HomeCertified CMMC Assessor PrepQuestions 11–20
Certified CMMC Assessor (CCA) ExamPart 2 of 3

Certified CMMC Assessor (CCA) Exam Exam Questions & Answers 2026 (11–20)

Certified CMMC Assessor (CCA) Exam practice questions and answers 2026. Tap an option to test yourself — you'll see the correct answer and a plain-English explanation for every question. Free, no login.

Practise Certified CMMC Assessor (CCA) Exam questions free, download the PDF, or unlock timed mock exams when you are ready.
Multiple choice — pick the best answer, then reveal it
  1. Q11An organization's incident response policy requires all security incidents to be logged within 24 hours of detection. However, a recent audit reveals that incidents are logged on average 48 hours post-detection, and some critical incidents took over 72 hours to be addressed. Based on this information, how would you score the organization's implementation of the IR domain requirement on Logging and Tracking Security Incidents?

    • ANot Met (-1 point)
    • BMet (+5 points)
    • CMet (+1 point)
    • DNot Met (-5 points)
    Show answer

    ✓ Correct answer: A. Not Met (-1 point)

    Answer: Not Met (-1 point) The audit reveals that the organization fails to log security incidents within the 24-hour timeframe stipulated by their policy, leading to delays in threat response. This non-compliance indicates that the organization does not meet the CMMC requirements for efficient logging and tracking of security incidents, crucial for timely incident response and mitigation.

  2. Q12A financial services firm is preparing for a CMMC assessment, implementing a well-defined Risk Management Framework (RMF) and utilizing continuous monitoring tools. Their policies include comprehensive data classification procedures and regular security awareness training. An independent audit verifies the existence of a regularly updated risk register and a detailed policy on accepting risks. Considering this information, how would you evaluate the firm's compliance with RM.L2-3.11.2-Risk Management practice?

    • AMet (+5 points)
    • BNot Met (-5 points)
    • CNot Met (-1 point)
    • DMet (+1 point)
    Show answer

    ✓ Correct answer: A. Met (+5 points)

    Answer: Met (+5 points) The firm meets the requirements for CMMC RM.L2-3.11.2-Risk Management through its established RMF, continuous monitoring, regular trainings, and updated risk register, indicating a comprehensive risk management process.

  3. Q13In assessing an organization's incident response plan, you evaluate their list of actions upon detecting a security breach. Which of the following actions would you NOT expect to find included in the organization's immediate response protocol?

    • AImmediate lockout of affected user accounts
    • BActivation of incident response team
    • CPre-approved access for new software installations
    • DEscalation of alerts to security team
    Show answer

    ✓ Correct answer: C. Pre-approved access for new software installations

    Answer: Pre-approved access for new software installations Immediate response protocols are designed to contain and mitigate the impact of a security breach. They typically involve actions like alert escalation, affected account lockout, and incident response team activation. Pre-approved access for new software installations is unrelated to immediate threat response and would not typically be part of such protocols.

  4. Q14You are performing a cybersecurity assessment for a financial services company. They have quarterly audits of their applications to identify vulnerabilities but do not include source code analysis due to workflow integration challenges. Despite strong external application firewalls and regular security updates, internal reports show unresolved application layer vulnerabilities. Which of the following would be the most appropriate compensating control or mitigation for the absence of source code analysis?

    • AStrengthen existing external application firewalls
    • BConduct regular manual code reviews and application penetration testing
    • CActivate additional external monitoring with Intrusion Detection Systems (IDS)
    • DIncrease the frequency of security audits by an external firm
    Show answer

    ✓ Correct answer: B. Conduct regular manual code reviews and application penetration testing

    The lack of source code analysis can be mitigated by conducting regular manual code reviews and application penetration testing. This ensures that vulnerabilities in the application layer are identified and addressed, compensating for the absence of automated code scans. Strengthening external defenses and increasing audit frequency are beneficial but do not directly address code vulnerabilities. Similarly, enhancing external monitoring helps identify attacks but doesn't identify code-level flaws.

  5. Q15A contractor is implementing a cybersecurity strategy to protect sensitive data during transmission over networks to meet CMMC compliance. The contractor has implemented several techniques, including network segmentation, secure communication protocols, and data encryption in transit. To adhere to the requirements of protecting data in transit, which strategy should the contractor NOT consider?

