10 free Cyber AB CCP practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 201 questions. Work through them, then open each answer to check your reasoning.
Get all 201 questions (US$39) · Download these 10 as a PDF
Question 1
During an assessment, which phase of the process identifies conflicts of interest?
Show answer and explanation
Correct answer: C. Verify readiness to conduct assessment.
Verifying readiness to conduct assessment is the phase where conflicts of interest are identified. This occurs before the actual assessment begins, ensuring that the assessment team has no conflicts that would compromise objectivity and independence. The readiness verification process includes checking for potential conflicts of interest among team members and the organization being assessed.
Why the other options are wrong
- A. Analyzing requirements focuses on understanding what needs to be assessed, not identifying conflicts of interest.
- B. Developing the assessment plan establishes the scope and approach, but the formal identification of conflicts occurs during readiness verification.
- D. Generating final recommended results is the conclusion phase and occurs after the assessment is complete, too late to identify conflicts.
Question 2
Which authority leads the CMMC direction, standards, best practices, and knowledge framework for how to map the controls and processes across different Levels that range from basic cyber hygiene to advanced cyber practices?
Show answer and explanation
Correct answer: B. DoD CIO office
The DoD CIO office leads the CMMC direction, establishes standards, develops best practices, and maintains the knowledge framework for mapping controls and processes across the CMMC Levels. This authority ensures consistency and alignment with Department of Defense cybersecurity strategy and requirements.
Why the other options are wrong
- A. NIST develops general cybersecurity frameworks and standards but does not lead CMMC specifically, which is a DoD-specific program.
- C. The Federal CIO office has broader government-wide responsibilities but does not lead the CMMC program.
- D. The Defense Federal Acquisition Regulation Council develops acquisition regulations but does not lead CMMC direction and standards.
Question 3
What is objectivity as it applies to activities with the CMMC-AB?
Show answer and explanation
Correct answer: C. Avoiding the appearance of, or actual, conflicts of interest
Objectivity in CMMC-AB activities means avoiding the appearance of, or actual, conflicts of interest. This principle ensures that assessments and services are conducted impartially and that stakeholders can have confidence in the independence and credibility of CMM-B work.
Why the other options are wrong
- A. Ensuring full disclosure relates to transparency but is a separate principle from objectivity.
- B. Reporting results completely is about comprehensive communication rather than the absence of conflicts of interest.
- D. Demonstrating integrity in material use relates to proper handling of assessment materials but does not define objectivity.
Question 4
What service is the MOST comprehensive that the RPO provides?
Show answer and explanation
Correct answer: C. Consulting services
Consulting services provided by the RPO (Registered Provider Organization) are the most comprehensive service offering. Consulting encompasses assessment preparation, gap analysis, remediation planning, and guidance across all aspects of CMMC compliance, making it broader in scope than training, education, or assessment services alone.
Why the other options are wrong
- A. Training services focus on knowledge delivery but do not include the full range of organizational assessment and planning activities.
- B. Education services provide foundational knowledge but are narrower in scope than comprehensive consulting engagement.
- D. Assessment services evaluate compliance but do not include the advisory and planning elements that consulting provides.
Question 5
The Assessment Team has completed Phase 2 of the Assessment Process. In conducting Phase 3 of the Assessment Process, the Assessment Team is reviewing evidence to address Limited Practice Deficiency Corrections.
How should the team score practices in which the evidence shows the deficiencies have been corrected?
Show answer and explanation
Correct answer: A. MET
When an assessment team reviews evidence in Phase 3 showing that Limited Practice Deficiency Corrections have been completed, the practice should be scored as MET. This indicates that the organization has addressed the previously identified deficiencies and now satisfies the practice requirements.
Why the other options are wrong
- B. POA&M (Plan of Action and Milestones) applies to practices that remain unmet and require a remediation timeline, not to corrected deficiencies.
- C. NOT MET is inappropriate when evidence demonstrates that deficiencies have been corrected.
