The IT manager is scoping the company's CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?
Understanding Asset Types in CMMC 2.0In CMMC 2.0, assets are categorized based on their role in handlingFederal Contract Information (FCI)orControlled Unclassified Information (CUI). TheCybersecurity Maturity Model Certification (CMMC) Scoping GuidanceforLevel 1andLevel 2provides asset definitions to help organizations identify what needs protection.
According toCMMC Scoping Guidance, there are five primary asset types:
Security Protection Assets (ESP - External Service Providers & Security Systems)
People (Personnel who interact with FCI/CUI)
Facilities (Physical locations housing FCI/CUI)
Technology (Hardware, software, and networks that store, process, or transmit FCI/CUI)
CUI Assets (For Level 2 assessments, assets specifically storing CUI)
Why 'Technology' Is the Correct AnswerThe IT manager is evaluatingservers, laptops, databases, and applications---all of which aretechnology assetsused to store, process, or transmit FCI.
According toCMMC Scoping Guidance,Technology assetsinclude:
Endpoints(Laptops, Workstations, Mobile Devices)
Servers(On-premise or cloud-based)
Networking Devices(Routers, Firewalls, Switches)
Applications(Software, Cloud-based tools)
Databases(Storage of FCI or CUI)
Since the IT manager is focusing on these components, the correct asset category isTechnology (Option D).
A . ESP (Security Protection Assets)Incorrect. ESPs refer tosecurity-related assets(e.g., firewalls, monitoring tools, managed security services) thathelp protectFCI/CUI but do notstore, process, or transmitit directly.
B . PeopleIncorrect. While employees play a role in handling FCI, the question focuses onhardware and software---which falls underTechnology, not People.
C . FacilitiesIncorrect. Facilities refer tophysical buildingsor secured areas where FCI/CUI is stored or processed. The question explicitly mentionsservers, laptops, and applications, which arenot physical facilities.
Why the Other Answers Are Incorrect
CMMC Level 1 Scoping Guide (CMMC-AB)-- Defines asset categories, including Technology.
CMMC 2.0 Scoping Guidance for Assessors-- Provides clarification on FCI assets.
CMMC Official ReferenceThus,option D (Technology) is the most correct choiceas per official CMMC 2.0 guidance.
Fannie
9 hours agoElly
6 days agoJohnna
11 days agoLyla
16 days agoShawnta
21 days agoRikki
26 days agoSommer
1 month agoCheryl
1 month agoKayleigh
1 month agoMarkus
2 months agoCarlee
2 months agoYolande
2 months agoAudra
2 months agoAntonio
2 months agoOlen
3 months agoLemuel
3 months agoGeoffrey
3 months agoBlondell
3 months agoAnnmarie
4 months agoMalinda
4 months agoCatarina
4 months agoAmie
4 months agoLucina
4 months agoJosefa
4 months agoCecil
5 months agoSheron
2 months ago