CGRC Authorization Process 3 — Questions and Answers
Question 1: An Authorizing Official Designated Representative (AODR) may perform all AO functions EXCEPT:
- Reviewing the authorization package
- Coordinating with the security assessment team
- Signing the authorization decision document (Correct answer)
- Communicating risk concerns to the AO
Correct answer: Signing the authorization decision document
The AODR can perform most AO functions but cannot sign the actual authorization decision — that responsibility cannot be further delegated.
Question 2: What is the primary purpose of the Plan of Action and Milestones (POA&M) in the authorization process?
- To document the system's operational boundaries
- To track remediation of identified security weaknesses (Correct answer)
- To assign risk categorization to information types
- To define the security control baseline
Correct answer: To track remediation of identified security weaknesses
The POA&M documents known security weaknesses and the plans, resources, and milestones for correcting them.
Question 3: A cloud service provider seeks authorization to serve multiple federal agencies through a single assessment. This approach is called:
- Joint Authorization
- Reciprocity Agreement
- FedRAMP Authorization (Correct answer)
- Delegated Authorization
Correct answer: FedRAMP Authorization
FedRAMP provides a standardized approach for cloud service providers to obtain a single authorization that multiple federal agencies can leverage.
Question 4: When an agency accepts the existing authorization of a system operated by another agency, this is known as:
- Mutual recognition
- Authorization reciprocity (Correct answer)
- Joint authorization
- Delegated authorization
Correct answer: Authorization reciprocity
Authorization reciprocity allows agencies to accept each other's authorizations, reducing duplicative assessment effort.
Question 5: Which factor most directly determines the length of an ATO authorization period?
- The system's categorization level (Low/Moderate/High)
- Organizational policy and the AO's risk acceptance decision (Correct answer)
- The number of controls assessed
- The vendor's software support lifecycle
Correct answer: Organizational policy and the AO's risk acceptance decision
The ATO period is determined by organizational policy and the AO's judgment about acceptable risk over time, not automatically by categorization.
Question 6: A denial of authorization (DATO) most likely results in which immediate action?
- Escalation to the CIO for override
- Shutdown or disconnection of the system (Correct answer)
- Immediate remediation of all findings
- Transfer of system ownership
Correct answer: Shutdown or disconnection of the system
A denial of authorization means the system cannot operate; it must be shut down or disconnected until risks are sufficiently mitigated.
Question 7: In the RMF, the 'Authorize' step occurs after which step?
- Select
- Implement
- Assess (Correct answer)
- Categorize
Correct answer: Assess
Authorization follows the Assess step, because the AO needs assessment results to make an informed authorization decision.
An Authorizing Official Designated Representative (AODR) may perform all AO functions EXCEPT: