Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cyber AB CMMC-CCA Exam - Topic 1 Question 12 Discussion

The team is assessing an OSC that uses the cloud for hosting its online services. Which of the following is NOT important for the assessor to consider?
D) FIPS encryption is authenticated as a prerequisite to system access.
A) Devices connecting to the system are authorized.
B) Processes acting on behalf of a user are authenticated.
C) Users are authorized as a prerequisite to system access.

Cyber AB CMMC-CCA Exam - Topic 1 Question 12 Discussion

Actual exam question for Cyber AB's CMMC-CCA exam
Question #: 12
Topic #: 1
[All CMMC-CCA Questions]

The team is assessing an OSC that uses the cloud for hosting its online services. Which of the following is NOT important for the assessor to consider?

Show Suggested Answer Hide Answer
Suggested Answer: D

Applicable Requirement: SC.L2-3.13.8 (Cryptographic protection of communications) and IA.L2-3.5.x (Identification and authentication).

Why D is Correct: Encryption must be validated as FIPS 140-2/3 compliant but is never ''authenticated as a prerequisite to access.'' Authentication applies to users, devices, and processes, not cryptographic modules themselves.

Why A, B, C are Correct Considerations:

Devices must be authorized before connecting.

Processes acting on behalf of a user must be authenticated.

Users must be authorized prior to access. These are all directly mapped to AC and IA domains.

Reference (CCA Official Sources):

NIST SP 800-171 Rev. 2 --- IA and SC requirements

NIST SP 800-171A --- Assessment Objectives for AC/IA wireless and cloud access

CMMC Assessment Guide -- Level 2, Cloud/ESP Considerations

===========


Contribute your Thoughts:

0/2000 characters
Alpha
5 hours ago
D is definitely not important.
upvoted 0 times
...
Allene
5 days ago
I'm not so sure about D being unimportant.
upvoted 0 times
...
Leeann
11 days ago
Wait, FIPS encryption isn't always necessary?
upvoted 0 times
...
Roselle
16 days ago
B and C are must-haves for sure!
upvoted 0 times
...
Dexter
2 months ago
I think A is crucial, though.
upvoted 0 times
...
Dylan
2 months ago
D is definitely not important.
upvoted 0 times
...
Margart
3 months ago
I feel like D might be the odd one out here. We talked about encryption, but I don't recall it being a direct requirement for access like the others.
upvoted 0 times
...
Keneth
3 months ago
This question reminds me of a practice exam where we had to identify what factors were essential for system security. I think B is definitely important.
upvoted 0 times
...
Stefany
3 months ago
I'm a bit unsure about D. I know FIPS encryption is important, but I'm not sure if it's a prerequisite for access.
upvoted 0 times
...
Royal
3 months ago
I remember discussing the importance of user authorization, so I think options A and C are definitely crucial.
upvoted 0 times
...

Save Cancel