Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cyber AB CMMC-CCP Exam - Topic 6 Question 14 Discussion

SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC's assessment. How does this affect the assessment scope?
D) VoIP technology is not used within scope boundary, so no assessment procedures are specified for this practice.
A) Any existing telephone system is in scope even if it is not using VoIP technology.
B) An error has been made and the Lead Assessor should be contacted to correct the error.
C) VoIP technology is within scope, and it uses FlPS-validated encryption, so it does not need to be assessed.

Cyber AB CMMC-CCP Exam - Topic 6 Question 14 Discussion

Actual exam question for Cyber AB's CMMC-CCP exam
Question #: 14
Topic #: 6
[All CMMC-CCP Questions]

SC.L2-3 13.14: Control and monitor the use of VoIP technologies is marked as NOT APPLICABLE for an OSC's assessment. How does this affect the assessment scope?

Show Suggested Answer Hide Answer
Suggested Answer: D

Understanding SC.L2-3.13.14 -- Control and Monitor the Use of VoIP Technologies

TheCMMC 2.0 Level 2requirementSC.L2-3.13.14comes fromNIST SP 800-171, Security Requirement 3.13.14, which mandates that organizations mustcontrol and monitor the use of VoIP (Voice over Internet Protocol) technologiesif used within their system boundary.

If a systemdoes not use VoIP technology, then this control isNot Applicable (N/A)because there is nothing to assess.

Why Option D is Correct

When a requirement is marked as Not Applicable (N/A), it means the OSC does not use the technology or process covered by that controlwithin its assessment boundary.

No assessment procedures are neededsince there is no VoIP system to evaluate.

Option A (Existing telephone system in scope)is incorrect becausetraditional (non-VoIP) telephone systems are not covered by SC.L2-3.13.14---only VoIP is within scope.

Option B (Error, contact the Lead Assessor)is incorrect because markingSC.L2-3.13.14 as N/A is valid if VoIP is not used. This is not an error.

Option C (VoIP in scope but using FIPS-validated encryption, so it doesn't need to be assessed)is incorrect becauseeven if VoIP uses FIPS-validated encryption, the control would still need to be assessed to ensure monitoring and usage control are in place.

Official CMMC Documentation Reference

CMMC 2.0 Level 2 Assessment Guide -- SC.L2-3.13.14

NIST SP 800-171, Security Requirement 3.13.14

CMMC Scoping Guidance -- Determining Not Applicable (N/A) Practices

Final Verification

IfVoIP is not used within the OSC's system boundary, the control does not require assessment, making Option D the correct answer.


Contribute your Thoughts:

0/2000 characters
A) makes sense, old systems still count.
upvoted 0 times
...
Roosevelt
5 days ago
I recall that if something is marked as not applicable, it usually means it’s outside the assessment boundaries. So, I think D makes sense, but I need to double-check that.
upvoted 0 times
...
Vicky
10 days ago
I’m leaning towards option D because if VoIP isn’t in scope, then it seems logical that we wouldn’t assess it at all. But I’m a bit unsure.
upvoted 0 times
...
Nichelle
15 days ago
I think I saw a similar question about technology scope in our practice exams. If VoIP is not applicable, does that mean we just focus on traditional systems?
upvoted 0 times
...
Daniel
2 months ago
I remember discussing how the assessment scope changes when certain technologies are marked as not applicable, but I'm not sure how that specifically relates to VoIP here.
upvoted 0 times
...

Save Cancel