nerdexam
(ISC)2

CSSLP · Question #106

Continuous Monitoring is the fourth phase of the security certification and accreditation process. What activities are performed in the Continuous Monitoring process? Each correct answer represents…

The correct answer is B. Security control monitoring and impact analyses of changes to the information system D. Configuration management and control E. Status reporting and documentation. Continuous monitoring involves ongoing oversight of an information system's security posture, which includes actively monitoring security controls, managing configurations, and regularly reporting on its security status.

Secure Software Deployment, Operations, Maintenance

Question

Continuous Monitoring is the fourth phase of the security certification and accreditation process. What activities are performed in the Continuous Monitoring process? Each correct answer represents a complete solution. Choose all that apply.

Options

  • ASecurity accreditation decision
  • BSecurity control monitoring and impact analyses of changes to the information system
  • CSecurity accreditation documentation
  • DConfiguration management and control
  • EStatus reporting and documentation

How the community answered

(57 responses)
  • A
    5% (3)
  • B
    88% (50)
  • C
    7% (4)

Why each option

Continuous monitoring involves ongoing oversight of an information system's security posture, which includes actively monitoring security controls, managing configurations, and regularly reporting on its security status.

ASecurity accreditation decision

The security accreditation decision is made by the Designated Approving Authority (DAA) in the Authorization phase, which precedes continuous monitoring, rather than being an activity within continuous monitoring itself.

BSecurity control monitoring and impact analyses of changes to the information systemCorrect

Security control monitoring and impact analyses of changes to the information system are fundamental to continuous monitoring, as they involve regularly assessing the effectiveness of implemented controls and understanding how system modifications affect the security posture.

CSecurity accreditation documentation

Security accreditation documentation is prepared during the earlier phases of the C&A process, such as Security Assessment and Authorization, to support the accreditation decision, not as a primary activity of the ongoing continuous monitoring phase.

DConfiguration management and controlCorrect

Configuration management and control ensures that the system's baseline configuration is maintained securely and that all changes are managed and assessed for security implications, which is a core activity within continuous monitoring.

EStatus reporting and documentationCorrect

Status reporting and documentation involves consistently communicating the security status, identified risks, and remediation activities to stakeholders, providing transparency and accountability in the continuous monitoring process.

Concept tested: Continuous Monitoring activities in C&A/RMF

Source: https://learn.microsoft.com/en-us/azure/security/benchmarks/security-controls-v3-governance-strategy-security-posture

Topics

#Continuous Monitoring#Security Certification and Accreditation#Configuration Management#Information System Security

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice