CCP Sample Questions

CCP Sample Questions & Answers

The CMMC model's architecture and assessment criteria carry the top weight, alongside the three-phase assessment process, FCI and CUI governance with source documents, scoping decisions, and the ecosystem's roles and code of conduct.

Launch the full CCP simulator →

Showing 10 of 20 free samples.

  1. Question 1Advanced

    CMMC Assessment Process (CAP) · POA&M Evaluation

    True or False: An organization can achieve CMMC Level 2 certification if they have a 'NOT MET' finding for practice CA.L2-3.12.4 (Develop, document, and periodically update system security plans), as long as it is the only failed practice and is on a POA&M.

    Show answer & explanation

    Correct answer: B

    This is false. According to the DoD Assessment Methodology, which informs the CMMC process, certain high-weighted practices cannot be on a POA&M for a conditional certification to be granted. The practice for maintaining a System Security Plan (SSP) is one of these critical, high-weighted requirements. Failure to have an SSP is a fundamental deficiency, and therefore the OSC cannot achieve certification with this practice on a POA&M.

  2. Question 2Intermediate

    CMMC Assessment Process (CAP) · POA&M Evaluation

    An OSC has completed its CMMC Level 2 assessment and has three 'NOT MET' findings on their POA&M. They must remediate and close these items within a specific timeframe to be awarded certification. What is the maximum time allowed for POA&M closeout?

    Show answer & explanation

    Correct answer: D

    According to the CMMC Assessment Process (CAP), an OSC that undergoes an assessment and has remaining POA&M items has a maximum of 180 days from the end of the assessment to complete remediation and have the items successfully closed out by the C3PAO.

  3. Question 3Advanced

    CMMC Assessment Process (CAP) · POA&M Evaluation

    A C3PAO completes a Level 2 assessment for an OSC and determines a final score that qualifies for certification with a POA&M. The OSC has 180 days to remediate the open items. A CCP is part of the team conducting the POA&M closeout assessment in Phase 4. What is the primary focus of the CCP's work during this phase?

    Show answer & explanation

    Correct answer: A

    The POA&M closeout assessment is tightly focused. Its purpose is not a full reassessment but to specifically verify that the deficiencies documented in the POA&M have been corrected. The CCP's role is to assist in collecting and analyzing new evidence for only those 'NOT MET' practices to determine if they now score as 'MET'.

  4. Question 4Intermediate

    CMMC Ecosystem · Identify and compare roles/responsibilities/requirements of authorities across the CMMC Ecosystem.

    A small defense subcontractor is preparing for a CMMC Level 2 assessment. They hire a Registered Provider Organization (RPO) for readiness consulting. The RPO's lead consultant, a Registered Practitioner (RP), recommends a specific C3PAO for the formal assessment, mentioning they have a "close working relationship." What is the MOST significant concern this situation raises within the CMMC ecosystem?

    Show answer & explanation

    Correct answer: A

    The CMMC ecosystem is built on the principle of objectivity and independence, especially for assessment bodies. A C3PAO must be impartial. An RPO recommending a specific C3PAO due to a "close working relationship" creates a potential or actual conflict of interest, which is a serious ethical violation. This could imply a quid-pro-quo arrangement or suggest that the assessment may not be entirely objective.

  5. Question 5Beginner

    CMMC Ecosystem · Identify and compare roles/responsibilities/requirements of authorities across the CMMC Ecosystem.

    What is the primary function of a Licensed Partner Publisher (LPP) within the CMMC ecosystem?

    Show answer & explanation

    Correct answer: A

    Licensed Partner Publishers (LPPs) are authorized by the CMMC-AB to create and manage the official curriculum and training materials. They license this content to Licensed Training Providers (LTPs), who then use it to deliver training to CCP candidates and other CMMC professionals. LPPs focus on content creation, while LTPs focus on content delivery.

