Courseiva

CCNA System Compliance Questions

28 questions · System Compliance topic · All types, answers revealed

1
MCQmedium

When a system is undergoing a major change, what is the impact on the existing ATO?

A.The ATO is suspended until the next fiscal year
B.The ATO must be re-evaluated
C.The ATO remains valid until the expiration date
D.The ATO is automatically extended
AnswerB

Major changes trigger a re-authorization process.

Why this answer

A major change invalidates the existing ATO because the security posture has fundamentally changed, requiring a re-assessment.

2
MCQeasy

What is the purpose of the Security Assessment Report (SAR)?

A.To provide a snapshot of the control implementation effectiveness
B.To request funding for security improvements
C.To authorize the system for production
D.To list all authorized users
AnswerA

It summarizes the assessment findings.

Why this answer

The SAR documents the results of the control assessment, including findings and recommendations.

3
MCQhard

You are auditing an organization's POA&M process. Which of the following indicates an ineffective process?

A.The POA&M contains vulnerabilities found by automated scans
B.The POA&M lists items with no completion dates
C.The POA&M is stored in a secure repository
D.The POA&M is reviewed by the CISO
AnswerB

This prevents tracking and accountability.

Why this answer

POA&Ms must include completion dates. Without them, there is no accountability for remediation.

4
MCQeasy

Which role is responsible for the ongoing monitoring of security controls after an ATO is granted?

A.Authorizing Official
B.Chief Information Security Officer (CISO)
C.Security Control Assessor (SCA)
D.Information System Security Officer (ISSO)
AnswerD

The ISSO performs the continuous monitoring tasks.

Why this answer

The ISSO is responsible for the day-to-day management and monitoring of the security controls.

5
MCQeasy

Which phase of the RMF includes the 'continuous monitoring' of security controls?

A.Monitor
B.Authorize
C.Select
D.Categorize
AnswerA

This is where continuous monitoring occurs.

Why this answer

The 'Monitor' step is the final phase of the RMF, focused on ongoing compliance.

6
Multi-Selectmedium

Which THREE elements are necessary for a compliant continuous monitoring program?

Select 3 answers
A.Configuration management of the system
B.Regular assessment of security controls
C.Full system replacement every year
D.Status reporting to the AO
E.Daily physical site visits
AnswersA, B, D

Ensures changes are tracked.

Why this answer

Continuous monitoring requires regular assessment, tracking of changes, and reporting of the security posture.

7
MCQmedium

An Authorizing Official grants an 'ATO with Conditions.' What does this mean for the system owner?

A.The system is unauthorized for production use
B.The system is prohibited from processing sensitive data
C.The system must meet specific security requirements to remain authorized
D.The system is permanently compliant
AnswerC

Conditions require timely remediation of identified risks.

Why this answer

An ATO with conditions means the system can operate, but specific security gaps must be closed within a defined timeframe to maintain authorization.

8
MCQmedium

You are utilizing the NIST SP 800-37 R2 process for an Authorization to Operate (ATO). At what point is the Security Assessment Report (SAR) presented to the Authorizing Official?

A.During the 'Categorize' step
B.After the 'Monitor' step
C.During the 'Prepare' step
D.After the 'Assess' step and before the 'Authorize' step
AnswerD

The SAR is a required input for the authorization decision.

Why this answer

The SAR provides the technical basis for the AO to make the risk-based decision after the assessment is complete.

9
Multi-Selectmedium

Which TWO factors should an ISSO consider when determining if a system change requires a re-authorization?

Select 2 answers
A.The color of the server casing
B.The impact on the security control baseline
C.The scope of the changes made to the system
D.The number of administrative staff
E.The age of the hardware
AnswersB, C

If controls are weakened, it requires re-evaluation.

Why this answer

The magnitude of the change and the impact on the security controls are the two key triggers for re-authorization.

10
Multi-Selectmedium

Which TWO actions should an ISSO take when a critical security control is found to be ineffective during assessment?

Select 2 answers
A.Delete the control from the SSP
B.Change the system password
C.Document the finding in the SAR
D.Create a POA&M entry to track remediation
E.Immediately disconnect the system
AnswersC, D

Findings must be reported.

