Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Certified CMMC Professional (CCP) Exam Question and Answers

Certified CMMC Professional (CCP) Exam

Last Update Jul 26, 2026
Total Questions : 236

We are offering FREE CMMC-CCP Cyber AB exam questions. All you do is to just go and sign up. Give your details, prepare CMMC-CCP free exam questions and then go for complete pool of Certified CMMC Professional (CCP) Exam test questions that will help you more.

CMMC-CCP pdf

CMMC-CCP PDF

$36.75  $104.99
CMMC-CCP Engine

CMMC-CCP Testing Engine

$43.75  $124.99
CMMC-CCP PDF + Engine

CMMC-CCP PDF + Testing Engine

$57.75  $164.99
Questions 1

What is the MINIMUM required marking for a document containing CUI?

Options:

A.  

" CUI " must be placed in the header and footer of the document

B.  

" WCUI " must be placed in the header and footer of the document

C.  

Portion marks must be placed on all sections, parts, paragraphs, etc. known to contain CUI

D.  

A cover page must be placed to obscure content with the acronym " CUI " prominently placed

Discussion 0
Questions 2

Which government agency are DoD contractors required to report breaches of CUI to?

Options:

A.  

FBI

B.  

NARA

C.  

DoD Cyber Crime Center

D.  

Under Secretary of Defense for Intelligence and Security

Discussion 0
Questions 3

Which entity requires that organizations handling FCI or CUI be assessed to determine a required Level of cybersecurity maturity?

Options:

A.  

DoD

B.  

CISA

C.  

NIST

D.  

CMMC-AB

Discussion 0
Questions 4

Which statement is NOT a measure to determine if collected evidence is sufficient?

Options:

A.  

Evidence covers the sampled organization

B.  

Evidence is not required if the practice is ISO certified

C.  

Evidence covers the model scope of the Assessment (Target CMMC Level)

D.  

Evidence corresponds to the sampled organization in the evidence collection approach

Discussion 0
Questions 5

Where does the requirement to include a required practice of ensuring that personnel are trained to carry out their assigned information security-related duties and responsibilities FIRST appear?

Options:

A.  

Level 1

B.  

Level 2

C.  

Level 3

D.  

All levels

Discussion 0
Questions 6

Which standard of assessment do all C3PAO organizations execute an assessment methodology based on?

Options:

A.  

ISO 27001

B.  

NISTSP800-53A

C.  

CMMC Assessment Process

D.  

Government Accountability Office Yellow Book

Discussion 0
Questions 7

During assessment planning, the OSC recommends a person to interview for a certain practice. The person being interviewed MUST be the person who:

Options:

A.  

funds that practice.

B.  

audits that practice.

C.  

supports, audits, and performs that practice.

D.  

implements, performs, or supports that practice.

Discussion 0
Questions 8

What is objectivity as it applies to activities with the CMMC-AB?

Options:

A.  

Ensuring full disclosure

B.  

Reporting results of CMMC services completely

C.  

Avoiding the appearance of or actual, conflicts of interest

D.  

Demonstrating integrity in the use of materials as described in policy

Discussion 0
Questions 9

What is the primary intent of the verify evidence and record gaps activity?

Options:

A.  

Map test and demonstration responses to CMMC practices.

B.  

Conduct interviews to test process implementation knowledge.

C.  

Determine the one-to-one relationship between a practice and an assessment object.

D.  

Identify and describe differences between what the Assessment Team required and the evidence collected.

Discussion 0
Questions 10

When are data and documents with legacy markings from or for the DoD required to be re-marked or redacted?

Options:

A.  

When under the control of the DoD

B.  

When the document is considered secret

C.  

When a document is being shared outside of the organization

D.  

When a derivative document ' s original information is not CUI

Discussion 0
Questions 11

Which document BEST determines the existence of FCI and/or CUI in scoping an assessment with an OSC?

Options:

A.  

OSC SSP

B.  

OSC POA & M

C.  

OSC Evidence

D.  

OSC Contract with DoD

Discussion 0
Questions 12

Which term describes the process of granting or denying specific requests to obtain and use information, related information processing services, and enter specific physical facilities?

Options:

A.  

Access control

B.  

