FedRAMP Continuous Monitoring & Incident Response 4 — Questions and Answers
Question 1: Which FedRAMP ConMon deliverable must CSPs submit to the FedRAMP PMO on a monthly basis?
- Full security assessment report
- Vulnerability scan results and updated POA&M (Correct answer)
- Penetration test results
- Updated System Security Plan
Correct answer: Vulnerability scan results and updated POA&M
CSPs must submit monthly vulnerability scan results and an updated POA&M to demonstrate ongoing remediation progress.
Question 2: During incident response containment, a CSP isolates a compromised virtual machine. Which action should occur FIRST before isolation?
- Notify all system users
- Capture forensic memory image and logs (Correct answer)
- Patch the vulnerability
- Decommission the VM permanently
Correct answer: Capture forensic memory image and logs
Forensic preservation of volatile evidence (memory, logs) must occur before isolation to avoid losing critical investigation data.
Question 3: A CSP operating under a FedRAMP ATO discovers a zero-day vulnerability in a core component. What is the FIRST required action?
- Immediately patch all affected systems
- Add it to the POA&M with a 30-day remediation plan
- Notify the AO and agency customers per the incident response plan (Correct answer)
- Request a temporary deviation from the AO
Correct answer: Notify the AO and agency customers per the incident response plan
Zero-day vulnerabilities with active exploitation risk must be reported to the AO and affected agencies immediately per the incident response plan before other remediation steps.
Question 4: In FedRAMP ConMon, what distinguishes an 'operational requirement' deviation from a 'risk acceptance' deviation?
- Operational requirements are temporary; risk acceptances are permanent
- Operational requirements justify why a control cannot be implemented; risk acceptances acknowledge a known weakness will remain (Correct answer)
- Risk acceptances require 3PAO review; operational requirements do not
- There is no distinction—both terms are interchangeable in FedRAMP
Correct answer: Operational requirements justify why a control cannot be implemented; risk acceptances acknowledge a known weakness will remain
An operational requirement deviation explains why a control is technically not implementable, while a risk acceptance acknowledges an implementable control is knowingly not being applied.
Question 5: Which continuous monitoring capability is specifically required for FedRAMP High systems but NOT explicitly mandated for Moderate systems?
- Web application scanning
- Daily automated vulnerability scanning (Correct answer)
- POA&M maintenance
- Incident response planning
Correct answer: Daily automated vulnerability scanning
FedRAMP High requires daily automated vulnerability scanning of databases and web applications, exceeding the Moderate requirement.
Question 6: What does the FedRAMP 'significant change' process require a CSP to do BEFORE implementing the change?
- Notify US-CERT
- Obtain AO approval and update the SSP (Correct answer)
- Conduct a full 3PAO assessment
- Pause all active POA&M items
Correct answer: Obtain AO approval and update the SSP
CSPs must notify and obtain approval from the AO and update the SSP before implementing significant changes to their FedRAMP environment.
Question 7: In the context of FedRAMP incident response, what is the definition of a 'major incident' per OMB guidance?
- Any incident requiring system downtime
- A breach affecting 100 or more individuals
- An incident that is likely to cause demonstrable harm to national security interests or more than de minimis impact (Correct answer)
- Any vulnerability with CVSS score above 7.0
Correct answer: An incident that is likely to cause demonstrable harm to national security interests or more than de minimis impact
OMB M-16-03 defines a major incident as one likely to cause demonstrable harm to national security interests, foreign relations, or the economy, or public confidence.
Which FedRAMP ConMon deliverable must CSPs submit to the FedRAMP PMO on a monthly basis?