CGRC Continuous Monitoring 3 — Questions and Answers
Question 1: Under the NIST RMF, which step explicitly incorporates continuous monitoring activities into the system authorization lifecycle?
- Step 3 – Implement
- Step 4 – Assess
- Step 6 – Monitor (Correct answer)
- Step 5 – Authorize
Correct answer: Step 6 – Monitor
Step 6 (Monitor) of the NIST RMF is dedicated to ongoing monitoring of security and privacy controls, organizational risk posture, and reporting security status.
Question 2: An organization uses automated tools to continuously collect security data but never analyzes or acts on the reports. Which ISCM principle is being violated?
- Defense in depth
- Tiered risk management
- Analyze and report findings (Correct answer)
- Least privilege
Correct answer: Analyze and report findings
Collecting data without analysis and action defeats the purpose of ISCM; findings must be reviewed and drive corrective actions.
Question 3: Which type of control assessment is MOST consistent with a mature continuous monitoring program?
- Comprehensive manual assessments conducted every three years
- Automated testing of selected controls on a defined, ongoing schedule (Correct answer)
- Annual penetration tests of all external-facing systems
- Quarterly interviews with system owners about control effectiveness
Correct answer: Automated testing of selected controls on a defined, ongoing schedule
Mature ISCM programs rely on automated, scheduled testing of controls to provide near-real-time data on control effectiveness.
Question 4: A compliance team wants to demonstrate that their continuous monitoring program supports FedRAMP requirements. Which reporting artifact is most critical?
- System Security Plan (SSP) update log
- Plan of Action and Milestones (POA&M)
- Continuous Monitoring Plan with defined metrics and reporting frequencies (Correct answer)
- Annual security awareness training completion report
Correct answer: Continuous Monitoring Plan with defined metrics and reporting frequencies
FedRAMP requires a Continuous Monitoring Plan that specifies which controls are monitored, at what frequency, and how results are reported to the authorizing official.
Question 5: What is the role of the 'security status report' in an ISCM program?
- It replaces the System Security Plan after authorization
- It communicates the current state of implemented controls and risk posture to authorizing officials (Correct answer)
- It documents all corrective actions taken during the reporting period
- It provides audit evidence for annual compliance reviews
Correct answer: It communicates the current state of implemented controls and risk posture to authorizing officials
The security status report provides authorizing officials with timely updates on control effectiveness, vulnerabilities, and overall risk so they can make informed ongoing authorization decisions.
Question 6: An organization's ISCM program flags a critical misconfiguration but the POA&M shows it was remediated six months ago. What does this most likely indicate?
- The ISCM tool is generating false positives
- The POA&M was not updated after remediation, indicating a process breakdown
- The vulnerability was re-introduced after remediation (Correct answer)
- The authorizing official did not approve the remediation
Correct answer: The vulnerability was re-introduced after remediation
When a monitoring tool re-flags a previously remediated item, the most likely cause is re-introduction of the vulnerability, not a false positive.
Question 7: Which concept describes the practice of adjusting monitoring rigor based on a system's categorization level and data sensitivity?
- Risk-based monitoring (Correct answer)
- Blanket assessment
- Threat modeling
- Control inheritance
Correct answer: Risk-based monitoring
Risk-based monitoring allocates more intensive oversight to higher-impact, higher-risk systems while applying lighter monitoring to low-impact systems.
Under the NIST RMF, which step explicitly incorporates continuous monitoring activities into the system authorization lifecycle?