- D. NOT APPLICABLE is used for practices that do not apply to the organization, not for practices with corrected deficiencies.
Question 6
A dedicated local printer is used to print out documents with FCI in an organization. This is considered an FCI Asset.
Which function BEST describes what the printer does with the FCI?
Show answer and explanation
Correct answer: C. Process
A printer that outputs documents containing FCI is processing the FCI. Processing refers to performing operations on information, including printing, displaying, or producing information in various forms. The printer takes FCI as input and produces physical documents, which constitutes a processing function.
Why the other options are wrong
- A. Encrypt refers to converting information into a coded form, which is not the primary function of a standard printer.
- B. Manage relates to organizing and controlling information assets over time, not the active operation of printing.
- D. Distribute refers to transmitting or delivering information to other locations or recipients, which printing does not inherently accomplish.
Question 7
What is the LAST step when developing an assessment plan for an OSC?
Show answer and explanation
Correct answer: D. Obtain and record commitment to the assessment plan.
Obtaining and recording commitment to the assessment plan is the final step in developing an assessment plan for an Onsite Service Contractor (OSC). This step ensures all stakeholders formally agree to proceed with the plan and its requirements, establishing accountability before assessment activities begin.
Why the other options are wrong
- A. Verifying readiness to conduct the assessment occurs before obtaining commitment and is not the final step.
- B. Performing certification assessment readiness review is an intermediary step that precedes final commitment.
- C. Updating the assessment plan and schedule as needed is an ongoing activity that can occur before the commitment step.
Question 8
Which domain has a practice requiring an organization to restrict, disable, or prevent the use of nonessential programs?
Show answer and explanation
Correct answer: D. Configuration Management (CM)
Configuration Management (CM) domain contains practices requiring organizations to restrict, disable, or prevent the use of nonessential programs. This aligns with the CM principle of maintaining authorized system configurations and removing unnecessary software that could introduce vulnerabilities.
Why the other options are wrong
- A. Access Control (AC) focuses on user authentication and authorization but does not specifically address restricting nonessential programs.
- B. Media Protection (MP) deals with physical and digital media safeguards, not program restrictions.
- C. Asset Management (AM) addresses inventory and tracking of assets but not the restriction of program execution.
Question 9
In preparation for a CMMC Level 1 Self-Assessment, the IT manager for a DIB organization is documenting asset types in the company’s SSP. The manager determines that identified machine controllers and assembly machines should be documented as Specialized Assets.
Which type of Specialized Assets has the manager identified and documented?
Show answer and explanation
Correct answer: D. Operational technology
Machine controllers and assembly machines are industrial/manufacturing equipment that operate in a production environment. These are classified as Operational Technology (OT), which encompasses industrial control systems, programmable logic controllers, and automated manufacturing equipment used to manage physical processes. This distinguishes them from Information Technology (IT) systems and other specialized asset categories.
Why the other options are wrong
- A. IoT refers to internet-connected devices for data collection and communication, not dedicated industrial manufacturing machines.
- B. Restricted IS applies to information systems with specific access controls or classification requirements, not manufacturing equipment.
- C. Test equipment is used for validation and testing purposes, not for operational production processes.
Question 10
According to the Configuration Management (CM) domain, which principle is the basis for defining essential system capabilities?
Show answer and explanation
Correct answer: C. Least functionality
Least functionality is the foundational principle in Configuration Management that requires systems be configured with only the essential capabilities needed to perform their intended function. All other settings, services, and features should be disabled or removed. This principle forms the basis for defining what essential system capabilities are required versus what should be restricted or eliminated.
Why the other options are wrong
- A. Least privilege applies to access controls and permissions, not to defining system capabilities within the CM domain.
- B. Essential concern is not an established CM principle for defining system capabilities.
- D. Separation of duties relates to role-based access control, not to the definition of essential system capabilities.
That was 10 of 201.
The full Cyber AB CCP pack has all 201 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
