CMMC-CCA試験は出題範囲が広く、独学だけでは論点の取りこぼしが起こりがちです。CertJukenでは2026年の出題傾向を反映したCyber AB Certified CMMC Assessor (CCA)の問題集を提供していますので、本番に近い形で実力を確認できます。
Cyber AB CMMC-CCA 試験概要:
| 認定ベンダー: | Cyber AB (formerly CMMC-AB) |
|---|---|
| 試験名: | 認定CMCCアセッサー(CCA)試験 |
| 試験番号: | CMMC-CCA |
| 試験形式: | 多肢選択式, シナリオベースの問題 |
| 関連資格: | CMMC認定(レベル1〜3エコシステム) 認定CMCCプロフェッショナル(CCP) |
| 対応言語: | 英語 |
| 推奨トレーニング: | Cyber ABトレーニングプログラム DoD CMCCリソース |
| 受験申し込み: | Cyber AB公式認定ポータル |
| サンプル問題: | ![]() |
| 受験方法: | オンライン監視試験(Cyber AB認定テストプロバイダーが実施) |
| 前提条件: | 通常、Cyber ABの資格要件に基づき、CMMC認定CMCCプロフェッショナル(CCP)トレーニングの修了と、サイバーセキュリティまたはアセスメントに関する実務経験が必要です。 |
| 公式シラバスのURL: | https://cyberab.org |
Cyber AB CMMC-CCA 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: サイバーセキュリティガバナンスとコンプライアンス | - コンプライアンスおよび規制上の要求事項
|
| トピック 2: CMCCアセスメントプロセスと方法論 | - アセスメントの報告と文書化
|
| トピック 3: CMCCモデルとコントロール | - NIST SP 800-171との整合
|
| トピック 4: 技術的セキュリティドメイン | - アクセス制御とアイデンティティ管理
|
CMMC-CCA試験で受験者がよく抱く疑問
CMMC-CCAは、Cyber ABが実施する「Cyber AB認定CMCCアセッサー(CCA)」を取得するための認定試験です。認定レベルはプロフェッショナルで、実務に即した知識とスキルが問われます。認定CMCCプロフェッショナル(CCP)、CMMC認定(レベル1〜3エコシステム)などの関連認定へのステップとしても位置づけられており、キャリアアップを目指す方に広く選ばれています。CertJukenの練習問題を活用すれば、試験の全体像を把握しながら計画的に対策を進められます。
はい。CertJukenではCMMC-CCA練習問題の無料サンプル(PDFデモ)を用意しており、内容や使い勝手を確かめてから購入を判断できます。購入後は365日間の無料更新が付き、更新期間の終了後は50%割引で継続更新を利用できます。
CertJukenでは「返金保証」を用意しています。購入後60日以内にCMMC-CCA試験を受験して不合格だった場合、受験票の写しと公式のスコアレポート(Score Report)のPDFを試験後2日以内に提出すれば、7日以内に全額返金の手続きが完了します。なお、受験者名と購入時の支払者名が一致している必要があり、購入から3日以内の受験や、実際に受験しなかった場合は対象外です。返金の代わりに、同等の試験対策教材2つを無料で受け取り、購入済み製品の更新サービスを継続する選択も可能です。商品は購入後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間経っても届かない場合はカスタマーサポートまでご連絡ください。インストールできるパソコンの台数に制限はありません。
CMMC-CCA試験の出題範囲は4の分野に分かれています。主な分野はCMCCアセスメントプロセスと方法論、技術的セキュリティドメイン、サイバーセキュリティガバナンスとコンプライアンスです。各分野の詳細な出題項目は、このページ上部の出題範囲一覧で確認できます。
Cyber AB Certified CMMC Assessor (CCA) 認定 CMMC-CCA 試験問題:
A C3PAO has contracted by an OSC to perform its assessment. Before the assessment, the Lead Assessor asks the OSC to provide an extensive list of evidence, some of which is optional and beyond the minimum requirements. The OSC is not able to fulfill the entire request. One missing document was a current and organized list of the OSC's evidence and mappings.
Given that this is a Level 2 Assessment, what should the Lead Assessor tell the OSC?
- A. "The OSC's Assessment Official will be asked to collect evidence when requested by the assessment team."
- B. "It's okay that the document is missing. The Assessment Team will collect all evidence themselves to ensure its integrity."
- C. "The OSC must provide the Assessment Team with hardcopy evidence. Electronic evidence will only be collected when needed."
- D. "The OSC should provide the Assessment Team with a current and organized list of their evidence and process mappings, but the assessment can continue."
解説: (CertJuken メンバーにのみ表示されます)
While conducting a CMMC Level 2 Third-Party Assessment of a small defense contractor, an assessor discovers that the contractor's Information Security Policy has no documented change records demonstrating executive approval. The IT director states that they will add change records in the future, but that other evidence exists. Which documentation is MOST able to demonstrate persistent and habitual adherence to CMMC requirements?
- A. Handwritten notes from executive committee meetings discussing implementation
- B. Transcribed interviews with new employees discussing their understanding of information security policies
- C. Several years' worth of saved emails from the executive team approving policies and directing adherence
- D. A notarized letter from the previous CEO stating that they approved information security policies annually
解説: (CertJuken メンバーにのみ表示されます)
While conducting a CMMC Level 2 Assessment for a small waveguide manufacturer, the client provides a copy of their CMMC Level 1 Self-Assessment that their senior official has recently approved and uploaded to the Supplier Performance Risk System (SPRS). What type of information may be covered within the Level 1 Self-Assessment that is OUTSIDE the scope of a Level 2 assessment?
- A. FCI data within the description in the contractor self-assessment
- B. Sensitive Compartmented Information (SCI) shredded by an approved vendor
- C. FCI within the CUI production enclave
- D. CUI in paper format
解説: (CertJuken メンバーにのみ表示されます)
During an assessment, the OSC IT security team provided documentation on how they use replay-resistant authentication to protect CUI. What can be used as a replay-resistant mechanism?
- A. Encrypted messages
- B. MFA devices to protect access for local users
- C. Biometric techniques
- D. Requiring Transport Layer Security (TLS)
解説: (CertJuken メンバーにのみ表示されます)
During a company's assessment, the CCA notices that the server room door is kept open with a fan in the entryway because the cooling system is inadequate and the machines are overheating. According to the physical protection policy, the server room's keypad is the mechanism for managing and controlling access to this equipment, and only the IT team should have access to the server room. However, with the door open, the keypad is not necessary, and anyone can enter the room.
The CCA asks the IT manager how access to this room is protected while the door is open. Which response would allow the company to still meet the physical security requirement?
- A. "The server is located inside another room that only the IT team has access to."
- B. "We trust our employees not to enter the room if they are not supposed to."
- C. "Only employees are allowed in this area."
- D. "The CEO emailed all employees that the server room door would be kept open but only the IT team should enter."
解説: (CertJuken メンバーにのみ表示されます)




田岛**
Hori
佐藤**
Kurusu
