FedRAMP Continuous Monitoring & Incident Response 5 β Questions and Answers
Question 1: Which automated tool output is accepted by FedRAMP for vulnerability scanning of container-based infrastructure?
- Only Nessus Professional scans
- SCAP-validated or agency-approved container image scanners (Correct answer)
- Manual configuration reviews only
- OWASP ZAP web scans exclusively
Correct answer: SCAP-validated or agency-approved container image scanners
FedRAMP accepts SCAP-validated tools and agency-approved container image scanners for vulnerability scanning of container environments.
Question 2: A CSP's POA&M shows a high vulnerability that is 45 days past its required remediation date. What must the CSP do?
- Automatically escalate to a breach notification
- Immediately revoke the ATO
- Submit a remediation plan update and notify the AO of the delay (Correct answer)
- Close the item and re-open after remediation
Correct answer: Submit a remediation plan update and notify the AO of the delay
For overdue POA&M items, CSPs must update the remediation plan with revised dates and proactively notify the AO of any delays.
Question 3: What is the role of the FedRAMP PMO in the continuous monitoring of an agency-authorized (non-JAB) cloud system?
- The PMO acts as the authorizing official for all agency systems
- The PMO provides oversight tools and templates but the agency AO retains primary responsibility (Correct answer)
- The PMO conducts monthly scans on behalf of the CSP
- The PMO has no role in agency-authorized systems
Correct answer: The PMO provides oversight tools and templates but the agency AO retains primary responsibility
For agency-authorized systems, the agency AO retains authority while the FedRAMP PMO provides standardized templates, tools, and program guidance.
Question 4: Which incident response activity is most critical for maintaining the chain of custody during a FedRAMP security investigation?
- Sending email notifications to stakeholders
- Documenting every action taken on evidence with timestamps and signatures (Correct answer)
- Running additional vulnerability scans
- Immediately restoring systems from backup
Correct answer: Documenting every action taken on evidence with timestamps and signatures
Chain of custody requires meticulous documentation of who handled evidence, when, and what actions were taken to ensure evidence integrity for potential legal proceedings.
Question 5: Under FedRAMP ConMon, when must a CSP perform a penetration test?
- Every 6 months
- Only at initial authorization
- Annually and after significant changes (Correct answer)
- Only when requested by the AO
Correct answer: Annually and after significant changes
FedRAMP requires annual penetration testing as well as penetration testing following any significant changes to the authorization boundary.
Question 6: A new agency wants to reuse an existing FedRAMP authorized system. Which document does the new agency AO review to understand inherited controls?
- The 3PAO's penetration test report
- The CSP's customer responsibility matrix (CRM) within the SSP (Correct answer)
- The CSP's incident response logs
- The FedRAMP marketplace listing only
Correct answer: The CSP's customer responsibility matrix (CRM) within the SSP
The Customer Responsibility Matrix within the SSP delineates which controls are CSP-managed, customer-managed, or shared, informing agency risk decisions.
Question 7: Which FedRAMP ConMon requirement specifically addresses the need for CSPs to monitor for unauthorized configuration changes?
- Vulnerability scanning (RA-5)
- Configuration management monitoring (CM-3, CM-6) (Correct answer)
- Incident response testing (IR-3)
- Access control reviews (AC-2)
Correct answer: Configuration management monitoring (CM-3, CM-6)
NIST controls CM-3 (Configuration Change Control) and CM-6 (Configuration Settings) require continuous monitoring for unauthorized configuration changes in FedRAMP systems.
Which automated tool output is accepted by FedRAMP for vulnerability scanning of container-based infrastructure?