CCP Practice Questions
Prepare for CCP with more than an answer.
- Exam fee
- $275 USD
- Level
- Professional
- Valid for
- 3 years
Domains covered on the exam 6
- CMMC Ecosystem5%
- CMMC-AB Code of Professional Conduct (Ethics)5%
- CMMC Governance and Source Documents15%
- CMMC Model Construct and Implementation Evaluation35%
- CMMC Assessment Process (CAP)25%
- Scoping15%
- 1
When preparing for a CMMC Level 1 assessment, which source document provides the most detailed, practice-by-practice guidance including assessment objectives and potential assessment methods?
Show answer details
Correct answer: B
The CMMC Level 1 Assessment Guide is the authoritative source document specifically designed for this purpose. It breaks down each of the 17 practices for Level 1, detailing the specific assessment objectives that must be met and providing examples of evidence and assessment methods (Examine, Interview, Test) that could be used to verify implementation.
- 2
A defense contractor knowingly misrepresents their cybersecurity posture on a self-assessment submitted to the DoD to win a contract. Later, a data breach reveals significant non-compliance with NIST SP 800-171. Under which initiative could the Department of Justice pursue legal action against the contractor for this misrepresentation?
Show answer details
Correct answer: C
The Department of Justice's Civil Cyber-Fraud Initiative uses the False Claims Act to pursue cybersecurity-related fraud by government contractors. Knowingly providing deficient cybersecurity products or services, misrepresenting the state of cybersecurity practices, or violating obligations to monitor and report cyber incidents are all grounds for action under this initiative. The scenario described is a classic example of what this initiative was created to address.
- 3
The CMMC Level 2 Assessment Guide is directly derived from which two primary source documents?
Show answer details
Correct answer: B
The CMMC Level 2 Assessment Guide is built upon the NIST framework for protecting CUI. NIST SP 800-171 defines the 110 security requirements that must be implemented. NIST SP 800-171A ('Assessing Security Requirements for Controlled Unclassified Information') provides the corresponding assessment procedures and objectives for verifying that each requirement has been met. The CMMC Level 2 guide combines and adapts these two documents for the CMMC assessment context.
- 4
A CCP is helping to define the assessment scope for a CMMC Level 1 certification. The company's network is depicted below. The company processes FCI on the 'Internal Network' and stores it on the 'File Server'. The 'Guest Wi-Fi' is used by visitors and is on a separate physical switch. Which asset is definitively an FCI Asset and must be included in the assessment scope?
graph TD subgraph "Company Network" Router --> Firewall Firewall --> InternalSwitch["Internal Network Switch"] Firewall --> GuestSwitch["Guest Wi-Fi Switch"] InternalSwitch --> WorkstationA[Workstation A] InternalSwitch --> WorkstationB[Workstation B] InternalSwitch --> FileServer[(File Server)] GuestSwitch --> GuestDevice[Visitor Laptop] end Internet((Internet)) --> RouterShow answer details
Correct answer: C
According to CMMC scoping guidance, FCI Assets are systems that process, store, or transmit Federal Contract Information. The scenario explicitly states that FCI is stored on the 'File Server'. Therefore, the File Server is, by definition, an FCI Asset and must be included in the CMMC Level 1 assessment scope. The visitor laptop and guest network are out of scope as they do not handle FCI.
- 5
A small manufacturing company uses a cloud-based ERP system from a major External Service Provider (ESP) to manage its production schedule, which contains CUI. The ESP provides a shared responsibility matrix indicating they are responsible for the physical security of the data centers and the hypervisor. For the CMMC Level 2 assessment, how should the manufacturer's assessment scope be defined regarding the ERP system?
Show answer details
Correct answer: C
When using an ESP, the OSC is still responsible for protecting CUI. The assessment scope includes the OSC's configuration and use of the cloud service. The OSC can inherit controls covered by the ESP, provided the ESP has a security certification equivalent to or higher than the OSC's target CMMC level (e.g., FedRAMP Moderate for CMMC Level 2). The OSC must verify this and still demonstrate compliance for all controls that fall under their responsibility in the shared model, such as identity and access management.
