The Delivery Cycle
Security Stuff
Tier 4 - Yes or No?
Technical Teasers
Notification! – What to do now…
100

To enhance communication with our COR, we write these and ensure they are displayed during our Sprint Review meetings when presenting both our Highlighted and Summary User Stories.

What are Value Added Statements?

100

VA Security Incident Response

What was the topic of October 2019 or the 1st security refresher awareness training topic?

100

What is daily or as needed?

What is when I should report tier 4 hours?

100

The tool that mirrors the contents of any given Git repository into Consul key-values in Sandbox, SQA, and Prod.

What is 'git2consul'?

100

The Slack channel where Alertmanager posts the most.

What is 'apphealthchecks'?

200

In order to be paid in full for our work, we must report that no less than 95% of these ticket types have a response time of less than one day in our SLA report and MSR.

What are engineering support (MAPSUP) and change management (ECCB & NGD) tickets?

200

PII and PHI data transfers must _______....

What is never leave the VA network?

What is 

•Over sFTP to the VAEC-AWS MAP environment

•Over VA email Encrypted?

200

2 hours

What is the number of tier 4 hours we report when we are "on call"?

200

The tool used by MACM to build, change, and version infrastructure, which is also utilized by Ansible scripting to discover instances, both generally and in particular environments.

What is 'Terraform'?

200

The Slack channel that tracks changes to MAPSUP tickets.

What is 'mapsupalerts'?

300

In order to be paid in full for our work, we must report that no less than 95% of these ticket types have a resolution time of less than three days in our SLA report and MSR.

What are Engineering Support (MAPSUP) tickets?

300

Only use passwords that meet the VA minimum requirements (Passwords must contain at least 8 non-blank characters. They must contain characters from 3 of the following 4 categories: English upper case characters, English lower case characters, Base 10 digits, and non-alphanumeric special characters. Six of the characters must not occur more than once in the password. System administrator and service accounts must contain at least 12 non-blank characters and use 3 of the 4 categories mentioned

What is the VA's password policy?

300

Providing direct assistance to another team that benefits that team and not our Infrastructure as Code solution in all MACM environments.  

What is MACM Tier 4 Support Criteria Summary?

300

The in-VPN VA address to go to in order to submit CSRs for certificate creation.

What is 'vaww.pki.va.gov'?

300

The Slack channel where deployments can be scheduled.

What is 'resource-scheduling'?

400

A screenshot of this is included in the SLA report and shows information gathered from the K8 cluster gathered during the month including: application pods metrics, pod deployment information that shows the pods currently running, CPU/Memory metrics for applications and EFK stack, and output from Prometheus showing up/down status.  

What is the Grafana dashboard?

400

VA Policy requires all sensitive information (including attachments) be ________ during transmission

What is encrypted?

400

Working with end users in the troubleshooting of application issues in all MACM environments.

What is not tier 4 support?

400

The tool used in the MACM environments as a log collector for containers.

What is 'Fluentd'?

400

The Slack channel that shows changes to coderepo, such as pushes, approvals, etc.

What is 'vaecmap'?

500

Screenshots of these are included in the SLA report and have information from CPU Alerts, overall metric info on RDS instance, CPU utilization of overall EC2 instances, snapshot information, and snippet of log gathering via AWS Cloudwatch.

What is the Cloudwatch dashboard list?

500

IP addresses of VA resources

What is must always be sent in encrypted format?

500

Daily double: Name 2 examples of tier 4 support as listed in the MACM Tier 4 Support Criteria Summary document. 

  • Supporting application issues and errors not caused by MACM, but due to application limitations or bugs

  • Requests for application logs due to access limitations or the app not producing logs
  • MAP shared services (a.k.a. NextGen Shared Services)

  • VA integrated systems (e.g. IAM, DS Logon)

  • API Gateway

  • other VA mobile apps (VistA, Virtual Care Manager, etc.)
  • Deployment requests into staging

  • IVS testing support in SQA

  • CHAMPVA support into SQA
  • Rare: Requested support to the COMS team to troubleshoot AWS issues
  • Rare: Remediation of security findings in apps and/or shared services


  • Drupal Support: attending recurring technical meetings, providing development support and guidance
  •  
  • New user accounts to access Atlassian resources, e.g. JIRA, Wiki, etc.
  •  
  • New application project creation and configuration, may include updates to workflows, fields, ticket types, etc.
500

The name of the webagent available in the MACM infrastructure that is utilized by staff-side users (SSOi) to login to applications.

What is 'Siteminder'?

500

The de facto monitoring service for monitoring AWS cloud resources and the applications you run on AWS.

What is 'AWS Cloudwatch'?

M
e
n
u