Why this answer

The ISSO must document the finding in the SAR and work with the system owner to document the mitigation in a POA&M.

11
MCQmedium

A contractor provides a service for your organization. How do you ensure the contractor's system is compliant?

A.Grant them access to your internal ATO database
B.Include security requirements in the contract language
C.Perform an audit of the contractor's office
D.Trust the contractor's internal IT department
AnswerB

Contractual requirements are the primary mechanism for third-party compliance.

Why this answer

Incorporating security requirements into the contract (like FAR/DFARS clauses) ensures the contractor is legally bound to meet security standards.

12
MCQeasy

An Authorizing Official (AO) is reviewing a Plan of Action and Milestones (POA&M) for a high-impact system. What is the AO's primary responsibility regarding this document?

A.Drafting the mitigation tasks
B.Conducting the security controls assessment
C.Implementing the technical patches
D.Accepting the residual risk associated with the POA&M
AnswerD

The AO signs off on the risk acceptance.

Why this answer

The AO is accountable for the risk the system poses to the organization and must approve the mitigation strategy outlined in the POA&M.

13
MCQmedium

If a security control is deemed 'Not Applicable' (NA) in the System Security Plan (SSP), what must the system owner provide?

A.A waiver request to the CISO
B.A copy of the vendor's warranty
C.A technical justification for the N/A status
D.The procurement contract
AnswerC

Justification is required to ensure the control was not mistakenly omitted.

Why this answer

For a control to be N/A, there must be a valid justification based on the system's architecture or operational environment.

14
MCQhard

When assessing a cloud service provider (CSP) using a FedRAMP-authorized solution, what is the primary benefit to your organization?

A.It guarantees the system will never be breached
B.It reduces the level of effort for the security assessment
C.It eliminates the need for any internal security oversight
D.It allows the organization to bypass the RMF
AnswerB

The 'do once, use many' principle applies here.

Why this answer

Using a pre-authorized CSP means the government has already assessed the security controls, reducing the need for redundant assessments.

15
Multi-Selecthard

Which THREE of the following are valid components of an Authorization Package?

Select 3 answers
A.Vendor invoices
B.Security Assessment Report (SAR)
C.User training records
D.System Security Plan (SSP)
E.Plan of Action and Milestones (POA&M)
AnswersB, D, E

Core component.

Why this answer

The Authorization Package consists of the SSP, SAR, and POA&M as the core elements for the AO.

16
Multi-Selecthard

Which THREE categories of controls are identified in NIST SP 800-53?

Select 3 answers
A.Financial
B.Operational
C.Management
D.Environmental
E.Technical
AnswersB, C, E

A valid control category.

Why this answer

NIST categorizes controls into Technical, Management, and Operational families.

17
Multi-Selecteasy

Which TWO of the following are responsibilities of the Authorizing Official?

Select 2 answers
A.Conducting the scan
B.Signing the authorization decision
C.Accepting the residual risk
D.Writing the user manual
E.Updating the firewall rules
AnswersB, C

AO responsibility.

Why this answer

The AO is the final risk decision maker and is accountable for the system's security status.

18
MCQeasy

Which document provides the formal authority to operate a system?

A.System Security Plan
B.Risk Assessment Report
C.Security Control Assessment
D.Authorization Decision Document
AnswerD

This document conveys the AO's decision.

Why this answer

The Authorization Decision Document (ADD) or ATO letter is the formal record of the AO's decision.

19
Multi-Selectmedium

Which TWO documents are essential for an Authorizing Official to make an informed risk-based decision?

Select 2 answers
A.System Security Plan (SSP)
B.Hardware inventory list
C.Plan of Action and Milestones (POA&M)
D.Security Assessment Report (SAR)
E.Network diagram
AnswersC, D

Essential for knowing the remediation plan for weaknesses.

Why this answer

The SAR provides the technical assessment, and the POA&M identifies how identified weaknesses will be addressed.

20
MCQmedium

What is the relationship between the System Security Plan (SSP) and the Security Assessment Report (SAR)?