- 6
For an OSC to achieve a CMMC Level 2 certification with some remaining deficiencies, those deficiencies can be placed on a Plan of Action & Milestones (POA&M). Which of the following is a strict requirement for a practice to be eligible for a POA&M?
Show answer details
Correct answer: A
Under the CMMC Assessment Process and the associated DoD Assessment Methodology, not all practices are weighted equally. Certain critical practices are assigned higher point values (e.g., 5 points). A deficiency in one of these highest-weighted practices cannot be placed on a POA&M; it must be fully MET for certification. Only lower-weighted practices are eligible for a POA&M, and there is a cap on the total number of deficiencies allowed.
- 7
Case Study:
Scenario: A C3PAO conducted a CMMC Level 2 assessment for an OSC and issued a certification with one open POA&M item related to practice CA.L2-3.12.4 (Security Control Assessments). The POA&M stated that the OSC would develop and implement a plan for periodic internal security assessments within 120 days.
Follow-up: 150 days later, a CCP is part of the team conducting the POA&M closeout assessment (Phase 4). The OSC provides the following evidence: 1) A newly documented 'Internal Security Assessment Policy'. 2) A schedule showing that the first internal assessment is planned to occur in 90 days. No internal assessments have been conducted yet.
Question: As the CCP reviewing this evidence, what should you conclude about the status of the POA&M item?
Show answer details
Correct answer: C
Closing a POA&M item requires sufficient evidence that the underlying practice is fully implemented and 'MET'. Practice CA.L2-3.12.4 requires that security controls are periodically assessed. Simply having a policy and a future schedule is not enough; it only shows planning. To close the POA&M, the OSC would need to provide evidence that at least one internal assessment has actually been conducted and its results documented, demonstrating the process is operational.
- 8
An OSC has a POA&M item for a CMMC Level 2 practice that requires a hardware purchase and significant network reconfiguration. The DoD Assessment Methodology allows certain practices to be on a POA&M at the time of assessment, provided specific conditions are met. What is the maximum number of days the OSC has to close this POA&M item after the assessment is completed?
Show answer details
Correct answer: C
For a CMMC Level 2 assessment, the OSC has a maximum of 180 days from the end of the assessment to remediate any open items on their POA&M. After this period, the C3PAO will conduct a closeout assessment to verify the remediation, and if successful, recommend the OSC for certification.
- 9
During a POA&M closeout assessment (Phase 4), a CCP is part of the team verifying that an OSC has remediated a deficiency in practice CM.L2-3.4.2 (Establish and enforce security configuration settings). What would be considered sufficient evidence to close this item?
Show answer details
Correct answer: C
POA&M closeout requires the same level of rigor as the initial assessment. The team must verify that the control is now fully implemented. This requires objective evidence, such as examining the new configuration settings (e.g., in Group Policy) and testing their effectiveness (e.g., via a compliance scan report). This combination of 'Examine' and 'Test' evidence is sufficient to prove remediation.
- 10
A CCP is part of a team conducting a POA&M closeout assessment (Phase 4). The OSC had a 'NOT MET' finding for CM.L2-3.4.1 (Establish configuration baselines). To close the POA&M item, the OSC provides a newly written policy document for configuration management and purchase orders for a vulnerability scanning tool. Is this evidence sufficient to close the POA&M item and change the finding to MET?
Show answer details
Correct answer: B
Closing a POA&M item requires evidence that the practice is fully implemented, not just planned. A policy document and a purchase order show intent, but they do not prove that configuration baselines have been established, documented, and applied to the systems in scope. The assessment team would need to see the actual baseline configuration documents and evidence of their application (e.g., scanner results showing compliance) to mark the practice as MET.
