Valid CMMC-CCA Dumps shared by EduDump.com for Helping Passing CMMC-CCA Exam! EduDump.com now offer the newest CMMC-CCA exam dumps, the EduDump.com CMMC-CCA exam questions have been updated and answers have been corrected get the newest EduDump.com CMMC-CCA dumps with Test Engine here:
While conducting a CMMC Level 2 self-assessment, an organization's Chief Information Security Officer asks the system administrator for evidence that remote access is routed through fully managed access control points. Which documentation would BEST demonstrate that all remote access is routed through managed access control points?
Correct Answer: A
To validate that remote access is routed through managed access control points, the assessor requires technical evidence, not just policy. The network diagram shows the design and routing of remote access through controlled points (e.g., VPN gateways), and VPN logs provide operational evidence that remote sessions are enforced through those points. Exact Extracts: * AC.L2-3.1.14: "Route remote access through managed access control points." * Assessment Objective (AC.L2-3.1.14[a]): "Remote access is routed through managed access control points." * Assessment Method (Examine/Interview/Test): Requires network diagrams and remote access logs as evidence. * CMMC Assessment Guide specifies: "Network diagrams and supporting logs are required to demonstrate implementation of remote access routing." Why the other options are not correct: * B (policy/procedures): Policies describe intent, not proof of implementation. * C (SSP/vendor mgmt): SSPs provide system description but not direct evidence of enforcement. * D (cloud logs/hardware inventory): These do not specifically demonstrate remote access routing through managed points. References: CMMC Assessment Guide - Level 2, Version 2.13: AC.L2-3.1.14 (pp. 25-27). NIST SP 800-171A, Access Control assessment procedures.