What are FedRAMP Baselines?
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is a FedRAMP baseline?
A. A cloud provider marketing slogan.
B. A defined set of security control expectations used as a starting point for assessment and authorization.
C. A replacement for all agency risk decisions.
D. A list of unrelated software features.
2. Why do FedRAMP baselines matter?
A. They help agencies, cloud service providers, and assessors work from a common set of security expectations.
B. They eliminate the need for security testing.
C. They guarantee that every cloud service is identical.
D. They replace continuous monitoring.
3. What does impact level thinking consider?
A. Logo design and brand preference.
B. The number of developers on the team.
C. The potential adverse effect of a loss of confidentiality, integrity, or availability.
D. The preferred programming language.
4. Why should a team not select a baseline only because it seems easier?
A. Easier baselines always cost more.
B. Baseline selection has no connection to data.
C. Agencies never review baseline choices.
D. The baseline should reflect the federal data, mission impact, use case, and system risk.
5. Which statement best describes a Low-impact cloud service?
A. A service where adverse effects from a security incident are expected to be limited.
B. A service with no security responsibilities.
C. A service that cannot process any federal information.
D. A service that does not need logging.
6. What is the main idea behind LI-SaaS or tailored low-impact concepts?
A. They are designed for the highest-risk national security systems.
B. They remove all documentation.
C. They provide a more focused path for certain low-impact SaaS use cases with limited sensitivity.
D. They replace the need for authorization.
7. Why is Moderate commonly important in FedRAMP discussions?
A. It is always the easiest baseline.
B. It often applies to cloud services with meaningful federal data sensitivity or mission impact.
C. It applies only to public marketing websites.
D. It eliminates the need for assessment.
8. What does the High baseline generally indicate?
A. A system with no operational impact.
B. A system that does not require access control.
C. A system where security incidents are always impossible.
D. A system where loss of confidentiality, integrity, or availability could have severe or catastrophic adverse effects.
9. How do FedRAMP baselines relate to NIST controls?
A. They are cloud-focused selections and expectations based on NIST security control concepts.
B. They are unrelated to security controls.
C. They replace all technical implementation.
D. They apply only to physical office buildings.
10. What is an inherited control?
A. A control that is always ignored.
B. A control capability provided by another system, platform, service, or organization and relied on by the cloud service.
C. A control chosen randomly.
D. A control that never needs evidence.
11. Why does shared responsibility matter for baselines?
A. It hides responsibility from customers.
B. It proves the provider handles everything.
C. It clarifies which controls are handled by the provider, the customer, the platform, or a combination.
D. It eliminates documentation.
12. What should an authorization package show?
A. Only a sales summary.
B. Only screenshots with no explanation.
C. Only future plans with no current evidence.
D. How the system implements, documents, assesses, and monitors required controls.
13. Why should documentation match the real system?
A. Assessment evidence must reflect actual architecture, operations, responsibilities, and control implementation.
B. Documentation is only decorative.
C. Real architecture is irrelevant.
D. Baselines remove the need for accuracy.
14. What is continuous monitoring?
A. A one-time kickoff meeting.
B. A replacement for incident response.
C. Ongoing security visibility, reporting, assessment, and risk management after authorization.
D. A graphic design review.
15. Who should be involved in baseline selection and implementation?
A. Only the marketing team.
B. Only the LMS administrator.
C. Only the database administrator.
D. Technical, security, compliance, legal, customer, operational, and business stakeholders as appropriate.
16. Which statement best summarizes FedRAMP baselines?
A. Baselines are optional decorative labels.
B. Baselines connect federal cloud risk to security control expectations, assessment evidence, authorization decisions, and ongoing monitoring.
C. Baselines guarantee perfect security.
D. Baselines apply only after a system is retired.
Submit Quiz
Previous