Certified Records Manager (CRM) Exam — Questions and Answers
Question 1: What is 'records reconstruction' in the context of disaster recovery?
- Rebuilding destroyed physical folders and filing cabinets
- Converting surviving paper records to digital format after a disaster
- Reorganizing and reclassifying records after a system migration
- The process of recreating records lost in a disaster using secondary sources such as copies, backups, or related documents (Correct answer)
Correct answer: The process of recreating records lost in a disaster using secondary sources such as copies, backups, or related documents
Records reconstruction involves recreating lost or damaged records using alternate sources—backups, partner records, or related documents—when originals cannot be recovered.
Question 2: A legal hold is lifted after litigation concludes. What should the records manager do next regarding affected records?
- Transfer all held records to permanent archives
- Immediately destroy all records that were on hold
- Extend all hold records' retention by 5 additional years automatically
- Resume normal retention schedules and destroy records that have met their retention period (Correct answer)
Correct answer: Resume normal retention schedules and destroy records that have met their retention period
Once a legal hold is lifted, the records manager should evaluate each record against the retention schedule and dispose of any that have already met their retention period.
Question 3: What role does HIPAA play in records compliance?
- Restricts military records.
- Regulates tax records.
- Protects patient health information. (Correct answer)
- Controls banking disclosures.
Correct answer: Protects patient health information.
HIPAA, the Health Insurance Portability and Accountability Act, is a U.S. federal law that establishes national standards to protect sensitive patient health information. It governs how healthcare providers, health plans, and healthcare clearinghouses handle and secure Protected Health Information (PHI). Compliance with HIPAA is crucial for organizations dealing with medical records to avoid significant penalties.
Question 4: How does records management support a 'business continuity plan' (BCP)?
- By creating financial plans for operating during economic downturns
- By ensuring vital records are identified, protected, and accessible so essential functions can be maintained during disruptions (Correct answer)
- By creating succession plans for leadership transitions during emergencies
- By developing marketing strategies for business growth after a disaster
Correct answer: By ensuring vital records are identified, protected, and accessible so essential functions can be maintained during disruptions
Records management supports the BCP by ensuring vital records are protected and accessible, providing the information foundation needed to maintain essential operations during disruptions.
Question 5: What is the first step in establishing a vital records protection program?
- Conducting an inventory and risk assessment to identify which records are vital and the threats they face (Correct answer)
- Installing fireproof storage cabinets throughout the facility
- Training all employees in emergency response procedures
- Purchasing or contracting for off-site storage facilities
Correct answer: Conducting an inventory and risk assessment to identify which records are vital and the threats they face
Identifying vital records through inventory and assessing risks is the foundational step, as you must know what to protect and from what threats before implementing protection measures.
Question 6: What is an Electronic Document and Records Management System (EDRMS) primarily designed to do?
- Replace all paper-based communication
- Generate financial reports for auditors
- Capture, store, manage, and provide access to records throughout their lifecycle (Correct answer)
- Automate payroll processing
Correct answer: Capture, store, manage, and provide access to records throughout their lifecycle
An EDRMS is designed to capture, store, manage, and provide access to records throughout their entire lifecycle in a digital environment.
Question 7: Which disposition method involves permanently removing records from active use by either destruction or transfer to an archives?
- Migration
- Appraisal
- Final disposition (Correct answer)
- Conversion
Correct answer: Final disposition
Final disposition is the action taken at the end of a record's retention period, either destroying it or transferring it to permanent archives.
Question 8: What should organizations do to manage privacy risks?
- Conduct privacy impact assessments. (Correct answer)
- Ignore data subject rights.
- Avoid using passwords.
- Collect as much personal data as possible.
Correct answer: Conduct privacy impact assessments.
To effectively manage privacy risks, organizations should conduct Privacy Impact Assessments (PIAs) or Data Protection Impact Assessments (DPIAs). These assessments systematically identify and evaluate potential privacy risks associated with new projects, systems, or data processing activities. They help organizations implement appropriate safeguards and ensure compliance with privacy regulations before issues arise.
Question 9: A records manager is developing a security policy for email records containing PII. The FIRST step should be to:
- Identify and classify the PII contained in email records (Correct answer)
- Delete emails older than one year
- Migrate all email records to cloud storage
- Immediately encrypt all email archives
Correct answer: Identify and classify the PII contained in email records
Before applying controls, the manager must identify and classify what PII exists in email records to determine the appropriate protection level.
Question 10: What differentiates fixed from variable costs in CRM?
- No difference
- Variable are optional
- Fixed are always higher
- Fixed costs stay constant; variable costs change with volume (Correct answer)
Correct answer: Fixed costs stay constant; variable costs change with volume
Fixed costs (rent, salaries) remain constant; variable costs (materials, commissions) fluctuate with activity volume.
Question 11: What is the primary purpose of a records retention schedule?
- To document how long each record series must be kept and its final disposition (Correct answer)
- To establish backup procedures for electronic records
- To categorize records by their physical format
- To list all employees who have access to records
Correct answer: To document how long each record series must be kept and its final disposition
A retention schedule identifies each record series, specifies its retention period, and defines the final disposition action (destroy, transfer, archive).
Question 12: Which ARMA International principle addresses the requirement that records be accessible and usable when needed, including during and after a disaster?