Physical access control

C.  

Mandatory access control

D.  

Discretionary access control

Discussion 0
Questions 13

During a Level 2 Assessment, the OSC has provided an inventory list of all hardware. The list includes servers, workstations, and network devices. Why should this evidence be sufficient for making a scoring determination for AC.L2-3.1.19: Encrypt CUI on mobile devices and mobile computing platforms?

Options:

A.  

The inventory list does not specify mobile devices.

B.  

The interviewee attested to encrypting all data at rest.

C.  

The inventory list does not include Bring Your Own Devices.

D.  

The DoD has accepted an alternative safeguarding measure for mobile devices.

Discussion 0
Questions 14

Companies that knowingly defraud the government by not being in compliance with cybersecurity regulations are at risk of being held liable for:

Options:

A.  

The contract value plus a penalty as stated in the Cyber Claims Act

B.  

The contract value plus a penalty as stated in the False Claims Act

C.  

Three times the contract value plus a penalty as stated in the Cyber Claims Act

D.  

Three times the contract value plus a penalty as stated in the False Claims Act

Discussion 0
Questions 15

While conducting a CMMC Assessment, an individual from the OSC provides documentation to the assessor for review. The documentation states an incident response capability is established and contains information on incident preparation, detection, analysis, containment, recovery, and user response activities. Which CMMC practice is this documentation attesting to?

Options:

A.  

IR.L2-3.6.1: Incident Handling

B.  

IR.L2-3.6.2: Incident Reporting

C.  

IR.L2-3.6.3: Incident Response Testing

D.  

IR.L2-3.6.4: Incident Spillage

Discussion 0
Questions 16

What is a conflict of interest?

Options:

A.  

Lack of transparency.

B.  

Any violation of the law.

C.  

A perceived or actual conflict.

D.  

Any inadvertent disclosure.

Discussion 0
Questions 17

An Assessment Team is conducting a Level 2 Assessment at the request of an OSC. The team has begun to score practices based on the evidence provided. At a MINIMUM what is required of the Assessment Team to determine if a practice is scored as MET?

Options:

A.  

All three types of evidence are documented for every control.

B.  

Examine and accept evidence from one of the three evidence types.

C.  

Complete one of the following; examine two artifacts, either observe a satisfactory demonstration of one control or receive one affirmation from the OSC personnel.

D.  

Complete two of the following: examine one artifact, either observe a satisfactory demonstration of one control or receive one affirmation from the OSC personnel.

Discussion 0
Questions 18

What banner markings MUST a document that contains CUI include?

Options:

A.  

A highest level of CUI contained within the document marking on each page

B.  

All CUI Category and Subcategory markings contained within the document on each page

C.  

A special Category or Subcategory marking on the cover page only

D.  

A special Category or Subcategory marking on only the page(s) that include the CUI

Discussion 0
Questions 19

Which statement BEST describes the key references a Lead Assessor should refer to and use the:

Options:

A.  

DoD adequate security checklist for covered defense information.

B.  

CMMC Model Overview as it provides assessment methods and objects.

C.  

safeguarding requirements from FAR Clause 52.204-21 for a Level 2 Assessment.

D.  

published CMMC Assessment Guide practice descriptions for the desired certification level.

Discussion 0
Questions 20

Who will verify the adequacy and sufficiency of evidence to determine whether the practices and related components for each in-scope Host Unit, Supporting Organization/Unit, or enclave have been met?

Options:

A.  

OSC

B.  

Assessment Team

C.  

Authorizing official

D.  

Assessment official

Discussion 0
Questions 21

The Audit and Accountability (AU) domain has practices in:

Options:

A.  

Level 1.

B.  

Level 2.

C.  

Levels 1 and 2.

D.  

Levels 1 and 3.

Discussion 0
Questions 22

How many domains does the CMMC Model consist of?

Options:

A.  

14 domains

B.  

43 domains

C.  

72 domains

D.  

110 domains

Discussion 0
Questions 23

What is the BEST description of the purpose of FAR clause 52 204-21?

Options:

A.  

It directs all covered contractors to install the cyber security systems listed in that clause.

B.  

It describes all of the safeguards that contractors must take to secure covered contractor IS.

C.  

It describes the minimum standard of care that contractors must take to secure covered contractor IS.

D.  

It directs covered contractors to obtain CMMC Certification at the level equal to the lowest requirement of their contracts.

Discussion 0
Questions 24

Which term describes the prevention of damage to. protection of, and restoration of computers and electronic communications systems/services, including information contained therein, to ensure its availability, integrity, authentication, confidentiality, and nonrepudiation?

Options:

A.  

Cybersecurity

B.  

Data security

C.  

Network security

D.  

Information security

Discussion 0
Questions 25

Which organization is the governmental authority responsible for identifying and marking CUI?

Options:

A.  

NARA

B.  

NIST

C.  

CMMC-AB

D.  

Department of Homeland Security

Discussion 0
Questions 26

A machining company has been awarded a contract with the DoD to build specialized parts. Testing of the parts will be done by the company using in-house staff and equipment. For a Level 1 Self-Assessment, what type of asset is this?

Options:

A.  

CUI Asset

B.  

In-scope Asset

C.  

Specialized Asset

D.  

Contractor Risk Managed Asset

Discussion 0
Questions 27

The Advanced Level in CMMC will contain Access Control {AC) practices from:

Options:

A.  

Level 1.

B.  

Level 3.

C.  

Levels 1 and 2.

D.  

Levels 1,2, and 3.

Discussion 0
Questions 28

Exercising due care to ensure the information gathered during the assessment is protected even after the engagement has ended meets which code of conduct requirement?

Options:

A.  

Availability

B.  

Confidentiality

C.  

Information Integrity

D.  

Respect for Intellectual Property

Discussion 0
Questions 29

The Lead Assessor is presenting the Final Findings Presentation to the OSC. During the presentation, the Assessment Sponsor and OSC staff inform the assessor that they do not agree with the assessment results. Who has the final authority for the assessment results?

Options:

A.  

C3PAO

B.  

CMMC-AB

C.  

Assessment Team

D.  

Assessment Sponsor

Discussion 0
Questions 30

During a Level 2 Assessment, an OSC provides documentation that attests that they utilize multifactor authentication on nonlocal remote maintenance sessions. The OSC feels that they have met the controls for the Level 2 certification. What additional measures should the OSC perform to fully meet the maintenance requirement?

Options:

A.  

Connections for nonlocal maintenance sessions should be terminated when maintenance is complete.

B.  

Connections for nonlocal maintenance sessions should be unlimited to ensure maintenance is performed properly

C.  

The nonlocal maintenance personnel complain that restrictions slow down their response time and should be removed.

D.  

The maintenance policy states multifactor authentication must have at least two factors applied for nonlocal maintenance sessions.

Discussion 0
Questions 31

Within what amount of time MUST convictions, guilty pleas, or no contest pleas to crimes of fraud, larceny, embezzlement, misappropriation of funds, misrepresentation, perjury, false swearing, conspiracy to conceal, or a similar offense in any legal proceeding, civil or criminal, whether or not connected with activities that relate to carrying out a Lead Assessor role, be reported to the CMMC Accreditation Body?

Options:

A.  

90 days.

B.  

30 days.

C.  

3 days.

D.  

7 days.

Discussion 0
Questions 32

Contractor scoping requirements for a CMMC Level 2 Assessment to document the asset in an inventory, in the SSP and on the network diagram apply to:

Options:

A.  

GUI Assets.

B.  

CUI and Security Protection Asset categories.

C.  

all asset categories except for the Out-of-scope Assets.

D.  

Contractor Risk Managed Assets and Specialized Assets.

Discussion 0
Questions 33

In the Code of Professional Conduct, what does the practice of Professionalism require?

Options:

A.  

Do not copy materials without permission to do so.

B.  

Do not make assertions about assessment outcomes.

C.  

Refrain from dishonesty in all dealings regarding CMM

C.  

D.  

Ensure the security of all information discovered or received.

Discussion 0
Questions 34

The practices in CMMC Level 2 consist of the security requirements specified in:

Options:

A.  

NIST SP 800-53

B.  

NIST SP 800-171

C.  

48 CFR 52.204-21

D.  

