FedRAMP Continuous Monitoring & Incident Response 3 — Questions and Answers
Question 1: Which NIST publication provides the primary guidance for continuous monitoring strategies referenced by FedRAMP?
- NIST SP 800-37
- NIST SP 800-137 (Correct answer)
- NIST SP 800-53
- NIST SP 800-61
Correct answer: NIST SP 800-137
NIST SP 800-137, 'Information Security Continuous Monitoring for Federal Information Systems,' is the primary guide for ConMon.
Question 2: A FedRAMP CSP's web application scanner finds a critical vulnerability. What is the maximum remediation timeframe allowed by FedRAMP for critical/high vulnerabilities on a Moderate system?
- 30 days (Correct answer)
- 90 days
- 14 days
- 60 days
Correct answer: 30 days
FedRAMP requires remediation of critical and high vulnerabilities within 30 days for Moderate impact systems.
Question 3: During the 'lessons learned' step of incident response, what is the primary output?
- An updated incident ticket closure
- A post-incident report with process improvements (Correct answer)
- A new vulnerability scan
- A revised POA&M entry
Correct answer: A post-incident report with process improvements
The post-incident report documents what happened, what worked, what didn't, and recommendations for improving the incident response process.
Question 4: Which metric best demonstrates the effectiveness of a FedRAMP continuous monitoring program over time?
- Number of vulnerability scans performed
- Mean time to remediate identified vulnerabilities (Correct answer)
- Total number of open POA&M items
- Frequency of 3PAO assessments
Correct answer: Mean time to remediate identified vulnerabilities
Mean time to remediate (MTTR) measures how quickly vulnerabilities are resolved, directly indicating ConMon program effectiveness.
Question 5: Under FedRAMP, who is authorized to perform the independent annual security assessment of a cloud service offering?
- The CSP's internal security team
- FedRAMP PMO staff
- A FedRAMP-accredited Third-Party Assessment Organization (3PAO) (Correct answer)
- The agency's CISO
Correct answer: A FedRAMP-accredited Third-Party Assessment Organization (3PAO)
Only FedRAMP-accredited 3PAOs may perform the independent security assessments required for initial and ongoing FedRAMP authorization.
Question 6: A FedRAMP incident response plan must define 'incident categories.' Which source provides the standard incident taxonomy used in FedRAMP?
- NIST SP 800-61
- CISA KEV Catalog
- FedRAMP Incident Communications Procedure
- US-CERT Federal Incident Notification Guidelines (Correct answer)
Correct answer: US-CERT Federal Incident Notification Guidelines
The US-CERT Federal Incident Notification Guidelines define the incident categories and severity levels that FedRAMP CSPs must use for reporting.
Question 7: What is the purpose of a FedRAMP 'deviation request' in the context of continuous monitoring?
- To request an extension for an overdue POA&M item
- To formally document an accepted risk or operational requirement that cannot meet a control baseline (Correct answer)
- To notify the AO of a system outage
- To request a change in impact level
Correct answer: To formally document an accepted risk or operational requirement that cannot meet a control baseline
A deviation request formally documents and seeks AO approval for a control implementation that differs from the FedRAMP baseline due to operational constraints.
Which NIST publication provides the primary guidance for continuous monitoring strategies referenced by FedRAMP?