- The Compliance Principle
- The Integrity Principle
- The Retention Principle
- The Availability Principle (Correct answer)
Correct answer: The Availability Principle
ARMA's Availability Principle within the Generally Accepted Recordkeeping Principles (GARP) requires that records be accessible and usable when needed, which encompasses vital records protection.
Question 13: What is the primary challenge of managing email as official business records?
- Email systems do not support metadata attachment
- Email cannot be legally admitted as evidence in court proceedings
- High volume, informal communication style, and difficulty determining which emails constitute official records (Correct answer)
- Email servers are too unreliable for records storage
Correct answer: High volume, informal communication style, and difficulty determining which emails constitute official records
The primary challenge with email records management is the enormous volume of messages combined with the difficulty of determining which emails constitute official records requiring retention.
Question 14: What is the primary goal of information security?
- To increase data volume.
- To ensure data is protected from unauthorized access or changes. (Correct answer)
- To print more paper files.
- To improve aesthetics.
Correct answer: To ensure data is protected from unauthorized access or changes.
The primary goal of information security is to protect the confidentiality, integrity, and availability (CIA triad) of information assets. This means safeguarding data from unauthorized access, use, disclosure, disruption, modification, or destruction. Effective information security measures are crucial for maintaining trust, complying with regulations, and protecting an organization's valuable data.
Question 15: Why is regular review important in CRM risk management?
- Only needed after incidents
- Prohibited more than annually
- Assessments stay valid forever
- Conditions change and new risks emerge requiring updates (Correct answer)
Correct answer: Conditions change and new risks emerge requiring updates
Regular reviews ensure assessments remain current as conditions change and lessons from incidents are incorporated.
Question 16: Why is multi-factor authentication important?
- It enhances account protection with multiple verification methods. (Correct answer)
- It increases login errors.
- It eliminates passwords completely.
- It slows down users.
Correct answer: It enhances account protection with multiple verification methods.
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more verification factors to gain access to an account or system. These factors typically include something the user knows (like a password), something the user has (like a phone or token), and something the user is (like a fingerprint). This layered approach makes it much harder for unauthorized individuals to compromise accounts, even if they steal a password.
Question 17: According to the records lifecycle model, which phase immediately follows the creation phase?
- Distribution/Use (Correct answer)
- Appraisal
- Archival storage
- Disposition
Correct answer: Distribution/Use
After a record is created, it enters the distribution and active use phase, during which it is accessed and referenced for business purposes.
Question 18: What is the purpose of data analysis in CRM practice?
- Replacing professional judgment
- Collecting data regardless of relevance
- Creating attractive charts only
- Transforming raw data into insights for informed decision-making (Correct answer)
Correct answer: Transforming raw data into insights for informed decision-making
Data analysis examines, cleans, and models data to discover useful information and support decision-making.
Question 19: Which concept describes the legally recognized principle that organizations must not destroy records once they are aware that litigation or investigation is reasonably anticipated?
- Accession
- Appraisal
- Spoliation (Correct answer)
- Cutoff
Correct answer: Spoliation
Spoliation refers to the destruction or alteration of evidence once litigation is reasonably anticipated; it can result in severe legal sanctions including adverse inference instructions.
Question 20: The Sarbanes-Oxley Act (SOX) Section 802 primarily affects records management by doing which of the following?
- Requiring 7-year retention for all employee personnel records
- Making it a federal crime to alter, destroy, or falsify records related to federal investigations (Correct answer)
- Mandating annual records audits for all public companies
- Requiring all financial records to be stored in the cloud
Correct answer: Making it a federal crime to alter, destroy, or falsify records related to federal investigations
SOX Section 802 criminalizes the destruction, alteration, or falsification of records in federal investigations and bankruptcy proceedings.
Question 21: In the context of records security, 'chain of custody' refers to:
- The hierarchy of employees authorized to approve records destruction
- A process for encrypting records during transit
- The legal retention period for evidence records
- The documented history of who has accessed, transferred, or handled a record (Correct answer)
Correct answer: The documented history of who has accessed, transferred, or handled a record
Chain of custody tracks every person who has accessed or handled a record, ensuring its integrity and admissibility as evidence.
Question 22: Under the Generally Accepted Recordkeeping Principles® (GARP®), which principle emphasizes that records must be complete and unaltered?
- Compliance
- Protection
- Availability
- Integrity (Correct answer)
Correct answer: Integrity
The Integrity principle under GARP® requires that records be complete, accurate, and protected against unauthorized alteration.
Question 23: What are 'emergency operating records' in a vital records program?
- Personnel files for designated emergency response staff
- Records documenting past emergency incidents and their outcomes
- Records needed to continue or resume essential operations immediately following a disaster (Correct answer)
- Records required for annual regulatory audits
Correct answer: Records needed to continue or resume essential operations immediately following a disaster
Emergency operating records include those needed to immediately resume essential business functions after a disaster, such as contact lists, system documentation, and operational procedures.
Question 24: What is a 'Recovery Point Objective' (RPO) in disaster recovery planning?
- The geographic location designated as the primary records recovery site
- The priority ranking assigned to records for recovery sequencing
- The maximum age of the most recent backup from which data can be recovered after a disaster (Correct answer)
- The number of backup copies required for all vital records
Correct answer: The maximum age of the most recent backup from which data can be recovered after a disaster
RPO defines the maximum acceptable data loss measured in time, determining how frequently backups must be made to meet recovery requirements.
Question 25: Which of the following is an example of 'data minimization' in records management?
