FedRAMP Cloud Security & Governance 2 — Questions and Answers
Question 1: Which FedRAMP impact level is required for cloud systems processing information where loss of confidentiality could cause severe or catastrophic harm to national security?
- Low
- Moderate
- High (Correct answer)
- Critical
Correct answer: High
FedRAMP High is required when unauthorized disclosure could cause severe or catastrophic adverse effects on national security, government operations, or individuals.
Question 2: In FedRAMP, what is the purpose of the Plan of Action and Milestones (POA&M)?
- Document the system's authorization boundary
- Track and manage remediation of security weaknesses (Correct answer)
- List all authorized cloud service providers
- Define the continuous monitoring strategy
Correct answer: Track and manage remediation of security weaknesses
A POA&M documents identified security weaknesses, their risk levels, and the planned corrective actions with target completion dates.
Question 3: What NIST publication serves as the primary source for the security control baselines used in FedRAMP?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-137
- NIST SP 800-171
Correct answer: NIST SP 800-53
NIST SP 800-53 provides the catalog of security and privacy controls from which FedRAMP derives its Low, Moderate, and High baselines.
Question 4: Which cloud deployment model is most commonly associated with FedRAMP authorizations?
- Private cloud hosted on-premises
- Public cloud or government community cloud (Correct answer)
- Hybrid cloud with no federal data
- Edge computing nodes
Correct answer: Public cloud or government community cloud
FedRAMP primarily governs public cloud and government community cloud services used by federal agencies to store, process, or transmit federal data.
Question 5: What is the role of a Third Party Assessment Organization (3PAO) in the FedRAMP process?
- Grants the Authority to Operate to a CSP
- Independently assesses and validates a CSP's security controls (Correct answer)
- Manages the FedRAMP Marketplace listings
- Monitors CSP systems daily on behalf of agencies
Correct answer: Independently assesses and validates a CSP's security controls
A 3PAO is an accredited independent assessor that evaluates whether a CSP's security controls meet FedRAMP requirements.
Question 6: Under FedRAMP, which document formally describes the boundary of a cloud system and the controls implemented to protect it?
- System Security Plan (SSP) (Correct answer)
- Security Assessment Report (SAR)
- Authorization Decision Letter
- Incident Response Plan
Correct answer: System Security Plan (SSP)
The System Security Plan describes the authorization boundary, the environment of operations, and how each security control is implemented.
Question 7: Which FedRAMP authorization path allows agencies to reuse an existing security assessment package from another agency?
- Agency Authorization only
- FedRAMP Tailored
- Authorization to Operate reuse (leverage) (Correct answer)
- JAB Provisional ATO
Correct answer: Authorization to Operate reuse (leverage)
FedRAMP's 'reuse' model lets agencies leverage an existing ATO package—either a JAB P-ATO or another agency ATO—rather than requiring a new full assessment.
Which FedRAMP impact level is required for cloud systems processing information where loss of confidentiality could cause severe or catastrophic harm to national security?