The IT manager is scoping the company's CMMC Level 1 Self-Assessment. The manager considers which servers, laptops. databases, and applications are used to store, process, or transmit FCI. Which asset type is being considered by the IT manager?
Understanding Asset Types in CMMC 2.0In CMMC 2.0, assets are categorized based on their role in handlingFederal Contract Information (FCI)orControlled Unclassified Information (CUI). TheCybersecurity Maturity Model Certification (CMMC) Scoping GuidanceforLevel 1andLevel 2provides asset definitions to help organizations identify what needs protection.
According toCMMC Scoping Guidance, there are five primary asset types:
Security Protection Assets (ESP - External Service Providers & Security Systems)
People (Personnel who interact with FCI/CUI)
Facilities (Physical locations housing FCI/CUI)
Technology (Hardware, software, and networks that store, process, or transmit FCI/CUI)
CUI Assets (For Level 2 assessments, assets specifically storing CUI)
Why 'Technology' Is the Correct AnswerThe IT manager is evaluatingservers, laptops, databases, and applications---all of which aretechnology assetsused to store, process, or transmit FCI.
According toCMMC Scoping Guidance,Technology assetsinclude:
Endpoints(Laptops, Workstations, Mobile Devices)
Servers(On-premise or cloud-based)
Networking Devices(Routers, Firewalls, Switches)
Applications(Software, Cloud-based tools)
Databases(Storage of FCI or CUI)
Since the IT manager is focusing on these components, the correct asset category isTechnology (Option D).
A . ESP (Security Protection Assets)Incorrect. ESPs refer tosecurity-related assets(e.g., firewalls, monitoring tools, managed security services) thathelp protectFCI/CUI but do notstore, process, or transmitit directly.
B . PeopleIncorrect. While employees play a role in handling FCI, the question focuses onhardware and software---which falls underTechnology, not People.
C . FacilitiesIncorrect. Facilities refer tophysical buildingsor secured areas where FCI/CUI is stored or processed. The question explicitly mentionsservers, laptops, and applications, which arenot physical facilities.
Why the Other Answers Are Incorrect
CMMC Level 1 Scoping Guide (CMMC-AB)-- Defines asset categories, including Technology.
CMMC 2.0 Scoping Guidance for Assessors-- Provides clarification on FCI assets.
CMMC Official ReferenceThus,option D (Technology) is the most correct choiceas per official CMMC 2.0 guidance.
Talia
27 days agoFannie
2 months agoElly
2 months agoJohnna
2 months agoLyla
2 months agoShawnta
2 months agoRikki
2 months agoSommer
3 months agoCheryl
3 months agoKayleigh
3 months agoMarkus
3 months agoCarlee
3 months agoYolande
3 months agoAudra
4 months agoAntonio
4 months agoOlen
4 months agoLemuel
4 months agoGeoffrey
5 months agoBlondell
5 months agoAnnmarie
5 months agoMalinda
5 months agoCatarina
5 months agoAmie
6 months agoLucina
6 months agoJosefa
6 months agoCecil
6 months agoJonell
11 days agoNan
17 days agoKina
22 days agoSheron
4 months ago