CCA Sample Questions

CCA Sample Questions & Answers

Evaluating how well an organization implements NIST SP 800-171 practices is weighted heaviest, well ahead of running the CMMC assessment process itself, scoping a Level 2 assessment, and understanding the organization seeking certification.

Launch the full CCA simulator →

Showing 6 of 12 free samples.

  1. Question 1IntermediateSelect 2

    Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 · OSC Readiness

    Before a CMMC Level 2 assessment can officially commence, an assessor must verify that the OSC has prepared specific mandatory documentation. Which TWO of the following documents are absolute prerequisites for initiating the assessment process? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    The Plan of Action and Milestones (POA&M) is required to document any unmet or planned security requirements. Even if no items are currently deficient, a formal POA&M process must exist and be provided to the assessment team.

    The System Security Plan (SSP) is the foundational document that defines the assessment boundary and describes how the NIST SP 800-171 practices are implemented. Without it, the assessment cannot begin.

  2. Question 2Advanced

    Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 · CMMC Level 2 applicability and objectives

    An Organization Seeking Certification (OSC) is preparing for a CMMC Level 2 assessment. During the readiness review, the Lead CCA analyzes the OSC's proposed data flow architecture for handling Controlled Unclassified Information (CUI).

    Based on the architecture diagram provided, what represents the MOST critical readiness risk that would prevent the OSC from achieving CMMC Level 2 certification?

    flowchart TD Gov([DoW Contract Portal]) -->|CUI Download| UserPC[Contractor Workstation] UserPC -->|Uploads to| CloudApp[Commercial SaaS Application] CloudApp -->|Syncs| Mobile[Employee BYOD Mobile Device]
    Show answer & explanation

    Correct answer: C

    Under DFARS 252.204-7012 and CMMC Level 2 requirements, any Cloud Service Provider (CSP) used to store, process, or transmit CUI must meet security requirements equivalent to FedRAMP Moderate baseline. Using a standard commercial SaaS application without establishing this equivalency is a critical compliance failure and a major readiness risk.

  3. Question 3Advanced

    Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 · CMMC Level 2 applicability and objectives

    An aerospace manufacturing subcontractor is reviewing their contractual obligations to determine their CMMC readiness. They hold multiple subcontracts. Subcontract A includes FAR 52.204-21 but no DFARS clauses. Subcontract B includes DFARS 252.204-7012 and involves the transmission of technical drawings marked as Controlled Unclassified Information (CUI). Subcontract C involves commercial off-the-shelf (COTS) items only.

    To achieve compliance for all current obligations, what is the MINIMUM certification level the subcontractor must prepare for, and to which systems does it apply?

    Show answer & explanation

    Correct answer: B

    Because Subcontract B involves CUI and DFARS 7012, the organization must achieve CMMC Level 2. However, this requirement only applies to the systems within the assessment boundary (the CUI enclave) that process, store, or transmit that CUI, along with the Security Protection Assets that secure them. COTS contracts (Subcontract C) do not inherently require CMMC, and FAR 52.204-21 (Subcontract A) only requires Level 1 for those specific systems.

  4. Question 4Beginner

    CMMC Level 2 Assessment Scoping · Asset categories and scoping guidance

    According to the CMMC Level 2 Scoping Guidance, which asset category is defined as systems or components that provide security functions or capabilities to the OSC's CMMC assessment scope, regardless of whether they process, store, or transmit CUI themselves?

    Show answer & explanation

    Correct answer: A

    Security Protection Assets (SPA) are defined as assets that provide security functions or capabilities to the OSC's CMMC assessment scope. Examples include firewalls, SIEMs, and domain controllers. Even if they don't hold CUI, they are fully in scope and must be assessed against all applicable CMMC practices.

  5. Question 5Beginner

    CMMC Level 2 Assessment Scoping · Asset categories and scoping guidance

    An OSC utilizes legacy Computer Numerical Control (CNC) machines on their manufacturing floor to produce parts based on DoD technical drawings. These machines run embedded operating systems that cannot be patched or updated with modern endpoint protection. Under CMMC Level 2, how are these machines categorized?

    Show answer & explanation

    Correct answer: B

    Specialized Assets (SA) include Operational Technology (OT), Internet of Things (IoT), Industrial Internet of Things (IIoT), Government Property, and Restricted Information Systems. CNC machines fall under OT/Specialized Assets. They are part of the assessment scope but are typically assessed against alternative or compensating controls because they often cannot support standard IT security agents.

  6. Question 6Intermediate

    CMMC Level 2 Assessment Scoping · Scope boundaries and enclaves

    An OSC uses a Managed Service Provider (MSP) to manage the firewalls and intrusion detection systems that protect their CUI enclave. The MSP technicians access these systems remotely. How must the assessor handle the MSP during a CMMC Level 2 assessment?

    Show answer & explanation

    Correct answer: C

    Because the MSP manages Security Protection Assets (firewalls/IDS) that protect the CUI enclave, they are an External Service Provider (ESP) affecting the assessment scope. The OSC must have a documented Shared Responsibility Matrix (SRM), and the assessor must verify that the ESP's services comply with the applicable NIST SP 800-171 practices.

Ready for the real thing?

The full CCA simulator has every exam-style question, timed mode, and instant scoring.

Go to the CCA simulator →