Valid CMMC-CCA Dumps shared by EduDump.com for Helping Passing CMMC-CCA Exam! EduDump.com now offer the newest CMMC-CCA exam dumps, the EduDump.com CMMC-CCA exam questions have been updated and answers have been corrected get the newest EduDump.com CMMC-CCA dumps with Test Engine here:
Does CMMC Level 2 require that a Cloud Service Provider (CSP) hold a FedRAMP HIGH authorization hosted in a government community cloud (GCC)?
Correct Answer: B
CMMC Level 2 requires CSPs that process, store, or transmit CUI to meet FedRAMP Moderate (or equivalent) authorization, not FedRAMP High. FedRAMP High is not a CMMC requirement but may be required by contract or specific agencies. Exact Extracts: * DoD CMMC Scoping Guide: "External Cloud Service Providers must meet FedRAMP Moderate equivalency when storing, processing, or transmitting CUI." * CMMC Assessment Guide: "The baseline requirement for CUI in cloud environments is FedRAMP Moderate; higher levels may be contractually required." Why other options are not correct: * A: Equivalency is allowed, but only to FedRAMP Moderate level. * C/D: Incorrect, because CMMC Level 2 does not mandate FedRAMP High. References: CMMC Assessment Guide - Level 2, Version 2.13: External Service Providers and FedRAMP Moderate equivalency requirements. DoD Cloud Computing SRG (referenced in CMMC documentation): CUI requires FedRAMP Moderate baseline.