CGRC Continuous Monitoring 5 — Questions and Answers
Question 1: A system owner receives a security status report showing a high-risk finding that has been open for 90 days with no remediation progress. What ISCM process should be triggered?
- Automatic system decommissioning
- Escalation to the authorizing official with a revised POA&M and risk acceptance decision (Correct answer)
- Immediate system shutdown pending remediation
- Transfer of the finding to the next annual assessment cycle
Correct answer: Escalation to the authorizing official with a revised POA&M and risk acceptance decision
Unresolved high-risk findings must be escalated to the AO, who can require accelerated remediation, accept residual risk, or revoke authorization.
Question 2: What is the primary benefit of integrating threat intelligence feeds into a continuous monitoring program?
- Eliminating the need for internal vulnerability assessments
- Providing context about active threats to prioritize monitoring and response activities (Correct answer)
- Automating all incident response actions
- Replacing periodic penetration testing requirements
Correct answer: Providing context about active threats to prioritize monitoring and response activities
Threat intelligence feeds help organizations understand which threats are actively targeting their sector, allowing them to prioritize monitoring efforts on the most relevant risks.
Question 3: Under FISMA, how frequently must agencies report security status to OMB and DHS?
- Monthly
- Quarterly
- Annually (Correct answer)
- On a continuous basis using automated tools
Correct answer: Annually
FISMA requires federal agencies to report their security posture to OMB and DHS annually, though continuous monitoring data informs those reports.
Question 4: Which approach BEST supports continuous monitoring in a DevSecOps pipeline?
- Running security scans on finished products before deployment
- Embedding automated security testing and compliance checks at every stage of the CI/CD pipeline (Correct answer)
- Conducting manual code reviews for all commits
- Limiting continuous monitoring to production environments
Correct answer: Embedding automated security testing and compliance checks at every stage of the CI/CD pipeline
Embedding automated security checks throughout the CI/CD pipeline (shift-left) enables continuous monitoring from code commit through deployment, catching issues early.
Question 5: An ISCM program identifies that a critical control is consistently failing across multiple systems but no corrective action has been taken for months. What organizational issue does this most likely reflect?
- Insufficient monitoring tool coverage
- A lack of governance mechanisms to drive remediation from monitoring findings to closure (Correct answer)
- Overly aggressive monitoring frequency generating alert fatigue
- Inaccurate risk categorization of the affected systems
Correct answer: A lack of governance mechanisms to drive remediation from monitoring findings to closure
When findings persist without remediation, the root cause is typically a governance gap — no clear ownership, accountability, or escalation process to turn monitoring data into action.
Question 6: Which element of the ISCM strategy defines what will be monitored, how often, and by what means?
- Security Assessment Report (SAR)
- Monitoring strategy with defined metrics, frequencies, and automated tools (Correct answer)
- Risk Register
- System Security Plan (SSP) control implementation statements
Correct answer: Monitoring strategy with defined metrics, frequencies, and automated tools
The ISCM monitoring strategy document specifies the scope, metrics, frequencies, responsible parties, and tools that govern the entire program.
Question 7: A CGRC professional is asked to evaluate whether an organization's continuous monitoring program is mature. Which capability BEST distinguishes a mature program from a basic one?
- Possession of a SIEM tool
- Documented security policies referencing continuous monitoring
- Automated, risk-based monitoring with closed-loop remediation tracking and executive dashboards (Correct answer)
- Annual vulnerability scans covering all in-scope systems
Correct answer: Automated, risk-based monitoring with closed-loop remediation tracking and executive dashboards
A mature ISCM program combines automation, risk-prioritized coverage, closed-loop tracking of remediation, and meaningful reporting to leadership — not just tool ownership or policy documentation.
A system owner receives a security status report showing a high-risk finding that has been open for 90 days with no remediation progress.
What ISCM process should be triggered?