DFARS 252.204-7012

Discussion 0
Questions 35

A company is about to conduct a press release. According to AC.L1-3.1.22: Control information posted or processed on publicly accessible systems, what is the MOST important factor to consider when addressing CMMC requirements?

Options:

A.  

That the information is correct

B.  

That the CEO approved the message

C.  

That the company has to safeguard the release of FCI

D.  

That so long as the information is only FCI, it can be released

Discussion 0
Questions 36

A contractor provides services and data to the DoD. The transactions that occur to handle FCI take place over the contractor ' s business network, but the work is performed on contractor-owned systems, which must be configured based on government requirements and are used to support a contract. What type of Specialized Asset are these systems?

Options:

A.  

loT

B.  

Restricted IS

C.  

Test equipment

D.  

Government property

Discussion 0
Questions 37

Which statement BEST describes a LTP?

Options:

A.  

Creates DoD-licensed training

B.  

Instructs a curriculum approved by CMMC-AB

C.  

May market itself as a CMMC-AB Licensed Provider for testing

D.  

Delivers training using some CMMC body of knowledge objectives

Discussion 0
Questions 38

Which domains are a part of a Level 1 Self-Assessment?

Options:

A.  

Access Control (AC), Risk Management < RM), and Media Protection (MP)

B.  

Risk Management (RM). Access Control (AC), and Physical Protection (PE)

C.  

Access Control (AC), Physical Protection (PE), and Identification and Authentication (IA)

D.  

Risk Management (RM). Media Protection (MP), and Identification and Authentication (IA)

Discussion 0
Questions 39

At which CMMC Level do the Security Assessment (CA) practices begin?

Options:

A.  

Level 1

B.  

Level 2

C.  

Level 3

D.  

Level 4

Discussion 0
Questions 40

A Level 2 Assessment was conducted for an OSC, and the results are ready to be submitted. Prior to uploading the assessment results, what step MUST the C3PAO complete?

Options:

A.  

Pay an assessment submission fee.

B.  

Complete an internal review of the results.

C.  

Notify the CMMC-AB that submission is forthcoming.

D.  

Coordinate a final briefing between the Lead Assessor and the OSC.

Discussion 0
Questions 41

What service is the MOST comprehensive that the RPO provides?

Options:

A.  

Training services

B.  

Education services

C.  

Consulting services

D.  

Assessment services

Discussion 0
Questions 42

Recording evidence as adequate is defined as the criteria needed to:

Options:

A.  

verify, based on an assessment and organizational scope.

B.  

verify, based on an assessment and organizational practice.

C.  

determine if a given artifact, interview response, demonstration, or test meets the CMMC scope.

D.  

determine if a given artifact, interview response, demonstration, or test meets the CMMC practice.

Discussion 0
Questions 43

When executing a remediation review, the Lead Assessor should:

Options:

A.  

help OSC to complete planned remediation activities.

B.  

plan two consecutive remediation reviews for an OSC.

C.  

submit a delta assessment remediation package for C3PAO ' s internal quality review.

D.  

validate that practices previously listed on the POA & M have been removed on an updated Risk Assessment.

Discussion 0
Questions 44

Prior to conducting a CMMC Assessment, the contractor must specify the CMMC Assessment scope by categorizing all assets. Which two asset categories are always assessed against CMMC practices?

Options:

A.  

CUI Assets and Specialized Assets

B.  

Security Protection Assets and CUI Assets

C.  

Specialized Assets and Contractor Risk Managed Assets

D.  

Security Protection Assets and Contractor Risk Managed Assets

Discussion 0
Questions 45

The Level 1 practice description in CMMC is Foundational. What is the Level 2 practice description?

Options:

A.  

Expert

B.  

Advanced

C.  

Optimizing

D.  

Continuously Improved

Discussion 0
Questions 46

During the assessment process, who is the final interpretation authority for recommended findings?

Options:

A.  

C3PAO

B.  

CMMC-AB

C.  

OSC sponsor

D.  

Assessment Team Members

Discussion 0
Questions 47

What is the legal entity under a contract that has agreed to deliver products or services?

Options:

A.  

Supporting Organization/Unit

B.  

Commercial and Government Entity Code

C.  

