CAP Continuous Monitoring and System Lifecycle 1 — Questions and Answers
Question 1: What is the primary goal of an Information Security Continuous Monitoring (ISCM) program?
- To replace the need for ATOs entirely
- To maintain ongoing awareness of information security, vulnerabilities, and threats (Correct answer)
- To automate all security control implementation
- To reduce the number of security staff required
Correct answer: To maintain ongoing awareness of information security, vulnerabilities, and threats
ISCM maintains situational awareness of the security posture so organizations can make risk-based decisions in a timely manner.
Question 2: NIST SP 800-137 provides guidance on which topic?
- Security categorization
- Incident response
- Information Security Continuous Monitoring (ISCM) for federal systems (Correct answer)
- Penetration testing methodology
Correct answer: Information Security Continuous Monitoring (ISCM) for federal systems
NIST SP 800-137 provides guidance for developing an ISCM strategy and program for federal information systems and organizations.
Question 3: In the context of continuous monitoring, what is a 'security metric'?
- A financial cost associated with a security breach
- A quantifiable measure used to assess the effectiveness of security controls over time (Correct answer)
- A vulnerability severity score
- A user access log entry
Correct answer: A quantifiable measure used to assess the effectiveness of security controls over time
Security metrics provide measurable data on control effectiveness, enabling organizations to track trends and make informed risk decisions.
Question 4: How does continuous monitoring support the RMF Monitor step?
- It replaces the need for security assessments
- It provides ongoing data to ensure controls remain effective and risks are within acceptable levels (Correct answer)
- It automatically grants ATOs without human review
- It eliminates the need for a POA&M
Correct answer: It provides ongoing data to ensure controls remain effective and risks are within acceptable levels
Continuous monitoring feeds ongoing assurance to the AO that the system's security posture remains acceptable between formal re-authorizations.
Question 5: Which tool is commonly used in US federal agencies to automate continuous monitoring data collection?
- FedRAMP Portal
- Continuous Diagnostics and Mitigation (CDM) Dashboard (Correct answer)
- NIST Cybersecurity Framework Tool
- OMB MAX Portal
Correct answer: Continuous Diagnostics and Mitigation (CDM) Dashboard
CISA's CDM program provides federal agencies with tools, integration services, and a dashboard to automate continuous monitoring.
Question 6: Under an ongoing authorization approach, how often must a full re-authorization be conducted?
- Every six months
- Every year
- When risk exceeds defined thresholds rather than on a fixed schedule (Correct answer)
- Every five years regardless of risk
Correct answer: When risk exceeds defined thresholds rather than on a fixed schedule
Ongoing authorization uses continuous monitoring to maintain a current security posture, triggering re-authorization based on risk events rather than time.
What is the primary goal of an Information Security Continuous Monitoring (ISCM) program?