Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cyber AB CMMC-CCA Exam - Topic 4 Question 10 Discussion

Actual exam question for Cyber AB's CMMC-CCA exam
Question #: 10
Topic #: 4
[All CMMC-CCA Questions]

During an assessment, the OSC was found to have implemented 68% of CMMC practice SC.L2-3.13.11 -- CUI Encryption. However, the OSC Assessment Official cited issues with the vendor for not fully implementing the practice. Nonetheless, it has been listed in their POA&M. Which of the following is true regarding the use of a POA&M during a CMMC assessment?

Show Suggested Answer Hide Answer
Suggested Answer: A

Comprehensive and Detailed In-Depth Explanatio n:

SC.L2-3.13.11 (5-point practice) requires full implementation for certification. Per CAP, a POA&M documents deficiencies but isn't a substitute for completion (A). Options B, C, and D contradict CMMC rules, as partial implementation or POA&M listing doesn't equate to Met status, especially for 5-point practices ineligible for POA&M deferral.

Extract from Official CMMC Documentation:

CMMC Assessment Guide Level 2 (v2.0), SC.L2-3.13.11: 'Full implementation required.'

CAP v5.6.1: 'POA&M not a substitute for Met status.'

Resources:

https://dodcio.defense.gov/Portals/0/Documents/CMMC/AG_Level2_MasterV2.0_FINAL_202112016_508.pdf


Contribute your Thoughts:

0/2000 characters
Ben
24 hours ago
Totally agree, it’s just a plan, not proof.
upvoted 0 times
...
Crista
6 days ago
A POA&M isn't a substitute for actual implementation.
upvoted 0 times
...
Elmer
11 days ago
I recall that assessors have to be strict about what counts as evidence, so D seems wrong too. A must be the answer!
upvoted 0 times
...
Sharen
16 days ago
I practiced a similar question, and I believe C is definitely incorrect because just being on the POA&M doesn't mean it's implemented.
upvoted 0 times
...
Tyra
22 days ago
I'm a bit unsure, but I think B sounds tempting since it mentions evidence, but I feel like that's not how it works.
upvoted 0 times
...
Jutta
27 days ago
I remember that a POA&M can't replace actual implementation, so I think A is the right choice.
upvoted 0 times
...

Save Cancel