CISSP Asset Security Practice Question
What is the primary purpose of a configuration management database (CMDB) in asset management?
⚠ Common exam trap
CISSP often tests the confusion between a CMDB and other asset management tools, leading candidates to choose software license tracking or network monitoring as the primary purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Provide a repository of configuration items and their relationships
The primary purpose of a configuration management database (CMDB) is to provide a repository of configuration items (CIs) and their relationships, enabling IT service management processes like change management, incident management, and asset management. It tracks the components of an IT environment and how they interconnect.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Monitor network traffic for anomalies
Why it's wrong here
A Configuration Management Database (CMDB) is a static repository of IT asset information and their interdependencies, not an active monitoring system. Monitoring network traffic for anomalies is a dynamic, real-time function performed by Network Intrusion Detection Systems (NIDS), Security Information and Event Management (SIEM) platforms, or Network Performance Monitoring (NPM) tools. These systems analyze packet flows and log data to identify unusual patterns indicative of security incidents or performance issues, which is distinct from the CMDB's role in maintaining configuration data.
- ✗
Store and manage data classification labels
Why it's wrong here
Storing and managing data classification labels, such as "Confidential" or "Public," is primarily a function of Data Loss Prevention (DLP) systems, Information Rights Management (IRM) solutions, or dedicated data governance platforms. While a CMDB might contain metadata about systems that process classified data, its core purpose is to manage the configuration of IT infrastructure components, not the sensitivity or classification of the data residing on or processed by those components. Data classification focuses on the information itself, whereas a CMDB focuses on the assets.
- ✗
Track software licenses and compliance
Why it's wrong here
Tracking software licenses and ensuring compliance with vendor agreements is the primary responsibility of Software Asset Management (SAM) systems. While a CMDB may contain records of installed software as configuration items, its scope does not typically extend to the detailed management of license entitlements, usage metrics, or complex compliance calculations required by SAM. SAM tools specifically manage the lifecycle of software assets from procurement to retirement, optimizing costs and mitigating legal risks associated with under- or over-licensing.
- ✓
Provide a repository of configuration items and their relationships
Why this is correct
The fundamental purpose of a Configuration Management Database (CMDB) is to serve as a centralized repository for all relevant information about Configuration Items (CIs) within an IT environment. CIs encompass any component, service, or other asset that needs to be managed to deliver an IT service, such as servers, applications, networks, and documentation. Crucially, the CMDB also meticulously maps the interdependencies and relationships between these CIs, providing a holistic view that is vital for impact analysis, incident resolution, and change management processes.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Incident management
Incident management is the process of identifying, logging, prioritizing, and resolving IT service disruptions to restore normal operations as quickly as possible with minimal business impact.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.