Question 71
An OSC seeking Level 2 certification is working with an ESP. The organization is trying to determine if the ESP is considered within the assessment and is reviewing the Service Level Agreement (SLA) between the organization and the ESP. Which SLA component should be taken into consideration to determine if the ESP is within the assessment scope?
Question 72
During scoping discussions with a Lead Assessor, the OSC mentions that there are several connected systems within the organization's network. How should the Lead Assessor consider connected systems in the scoping of the CMMC assessment?
Question 73
A CCA is offered a significant discount on cybersecurity software from a vendor whose productthey will be evaluating during a CMMC assessment. How should the CCA handle this situation according to the CoPC's conflict of interest principle?
Question 74
To meet AC.L2-3.1.5: Least Privilege, the following procedure is established:
* All employees are given a basic (non-privileged) user account.
* System Administrators are given a separate System Administrator account.
* Database Administrators are given a separate Database Administrator account.
Which steps should be added to BEST meet all of the standards for least privilege?
Question 75
John, a CCA, has been assigned by his C3PAO to conduct a CMMC assessment for an OSC. During the assessment, John notices that the OSC's security practices leave much to be desired. After speaking with the OSC's IT staff, John offers to connect them with a vendor he knows who sells a vulnerability management tool that could address some of their weaknesses. According to the CMMC CoPC, which of the following best describes John's actions?
