Q: 6
When assessing a contractor’s implementation of CMMC requirements, you realize they have
multiple data centers and regional offices, each having its access control mechanisms and security
perimeter. The contractor uses a remote access solution to allow external partners and employees to
collaborate on projects that involve CUI. The solution requires routing configuration to ensure the
remote access to CUI is not compromised. In assessing the contractor's implementation of AC.L2-
3.1.14 – Remote Access Routing, what must you determine?
Options
Discussion
B. That's the only option that hits all the requirements for managed network access control points with remote access per CMMC AC.L2-3.1.14.
Makes sense to pick B here. The standard wants you to verify if remote access is routed through managed control points, not just that users are authenticated. Pretty sure that's what AC.L2-3.1.14 is really about, but let me know if you see it differently.
Probably B. Only that one specifically calls out identifying and routing remote access through managed control points per CMMC.
Yeah, I've seen similar wording in exam reports. Managed access points and routing all remote connections through them is key for this CMMC control. Option B matches what the standard actually requires.
I remember a similar scenario from labs, and it matched up with B. Routing remote access through managed network access control points is exactly what's needed for AC.L2-3.1.14 compliance. Pretty sure that's right here, but if anyone disagrees let me know.
D tbh, since authenticating all users before remote access feels like the main security check for most remote access controls. If only authenticated users get in, that should protect CUI, right? Maybe I'm missing something with the routing aspect, but I'd still pick D given the question's phrasing. Open to being corrected if others see it differently.
B
C vs D. Had something like this in a mock and I went with D since it sounded more about authenticating users for remote access, which seemed to match the control. Not totally confident here though, open to other views.
D
Be respectful. No spam.