FedRAMP Evidence and Documentation
Final Quiz
Connecting to LMS...
Progress: in progress
Assessment
1. What is the main purpose of FedRAMP evidence and documentation?
A. To replace operational security controls.
B. To show how a cloud service is scoped, secured, assessed, operated, and monitored.
C. To create marketing material for customers.
D. To avoid all future assessment work.
2. What is the difference between a claim and evidence?
A. A claim states something; evidence supports whether that statement is true for the system.
B. Evidence is always optional.
C. A claim is stronger when it has no supporting record.
D. Evidence replaces system implementation.
3. Why is authorization boundary documentation important?
A. It determines course navigation.
B. It replaces vulnerability management.
C. It clarifies which components, dependencies, identities, data flows, and responsibilities are in scope.
D. It guarantees perfect security.
4. What is a common problem with unclear scope?
A. It makes evidence easier to review.
B. It eliminates shared responsibility.
C. It proves all controls are inherited.
D. It creates assessment gaps, responsibility confusion, and risk misunderstandings.
5. Which item is an example of core security documentation?
A. Architecture diagrams, system descriptions, policies, procedures, inventories, and control narratives.
B. A company logo file only.
C. A social media post.
D. A color palette.
6. What makes evidence useful?
A. It is old, vague, and unrelated to the system.
B. It is decorative and easy to ignore.
C. It is current, relevant, traceable, reviewable, and connected to a control or assertion.
D. It is stored only in one person's memory.
7. What should a control implementation narrative explain?
A. Only the control title copied verbatim.
B. How the control is implemented, owned, operated, inherited or shared, and evidenced.
C. Only the preferred font for the document.
D. Why testing is unnecessary.
8. Why is copy-paste control language weak documentation?
A. It always proves the system is secure.
B. It automatically satisfies every assessment question.
C. It prevents reviewers from asking questions.
D. It may not explain how the actual system implements and operates the control.
9. Why should evidence repositories have access control?
A. Evidence may contain sensitive security, architecture, configuration, vulnerability, or operational information.
B. Evidence should be public by default.
C. Access control makes evidence invalid.
D. Evidence repositories should never be reviewed.
10. What is evidence ownership?
A. A way to avoid review.
B. A decorative label with no responsibility.
C. Assignment of responsibility for producing, maintaining, explaining, and refreshing evidence.
D. A replacement for remediation.
11. What is a finding?
A. A guaranteed authorization.
B. A documented weakness, gap, issue, or observation supported by assessment or monitoring evidence.
C. A graphic design note.
D. A password reset email.
12. What should remediation documentation show?
A. Only that a ticket was opened.
B. Only that someone discussed the issue.
C. Only that the finding was renamed.
D. The action taken, ownership, status, and evidence that the issue was corrected or otherwise addressed.
13. What is a POA&M conceptually used for?
A. Tracking weaknesses, planned corrective actions, ownership, milestones, and status.
B. Replacing all security controls.
C. Designing course graphics.
D. Avoiding risk discussion.
14. Why is continuous monitoring documentation important?
A. It proves historical evidence never changes.
B. It helps show current security posture, changes, vulnerabilities, incidents, remediation, and control operation over time.
C. It replaces the initial system description.
D. It eliminates the need for ownership.
15. What is a common documentation mistake?
A. Keeping documentation aligned to the live system.
B. Linking evidence to control assertions.
C. Maintaining stale, generic, inconsistent, or unsupported documentation.
D. Protecting sensitive artifacts.
16. Which statement best summarizes FedRAMP evidence and documentation?
A. More documents always mean better security.
B. Evidence and documentation are useful only before launch.
C. Documentation should be generic so it never needs review.
D. Strong evidence and documentation connect real implementation, operations, assessment, findings, remediation, monitoring, and risk decisions.
Submit Quiz
Previous