- Collecting only the personal data necessary for a specified purpose (Correct answer)
- Storing personal data in multiple backup locations
- Collecting all available customer data for potential future use
- Sharing personal data with all business units by default
Correct answer: Collecting only the personal data necessary for a specified purpose
Data minimization means collecting only the personal data actually needed for a defined purpose, reducing privacy risk.
Question 26: How should sensitive paper records be disposed?
- Recycled without review.
- Stored in unlocked cabinets.
- Thrown in public bins.
- Shredded or destroyed securely. (Correct answer)
Correct answer: Shredded or destroyed securely.
Sensitive paper records contain confidential or personal information that, if exposed, could lead to privacy breaches or identity theft. Therefore, they must be disposed of securely, typically through shredding, pulping, or incineration, to render the information unreadable and irrecoverable. This prevents unauthorized access and ensures compliance with data protection regulations.
Question 27: What is 'format obsolescence' in electronic records management?
- When file formats become unreadable due to discontinued software or hardware support (Correct answer)
- When a file format becomes too widely used and slows systems
- When records exceed their approved retention period
- When an electronic format is converted to a paper-based format
Correct answer: When file formats become unreadable due to discontinued software or hardware support
Format obsolescence occurs when a file format becomes inaccessible because the software or hardware needed to open or render it is no longer available or supported.
Question 28: What is the primary purpose of conducting regular tests of a vital records program?
- To generate documentation that justifies the budget for off-site storage
- To provide hands-on training for newly hired records management staff
- To satisfy annual regulatory audit requirements only
- To verify that protection measures work, recovery procedures are effective, and that the vital records inventory remains accurate (Correct answer)
Correct answer: To verify that protection measures work, recovery procedures are effective, and that the vital records inventory remains accurate
Regular testing confirms that vital records can actually be retrieved and used when needed and reveals any gaps in protection or recovery procedures.
Question 29: Under the GDPR, a data subject's 'right to erasure' is also known as the:
- Right to access
- Right to be forgotten (Correct answer)
- Right to rectification
- Right to portability
Correct answer: Right to be forgotten
The GDPR's right to erasure (Article 17) is commonly called the 'right to be forgotten,' allowing individuals to request deletion of their personal data.
Question 30: In records management, what does 'format migration' address?
- Moving physical records from one storage facility to another
- Reclassifying records under a new file plan structure
- Converting records from obsolete file formats to current ones to ensure long-term accessibility (Correct answer)
- Transferring records from paper to microfilm
Correct answer: Converting records from obsolete file formats to current ones to ensure long-term accessibility
Format migration converts electronic records from outdated or obsolete formats to current ones to prevent data loss due to technological obsolescence.
Question 31: What is the primary purpose of a vital records protection program?
- To comply with copyright and intellectual property laws
- To reduce storage costs for all organizational records
- To standardize the format of all organizational records
- To ensure critical records are protected and accessible to maintain operations during and after a disaster (Correct answer)
Correct answer: To ensure critical records are protected and accessible to maintain operations during and after a disaster
A vital records protection program ensures that records essential for business continuity, legal rights, and obligations are protected and recoverable in a disaster.
Question 32: What role does a 'records inventory' play in developing a retention schedule?
- It identifies what records exist, where they are located, and in what format, serving as the foundation for scheduling (Correct answer)
- It assigns retention periods based on legal research
- It authorizes the destruction of records past their retention period
- It establishes legal holds for records under litigation
Correct answer: It identifies what records exist, where they are located, and in what format, serving as the foundation for scheduling
A records inventory surveys all existing record series, their locations, formats, and volumes, providing the baseline data needed to develop an accurate retention schedule.
Question 33: In a records management system, what does 'interoperability' refer to?
- The system's ability to self-correct data entry errors
- The capacity of different systems to exchange and use information seamlessly (Correct answer)
- The ability of the system to run without internet
- The number of users who can access the system simultaneously
Correct answer: The capacity of different systems to exchange and use information seamlessly
Interoperability refers to the capacity of different systems and organizations to exchange and use information seamlessly without special effort.
Question 34: In records management, what is an 'enterprise content management' (ECM) system?
- A comprehensive platform for capturing, managing, storing, preserving, and delivering content across an organization (Correct answer)
- A tool used only for scanning physical documents
- A financial reporting platform for large corporations
- A system exclusively for managing email communications
Correct answer: A comprehensive platform for capturing, managing, storing, preserving, and delivering content across an organization
An ECM system is a comprehensive platform that captures, manages, stores, preserves, and delivers content and records across an entire organization.
Question 35: What is cloud storage's primary advantage for records management programs?
- It removes legal liability for records management compliance
- It provides scalable, offsite storage accessible from multiple locations with built-in redundancy (Correct answer)
- It eliminates the need for a records retention schedule
- It automatically classifies records by subject matter
Correct answer: It provides scalable, offsite storage accessible from multiple locations with built-in redundancy
Cloud storage provides scalable, offsite storage that is accessible from multiple locations and typically includes built-in redundancy to protect against data loss.
Question 36: Under the Sarbanes-Oxley Act (SOX), public companies must retain audit work papers and related records for a minimum of:
- 5 years
- 7 years (Correct answer)
- 10 years
- 3 years
Correct answer: 7 years
SOX Section 802 requires retention of audit and review work papers for at least 7 years from the end of the fiscal period covered.
