You are a CCA tasked with leading an Assessment Team conducting a CMMC Assessment for an OSC. Your team is assessing the OSC's readiness to determine whether you can proceed with the second phase of the assessment. To verify the OSC's readiness to proceed with the assessment, which of the following tasks will you not carry out?
During an interview with network administrators responsible for managing remote access, they mentioned using a next-generation firewall (NGFW) to secure the VPN connection, which can inspect remote device configurations and identify signs of potential split tunneling. How can the functionality of this NGFW contribute to achieving the objectives of CMMC practice SC.L2-3.13.7-Split Tunneling?
You are a CCA working for a C3PAO. An OSC has submitted a request for a CMMC Assessment, and the C3PAO is in the process of assigning a Lead Assessor for this engagement. As an experienced Assessor, you are being considered for the role of Lead Assessor. Once the C3PAO assigns the Lead Assessor, what is the next step in the process?
Marc passed his CCP exam and enrolled in CCA training with a Licensed Training Provider (LTP). To his astonishment, the instructor is his cousin. Marc tells his cousin that he feels like dropping out midway because the course is challenging. However, the cousin reassures Marc not to worry. Even if he drops out, the cousin will submit Marc's information to the Cyber AB, and he will pass the exam through a friend who works there.What is unethical about Marc's path to CCA certification?
In ensuring it meets its mandates to protect CUI under CMMC, a contractor has implemented a robust, dynamic session lock with pattern-hiding displays to prevent access and viewing of data. After every 5 minutes of inactivity, the current session is locked and a blank, black screen with a battery life indicator is displayed. In your assessment of the contractor?s implementation of AC.L2-3.1.10-Session Lock, do you find that they have adequately addressed the practice requirements? When assessing the contractors implementation of practice AC.L2-3.1.10, which of the following objectives will NOT be considered as part of your review?