FedRAMP Security Authorization & Compliance 4 — Questions and Answers
Question 1: An agency AO reviews a CSP's authorization package and decides the residual risk is acceptable. What document does the AO issue?
- Plan of Action & Milestones
- Authority to Operate (ATO) letter (Correct answer)
- Security Assessment Report
- Interconnection Security Agreement (ISA)
Correct answer: Authority to Operate (ATO) letter
After reviewing the authorization package and accepting residual risk, the AO issues an Authority to Operate (ATO) letter.
Question 2: Which FedRAMP document establishes the scope of what is being assessed, including system boundaries and external connections?
- Security Assessment Plan (SAP)
- System Security Plan (SSP) (Correct answer)
- POA&M
- Incident Response Plan
Correct answer: System Security Plan (SSP)
The SSP defines the authorization boundary, describes interconnections, and scopes what controls apply to the system.
Question 3: FedRAMP requires CSPs to use a FIPS 140-2 validated cryptographic module. What does FIPS 140-2 validate?
- Network firewall configurations
- Cryptographic module security (Correct answer)
- Physical data center access controls
- Identity proofing processes
Correct answer: Cryptographic module security
FIPS 140-2 is the federal standard for validating the security of cryptographic modules used to protect sensitive data.
Question 4: Under FedRAMP's shared responsibility model, which controls are typically the customer agency's responsibility in a SaaS deployment?
- Hypervisor patching and network segmentation
- User access provisioning and data classification (Correct answer)
- Physical security of data center facilities
- OS hardening and container orchestration
Correct answer: User access provisioning and data classification
In a SaaS model, the agency typically owns controls like user account management and data classification, while the CSP owns the infrastructure.
Question 5: What is the maximum validity period for a FedRAMP Agency ATO before it must be formally renewed or re-assessed?
- 1 year
- 2 years
- 3 years (Correct answer)
- 5 years
Correct answer: 3 years
FedRAMP ATOs are valid for three years, after which the authorization must be reviewed and renewed.
Question 6: A 3PAO conducting a FedRAMP assessment discovers that 15% of a control family's controls are not in place. What must the 3PAO document?
- Immediately halt the assessment and notify the PMO
- Document findings as risks in the Security Assessment Report (SAR) (Correct answer)
- Automatically downgrade the system to a lower impact level
- Issue a notice of suspension to the CSP
Correct answer: Document findings as risks in the Security Assessment Report (SAR)
The 3PAO must document all findings, including unimplemented controls, as risks in the SAR for the AO to review.
Question 7: Which FedRAMP process allows a CSP to pursue authorization through a partnering federal agency rather than the JAB?
- JAB P-ATO pathway
- Agency Authorization pathway (Correct answer)
- FedRAMP Connect
- FedRAMP Tailored pathway
Correct answer: Agency Authorization pathway
The Agency Authorization pathway allows a CSP to work directly with a sponsoring federal agency to obtain an ATO.
An agency AO reviews a CSP's authorization package and decides the residual risk is acceptable.
What document does the AO issue?