FedRAMP Security Authorization & Compliance 3 — Questions and Answers
Question 1: Which NIST publication provides the control families that FedRAMP baselines are derived from?
- NIST SP 800-37
- NIST SP 800-53 (Correct answer)
- NIST SP 800-137
- NIST SP 800-171
Correct answer: NIST SP 800-53
FedRAMP control baselines are built upon the security and privacy controls defined in NIST SP 800-53.
Question 2: A federal agency wants to use a FedRAMP-authorized SaaS product. What document must the agency issue before using the service?
- A Memorandum of Understanding (MOU)
- An Agency Authorization to Operate (ATO) (Correct answer)
- A Data Use Agreement (DUA)
- A Boundary Attestation Letter
Correct answer: An Agency Authorization to Operate (ATO)
Each federal agency must issue its own Agency ATO, leveraging the existing FedRAMP authorization package, before using the service.
Question 3: What is the FedRAMP continuous monitoring frequency requirement for vulnerability scanning of operating systems?
- Daily
- Monthly (Correct answer)
- Quarterly
- Annually
Correct answer: Monthly
FedRAMP requires OS vulnerability scans to be performed at least monthly as part of continuous monitoring.
Question 4: Under FedRAMP, which party is responsible for ensuring that underlying infrastructure controls are implemented in a CSP's IaaS environment?
- The federal agency customer
- The 3PAO assessor
- The IaaS provider (as inherited controls) (Correct answer)
- The FedRAMP PMO
Correct answer: The IaaS provider (as inherited controls)
In an IaaS model, the underlying infrastructure controls are inherited from the IaaS provider, who is responsible for their implementation.
Question 5: A CSP discovers a new critical vulnerability in its authorized system. Under FedRAMP ConMon, what is the FIRST required action?
- Immediately revoke the ATO
- Report the vulnerability in the POA&M within the required timeframe (Correct answer)
- Notify the FedRAMP PMO via phone before documenting anything
- Patch the vulnerability before informing anyone
Correct answer: Report the vulnerability in the POA&M within the required timeframe
FedRAMP requires CSPs to document discovered vulnerabilities in the POA&M within the specified reporting timeframe.
Question 6: Which FedRAMP control baseline requires the largest number of security controls?
- FedRAMP Low
- FedRAMP Moderate
- FedRAMP High (Correct answer)
- FedRAMP Tailored
Correct answer: FedRAMP High
FedRAMP High has the most controls (~421), reflecting the stringent requirements for systems handling the most sensitive federal data.
Question 7: What distinguishes a FedRAMP 'significant change' from a routine system update?
- Any change that costs more than $10,000 to implement
- A change that may alter the security posture or authorization boundary (Correct answer)
- Any software patch applied outside a maintenance window
- Changes requiring downtime longer than four hours
Correct answer: A change that may alter the security posture or authorization boundary
A significant change is one that could affect the security posture, authorization boundary, or implemented controls of the authorized system.
Which NIST publication provides the control families that FedRAMP baselines are derived from?