FedRAMP Cloud Security & Governance 5 — Questions and Answers
Question 1: Which FedRAMP deliverable must a CSP submit monthly as part of its continuous monitoring obligations?
- Updated System Security Plan
- Vulnerability scan results and POA&M updates (Correct answer)
- Full security assessment by the 3PAO
- New Authorization Decision Letter
Correct answer: Vulnerability scan results and POA&M updates
CSPs must provide monthly vulnerability scan results and updated POA&M status to authorizing officials and the FedRAMP PMO as part of continuous monitoring.
Question 2: In FedRAMP governance, what is the role of the Authorizing Official (AO)?
- Performs the technical security assessment of the CSP
- Accepts the residual risk and grants or denies the ATO (Correct answer)
- Manages the FedRAMP Marketplace listings
- Conducts daily monitoring of the CSP's environment
Correct answer: Accepts the residual risk and grants or denies the ATO
The Authorizing Official is a senior agency official who reviews the authorization package and formally accepts residual risk by signing the ATO letter.
Question 3: What is 'FedRAMP Ready' status on the Marketplace, and how does it differ from 'FedRAMP Authorized'?
- They are synonymous terms used interchangeably
- FedRAMP Ready means a 3PAO has confirmed readiness; Authorized means an ATO has been granted (Correct answer)
- FedRAMP Ready is a higher-tier designation than Authorized
- FedRAMP Ready applies only to JAB authorizations
Correct answer: FedRAMP Ready means a 3PAO has confirmed readiness; Authorized means an ATO has been granted
FedRAMP Ready indicates a 3PAO has validated the CSP's readiness for full assessment, while FedRAMP Authorized means an ATO (agency or JAB) has been officially granted.
Question 4: Which control family in NIST SP 800-53 addresses audit logging requirements that FedRAMP inherits for cloud systems?
- Access Control (AC)
- Audit and Accountability (AU) (Correct answer)
- Configuration Management (CM)
- Incident Response (IR)
Correct answer: Audit and Accountability (AU)
The Audit and Accountability (AU) control family specifies requirements for event logging, log content, log protection, and log review in federal systems.
Question 5: When a CSP wants to make a significant change to a FedRAMP-authorized system, what process must they follow?
- No formal process is required for changes after initial ATO
- Submit a Significant Change Request (SCR) and obtain approval before implementing (Correct answer)
- Implement the change and notify the PMO in the next monthly report
- Immediately revoke the ATO and restart the full authorization process
Correct answer: Submit a Significant Change Request (SCR) and obtain approval before implementing
Significant changes to authorized systems require a Significant Change Request submitted to the authorizing agency and PMO for review and approval prior to implementation.
Question 6: What does the principle of 'least privilege' mean in the context of FedRAMP access control requirements?
- Users receive the maximum access needed to complete all possible tasks
- Users and processes are granted only the minimum access rights necessary for their function (Correct answer)
- All users share a single privileged account for efficiency
- Least privilege only applies to database administrators
Correct answer: Users and processes are granted only the minimum access rights necessary for their function
Least privilege (AC-6) limits user and process access rights to only what is necessary for authorized tasks, reducing the attack surface if credentials are compromised.
Question 7: Under FedRAMP, which of the following is a key requirement for data residency and data sovereignty?
- All federal data must be stored on servers physically located in the continental US
- CSPs must disclose the geographic location of data storage and processing in their SSP (Correct answer)
- Federal data may be stored internationally without restriction if encrypted
- Data residency requirements only apply to classified information
Correct answer: CSPs must disclose the geographic location of data storage and processing in their SSP
FedRAMP requires CSPs to document in the SSP where federal data is stored and processed, and agencies may impose additional geographic restrictions based on data sensitivity.
Which FedRAMP deliverable must a CSP submit monthly as part of its continuous monitoring obligations?