    • AData encryption using secure protocols like TLS or SSL
    • BImplementing Virtual Private Networks (VPNs)
    • CUtilizing strong authentication mechanisms for network access
    • DEncrypting data at rest
    Show answer

    ✓ Correct answer: D. Encrypting data at rest

    Answer: Encrypting data at rest While implementing data encryption is crucial, the requirement here is specifically to protect data during transmission. Encrypting data at rest is concerned with data storage but does not protect data when it's being transmitted. CMMC compliance requires strategies like TLS or SSL for data encryption during transit.

  6. Q16During a company's CMMC self-assessment, a formal risk management strategy is presented, outlining identified threats and appropriate responses. However, upon interviewing the personnel responsible for executing this strategy, it becomes clear that the actions required to mitigate these threats are either not being taken or improperly implemented. What assessment objective has the company failed to implement from CMMC practice CA.L2.3.15.3-Risk Management Strategy?

    • ADevelop a formal risk management strategy
    • BConduct regular reviews of the risk management strategy
    • CEffectively execute the risk management strategy to mitigate identified threats.
    • DIdentify the potential threats and risks
    Show answer

    ✓ Correct answer: C. Effectively execute the risk management strategy to mitigate identified threats.

    Answer: Effectively execute the risk management strategy to mitigate identified threats. While the company has identified threats and developed a risk management strategy, the failure lies in the effective execution of this strategy to mitigate the identified threats, as evidenced by the interviews.

  7. Q17You are assessing SecureSoft Inc., a company that specializes in security software development. During your audit, you notice that certain employees have accessed a secure customer database without authorization. Upon reviewing access logs, it's evident that these unauthorized attempts weren't flagged nor reviewed by the security team. How should SecureSoft Inc. address this issue to align with AC.L2-3.1.7-Privileged Functions?

    • AImplement alerts for unauthorized access attempts and ensure logs are reviewed by the security team.
    • BAutomatically deny access and notify all users via email.
    • CImplement session timeouts after unauthorized access attempts.
    • DRestrict database access to business hours only.
    Show answer

    ✓ Correct answer: A. Implement alerts for unauthorized access attempts and ensure logs are reviewed by the security team.

    To comply with CMMC standards, SecureSoft Inc. should ensure that unauthorized access attempts generate alerts and logs are comprehensively reviewed by designated security personnel. This aligns with the principle of monitoring and managing privileged functions effectively.

  8. Q18You are conducting a CMMC Level 3 assessment for a defense contractor. Upon reviewing their subcontracted services, you find that an IT vendor is responsible for key network security functions. What should you verify about this vendor? Vendor Type Vendor Certification Level IT Vendor for Network Security None Bookkeeping Service Level 2 IT Vendor for Web Hosting Level 1

    • AAdvise the contractor to substitute the IT vendor with another vendor
    • BConfirm the IT vendor has a CMMC Level 3 or higher certification
    • CAccept the contractor's use of the vendor with any CMMC certification
    • DAsk for a self-assessment from the IT vendor
    Show answer

    ✓ Correct answer: B. Confirm the IT vendor has a CMMC Level 3 or higher certification

    In CMMC assessments, vendors providing critical services like network security must have a certification level equal to or higher than that sought by the organization. For a Level 3 target, the IT vendor should have CMMC Level 3 or higher.

  9. Q19An organization is preparing its documentation for a CMMC Level 3 assessment. As an assessor, you need to determine which of the following documents is not a requirement under the CMMC Model for risk-managed assets. Which document should NOT be included?

    • APenetration Test Report
    • BBusiness Impact Analysis
    • CAsset inventory
    • DNetwork diagram
    Show answer

    ✓ Correct answer: B. Business Impact Analysis

    Answer: Business Impact Analysis The Business Impact Analysis is not typically required as part of the documentation for CMMC compliance, whereas asset inventory, network diagram, and penetration test report are required.

  10. Q20In a healthcare organization, an IT Security Specialist is responsible for overseeing data encryption processes that secure Protected Health Information (PHI) as it moves between internal databases and external partners. All PHI is stored in a cloud environment and accessed via secure remote applications. What type of asset is the IT Security Specialist?

    • ASecurity Protection Asset (SPA)
    • BHealthcare Compliance Asset (HCA)
    • CEncryption Managed Asset (EMA)
    • DCloud Technological Asset (CTA)
    Show answer

    ✓ Correct answer: A. Security Protection Asset (SPA)

    The correct answer is Security Protection Asset (SPA). The IT Security Specialist's role in managing the encryption process is a security function aimed at protecting healthcare data. As such, they are considered a Security Protection Asset (SPA).

Free practice here. Timed mocks when you are ready.

Use the free Certified CMMC Assessor Prep sample, download the PDF, then unlock web-based timed mock exams for a full exam rehearsal.