Question 37: Under HIPAA, covered entities must retain medical records and documentation for a minimum of how many years from the date of creation or last effective date?
- 6 years (Correct answer)
- 10 years
- 5 years
- 3 years
Correct answer: 6 years
HIPAA requires covered entities to retain documentation (such as policies and procedures) for 6 years from the date of creation or last effective date, whichever is later.
Question 38: An organization's retention schedule conflicts with a state law requiring longer retention than the company policy specifies. Which takes precedence?
- The shorter period, to reduce storage costs
- The company policy, because it was created by internal stakeholders
- Whichever was established most recently
- The state law, because legal requirements supersede internal policy (Correct answer)
Correct answer: The state law, because legal requirements supersede internal policy
Legal and regulatory requirements always supersede organizational retention policies; the organization must comply with the more stringent legal requirement.
Question 39: A records manager receives a legal hold notice. What action regarding information security should be taken IMMEDIATELY?
- Apply the standard retention schedule and document the decision
- Suspend normal disposition and ensure all potentially relevant records are preserved and protected from alteration (Correct answer)
- Encrypt all organizational records enterprise-wide
- Transfer all records to legal counsel's office
Correct answer: Suspend normal disposition and ensure all potentially relevant records are preserved and protected from alteration
A legal hold supersedes normal retention schedules, requiring immediate preservation and protection of relevant records from any deletion or modification.
Question 40: Which protection method provides the highest level of safeguard for vital records against physical disaster?
- Maintaining duplicate copies at a geographically remote off-site location (Correct answer)
- Encrypting all digital records with strong encryption
- Using acid-free archival storage materials for paper records
- Storing records in fireproof cabinets located on-site
Correct answer: Maintaining duplicate copies at a geographically remote off-site location
Geographically remote off-site duplication protects vital records from site-specific disasters—fires, floods, earthquakes—that could destroy on-site storage entirely.
Question 41: What is the purpose of 'redaction' in records management?
- To permanently delete a record from all systems
- To remove or obscure sensitive information before releasing a record (Correct answer)
- To apply a retention hold to a record
- To convert paper records into digital format
Correct answer: To remove or obscure sensitive information before releasing a record
Redaction removes or blacks out sensitive portions of a document before it is shared or released, protecting private or privileged information.
Question 42: How do regulations differ from standards in CRM practice?
- They are the same
- Regulations only apply to individuals
- Standards are always stricter
- Regulations are legally binding; standards are typically voluntary (Correct answer)
Correct answer: Regulations are legally binding; standards are typically voluntary
Regulations are legally enforceable government rules; standards are industry-developed guidelines that may become requirements through adoption.
Question 43: What is a benefit of automating retention schedules?
- Increases manual errors.
- Reduces data integrity.
- Enhances compliance and reduces oversight. (Correct answer)
- Slows down audits.
Correct answer: Enhances compliance and reduces oversight.
Automating retention schedules streamlines the entire records lifecycle management process. It ensures that records are consistently retained for the correct periods and disposed of promptly when due, significantly enhancing compliance with legal and regulatory requirements. Automation reduces the need for manual tracking and human error, thereby minimizing oversight risks and improving efficiency.
Question 44: Why is written communication important in CRM practice?
- Eliminated by technology
- It creates permanent records and ensures clarity for future reference (Correct answer)
- Only for legal disputes
- Less effective than verbal always
Correct answer: It creates permanent records and ensures clarity for future reference
Written communication creates documented records, provides clarity, and serves as reference material for decisions and actions.
Question 45: What is stakeholder mapping in CRM practice?
- Identifying parties with project interest and assessing their influence (Correct answer)
- Tracking competitor locations
- Mapping demographics
- Creating geographical maps
Correct answer: Identifying parties with project interest and assessing their influence
Stakeholder mapping identifies everyone affected by a project, categorizing them by influence and expectations for targeted engagement.
Question 46: Which security control is specifically designed to detect unauthorized changes to records?
- Role-based access control (RBAC)
- Firewall rules
- Data loss prevention (DLP) software
- Audit trails and hash verification (Correct answer)
Correct answer: Audit trails and hash verification
Audit trails log all access and modifications, while cryptographic hashing can detect if a record's content has been altered.
Question 47: A 'functional classification scheme' organizes records based on which of the following?
- The chronological order in which records were created
- The business functions and activities that generated the records (Correct answer)
- The organizational unit that created the records
- The physical medium on which records are stored
Correct answer: The business functions and activities that generated the records
A functional classification scheme groups records according to the business functions and activities they document, rather than by department or creator.
Question 48: What is a 'Recovery Time Objective' (RTO) in business continuity planning?
- The maximum acceptable time to restore a business function after a disruption (Correct answer)
- The maximum amount of data loss an organization can tolerate measured in time
- The scheduled date for the next disaster recovery drill or test
- The time required to complete the annual vital records review
Correct answer: The maximum acceptable time to restore a business function after a disruption
RTO defines the maximum tolerable downtime before a business function must be restored, guiding recovery planning and resource allocation.
Question 49: Which federal law primarily governs privacy of student education records in the United States?
- HIPAA
- GLBA
- FERPA (Correct answer)
- SOX
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at institutions receiving federal funding.
Question 50: How should confidential records be stored?
- Under employee desks.
- In open office bins.
- Piled near exits.
- In locked cabinets or encrypted systems. (Correct answer)
Correct answer: In locked cabinets or encrypted systems.
