CAP Continuous Monitoring Strategy 1 — Questions and Answers
Question 1: What is the primary goal of continuous monitoring in the context of the RMF?
- To maintain ongoing situational awareness of the security state of information systems and detect changes that affect risk (Correct answer)
- To replace annual FISMA reporting with automated tools
- To eliminate the need for periodic security assessments
- To automate the granting of ATOs without AO review
Correct answer: To maintain ongoing situational awareness of the security state of information systems and detect changes that affect risk
Continuous monitoring provides real-time or near real-time visibility into the security posture of systems so that risk can be managed dynamically.
Question 2: Which NIST publication provides the primary guidance for information security continuous monitoring (ISCM)?
- NIST SP 800-137 (Correct answer)
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-30
Correct answer: NIST SP 800-137
NIST SP 800-137 provides guidance for developing a continuous monitoring strategy and program for federal information systems.
Question 3: What are the six steps of the ISCM process defined in NIST SP 800-137?
- Define, Establish, Implement, Analyze/Report, Respond, Review/Update (Correct answer)
- Plan, Do, Check, Act, Monitor, Report
- Identify, Protect, Detect, Respond, Recover, Adapt
- Prepare, Categorize, Select, Implement, Assess, Authorize
Correct answer: Define, Establish, Implement, Analyze/Report, Respond, Review/Update
NIST SP 800-137 defines the ISCM process as: Define strategy, Establish program, Implement program, Analyze/Report findings, Respond to findings, and Review/Update the program.
Question 4: What is a Security Information and Event Management (SIEM) system's primary role in continuous monitoring?
- To aggregate, correlate, and analyze security event logs from across the enterprise in near real-time (Correct answer)
- To replace firewalls with AI-driven packet inspection
- To generate the System Security Plan automatically
- To serve as the primary vulnerability scanner
Correct answer: To aggregate, correlate, and analyze security event logs from across the enterprise in near real-time
A SIEM collects logs from multiple sources, correlates events, and generates alerts to enable rapid detection of security incidents.
Question 5: What is the purpose of defining monitoring frequencies in a continuous monitoring strategy?
- To establish how often each control is assessed based on its volatility, importance, and available resources (Correct answer)
- To set how many times per year the AO must review the system
- To define the schedule for penetration tests only
- To comply with mandatory daily scanning requirements
Correct answer: To establish how often each control is assessed based on its volatility, importance, and available resources
Monitoring frequencies are tailored to each control based on how often it changes, its criticality, and the resources available to monitor it.
Question 6: How does continuous monitoring support the 'Monitor' step of the RMF?
- By providing ongoing assessment of controls, documenting changes, and reporting security status to the AO (Correct answer)
- By generating the initial SSP before authorization
- By replacing the need for the security assessment report
- By automating POA&M remediation without human involvement
Correct answer: By providing ongoing assessment of controls, documenting changes, and reporting security status to the AO
The Monitor step of the RMF is implemented through a continuous monitoring program that tracks control effectiveness and reports status to decision-makers.
What is the primary goal of continuous monitoring in the context of the RMF?