Cloud service providers for cloud products and services
C.
IT contractors for cybersecurity self-assessments
D.
Cloud service providers for on-premise products and services
The Answer Is:
B
This question includes an explanation.
Explanation:
The correct answer is B because FedRAMP is a federal authorization program for cloud services, not a self-assessment framework for ordinary IT contractors and not a program for on-premise products. In the CMMC context, FedRAMP becomes especially important when a contractor uses an external cloud service provider to store, process, or transmit covered defense information or CUI. DFARS 252.204-7012 requires the contractor to ensure that the cloud service provider meets security requirements equivalent to the FedRAMP Moderate baseline when covered defense information is handled in an external cloud service. FedRAMP itself also maintains a marketplace of certified cloud services, authorizing agencies, and recognized assessors. Therefore, the target participants are cloud service providers offering cloud products and services that need federal authorization or recognition. Options A and C incorrectly frame FedRAMP as a contractor self-assessment model. Option D is wrong because FedRAMP is focused on cloud service offerings, not traditional on-premise products or services. Reference/topics: FedRAMP, cloud service providers, DFARS 252.204-7012, external cloud services, FedRAMP Moderate baseline.
CMMC-CCP PDF/Engine
Printable Format
Value of Money
100% Pass Assurance
Verified Answers
Researched by Industry Experts
Based on Real Exams Scenarios
100% Real Questions
Get 65% Discount on All Products,
Use Coupon: "ac4s65"