Câu 10: CCA: CMMC Certified Assessor
A cloud-native OSC uses a popular vendor’s FedRAMP MODERATE authorized cloud environment for all aspects of their business’s CUI needs (identity, email, file storage, office suite, etc.) as well as the vendor’s locally installable applications. The OSC properly configured the vendor’s cloud-based SIEM system to monito…
Nội dung câu hỏi
A cloud-native OSC uses a popular vendor’s FedRAMP MODERATE authorized cloud environment for all aspects of their business’s CUI needs (identity, email, file storage, office suite, etc.) as well as the vendor’s locally installable applications. The OSC properly configured the vendor’s cloud-based SIEM system to monitor only aspects of the cloud environment. Additionally, the OSC’s SSP details the SI.L2-3.14.7: Identify Unauthorized Use practice by defining authorized system use and references the procedures for identifying unauthorized use. How should the Certified Assessor score this practice?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. MET because the cloud SIEM is configured to monitor all of the vendor’s cloud environment — đáp án hiện tại
- B. NOT MET because logs from physical infrastructure are not captured by the SIEM
- C. MET because being cloud-native is a great way to contain risk to a vendor’s environment
- D. NOT MET because locally installable applications from a cloud-native environment are not allowed
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.