FedRAMP Security Authorization & Compliance 2 — Questions and Answers
Question 1: Which FedRAMP document formally records the agreed-upon security controls and their implementation status for a cloud system?
- System Security Plan (SSP) (Correct answer)
- Plan of Action and Milestones (POA&M)
- Security Assessment Report (SAR)
- Authorization to Operate (ATO)
Correct answer: System Security Plan (SSP)
The System Security Plan (SSP) is the primary document that describes how a cloud system implements its required security controls.
Question 2: Under FedRAMP, what is the maximum time allowed to remediate a High-impact finding discovered during continuous monitoring?
- 30 days (Correct answer)
- 90 days
- 180 days
- 365 days
Correct answer: 30 days
FedRAMP requires that High-impact vulnerabilities be remediated within 30 days of discovery.
Question 3: Which entity is responsible for maintaining the FedRAMP Marketplace and publishing authorization statuses for CSPs?
- The Joint Authorization Board (JAB)
- The Program Management Office (PMO) (Correct answer)
- NIST
- DHS CISA
Correct answer: The Program Management Office (PMO)
The FedRAMP Program Management Office (PMO) maintains the FedRAMP Marketplace listing all authorized cloud services.
Question 4: A CSP's cloud offering is granted a P-ATO. What does this mean for other federal agencies?
- They must conduct their own full assessment before using the service
- They can issue their own ATO leveraging the P-ATO without a full reassessment (Correct answer)
- They must wait 90 days before onboarding
- They need JAB re-approval specific to their agency
Correct answer: They can issue their own ATO leveraging the P-ATO without a full reassessment
A Provisional ATO (P-ATO) from the JAB allows other agencies to issue their own ATO by reusing the existing assessment package.
Question 5: Which FedRAMP baseline applies to cloud systems processing data where loss of confidentiality, integrity, or availability would have a limited adverse effect?
- FedRAMP High
- FedRAMP Moderate
- FedRAMP Low (Correct answer)
- FedRAMP Tailored (LI-SaaS)
Correct answer: FedRAMP Low
FedRAMP Low baseline applies to systems where a security breach would have limited adverse effects on operations or individuals.
Question 6: During the FedRAMP authorization process, who reviews the Security Assessment Report (SAR) to determine whether risk is acceptable?
- The 3PAO that wrote it
- The Authorizing Official (AO) (Correct answer)
- NIST's Computer Security Division
- The CSP's CISO
Correct answer: The Authorizing Official (AO)
The Authorizing Official (AO) reviews the SAR and accepts or rejects residual risk before issuing an ATO.
Question 7: What is the primary purpose of a FedRAMP Readiness Assessment Report (RAR)?
- To replace the full security assessment for Low systems
- To provide an early indicator of a CSP's likelihood of achieving authorization (Correct answer)
- To document POA&M items before authorization
- To grant a temporary ATO while the full assessment is underway
Correct answer: To provide an early indicator of a CSP's likelihood of achieving authorization
The RAR is prepared by a 3PAO to signal whether a CSP is likely ready to pursue full FedRAMP authorization.
Which FedRAMP document formally records the agreed-upon security controls and their implementation status for a cloud system?