FedRAMP Cloud Security & Governance 4 — Questions and Answers
Question 1: Which FIPS standard governs the encryption algorithms approved for protecting federal data in FedRAMP-authorized systems?
- FIPS 140-2/140-3 (Correct answer)
- FIPS 199
- FIPS 200
- FIPS 186-4
Correct answer: FIPS 140-2/140-3
FIPS 140-2 (and its successor FIPS 140-3) specifies requirements for cryptographic modules used to protect sensitive federal information.
Question 2: In FedRAMP, what categorization standard determines whether a system is Low, Moderate, or High impact?
- NIST SP 800-53
- FIPS 199 (Correct answer)
- NIST SP 800-37
- OMB Circular A-130
Correct answer: FIPS 199
FIPS 199 defines standards for security categorization of federal information and information systems based on confidentiality, integrity, and availability impact levels.
Question 3: What is a FedRAMP 'inherited control' in the context of a SaaS built on an IaaS platform?
- A control the SaaS vendor must implement independently
- A control implemented by the underlying IaaS that the SaaS can rely upon (Correct answer)
- A control waived by the authorizing official
- A control that only applies during the assessment phase
Correct answer: A control implemented by the underlying IaaS that the SaaS can rely upon
Inherited controls are security controls already implemented by an underlying platform (e.g., IaaS/PaaS) that a higher-layer service can leverage rather than re-implement.
Question 4: Which FedRAMP requirement addresses supply chain risk management for cloud service providers?
- Only FISMA applies to supply chain
- SA-12 Supply Chain Protection control family (Correct answer)
- FedRAMP does not address supply chain risks
- Only export control regulations cover this area
Correct answer: SA-12 Supply Chain Protection control family
The SA-12 (and broader SA control family) addresses supply chain protection, requiring CSPs to manage risks from third-party components, software, and services.
Question 5: What is the purpose of the FedRAMP Security Assessment Framework (SAF)?
- To provide a uniform approach for assessing cloud services against FedRAMP requirements (Correct answer)
- To replace NIST RMF for cloud environments only
- To set pricing standards for FedRAMP assessments
- To automate continuous monitoring without human involvement
Correct answer: To provide a uniform approach for assessing cloud services against FedRAMP requirements
The FedRAMP SAF provides a standardized methodology for how 3PAOs assess and document CSP compliance with FedRAMP security controls.
Question 6: Under FedRAMP, which document captures the 3PAO's findings after performing a security assessment?
- System Security Plan (SSP)
- Security Assessment Report (SAR) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Authorization Decision Letter
Correct answer: Security Assessment Report (SAR)
The Security Assessment Report documents the 3PAO's assessment methodology, findings, identified risks, and residual vulnerabilities after testing.
Question 7: What FedRAMP requirement applies to multi-factor authentication for privileged users accessing a Moderate-impact system?
- MFA is optional if compensating controls are in place
- MFA is required for all privileged user access (Correct answer)
- MFA is only required for external-facing portals
- MFA requirements only apply to High-impact systems
Correct answer: MFA is required for all privileged user access
FedRAMP Moderate requires multi-factor authentication for all privileged accounts, implementing the IA-2 control at the enhanced level.
Which FIPS standard governs the encryption algorithms approved for protecting federal data in FedRAMP-authorized systems?