FedRAMP Risk Management Framework & Assessment 3 — Questions and Answers
Question 1: A 3PAO discovers that a CSP has a control that is 'planned but not yet implemented.' How should this be reflected in the FedRAMP package?
- Mark the control as 'compliant' if the plan is detailed enough
- Document it in the POA&M with target completion dates (Correct answer)
- Remove the control from the SSP until implementation is complete
- Issue an automatic denial of the ATO
Correct answer: Document it in the POA&M with target completion dates
Controls that are planned but not yet implemented must be tracked in the Plan of Action & Milestones (POA&M) with specific milestones and target remediation dates.
Question 2: What is the maximum timeframe FedRAMP generally allows for remediating a 'High' severity vulnerability discovered during continuous monitoring?
- 30 days (Correct answer)
- 60 days
- 90 days
- 180 days
Correct answer: 30 days
FedRAMP requires that High severity vulnerabilities be remediated within 30 days of discovery during continuous monitoring activities.
Question 3: Under the FedRAMP Moderate baseline, approximately how many security controls must a CSP implement and document?
- ~100 controls
- ~170 controls
- ~325 controls (Correct answer)
- ~420 controls
Correct answer: ~325 controls
The FedRAMP Moderate baseline requires implementation of approximately 325 security controls drawn from NIST SP 800-53 Rev 5.
Question 4: Which concept describes the practice of combining multiple FedRAMP-authorized services to build a larger system while leveraging existing authorizations?
- Provisional ATO stacking
- Inheritance and leveraging (Correct answer)
- Control aggregation
- Composite authorization
Correct answer: Inheritance and leveraging
Inheritance and leveraging allows agencies and CSPs to reuse security controls already authorized in underlying FedRAMP services, reducing duplicated assessment effort.
Question 5: Which phase of the RMF involves ongoing activities like vulnerability scanning, log review, and security status reporting after an ATO is granted?
- Implement
- Assess
- Authorize
- Monitor (Correct answer)
Correct answer: Monitor
The Monitor phase (step 6 of the RMF) encompasses continuous monitoring activities to ensure the security posture remains acceptable throughout the system's operational life.
Question 6: A CSP wants to use an encryption algorithm not listed in FIPS 140-2 approved modules. What is the correct FedRAMP position on this?
- It is allowed if documented in the SSP
- It is not allowed; only FIPS-validated cryptography is permitted (Correct answer)
- It is allowed if the 3PAO approves the deviation
- It is allowed for data in transit but not data at rest
Correct answer: It is not allowed; only FIPS-validated cryptography is permitted
FedRAMP mandates the use of FIPS 140-2 (or 140-3) validated cryptographic modules; non-approved algorithms are not permitted regardless of documentation.
Question 7: What is the purpose of a 'boundary definition' in a FedRAMP System Security Plan?
- To define the physical perimeter of the CSP's data center
- To delineate exactly which components, services, and data flows are within scope of the authorization (Correct answer)
- To list all network firewalls and their rule sets
- To identify which federal agencies have access to the system
Correct answer: To delineate exactly which components, services, and data flows are within scope of the authorization
The authorization boundary precisely defines what is in scope for the FedRAMP assessment, including all components, interconnections, and data flows subject to the control requirements.
A 3PAO discovers that a CSP has a control that is 'planned but not yet implemented.' How should this be reflected in the FedRAMP package?