FedRAMP
Security Controls
Security Assessments
ATO Certification
3PAO
100

The FedRAMP abbreviation stands for...

What is Federal Risk And Authorization Management Program?

100

There are only 38 controls in this FedRAMP security baseline.

What is Low Impact SaaS?

100

According to FedRAMP vulnerability remediation guidance, low risk findings must be remediated within this number of days.

What is 180 days?

100

The ATO abbreviation stands for....

What is Authority to Operate?

100

The 3PAO abbreviation stands for....

What is Third Party Assessment Organization?

200

Name the NIST publication which FedRAMP uses for its risk management framework of controls.

What is NIST SP 800-53 Rev 4

200

There are a total of 421 controls in this FedRAMP security impact baseline.

What is the High baseline?

200

This document is used to track discovered vulnerabilities from security assessments.

What is a POA&M (Plan of Actions and Milestones)?

200

This designation denotes that a Cloud Service Offering or Cloud Service Provider is ready to be listed on the FedRAMP Marketplace and that the   system has a high likelihood of obtaining a JAB P-ATO or an Agency ATO. 

What is the "FedRAMP Ready" designation?

200

The 3PAO provides this document to the CSP which details the processes for on site visits, personnel interviews, and security scans of the information system. 

What is the Security Assessment Plan?

300

Name the four (4) security impact baselines offered by the FedRAMP program?

What are Li-SaaS, Low, Moderate, and High?

300

This control in the SC family addresses the logical and physical separation of publicly accessible system components and internal organization networks, along with controlling and monitoring communications at key internal and external areas in the system.

What is SC-7 or Boundary Protection?

300

Unlike unauthenticated scans, these types of scans require system or application credentials to detect internal vulnerabilities.

What is an authenticated scan?

300

This is the name of the completed package which is submitted to the JAB or sponsoring Agency that contains the System Security Plan, Security Assessment Plan, Security Assessment Report, and Plan of Actions and Milestones.

What is the SAP or Security Authorization Package?

300

The 3PAO provides this document to the CSP as an analysis or report from the results of the SAP.

What is the SAR or Security Assessment Report?

400

True or False - FedRAMP security controls restrict data to reside only in the geographical region of the United States.

False.

400

This control in the AC family is about making sure that users or processes acting on behalf of users only have the minimum amount of permissions to perform mission or business functions.

What is AC-6 or Least Privilege?

400

The POA&M contains only these two tab names.

What are Open and Closed?

400

This is the last phase in either the JAB or Agency authorization process, it is also a reoccurring phase.

What is Con Mon or Continuous Monitoring?

400

This document, included in the SAP, enumerates all the rules for the assessment of the system and must be signed by both the CSP and 3PAO.

What are the Rules of Engagement?

500

Name two out of three of the Federal government executive branches that make up the Joint Authorization Board.

What are the Department of Homeland Security, General Services Administration, and/or Department of Defense?

500

This control in the RA family is all about vulnerability scanning.

What is RA-5?

500

All network, database, operating system, and web application vulnerability scan results are required to be submitted to the JAB or Authorizing Agency on a _______ basis. 

What is monthly?

500

True or False - High findings in a Security Assessment Report (SAR) must be remediated or mitigated to Moderate before submission to the JAB for a P-ATO.

True.

500

In order to become a FedRAMP accredited 3PAO, accreditation from this organization must be obtained before final approval by the FedRAMP PMO.

What is the A2LA or American Association for Laboratory Accreditation?

M
e
n
u