FedRAMP Security Authorization & Compliance 5 — Questions and Answers
Question 1: What is the purpose of the FedRAMP 'ConMon' monthly deliverables submitted by a CSP?
- To renew the ATO annually
- To provide ongoing evidence that security controls remain effective (Correct answer)
- To request changes to the authorization boundary
- To report new features added to the cloud service
Correct answer: To provide ongoing evidence that security controls remain effective
Monthly ConMon deliverables (scan results, POA&M updates) demonstrate that the authorized system continues to meet security requirements.
Question 2: An agency is evaluating a CSP listed as 'FedRAMP Authorized' on the Marketplace. Which document should the agency request to understand implemented controls?
- The CSP's marketing collateral
- The full authorization package including SSP, SAR, and POA&M (Correct answer)
- Only the executive summary of the SAR
- The CSP's ISO 27001 certificate
Correct answer: The full authorization package including SSP, SAR, and POA&M
Agencies should request the full authorization package—SSP, SAR, and POA&M—to fully understand the control implementation and residual risks.
Question 3: Under FedRAMP, what action is required when a CSP wants to add a new external service or API integration that was not in the original authorization boundary?
- No action needed if the service is also FedRAMP authorized
- Submit a significant change request and update the SSP and authorization boundary (Correct answer)
- Notify the FedRAMP PMO within 30 days after integration
- The agency customer approves the integration independently
Correct answer: Submit a significant change request and update the SSP and authorization boundary
Adding external integrations that affect the boundary requires a significant change request, SSP update, and AO review.
Question 4: Which of the following best describes the role of a 3PAO in the FedRAMP authorization process?
- They provide legal counsel to the CSP during authorization
- They independently assess the CSP's security controls and produce the SAR (Correct answer)
- They issue the final ATO on behalf of the JAB
- They manage the CSP's POA&M remediation activities
Correct answer: They independently assess the CSP's security controls and produce the SAR
A Third Party Assessment Organization (3PAO) independently evaluates the CSP's controls and documents findings in the Security Assessment Report.
Question 5: What does FedRAMP require for systems handling Controlled Unclassified Information (CUI) at the Moderate impact level?
- FedRAMP Low baseline controls are sufficient
- FedRAMP Moderate baseline controls must be implemented (Correct answer)
- FISMA Low designation overrides FedRAMP requirements
- No FedRAMP authorization is needed for CUI
Correct answer: FedRAMP Moderate baseline controls must be implemented
Systems handling CUI at Moderate impact must implement FedRAMP Moderate baseline controls (~325 controls).
Question 6: Which scenario would most likely trigger an immediate notification requirement to the FedRAMP PMO and agency AO?
- Routine monthly OS patches applied on schedule
- A confirmed data breach affecting federal agency data (Correct answer)
- Upgrading the cloud service's user interface
- Adding a new geographic region for redundancy
Correct answer: A confirmed data breach affecting federal agency data
A confirmed data breach affecting federal data is a security incident that requires immediate notification to the PMO and AO under FedRAMP incident response requirements.
Question 7: A CSP has a POA&M item for a Moderate-impact finding. What is the maximum remediation timeframe allowed under FedRAMP?
- 30 days
- 90 days
- 180 days (Correct answer)
- 1 year
Correct answer: 180 days
FedRAMP allows up to 180 days for remediating Moderate-impact vulnerabilities tracked in the POA&M.
What is the purpose of the FedRAMP 'ConMon' monthly deliverables submitted by a CSP?