A.The SAR evaluates the effectiveness of the controls described in the SSP
B.The SSP is a summary of the SAR
C.They are independent documents with no relationship
D.The SAR provides the controls to be documented in the SSP
AnswerA

The SAR is the validation of the SSP.

Why this answer

The SSP describes the controls that *should* be in place, and the SAR reports on whether those controls are actually effective.

21
Multi-Selecthard

Which THREE types of information should be included in a risk acceptance memo?

Select 3 answers
A.The name of the software vendor
B.The technical specifications of the server
C.Description of the identified risk
D.The impact on the organizational mission
E.Justification for accepting the risk
AnswersC, D, E

Must define what is being accepted.

Why this answer

Risk acceptance must document the specific risk, the impact, and the duration or justification for accepting it.

22
MCQmedium

An information system security officer (ISSO) is preparing the Security Assessment Plan (SAP) in the NIST Risk Management Framework. Which component must be identified first to ensure the assessment coverage is adequate?

A.Security control baselines
B.Contingency plan testing
C.System boundary and authorization boundary
D.Risk acceptance threshold
AnswerC

Establishing the boundary is the first step in assessing compliance.

Why this answer

Identifying the scope and boundaries of the system is the prerequisite for developing a SAP to ensure all components under the authorization boundary are evaluated.

23
MCQhard

A system is found to have a critical vulnerability that cannot be patched. You are documenting a risk acceptance request. What is the most critical piece of information to include for the AO?

A.The estimated cost of an upgrade
B.The manufacturer's release notes
C.The potential impact on the organization's mission
D.The CVSS score of the vulnerability
AnswerC

AO decisions are based on the balance of mission need vs. residual risk.

Why this answer

The AO needs to understand the impact of the risk on the organizational mission to make an informed decision.

24
MCQeasy

When determining compliance for a cloud-based service, which document serves as the primary evidence of the provider's security controls?

A.The service level agreement (SLA)
B.The organization's internal risk register
C.The network topology map
D.The cloud provider's System Security Plan (SSP) or Authorization Package
AnswerD

This contains the security control documentation for the service.

Why this answer

A FedRAMP Authorization Package or a third-party audit report (like SOC 2) is the standard evidence for cloud compliance.

25
MCQhard

You are performing a compliance determination on a system that shares data with an external partner. What is the most important factor in the authorization boundary determination?

A.The ownership and control of the components
B.The cost of the hardware
C.The physical location of the server racks
D.The number of users accessing the system
AnswerA

Boundary is defined by what the system owner has the authority to protect.

Why this answer

The authorization boundary defines the scope of the system and everything subject to the security controls, including interconnected systems.

26
MCQhard

During the compliance determination phase, you discover that a legacy application lacks multi-factor authentication (MFA) but is isolated within a physically secured enclave. Which action should you take to document this in the Security Assessment Report (SAR)?

A.Force an upgrade to the application
B.Document the compensating control and assess its effectiveness
C.Immediately revoke the Authorization to Operate (ATO)
D.Mark the control as 'Not Applicable'
AnswerB

Compensating controls are valid methods to meet security requirements.

Why this answer

Documenting compensating controls allows the assessor to show how the security objective is met despite the missing control.

27
MCQhard

While reviewing a system's compliance, you notice the Security Control Assessor (SCA) used an interview method for a technical control that requires automated testing. How should you address this in your review?

A.Accept the findings as-is
B.Escalate to the Chief Information Officer (CIO)
C.Request a re-assessment using the 'Test' method
D.Update the System Security Plan (SSP) to match the interview
AnswerC

Technical controls require testing (functional verification) rather than just interviews.

Why this answer

Security assessments must follow NIST SP 800-53A guidance, which specifies appropriate assessment methods (examine, interview, test) for each control.

28
MCQmedium

What is the primary role of the Security Control Assessor (SCA)?

A.To determine the effectiveness of the security controls
B.To implement the security controls
C.To remediate vulnerabilities
D.To accept the risk on behalf of the agency
AnswerA

The SCA validates the controls.

Why this answer

The SCA provides an objective, third-party assessment of the security controls to support the authorization decision.

Ready to test yourself?

Try a timed practice session using only System Compliance questions.