FedRAMP Risk Management Framework & Assessment 4 — Questions and Answers
Question 1: A CSP uses a subcontractor to provide physical data center services. Under FedRAMP, how must this relationship be handled?
- The subcontractor is excluded from FedRAMP scope since they are not the primary CSP
- The subcontractor's services must be included in the CSP's authorization boundary or separately authorized (Correct answer)
- The CSP must obtain a separate ATO for the subcontractor on their behalf
- The agency must directly contract with the subcontractor for security purposes
Correct answer: The subcontractor's services must be included in the CSP's authorization boundary or separately authorized
External services that process, store, or transmit federal data must either be within the CSP's authorization boundary or hold their own FedRAMP authorization that can be leveraged.
Question 2: Which FIPS publication establishes the standards for categorizing federal information and information systems?
- FIPS 140-2
- FIPS 199 (Correct answer)
- FIPS 200
- FIPS 186-4
Correct answer: FIPS 199
FIPS 199, 'Standards for Security Categorization of Federal Information and Information Systems,' defines the Low, Moderate, and High impact categories used in FedRAMP.
Question 3: What is the primary difference between a FedRAMP Provisional ATO (P-ATO) and an Agency ATO?
- A P-ATO is issued by the JAB and is reusable by any agency; an Agency ATO is issued by a single sponsoring agency (Correct answer)
- A P-ATO covers Low systems only; an Agency ATO covers Moderate and High systems
- A P-ATO requires no 3PAO assessment; an Agency ATO does
- A P-ATO is temporary and expires after 90 days; an Agency ATO lasts three years
Correct answer: A P-ATO is issued by the JAB and is reusable by any agency; an Agency ATO is issued by a single sponsoring agency
A JAB P-ATO is issued by the Joint Authorization Board and signals government-wide acceptance, allowing multiple agencies to reuse it; an Agency ATO is granted by a single agency's Authorizing Official.
Question 4: During risk assessment, what does 'likelihood' refer to in the context of threat analysis?
- The potential damage caused if a threat successfully exploits a vulnerability
- The probability that a threat source will exploit a given vulnerability (Correct answer)
- The number of known exploits for a specific vulnerability
- The time required to recover from a successful attack
Correct answer: The probability that a threat source will exploit a given vulnerability
Likelihood is the probability or chance that a threat actor will successfully exploit a vulnerability, considering factors such as threat motivation, capability, and existing controls.
Question 5: A federal agency's Authorizing Official (AO) reviews a FedRAMP package and decides to accept the risk and grant an ATO. Who is ultimately accountable for that risk acceptance decision?
- The FedRAMP PMO
- The Third Party Assessment Organization (3PAO)
- The Authorizing Official (AO) (Correct answer)
- The cloud service provider (CSP)
Correct answer: The Authorizing Official (AO)
The Authorizing Official bears personal accountability for the risk acceptance decision and is responsible for the security posture of the system they authorize.
Question 6: Which security objective is most directly threatened when unauthorized users can read sensitive federal data stored in a cloud system?
- Availability
- Integrity
- Confidentiality (Correct answer)
- Accountability
Correct answer: Confidentiality
Unauthorized reading of sensitive data is a breach of confidentiality, which protects information from being disclosed to unauthorized individuals.
Question 7: How does FedRAMP's 'continuous monitoring' differ from a point-in-time security assessment?
- Continuous monitoring only checks system availability, while assessments check all controls
- Continuous monitoring provides ongoing visibility into security posture versus a snapshot view at assessment time (Correct answer)
- Continuous monitoring is performed by the agency, while assessments are performed by the CSP
- Continuous monitoring replaces the need for periodic 3PAO assessments entirely
Correct answer: Continuous monitoring provides ongoing visibility into security posture versus a snapshot view at assessment time
Continuous monitoring provides real-time or near-real-time security status updates throughout the system's operation, whereas a point-in-time assessment captures security posture only at a specific moment.
A CSP uses a subcontractor to provide physical data center services.
Under FedRAMP, how must this relationship be handled?