Host Unit

D.  

HQ Organization

Discussion 0
Questions 48

A CCP is working as an Assessment Team Member on a CMMC Level 2 Assessment. The Lead Assessor has assigned the CCP to assess the OSC ' s Configuration Management (CM) domain. The CCP ' s first interview is with a subject-matter expert for user-installed software. With respect to user-installed software, what facet should the CCP ' s interview focus on?

Options:

A.  

Controlled and monitored

B.  

Removed from the system

C.  

Scanned for malicious code

D.  

Limited to mission-essential use only

Discussion 0
Questions 49

The Assessment Team has completed the assessment and determined the preliminary practice ratings. The preliminary practice ratings must be shared with the OSC prior to being finalized for submission. Based on this information, the assessor should present the preliminary practice ratings:

Options:

A.  

During the final Daily Checkpoint

B.  

After discussing with the CMMC-AB

C.  

Via email after the final Daily Checkpoint

D.  

Over the phone after the final Daily Checkpoint

Discussion 0
Questions 50

An organization that manufactures night vision cameras is looking for help to address the gaps identified in physical access control systems. Which certified individual should they approach for implementation support?

Options:

A.  

CCA of the C3PAO performing the assessment

B.  

RP of an organization not part of the assessment

C.  

Practitioner of the organization performing the assessment LTP

D.  

DoD Contract Official of the organization performing the assessment

Discussion 0
Questions 51

An Assessment Team Member is conducting a CMMC Level 2 Assessment for an OSC that is in the process of inspecting Assessment Objects for AC.L1-3.1.1: Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems) to determine the adequacy of evidence provided by the OSC. Which Assessment Method does this activity fall under?

Options:

A.  

Test

B.  

Observe

C.  

Examine

D.  

Interview

Discussion 0
Questions 52

CMMC scoping covers the CUI environment encompassing the systems, applications, and services that focus on where CUI is:

Options:

A.  

received and transferred.

B.  

stored, processed, and transmitted.

C.  

entered, edited, manipulated, printed, and viewed.

D.  

located on electronic media, on system component memory, and on paper.

Discussion 0
Questions 53

An assessor is collecting affirmations. So far, the assessor has collected interviews, demonstrations, emails, messaging, and presentations. Are these appropriate approaches to collecting affirmations?

Options:

A.  

No, emails are not appropriate affirmations.

B.  

No, messaging is not an appropriate affirmation.

C.  

Yes, the affirmations collected by the assessor are all appropriate.

D.  

Yes, the affirmations collected by the assessor are all appropriate, as are screenshots.

Discussion 0
Questions 54

The IT manager is scoping the company ' s CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?

Options:

A.  

ESP

B.  

People

C.  

Facilities

D.  

Technology

Discussion 0
Questions 55

Which CMMC Levels focus on protecting CUI from exfiltration?

Options:

A.  

Levels 1 and 2

B.  

Levels 1 and 3

C.  

Levels 2 and 3

D.  

Levels 1, 2, and 3

Discussion 0
Questions 56

Which resource could BEST help a CEO determine how to identify the category of CUI ?

Options:

A.  

NARA

B.  

CMMC-AB

C.  

DoD DFARS Part 252

D.  

CMMC Assessment Guide

Discussion 0
Questions 57

The CMMC Level 2 assessment methods include examination and can include:

Options:

A.  

documents, mechanisms, or activities.

B.  

specific hardware, software, or firmware safeguards employed within a system.

C.  

policies, procedures, security plans, penetration tests, and security requirements.

D.  

observation of system backup operations, exercising a contingency plan, and monitoring network traffic.

Discussion 0
Questions 58

Which document is the BEST source for descriptions of each practice or process contained within the various CMMC domains?

Options:

A.  

CMMC Glossary

B.  

CMMC Appendices

C.  

CMMC Assessment Process

D.  

CMMC Assessment Guide Levels 1 and 2

Discussion 0
Questions 59

Which term describes a group of individuals that conduct operational network vulnerability evaluations and provide mitigation techniques to customers?

Options:

A.  

Red team

B.  

Blue team

C.  

White hat hackers

D.  

