Q: 9
An aerospace company bids on a DoD contract that requires CMMC Level 2 compliance. The
company has multiple divisions, but only the Manufacturing Division will work on the project. The
Manufacturing Division has its own IT infrastructure and security policies, but it relies on
thecompany’s centralized IT department for some administrative tasks. Which unit will be assessed
for CMMC Level 2 compliance?
Options
Discussion
Makes sense that C is the scope since both units touch admin tasks but I'm still not 100% sure.
C/D? Had this exact scenario in my exam last year, C was the answer.
Pretty sure it's C. Manufacturing is in scope because they're handling CUI, but the centralized IT group does admin for them which makes their assets Security Protection Assets under CMMC guidance. So both must be assessed. I think that's how the scoping guidance reads, but open to correction if anyone interprets it differently.
Its A for me. Since only the Manufacturing Division is directly involved in the contract work, that should be the focus for CMMC Level 2 assessment. Saw some sample questions pushing just the unit working with CUI. The official practice test might help clarify if I'm missing something.
Maybe C. Saw a similar question on practice where both the division and centralized IT had to be assessed together.
A is wrong, C fits better here. CMMC scope catches both the Manufacturing Division and centralized IT since admin work from IT counts them as Security Protection Assets. That lines up with what the official CMMC docs and practice tests say, pretty sure about this. Check the official guide for details if unsure.
A is wrong, C is correct since centralized IT touches admin and that drags them into the scope as Security Protection Assets. That’s what the CMMC scoping docs say. Unless IT was totally hands-off, they can’t be excluded.
Yeah, it should be C. As long as centralized IT is doing anything admin-related for the Manufacturing folks, their systems are in-scope as Security Protection Assets per CMMC rules. Not just the Manufacturing division alone. Correct me if I'm missing something but that's how I've seen it handled.
C vs A. Centralized IT does admin work for Manufacturing, so both get scoped according to CMMC guidance.
Pretty sure it's C here, since both the Manufacturing Division and centralized IT have a role. That's how CMMC scoping usually works.
Be respectful. No spam.