Valid CMMC-CCA Dumps shared by EduDump.com for Helping Passing CMMC-CCA Exam! EduDump.com now offer the newest CMMC-CCA exam dumps, the EduDump.com CMMC-CCA exam questions have been updated and answers have been corrected get the newest EduDump.com CMMC-CCA dumps with Test Engine here:
When assessing an environment, the CCA determines that CUI is contained within an IoT device. Which statement MUST be true?
Correct Answer: B
When an IoT device processes, stores, or transmits CUI, it is categorized as a CUI Asset (not CRMA). All in- scope assets must be documented in the System Security Plan (SSP). The SSP must identify how the asset is managed, secured, and integrated into the OSC's environment. Exact Extracts: * CMMC Scoping Guide: "All CUI Assets must be identified and described in the SSP." * "Specialized Assets (including IoT) must be documented in the SSP if they process, store, or transmit CUI." * "Contractor Risk Managed Assets do not include assets that process, store, or transmit CUI." Why other options are not correct: * A: Incorrect, because an IoT device with CUI cannot be a CRMA. * C: Incorrect, IoT can process CUI if properly secured and documented. * D: While true in general (AC control applies), the mandatory requirement is accurate SSP documentation. References: CMMC Assessment Scope - Level 2, Version 2.13: Asset categories (pp. 5-10). CMMC Assessment Guide - Level 2: SSP documentation requirements.