Question 1
An Organization Seeking Certification (OSC) has submitted their self-assessment results showing all 110 NIST SP 800-171 practices as "MET." As a CCA, what is your primary concern before beginning the formal assessment?
Correct Answer:
A self-assessment showing all practices as MET without any deficiencies is statistically unlikely and warrants verification
Question 2
During a pre-assessment review, an OSC provides System Security Plan (SSP) documentation dated three years ago with no subsequent updates. What determination should the CCA make regarding AC.L2-3.1.1 (Access Control Policy)?
Correct Answer:
NOT MET because the SSP is outdated and does not reflect current system environment
Question 3
An OSC has provided evidence for IA.L2-3.5.6 (Identifier Handling) showing their identity management system automatically disables accounts after 90 days of inactivity. The System Security Plan (SSP) defines the inactivity disablement period as 35 days. What is the appropriate finding?
Correct Answer:
NOT MET because identifiers are not disabled after the organization-defined period of inactivity documented in the SSP
Question 4
During an assessment, the OSC provides audit logs showing successful authentication events but cannot produce logs for failed authentication attempts. The OSC claims their SIEM solution only captures successful logons due to storage constraints. What is the correct determination for AU.L2-3.3.1 (Audit Events)?
Correct Answer:
NOT MET because AU.L2-3.3.1 specifically requires auditing of failed logon attempts
Question 5
Before conducting a CMMC Level 2 assessment, what document must the CCA verify exists and is current?
Correct Answer:
A System Security Plan (SSP) that addresses all 110 NIST SP 800-171 security requirements
Question 1
Exam overview

About this Exam

Prepare with the CMMC CCA Practice Questions - Cyber AB CCA Certified CMMC Assessor Exam practice quiz. This question bank includes 100 questions covering l2-3, security, access, osc, and finding. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

CMMC CCA Practice Questions - Cyber AB CCA Certified CMMC Assessor Exam

This practice set contains 100 questions from the matching question bank and focuses on l2-3, security, access, osc, and finding. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions