Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cyber AB CMMC-CCA Exam - Topic 4 Question 19 Discussion

A company has multiple sites with employees at each site that must access the company's CUI network from their remote locations. The company has set up a single access point for all employees to access the network. What is the MOST significant factor in determining whether the security on this single access point is adequate?
A) Remote access is secured and monitored.
B) Physical access is monitored and controlled.
C) The security requirements for CUI and FCI are documented.
D) The remote personnel have notification procedures regarding connection issues.

Cyber AB CMMC-CCA Exam - Topic 4 Question 19 Discussion

Actual exam question for Cyber AB's CMMC-CCA exam
Question #: 19
Topic #: 4
[All CMMC-CCA Questions]

A company has multiple sites with employees at each site that must access the company's CUI network from their remote locations. The company has set up a single access point for all employees to access the network. What is the MOST significant factor in determining whether the security on this single access point is adequate?

Show Suggested Answer Hide Answer
Suggested Answer: A

Applicable Requirement: AC.L2-3.1.12 and AC.L2-3.1.14 --- ''Monitor and control remote access sessions'' and ''Route remote access through managed access control points.''

Why A is Correct: For a single centralized access point, the most critical control is that remote access sessions are properly secured and monitored to prevent unauthorized access to CUI systems. This ensures both confidentiality and integrity of remote connections.

Why Other Options Are Insufficient:

B: Physical access controls protect on-site systems but do not address remote connection security.

C: Documentation alone is not sufficient; actual monitoring and security enforcement are required.

D: Notification procedures relate to incident handling, not adequacy of access point security.

Reference (CCA Official Sources):

NIST SP 800-171 Rev. 2 --- AC.L2-3.1.12, AC.L2-3.1.14

NIST SP 800-171A --- Remote Access Assessment Objectives

CMMC Assessment Guide -- Level 2, Remote Access Guidance


Contribute your Thoughts:

0/2000 characters
Lavonda
4 days ago
I feel like C is also really important because if the security requirements for CUI are not documented, how can they ensure proper protection?
upvoted 0 times
...
Allene
9 days ago
I'm not entirely sure, but I remember a practice question that emphasized the importance of physical access control, so maybe B could be significant too.
upvoted 0 times
...
Jolanda
14 days ago
I think the most important factor is A, since securing and monitoring remote access seems crucial for protecting sensitive data.
upvoted 0 times
...

Save Cancel