Penetration test team

Discussion 0
Questions 60

Which phase of the CMMC Assessment Process includes developing the assessment plan?

Options:

A.  

Phase 1

B.  

Phase 2

C.  

Phase 3

D.  

Phase 4

Discussion 0
Questions 61

When a conflict of interest is unavoidable, a CCP should NOT:

Options:

A.  

Inform their organization

B.  

Take action to minimize its impact

C.  

Disclose it to affected stakeholders

D.  

Conceal it from the Assessment Team lead

Discussion 0
Questions 62

The results package for a Level 2 Assessment is being submitted. What MUST a Final Report. CMMC Assessment Results include?

Options:

A.  

Affirmation for each practice or control

B.  

Documented rationale for each failed practice

C.  

Suggested improvements for each failed practice

D.  

Gaps or deltas due to any reciprocity model are recorded as met

Discussion 0
Questions 63

An Assessment Team is reviewing a practice that is documented and being checked monthly. When reviewing the logs, the practice is only being completed quarterly. During the interviews, the team members say they perform the practice monthly but only document quarterly. Is this sufficient to pass the practice?

Options:

A.  

No, the work is not being done as stated.

B.  

Yes, the practice is being done as documented.

C.  

No, all three assessment methods must be met to pass.

D.  

Yes. the interview process is enough to pass a practice.

Discussion 0
Questions 64

The Advanced Level in CMMC will contain Access Control (AC) practices from:

Options:

A.  

Level 1

B.  

Level 3

C.  

Levels 1 and 2

D.  

Levels 1, 2, and 3

Discussion 0
Questions 65

A CCP is on their first assessment for CMMC Level 2 with an Assessment Team and is reviewing the CMMC Assessment Process to understand their responsibilities. Which method gathers information from the subject matter experts to facilitate understanding and achieve clarification?

Options:

A.  

Test

B.  

Examine

C.  

Interview

D.  

Assessment

Discussion 0
Questions 66

Which document is the BEST source for determining the sources of evidence for a given practice?

Options:

A.  

NISTSP 800-53

B.  

NISTSP 800-53A

C.  

CMMC Assessment Scope

D.  

CMMC Assessment Guide

Discussion 0
Questions 67

In late September. CA.L2-3.12.1: Periodically assess the security controls in organizational systems to determine if the controls are effective in their application is assessed. Procedure specifies that a security control assessment shall be conducted quarterly. The Lead Assessor is only provided the first quarter assessment report because the person conducting the second quarter ' s assessment is currently out of the office and will return to the office in two hours. Based on this information, the Lead Assessor should determine that the evidence is;

Options:

A.  

sufficient, and rate the audit finding as MET

B.  

insufficient, and rate the audit finding as NOT MET.

C.  

sufficient, and re-rate the audit finding after a quarter two assessment report is examined.

D.  

insufficient, and re-rate the audit finding after a quarter two assessment report is examined.

Discussion 0
Questions 68

A member of the Assessment Team has been assigned the responsibility of maintaining and protecting information from the OSC. The Assessment Results Package, PCI, CUI, and any notes must be retained and protected from disclosure. To protect the OSC ' s information, which principle should be used, and for how long?

Options:

A.  

Cryptography and hashing for 1 year

B.  

Confidentiality and non-disclosure for 3 years

C.  

Availability, confidentiality, and integrity for 1 year

D.  

Authentication, authorization, and accounting for 3 years

Discussion 0
Questions 69

An assessment is being completed at a client site that is not far from the Lead Assessor ' s home office. The client provides a laptop for the duration of the engagement. During a meeting with the network engineers, the Lead Assessor requests information about the network. They respond that they have a significant number of drawings they can provide via their secure cloud storage service. The Lead Assessor returns to their home office and decides to review the documents. What is the BEST way to retrieve the documents?

Options:

A.  

Log into the secure cloud storage service to save copies of the documents on both the work and client laptops.

B.  

Log into the client VPN from the client laptop and retrieve the documents from the secure cloud storage service.

C.  

Log into the client VPN from the assessor ' s laptop and retrieve the documents from the secure cloud storage service.

D.  

Use their home office workstation to retrieve the documents from the secure cloud storage service and save them to a USB stick.

Discussion 0