SSCP Security Auditing & Compliance Standards 4 — Questions and Answers
Question 1: Which of the following BEST describes a continuous compliance monitoring approach?
- Annual third-party audits with point-in-time assessments
- Automated, real-time checks of controls against compliance requirements (Correct answer)
- Manual quarterly review of security policies
- Periodic penetration testing every two years
Correct answer: Automated, real-time checks of controls against compliance requirements
Continuous compliance monitoring uses automated tools to provide real-time or near-real-time validation that controls remain effective and compliant.
Question 2: Under FedRAMP, which authorization path allows a CSP to receive authorization from a single agency that other agencies can then leverage?
- JAB Provisional Authorization
- Agency Authorization (Correct answer)
- FedRAMP Ready designation
- Continuous Authorization
Correct answer: Agency Authorization
Agency Authorization allows a federal agency to sponsor a CSP, and other agencies can reuse that authorization rather than starting from scratch.
Question 3: During an ISO 27001 surveillance audit, the auditor identifies a control that was previously certified but is now missing evidence of operation. This would MOST likely result in:
- Immediate certificate revocation
- A major nonconformity requiring corrective action within a defined timeframe (Correct answer)
- A minor nonconformity noted in the audit report
- An observation with no formal follow-up required
Correct answer: A major nonconformity requiring corrective action within a defined timeframe
A control that existed but lacks operational evidence is a major nonconformity that requires documented corrective action within a specified period.
Question 4: Which NIST SP 800-53 control family addresses audit and accountability?
- AC — Access Control
- AU — Audit and Accountability (Correct answer)
- CM — Configuration Management
- SI — System and Information Integrity
Correct answer: AU — Audit and Accountability
The AU (Audit and Accountability) control family in NIST SP 800-53 covers audit event logging, log content, audit review, and protection of audit information.
Question 5: A retail organization undergoes a PCI DSS Qualified Security Assessor (QSA) audit. The QSA's role is to:
- Perform penetration testing only
- Validate compliance with PCI DSS requirements and issue a Report on Compliance (Correct answer)
- Certify the organization's software development processes
- Conduct risk assessments and recommend insurance coverage
Correct answer: Validate compliance with PCI DSS requirements and issue a Report on Compliance
A QSA is authorized by the PCI SSC to assess compliance with PCI DSS and produce a formal Report on Compliance (ROC) for Level 1 merchants.
Question 6: Which technique involves comparing access rights granted to users with those actually required for their job function to identify excessive privileges?
- Penetration testing
- User access review (recertification) (Correct answer)
- Vulnerability assessment
- Security baseline review
Correct answer: User access review (recertification)
User access reviews (recertification campaigns) compare provisioned rights against job requirements to revoke unnecessary or excessive privileges.
Question 7: The 'right to audit' clause in a vendor contract primarily ensures that:
- The vendor must purchase cyber insurance
- The organization can inspect the vendor's security controls and records (Correct answer)
- The vendor's employees must pass background checks
- The organization assumes liability for vendor breaches
Correct answer: The organization can inspect the vendor's security controls and records
A right-to-audit clause contractually grants the organization (or its representatives) the ability to inspect, test, and review the vendor's security posture.
Which of the following BEST describes a continuous compliance monitoring approach?