CCA Sample Questions & Answers
Evaluating how well an organization implements NIST SP 800-171 practices is weighted heaviest, well ahead of running the CMMC assessment process itself, scoping a Level 2 assessment, and understanding the organization seeking certification.
Launch the full CCA simulator →Free CCA Sample Questions with Answers
Real questions from the CMMC Certified Assessor practice test — answers and explanations included. Showing 6 of 12 free samples.
- Question 1IntermediateSelect 2
Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 · OSC Readiness
Before a CMMC Level 2 assessment can officially commence, an assessor must verify that the OSC has prepared specific mandatory documentation. Which TWO of the following documents are absolute prerequisites for initiating the assessment process? (Select TWO)
Show answer & explanation
Correct answers: A, B
The System Security Plan (SSP) is the foundational document that defines the assessment boundary and describes how the NIST SP 800-171 practices are implemented. Without it, the assessment cannot begin.
The Plan of Action and Milestones (POA&M) is required to document any unmet or planned security requirements. Even if no items are currently deficient, a formal POA&M process must exist and be provided to the assessment team.
- Question 2Advanced
Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 · CMMC Level 2 applicability and objectives
An Organization Seeking Certification (OSC) is preparing for a CMMC Level 2 assessment. During the readiness review, the Lead CCA analyzes the OSC's proposed data flow architecture for handling Controlled Unclassified Information (CUI).
Based on the architecture diagram provided, what represents the MOST critical readiness risk that would prevent the OSC from achieving CMMC Level 2 certification?
flowchart TD Gov([DoW Contract Portal]) -->|CUI Download| UserPC[Contractor Workstation] UserPC -->|Uploads to| CloudApp[Commercial SaaS Application] CloudApp -->|Syncs| Mobile[Employee BYOD Mobile Device]Show answer & explanation
Correct answer: B
Under DFARS 252.204-7012 and CMMC Level 2 requirements, any Cloud Service Provider (CSP) used to store, process, or transmit CUI must meet security requirements equivalent to FedRAMP Moderate baseline. Using a standard commercial SaaS application without establishing this equivalency is a critical compliance failure and a major readiness risk.
- Question 3Advanced
Evaluating Organizations Seeking Certification (OSC) Against CMMC Level 2 · CMMC Level 2 applicability and objectives
An aerospace manufacturing subcontractor is reviewing their contractual obligations to determine their CMMC readiness. They hold multiple subcontracts. Subcontract A includes FAR 52.204-21 but no DFARS clauses. Subcontract B includes DFARS 252.204-7012 and involves the transmission of technical drawings marked as Controlled Unclassified Information (CUI). Subcontract C involves commercial off-the-shelf (COTS) items only.
To achieve compliance for all current obligations, what is the MINIMUM certification level the subcontractor must prepare for, and to which systems does it apply?
Show answer & explanation
Correct answer: B
Because Subcontract B involves CUI and DFARS 7012, the organization must achieve CMMC Level 2. However, this requirement only applies to the systems within the assessment boundary (the CUI enclave) that process, store, or transmit that CUI, along with the Security Protection Assets that secure them. COTS contracts (Subcontract C) do not inherently require CMMC, and FAR 52.204-21 (Subcontract A) only requires Level 1 for those specific systems.
- Question 4Beginner
CMMC Level 2 Assessment Scoping · Asset categories and scoping guidance
According to the CMMC Level 2 Scoping Guidance, which asset category is defined as systems or components that provide security functions or capabilities to the OSC's CMMC assessment scope, regardless of whether they process, store, or transmit CUI themselves?
Show answer & explanation
Correct answer: C
Security Protection Assets (SPA) are defined as assets that provide security functions or capabilities to the OSC's CMMC assessment scope. Examples include firewalls, SIEMs, and domain controllers. Even if they don't hold CUI, they are fully in scope and must be assessed against all applicable CMMC practices.
- Question 5Beginner
CMMC Level 2 Assessment Scoping · Asset categories and scoping guidance
An OSC utilizes legacy Computer Numerical Control (CNC) machines on their manufacturing floor to produce parts based on DoD technical drawings. These machines run embedded operating systems that cannot be patched or updated with modern endpoint protection. Under CMMC Level 2, how are these machines categorized?
Show answer & explanation
Correct answer: B
Specialized Assets (SA) include Operational Technology (OT), Internet of Things (IoT), Industrial Internet of Things (IIoT), Government Property, and Restricted Information Systems. CNC machines fall under OT/Specialized Assets. They are part of the assessment scope but are typically assessed against alternative or compensating controls because they often cannot support standard IT security agents.
- Question 6Intermediate
CMMC Level 2 Assessment Scoping · Scope boundaries and enclaves
An OSC uses a Managed Service Provider (MSP) to manage the firewalls and intrusion detection systems that protect their CUI enclave. The MSP technicians access these systems remotely. How must the assessor handle the MSP during a CMMC Level 2 assessment?
Show answer & explanation
Correct answer: B
Because the MSP manages Security Protection Assets (firewalls/IDS) that protect the CUI enclave, they are an External Service Provider (ESP) affecting the assessment scope. The OSC must have a documented Shared Responsibility Matrix (SRM), and the assessor must verify that the ESP's services comply with the applicable NIST SP 800-171 practices.
Ready for the real thing?
The full CCA simulator has every exam-style question, timed mode, and instant scoring.