  6. Question 6Intermediate

    CMMC-AB Code of Professional Conduct (Ethics) · Identify and apply knowledge of the Guiding Principles and Practices of the CMMC-AB Code of Professional Conduct (CoPC).

    A Certified CMMC Professional (CCP) is part of an assessment team evaluating a small engineering firm. During the assessment, the CCP realizes they were employed by this same firm two years ago as an IT consultant and helped design the network segmentation that is now being assessed. According to the CMMC-AB Code of Professional Conduct (CoPC), what is the CCP's most appropriate immediate action?

    Show answer & explanation

    Correct answer: C

    The CMMC-AB Code of Professional Conduct requires professionals to avoid both actual and perceived conflicts of interest. Having previously designed the systems under assessment compromises the CCP's objectivity. The correct and ethical action is to immediately disclose this to the Lead Assessor and the C3PAO so they can determine the appropriate course of action, which may include removing the CCP from the assessment.

  7. Question 7Beginner

    CMMC-AB Code of Professional Conduct (Ethics) · Identify and apply knowledge of the Guiding Principles and Practices of the CMMC-AB Code of Professional Conduct (CoPC).

    True or False: A C3PAO is permitted to share detailed findings, including specific vulnerabilities identified during a CMMC assessment, with the Department of Defense (DoD) without the explicit consent of the Organization Seeking Certification (OSC).

    Show answer & explanation

    Correct answer: B

    This is false. The CMMC-AB Code of Professional Conduct emphasizes strict confidentiality. The C3PAO has a contractual obligation with the OSC. While the final certification level is reported to the DoD, the detailed findings, evidence, and specific vulnerabilities are confidential information belonging to the OSC. Sharing this information without consent would be a breach of confidentiality unless required by law or a court order.

  8. Question 8Intermediate

    CMMC Governance and Source Documents · Demonstrate understanding of Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) in non-federal unclassified networks.

    A defense contractor receives a new contract that includes DFARS clause 252.204-7012. The contract data does not contain any ITAR, NNPI, or other specifically controlled information. The contractor's IT manager believes they only need to protect the data according to basic FAR 52.204-21 standards. Why is this interpretation incorrect?

    Show answer & explanation

    Correct answer: A

    The DFARS 252.204-7012 clause is specifically included in contracts that involve CUI. This clause mandates that contractors provide 'adequate security' for covered defense information, which is defined as implementing the security requirements in NIST SP 800-171. FAR 52.204-21 pertains to protecting Federal Contract Information (FCI) and represents a much lower security baseline (CMMC Level 1). The presence of the DFARS clause elevates the requirement to handle CUI, thus mandating NIST SP 800-171 controls (CMMC Level 2).

  9. Question 9IntermediateSelect 2

    CMMC Governance and Source Documents · Determine the appropriate roles/responsibilities/authority for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

    An Organization Seeking Certification (OSC) is reviewing its data assets to prepare for a CMMC assessment. Which of the following data types would be classified as CUI Specified? (Select TWO)

    Show answer & explanation

    Correct answers: B, C

  10. Question 10Advanced

    CMMC Governance and Source Documents · Determine the appropriate roles/responsibilities/authority for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).

    A university research lab receives DoD funding for a project. They generate research data that, when aggregated, reveals sensitive capabilities of a new military surveillance technology. The government has not explicitly marked the individual data points as CUI. According to DoD Instruction 5200.48, what is the lab's responsibility regarding this aggregated dataset?

    Show answer & explanation

    Correct answer: C

    DoDI 5200.48 and 32 CFR Part 2002 place responsibility on authorized holders (the contractor) to handle CUI appropriately. This includes situations where information is not explicitly marked but qualifies as CUI. If the lab, as the data generator, recognizes that the aggregated data meets the definition of CUI (as it pertains to sensitive government interests), they have a responsibility to provisionally mark it as CUI and apply the required protections (NIST SP 800-171) until they can get formal guidance from the government.

Ready for the real thing?

The full CCP simulator has every exam-style question, timed mode, and instant scoring.

Go to the CCP simulator →