Confidential records contain sensitive information that, if exposed, could cause harm to individuals or the organization. Therefore, they must be stored with robust security measures to prevent unauthorized access. Locked physical cabinets or secure, encrypted digital systems provide the necessary protection, ensuring data privacy and compliance with data protection regulations.
Question 51: What is a milestone in CRM project management?
- A physical construction marker
- A significant event marking progress at a key point in the timeline (Correct answer)
- A daily required task
- An optional checkpoint
Correct answer: A significant event marking progress at a key point in the timeline
Milestones are significant checkpoints marking completion of major deliverables or phase transitions.
Question 52: Which DoD standard establishes design criteria requirements for electronic records management software applications used by federal agencies?
- DoD 5015.2 (Correct answer)
- DoD 4150.7
- DoD 3020.26
- DoD 8570.01
Correct answer: DoD 5015.2
DoD 5015.2 (Design Criteria Standard for Electronic Records Management Software Applications) establishes requirements for RMA software used by DoD and other federal agencies.
Question 53: What is the hierarchy of controls in CRM risk management?
- Assessment, planning, implementation
- Elimination, substitution, engineering, administrative, then PPE (Correct answer)
- PPE first, then administrative
- Insurance, training, documentation
Correct answer: Elimination, substitution, engineering, administrative, then PPE
The hierarchy prioritizes the most effective controls first, from eliminating the hazard to using PPE as last resort.
Question 54: How frequently should an organization review and update its vital records inventory?
- At least annually, or whenever significant changes occur to business functions or systems (Correct answer)
- Only when a disaster occurs
- Once every five years as part of a full records audit
- Whenever a new employee joins the records management team
Correct answer: At least annually, or whenever significant changes occur to business functions or systems
Vital records inventories should be reviewed at least annually or when business functions change to ensure the inventory remains accurate and current.
Question 55: What does residual risk mean in CRM practice?
- Initial risk before assessment
- Budget overrun risk
- Risk remaining after all controls are implemented (Correct answer)
- Risk affecting waste materials
Correct answer: Risk remaining after all controls are implemented
Residual risk is the level remaining after practical controls are applied. Some is usually accepted as eliminating all risk is rarely feasible.
Question 56: What is the triple constraint in CRM project management?
- The interdependent relationship between scope, time, and cost (Correct answer)
- Three required team members
- Three mandatory approvals
- Three completion phases
Correct answer: The interdependent relationship between scope, time, and cost
Scope, time, and cost are interdependent: changing one affects the others. Managers must balance all three.
Question 57: Which records management concept refers to the degree to which records can be trusted as accurate representations of the transactions they document?
- Authenticity
- Usability
- Reliability (Correct answer)
- Integrity
Correct answer: Reliability
Reliability refers to the trustworthiness of a record as a full and accurate representation of the transaction or activity it documents, established at the time of creation.
Question 58: Which of the following best describes 'disposition' in records management?
- The final action taken on records at the end of their retention period (Correct answer)
- The transfer of records ownership between departments
- The physical arrangement of records in a filing system
- The process of classifying records by subject
Correct answer: The final action taken on records at the end of their retention period
Disposition refers to the final action taken on records once their retention period expires, which may include destruction, transfer, or permanent preservation.
Question 59: What is a communication plan in CRM project management?
- Restricting who can communicate
- Eliminating meetings
- Reducing total communication
- Defining what information is shared, with whom, when, and how (Correct answer)
Correct answer: Defining what information is shared, with whom, when, and how
A communication plan establishes content, audience, frequency, channels, and responsibilities for project communications.
Question 60: What does the term 'trustworthy digital repository' (TDR) refer to in records management?
- Any cloud storage service with a financially guaranteed uptime SLA
- A digital archive that reliably and sustainably provides long-term access to managed digital resources to its designated community (Correct answer)
- Any records system certified for use by a government agency
- A firewall-protected on-premise records server
Correct answer: A digital archive that reliably and sustainably provides long-term access to managed digital resources to its designated community
A trustworthy digital repository is a system that reliably and sustainably provides access to managed digital resources to a designated community, meeting established criteria for long-term preservation such as those in ISO 16363.
Question 61: What is a 'hybrid records environment'?
- A records program managed by two different departments jointly
- An environment where both physical paper records and electronic records coexist and must be managed together (Correct answer)
- A network that connects two separate office buildings
- A system that uses two different brands of servers
Correct answer: An environment where both physical paper records and electronic records coexist and must be managed together
A hybrid records environment is one where both physical paper records and electronic records coexist and must be managed together under a unified program.
Question 62: What is the primary purpose of an Electronic Document Management System (EDMS)?
- To print documents automatically
- To encrypt all organizational communications
- To capture, store, manage, and retrieve electronic records throughout their lifecycle (Correct answer)
- To replace physical filing systems exclusively
Correct answer: To capture, store, manage, and retrieve electronic records throughout their lifecycle
An EDMS is designed to capture, store, manage, and retrieve electronic documents and records throughout their entire lifecycle.
Question 63: What is the risk of keeping records beyond their retention period?
- Reduced compliance risk.
- More office space.
- Increased liability and costs. (Correct answer)
- Higher employee satisfaction.
Correct answer: Increased liability and costs.
Keeping records beyond their legally or operationally required retention period significantly increases an organization's liability. These unnecessary records can become discoverable in litigation, potentially exposing sensitive information or creating additional burdens during e-discovery. Furthermore, over-retention incurs unnecessary storage costs and complicates data management.
Question 64: What is budget variance analysis in CRM financial management?
- Comparing actual spending against budgeted amounts to explain differences (Correct answer)
- Counting cash
- Creating next year's budget
- Reviewing expense reports
Correct answer: Comparing actual spending against budgeted amounts to explain differences
Variance analysis compares actual results against budget, calculating differences and investigating causes.
Question 65: Who is responsible for compliance with records policies?
- Only IT staff.
- External vendors.
- Everyone in the organization. (Correct answer)
- Just the records manager.
Correct answer: Everyone in the organization.
While a records manager or specific department may oversee the records management program, compliance with records policies is a shared responsibility across the entire organization. Every employee who creates, receives, uses, or disposes of records must adhere to established policies and procedures. This collective responsibility ensures the integrity, security, and legal compliance of all organizational information.
Question 66: How are 'vital records' defined in records management?
- Records essential to resume or continue operations, protect legal rights, or fulfill obligations during or after a disaster (Correct answer)
- Any record classified as confidential or sensitive
- All records created by senior management
- Records older than 25 years that require permanent preservation
Correct answer: Records essential to resume or continue operations, protect legal rights, or fulfill obligations during or after a disaster
Vital records are those essential for an organization to resume operations, protect rights, and meet legal obligations following a disaster or emergency.
Question 67: What is the critical path in CRM project scheduling?
- Tasks that can be skipped
- The longest sequence of dependent tasks determining minimum duration (Correct answer)
- The shortest route to complete cheaply
- The most expensive phase
Correct answer: The longest sequence of dependent tasks determining minimum duration
The critical path identifies the longest chain of dependent tasks; delays on these directly delay project completion.
Question 68: What is the risk of applying a 'keep everything forever' records management approach?
- Faster obsolescence of record formats
- Reduced compliance with federal retention minimums
- Increased storage costs and expanded litigation discovery exposure (Correct answer)
- Records become too organized and findable
Correct answer: Increased storage costs and expanded litigation discovery exposure
Retaining all records indefinitely inflates storage costs and creates broader e-discovery obligations, as all retained records are potentially discoverable in litigation.
Question 69: How does a 'warm site' differ from both hot and cold sites in disaster recovery?
- A warm site stores only paper records while hot and cold sites store digital records
- A warm site is shared with other organizations while hot and cold sites are dedicated facilities
- A warm site is always located in a temperate climate zone
- A warm site is partially equipped with hardware and communications, requiring less setup time than a cold site but not immediately operational like a hot site (Correct answer)
Correct answer: A warm site is partially equipped with hardware and communications, requiring less setup time than a cold site but not immediately operational like a hot site
A warm site provides a middle ground—partial infrastructure reduces recovery time compared to a cold site, but at lower cost than a fully operational hot site.
Question 70: What does 'chain of custody' mean in the context of electronic records?
- A method for encrypting records during electronic transfer
- A series of legal regulations governing records retention
- The documented chronological sequence of possession and control of a record (Correct answer)
- The process of converting records between different file formats
Correct answer: The documented chronological sequence of possession and control of a record
Chain of custody documents the chronological sequence of possession and handling of a record, which is essential for establishing authenticity and legal admissibility in court.
Question 71: What is the purpose of a data breach response plan?
- To notify competitors.
- To address and mitigate data breach incidents. (Correct answer)
- To delay breach reporting.
- To increase data collection.
Correct answer: To address and mitigate data breach incidents.
A data breach response plan is a critical component of an organization's information security strategy. Its purpose is to provide a structured, pre-defined set of actions to be taken immediately following a data breach incident. This plan helps an organization quickly contain the breach, assess its impact, notify affected parties, and implement remediation steps to minimize damage and restore security.
Question 72: What is the primary purpose of a data classification policy in records management?
- To determine the physical storage location of records
- To index records for faster retrieval
- To assign retention schedules to all records
- To categorize information by sensitivity and apply appropriate controls (Correct answer)
Correct answer: To categorize information by sensitivity and apply appropriate controls
Data classification policies categorize records by sensitivity level so that appropriate security controls can be applied to each category.
Question 73: When selecting a records management software system, which factor is MOST important from a records management perspective?
- Compatibility with the CEO's personal device
- Lowest upfront licensing cost
- Attractive user interface design
- Compliance with recognized records management standards such as DoD 5015.2 or ISO 16175 (Correct answer)
Correct answer: Compliance with recognized records management standards such as DoD 5015.2 or ISO 16175
Compliance with recognized standards like DoD 5015.2 or ISO 16175 is most important because it ensures the system meets functional requirements for managing records properly.
Question 74: What is 'least privilege' in access control?
- Limiting access to only necessary data. (Correct answer)
- Allowing full access to all users.
- Revoking admin rights for IT staff.
- Giving access based on age.
Correct answer: Limiting access to only necessary data.
The principle of 'least privilege' in access control dictates that users, programs, or processes should be granted only the minimum level of access permissions necessary to perform their specific tasks. This minimizes the potential damage from accidental errors, misuse, or malicious activity, as it restricts what an unauthorized individual or compromised account can access or alter.
Question 75: Which principle states that records of an organization should not be mixed with records of another organization?
- Principle of Original Order
- Principle of Provenance (Correct answer)
- Principle of Pertinence
- Principle of Respect des Fonds
Correct answer: Principle of Provenance
The Principle of Provenance (also called Respect des Fonds) mandates that records from different organizations or creators must be kept separate.
Question 76: What is scope creep in CRM project management?
- Natural planned growth
- Reducing deliverables
- Uncontrolled scope expansion without adjusting time, cost, or resources (Correct answer)
- Incremental feature addition technique
Correct answer: Uncontrolled scope expansion without adjusting time, cost, or resources
Scope creep adds requirements without formal evaluation, causing schedule delays and budget overruns.
Question 77: Why is employee training essential for information security?
- It helps staff recognize and avoid security risks. (Correct answer)
- It replaces software updates.
- It encourages data sharing.
- It increases administrative tasks.
Correct answer: It helps staff recognize and avoid security risks.
Employee training is essential for information security because human error is a leading cause of security breaches. Training equips staff with the knowledge to recognize phishing attempts, understand data handling protocols, and follow security best practices. This proactive approach significantly reduces the risk of security incidents by fostering a security-aware culture.
Question 78: What must an organization do during a legal hold?
- Preserve potentially relevant records without alteration. (Correct answer)
- Continue routine disposal.
- Digitize all paper files.
- Delete all unrelated emails.
Correct answer: Preserve potentially relevant records without alteration.
A legal hold, also known as a litigation hold, is a process an organization must initiate when it anticipates litigation or an investigation. Its purpose is to prevent the destruction or alteration of any records, both physical and electronic, that might be relevant to the impending legal action. Failing to preserve such records can lead to severe sanctions for spoliation of evidence.
Question 79: What does disposition refer to in records management?
- Moving records to a new folder.
- Archiving or securely destroying records. (Correct answer)
- Scanning all papers.
- Changing font styles.
Correct answer: Archiving or securely destroying records.
In records management, disposition refers to the final phase of a record's lifecycle, which occurs after its active and inactive retention periods have expired. This involves either archiving records of enduring value for historical or permanent preservation or securely destroying records that are no longer needed and have met all legal and business retention requirements. Proper disposition is crucial for compliance and risk mitigation.
Question 80: Which category of vital records primarily protects the rights and interests of employees and individuals?
- Historical records
- Emergency operating records
- Rights and interests records (Correct answer)
- Regulatory compliance records
Correct answer: Rights and interests records
Rights and interests records—such as payroll, pension, and benefits records—protect employee entitlements and legal rights.
Question 81: What is an internal control in CRM financial management?
- Temperature control
- Controlling employee behavior
- A remote control device
- A process providing assurance about financial reporting reliability (Correct answer)
Correct answer: A process providing assurance about financial reporting reliability
Internal controls safeguard assets, ensure accurate reporting, promote efficiency, and ensure compliance.
Question 82: In records management, what does the term 'vital records' refer to?
- Records older than 50 years
- Records created most frequently
- Records essential to resume operations during or after a disaster (Correct answer)
- Records requiring the highest security classification
Correct answer: Records essential to resume operations during or after a disaster
Vital records are those critical to an organization's survival and ability to continue or resume operations following a disaster or emergency.
Question 83: When records are transferred to a third-party vendor for storage or processing, which document BEST protects the organization's privacy obligations?
- A service level agreement (SLA) for uptime
- A data processing agreement (DPA) specifying security and privacy requirements (Correct answer)
- An internal retention schedule
- A records destruction certificate
Correct answer: A data processing agreement (DPA) specifying security and privacy requirements
A DPA contractually obligates third-party vendors to uphold the organization's data protection standards when handling personal information.
Question 84: What is a 'record retention schedule'?
- A list of archived folders.
- A document that defines how long records should be retained. (Correct answer)
- An appointment log for shredding.
- A meeting calendar.
Correct answer: A document that defines how long records should be retained.
A record retention schedule is a critical document that specifies the minimum amount of time different types of records must be kept by an organization. It is developed based on legal, regulatory, fiscal, and operational requirements. This schedule ensures compliance, prevents premature destruction of important information, and guides the systematic disposition of records when they are no longer needed.
Question 85: What is a work breakdown structure in CRM practice?
- Team member roster
- Hierarchical decomposition of deliverables into manageable work packages (Correct answer)
- Organizational reporting diagram
- Employee schedule report
Correct answer: Hierarchical decomposition of deliverables into manageable work packages
A WBS breaks total scope into progressively smaller components for easier estimation, scheduling, and tracking.
Question 86: What is a 'superseded' record, and how is it typically treated in a retention schedule?
- A record that has been legally challenged; retained indefinitely
- A copy held by a secondary department; treated as the record of original entry
- An older version replaced by an updated record; often destroyed when replaced (Correct answer)
- A record requiring encryption; stored in a separate secure system
Correct answer: An older version replaced by an updated record; often destroyed when replaced
Superseded records are earlier versions replaced by updated documents; retention schedules typically allow their destruction once the current version is approved.
Question 87: What is a record retention schedule?
- An event planning document.
- A list of meeting times.
- A calendar of pay periods.
- A timeline for keeping and disposing of records. (Correct answer)
Correct answer: A timeline for keeping and disposing of records.
A record retention schedule is a systematic plan that specifies how long different types of records must be kept and when they can be legally and safely disposed of. It is a critical tool for managing the lifecycle of information, ensuring compliance with legal and regulatory requirements, and optimizing storage resources. This schedule dictates the minimum and maximum retention periods.
Question 88: Which regulation requires financial institutions to protect the privacy of consumers' nonpublic personal information (NPI)?
- HIPAA
- GLBA (Gramm-Leach-Bliley Act) (Correct answer)
- CCPA
- FERPA
Correct answer: GLBA (Gramm-Leach-Bliley Act)
The GLBA mandates that financial institutions safeguard the nonpublic personal information of their customers.
Question 89: What is trend analysis in CRM reporting?
- Analyzing fashion trends
- Predicting exact futures
- Comparing single data points
- Examining data over time to identify patterns and changes (Correct answer)
Correct answer: Examining data over time to identify patterns and changes
Trend analysis examines historical data to identify patterns, directions, and rates of change.
Question 90: What is a 'records series' in records management terminology?
- A set of records created by the same author
- A chronological sequence of documents filed by date
- A collection of records sharing the same security classification
- A group of related records filed or maintained together as a unit (Correct answer)
Correct answer: A group of related records filed or maintained together as a unit
A records series is a group of related records arranged under a single filing system and evaluated as a unit for retention and disposition purposes.
Question 91: Which document provides proof of compliance?
- Email threads.
- Employee surveys.
- Audit logs or trails. (Correct answer)
- Handwritten notes.
Correct answer: Audit logs or trails.
Audit logs or trails provide a chronological record of activities, such as who accessed a record, when, and what changes were made. These logs serve as irrefutable evidence of compliance with data access, security, and retention policies. They are essential for demonstrating accountability and transparency during internal or external audits.
Question 92: What is the primary purpose of a file plan?
- To schedule records for destruction
- To establish access controls for sensitive records
- To provide a framework for classifying and organizing records (Correct answer)
- To document the chain of custody for legal records
Correct answer: To provide a framework for classifying and organizing records
A file plan is a structured scheme for organizing, classifying, and filing records to ensure consistency and retrievability across an organization.
Question 93: Which metadata element is MOST critical for enabling retrieval of records in a records management system?
- Classification or subject descriptor (Correct answer)
- File size
- Font type used in the document
- Creator's email address
Correct answer: Classification or subject descriptor
Classification or subject descriptor metadata is most critical because it enables users to locate and retrieve records based on their content and context.
Question 94: Which concept describes the practice of building privacy protections into systems and processes from the start, rather than adding them later?
- Privacy by design (Correct answer)
- Privacy shield framework
- Privacy impact assessment
- Privacy by default
Correct answer: Privacy by design
Privacy by design embeds privacy protections into the architecture of systems and business practices from the outset, not as an afterthought.
Question 95: What is the benefit of classifying records?
- To confuse unauthorized users.
- To organize records systematically for easy access. (Correct answer)
- To automate backups.
- To delete old records faster.
Correct answer: To organize records systematically for easy access.
Classifying records involves categorizing them based on their function, content, or importance. This systematic organization is highly beneficial as it allows for efficient storage, retrieval, and management of information. Proper classification ensures that records can be easily located when needed, supports the application of correct retention schedules, and helps maintain the integrity and security of the organization's data.
Question 96: What is the role of a records manager in an organization's disaster recovery plan?
- To select and purchase disaster recovery insurance policies
- To manage financial recovery and insurance claims after a disaster
- To identify vital records, oversee their protection, and coordinate records recovery following a disaster (Correct answer)
- To train all employees in emergency evacuation and safety procedures
Correct answer: To identify vital records, oversee their protection, and coordinate records recovery following a disaster
Records managers identify vital records, ensure protection strategies are in place, and lead records recovery efforts as part of the broader disaster recovery plan.
Question 97: What is a key principle of digital records management?
- Restrict all access permanently.
- Maintain records in formats that are readable over time. (Correct answer)
- Delete records annually.
- Convert all to paper.
Correct answer: Maintain records in formats that are readable over time.
A critical challenge in digital records management is ensuring the long-term accessibility and readability of electronic information, often referred to as digital preservation. Technology evolves rapidly, and file formats can become obsolete, making older records unreadable. Therefore, a key principle is to proactively manage digital records by migrating them to current, stable formats or ensuring the availability of necessary software to maintain their usability over extended periods.
Question 98: What concept describes the chain of custody and ownership history of a record from creation to final disposition?
- Records lifecycle
- Custodial history (Correct answer)
- Archival bond
- Provenance
Correct answer: Custodial history
Custodial history tracks who has had custody of a record over time, which is important for establishing authenticity and evidentiary value.
Question 99: What is active listening in CRM practice?
- Hearing while multitasking
- Fully concentrating on the speaker and providing thoughtful feedback (Correct answer)
- Taking notes without engagement
- Waiting for your turn to speak
Correct answer: Fully concentrating on the speaker and providing thoughtful feedback
Active listening involves fully focusing on the speaker, processing the message, and providing thoughtful responses demonstrating understanding.
Question 100: Which electronic records management approach maintains records in their original business systems rather than transferring them to a separate repository?
- Centralized repository approach
- Digital vault consolidation strategy
- In-place records management (Correct answer)
- Archive migration approach
Correct answer: In-place records management
In-place records management applies records management policies to records where they reside in their original business systems without physically relocating them to a separate repository.
Certified Records Manager (CRM) Exam
The CRM certification validates expertise in managing records and information, from creation to disposition.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds