the organization

D.  

All assets processing, storing, or transmitting FCI/CUI and security protection assets

Discussion 0
Questions 64

Which are guiding principles in the CMMC Code of Professional Conduct?

Options:

A.  

Objectivity, information integrity, and higher accountability

B.  

Objectivity, information integrity, and proper use of methods

C.  

Proper use of methods, higher accountability, and objectivity

D.  

Proper use of methods, higher accountability, and information integrity

Discussion 0
Questions 65

How many cybersecurity levels does the CMMC Model structure contain?

Options:

A.  

2 Levels.

B.  

3 Levels.

C.  

5 Levels.

D.  

4 Levels.

Discussion 0
Questions 66

An assessor is in Phase 3 of the CMMC Assessment Process. The assessor has delivered the final findings, submitted the assessment results package, and provided feedback to the C3PAO and CMMC-AB. What must the assessor still do?

Options:

A.  

Determine level recommendation

B.  

Archive all assessment artifacts

C.  

Determine final practice pass/fail results

D.  

Archive or dispose of any assessment artifacts

Discussion 0
Questions 67

Which statement BEST describes a LTP?

Options:

A.  

Creates DoD-licensed training

B.  

Instructs a curriculum approved by CMMC-AB

C.  

May market itself as a CMMC-AB Licensed Provider for testing

D.  

Delivers training using some CMMC body of knowledge objectives

Discussion 0
Questions 68

While conducting a CMMC Assessment, a Lead Assessor is given documentation attesting to Level 1 identification and authentication practices by the OSC. The Lead Assessor asks the CCP to review the documentation to determine if identification and authentication controls are met. Which documentation BEST satisfies the requirements of IA.L1-3.5.1: Identify system users. processes acting on behalf of users, and devices?

Options:

A.  

Procedures for implementing access control lists

B.  

List of unauthorized users that identifies their identities and roles

C.  

User names associated with system accounts assigned to those individuals

D.  

Physical access policy that states. "All non-employees must wear a special visitor pass or be escorted."

Discussion 0