CCA Practice Questions
Prepare for CCA with more than an answer.
- Exam fee
- $200 USD
- Questions on the exam
- 60-65
- Level
- Associate
- Valid for
- 2 years
Domains covered on the exam 9
- Deploying Citrix Virtual Apps and Desktops12%
- Providing Resources to End Users11%
- Providing Access to App and Desktop Resources11%
- Citrix Virtual Apps and Desktops Basic Security Considerations11%
- Monitoring Citrix Virtual Apps and Desktops Deployments11%
- Troubleshooting11%
- Printing11%
- PowerShell11%
- Citrix Cloud11%
- 1
An OSC uses a Managed Service Provider (MSP) to manage the firewalls and intrusion detection systems that protect their CUI enclave. The MSP technicians access these systems remotely. How must the assessor handle the MSP during a CMMC Level 2 assessment?
Show answer details
Correct answer: B
Because the MSP manages Security Protection Assets (firewalls/IDS) that protect the CUI enclave, they are an External Service Provider (ESP) affecting the assessment scope. The OSC must have a documented Shared Responsibility Matrix (SRM), and the assessor must verify that the ESP's services comply with the applicable NIST SP 800-171 practices.
- 2
According to the official CMMC Level 2 Scoping Guidance, which TWO of the following asset categories must be fully assessed against all applicable CMMC Level 2 (NIST SP 800-171) practices? (Select TWO)
Show answer details
Correct answer: B, D
CUI Assets process, store, or transmit CUI and form the core of the assessment scope. They must be fully assessed against all CMMC Level 2 practices.
Security Protection Assets (SPA) provide security functions to the CUI boundary (e.g., firewalls, log servers). Because the security of the CUI depends on them, they must also be fully assessed against all applicable CMMC Level 2 practices.
- 3
An OSC has designed their network to limit the scope of their CMMC Level 2 assessment. They present the following architecture to the Lead CCA:
Based on the principles of scope boundaries and enclaves, what MUST the OSC demonstrate for the Corporate VLAN to be successfully categorized as an Out-of-Scope Asset (OSA)?
graph TD Internet((Internet)) --> EdgeFW[Edge Firewall] EdgeFW --> Corp[Corporate VLAN - Claims No CUI] EdgeFW --> EnclaveFW[Enclave Firewall] EnclaveFW --> CUI[CUI Enclave VLAN]Show answer details
Correct answer: B
To validate an enclave boundary and classify a network segment as Out-of-Scope (OSA), the OSC must demonstrate effective logical or physical separation. Policy alone is insufficient; technical controls (like strict ACLs on the Enclave Firewall) must prove that CUI cannot migrate or be accessed from the out-of-scope segment.
- 4
A defense contractor utilizes an on-premises Virtual Desktop Infrastructure (VDI) to isolate and process CUI. Employees access this VDI enclave remotely using their personal home computers (Bring Your Own Device - BYOD). The assessor verifies that strict technical controls within the VDI prevent any clipboard sharing, downloading, saving, or printing of CUI to the local BYOD endpoints.
According to the CMMC Level 2 Scoping Guidance, how MUST the assessment team categorize and handle these BYOD devices?
Show answer details
Correct answer: C
According to CMMC scoping guidance, endpoints like VDI clients that access a CUI environment but do not process, store, or transmit CUI locally (due to technical restrictions) are categorized as Contractor Risk Managed Assets (CRMA). CRMAs are part of the assessment scope—they must be documented in the SSP and managed according to the OSC's risk management policies—but they are not explicitly assessed against all NIST SP 800-171 practices like CUI assets are.
- 5
In the context of evaluating an Organization Seeking Certification (OSC) against CMMC Level 2, what is the fundamental difference between Federal Contract Information (FCI) and Controlled Unclassified Information (CUI)?
Show answer details
Correct answer: B
CUI requires stringent protection controls defined by NIST SP 800-171 (CMMC Level 2), as it involves specific safeguarding laws or regulations. FCI only requires the 15 basic safeguarding requirements outlined in FAR 52.204-21 (CMMC Level 1). Understanding this distinction is the first step in determining an OSC's readiness and applicability for a Level 2 assessment.
- 6
True or False: An Organization Seeking Certification (OSC) can undergo a formal CMMC Level 2 assessment even if their System Security Plan (SSP) is currently in draft format, provided they have a comprehensive Plan of Action and Milestones (POA&M).
Show answer details
Correct answer: B
False. A finalized, formally documented System Security Plan (SSP) is a fundamental prerequisite for any CMMC Level 2 assessment. The SSP describes the system boundary and how the security requirements are met. Without a finalized SSP, the assessor cannot establish the assessment scope or evaluate the baseline controls, making the OSC unready for an assessment.
