FedRAMP Cloud Security & Governance 3 — Questions and Answers
Question 1: What is the minimum frequency required for vulnerability scanning of operating systems under FedRAMP Moderate baseline?
- Annually
- Quarterly
- Monthly (Correct answer)
- Weekly
Correct answer: Monthly
FedRAMP Moderate requires OS vulnerability scans at least monthly, with web application and database scans also on a monthly basis.
Question 2: In FedRAMP governance, which entity is responsible for issuing a Provisional Authority to Operate (P-ATO)?
- Individual federal agencies
- Joint Authorization Board (JAB) (Correct answer)
- Department of Homeland Security
- NIST
Correct answer: Joint Authorization Board (JAB)
The Joint Authorization Board, composed of CIOs from DoD, DHS, and GSA, issues Provisional ATOs for cloud services with government-wide use potential.
Question 3: Which FedRAMP program allows low-risk SaaS applications to achieve authorization using a smaller, tailored set of controls?
- FedRAMP High
- FedRAMP Tailored (LI-SaaS) (Correct answer)
- FedRAMP Moderate
- FedRAMP Accelerated
Correct answer: FedRAMP Tailored (LI-SaaS)
FedRAMP Tailored LI-SaaS provides a reduced control set for low-impact software-as-a-service that processes only non-sensitive, publicly available information.
Question 4: What does 'continuous monitoring' mean in the context of FedRAMP authorization maintenance?
- Automated real-time blocking of all threats
- Ongoing assessment of security controls to maintain ATO over time (Correct answer)
- Annual third-party re-assessment of all controls
- Daily manual review of system logs by the agency ISSO
Correct answer: Ongoing assessment of security controls to maintain ATO over time
FedRAMP continuous monitoring is an ongoing program of security assessments, vulnerability management, and reporting to maintain an authorization's validity.
Question 5: Under FedRAMP, how must a CSP report a significant security incident to the federal government?
- Within 72 hours to the affected agencies only
- Within 1 hour to US-CERT and affected agencies (Correct answer)
- Within 30 days in the next monthly report
- Only if the breach exposes more than 100,000 records
Correct answer: Within 1 hour to US-CERT and affected agencies
FedRAMP requires CSPs to report major incidents to US-CERT and affected agencies within one hour of detection.
Question 6: Which type of interconnection agreement is typically used when a FedRAMP-authorized system connects to an external system not covered by the same ATO?
- Memorandum of Understanding (MOU)
- Interconnection Security Agreement (ISA) (Correct answer)
- Business Associate Agreement (BAA)
- End User License Agreement (EULA)
Correct answer: Interconnection Security Agreement (ISA)
An Interconnection Security Agreement documents the security requirements and rules of behavior for connecting two separate information systems.
Question 7: What is the significance of the FedRAMP Marketplace for federal agencies?
- It is where agencies purchase cloud licenses at discounted rates
- It lists cloud services that have achieved or are pursuing FedRAMP authorization (Correct answer)
- It provides a procurement portal for hardware acquisition
- It tracks all federal contractor compliance with FISMA
Correct answer: It lists cloud services that have achieved or are pursuing FedRAMP authorization
The FedRAMP Marketplace is a public registry showing which cloud services are FedRAMP Authorized, In Process, or FedRAMP Ready, helping agencies identify approved options.
What is the minimum frequency required for vulnerability scanning of operating systems under FedRAMP Moderate baseline?