FedRAMP Continuous Monitoring & Incident Response 2 — Questions and Answers
Question 1: Under FedRAMP, how frequently must High-impact systems submit an automated vulnerability scan of their operating system/infrastructure?
- Monthly
- Weekly (Correct answer)
- Daily
- Quarterly
Correct answer: Weekly
FedRAMP High systems must perform OS/infrastructure vulnerability scans weekly.
Question 2: What is the maximum allowable time for a FedRAMP-authorized CSP to report a security incident to US-CERT after discovery?
- 72 hours
- 1 hour
- 24 hours (Correct answer)
- 7 days
Correct answer: 24 hours
FedRAMP requires CSPs to report incidents to US-CERT within 1 hour of discovery for High systems, but the general threshold across impact levels is within 1 hour per NIST SP 800-61.
Question 3: Which FedRAMP document formalizes the ongoing relationship between a CSP and its authorizing official for continuous monitoring?
- Plan of Action & Milestones (POA&M)
- System Security Plan (SSP)
- Continuous Monitoring Strategy (Correct answer)
- Security Assessment Report (SAR)
Correct answer: Continuous Monitoring Strategy
The Continuous Monitoring Strategy document formalizes the ongoing monitoring activities and responsibilities between the CSP and AO.
Question 4: A CSP discovers that an attacker exfiltrated data from a FedRAMP system. Which incident response phase focuses on removing the attacker's foothold?
- Detection & Analysis
- Eradication (Correct answer)
- Containment
- Recovery
Correct answer: Eradication
The Eradication phase involves removing the root cause of the incident, including malware and attacker access.
Question 5: In FedRAMP continuous monitoring, what triggers a requirement for an updated security assessment rather than routine monitoring?
- Annual renewal of the ATO
- A significant change to the system (Correct answer)
- Monthly vulnerability scan results
- Rotation of system administrators
Correct answer: A significant change to the system
Significant changes to a FedRAMP system require an updated security assessment to re-evaluate risk.
Question 6: Which role is responsible for accepting the residual risk in a FedRAMP authorization decision?
- Cloud Service Provider (CSP)
- Authorizing Official (AO) (Correct answer)
- Third-Party Assessment Organization (3PAO)
- FedRAMP PMO
Correct answer: Authorizing Official (AO)
The Authorizing Official formally accepts residual risk and grants or denies the Authority to Operate.
Question 7: What type of FedRAMP artifact must a CSP maintain to track unresolved security weaknesses and planned remediation timelines?
- Security Assessment Plan (SAP)
- Plan of Action & Milestones (POA&M) (Correct answer)
- Incident Response Plan (IRP)
- System Security Plan (SSP)
Correct answer: Plan of Action & Milestones (POA&M)
The POA&M tracks open vulnerabilities and weaknesses along with remediation milestones and responsible parties.
Under FedRAMP, how frequently must High-impact systems submit an automated vulnerability scan of their operating system/infrastructure?