CSPM (Certified Security Project Manager) Exam — Questions and Answers
Question 1: How does the CSPM body of knowledge relate to daily professional practice?
- It is relevant only for academic research
- It only applies during certification exams
- It is theoretical and has limited practical application
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 2: During security project planning, the team identifies that a critical firewall upgrade depends on a network assessment being completed first. This relationship is best described as a:
- Resource conflict
- Finish-to-start dependency (Correct answer)
- Start-to-start dependency
- Lag dependency
Correct answer: Finish-to-start dependency
A finish-to-start dependency means the predecessor activity must finish before the successor activity can start.
Question 3: Which of the following is the CORRECT order for closing a security project?
- Archive records → Obtain acceptance → Release team → Close contracts
- Release team → Close contracts → Archive records → Obtain acceptance
- Close contracts → Release team → Obtain acceptance → Archive records
- Obtain acceptance → Close contracts → Release team → Archive records (Correct answer)
Correct answer: Obtain acceptance → Close contracts → Release team → Archive records
Best practice dictates obtaining stakeholder acceptance first, then closing contracts, releasing the team, and finally archiving project records.
Question 4: Which statement BEST describes the relationship between Certified Security Project Manager certification requirements and industry evolution?
- Requirements become less stringent over time
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Certification requirements never change once established
- Changes only occur when government mandates new requirements
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 5: What is the PRIMARY purpose of obtaining CSPM certification in Certified Security Project Manager?
- To satisfy a personal achievement goal
- To bypass educational requirements
- To guarantee employment in the field
- To demonstrate verified competency and adherence to professional standards (Correct answer)
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 6: The concept of 'separation of duties' in security governance is primarily designed to:
- Prevent fraud and errors by ensuring no single person controls an entire process (Correct answer)
- Satisfy PCI-DSS network segmentation requirements
- Reduce employee workload by dividing tasks
- Speed up security project delivery timelines
Correct answer: Prevent fraud and errors by ensuring no single person controls an entire process
Separation of duties divides critical processes among multiple individuals to reduce the risk of insider fraud, error, or abuse by ensuring no single employee has complete control.
Question 7: What distinguishes a Certified Security Project Manager certified professional from a non-certified practitioner?
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
- Certified professionals always have more years of experience
- There is no meaningful difference in competency
- Certified professionals exclusively work in larger organizations
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 8: What is the purpose of an Incident Severity Classification system?
- To determine which regulatory body must be notified
- To prioritize resource allocation and response speed based on business impact (Correct answer)
- To assign blame to responsible parties after an incident
- To calculate the financial cost of each incident
Correct answer: To prioritize resource allocation and response speed based on business impact
Severity classification (e.g., Critical, High, Medium, Low) helps organizations prioritize their response efforts and allocate appropriate resources based on the incident's potential business impact.
Question 9: What is the PRIMARY purpose of a security project status report during the monitoring phase?
- To update the work breakdown structure
- To document lessons learned for future projects
- To obtain formal acceptance of security deliverables
- To communicate current progress, risks, and issues to stakeholders (Correct answer)
Correct answer: To communicate current progress, risks, and issues to stakeholders
Status reports during monitoring primarily serve to communicate current project health, including progress against the baseline, active risks, and open issues to stakeholders.
Question 10: What is the PRIMARY benefit of using data-driven decision making in Certified Security Project Manager management?
- It guarantees positive results for every decision
- It simplifies the decision-making process to one approach
- It provides objective evidence to support decisions, reduce bias, and track outcomes (Correct answer)
- It eliminates the need for professional judgment
Correct answer: It provides objective evidence to support decisions, reduce bias, and track outcomes
Data-driven decision making provides objective evidence that supports more informed decisions, helps reduce personal bias, and enables tracking of outcomes to evaluate effectiveness. It complements, rather than replaces, professional judgment.
Question 11: When assessment results for a Certified Security Project Manager evaluation are inconclusive, the BEST practice is to:
- Delay reporting until results are favorable
- Report the results as definitive anyway
- Conduct additional assessment using alternative methods (Correct answer)
- Discard the results and start over completely
Correct answer: Conduct additional assessment using alternative methods
Inconclusive results require additional assessment using alternative methods to gather more data. This triangulation approach helps clarify findings without compromising the integrity of the assessment process.
Question 12: Which ASIS International standard specifically addresses the baseline competency and training requirements for security management professionals?
- ASIS SMS (Security Management Standard) (Correct answer)
- ANSI/ASIS PSC.1
- ASIS ORM.1
- ASIS BCM.1
Correct answer: ASIS SMS (Security Management Standard)
The ASIS Security Management Standard (SMS) defines organizational and operational requirements for security management programs, including competency benchmarks.
Question 13: What is the purpose of a security awareness and training program from a governance perspective?
- To teach developers how to write secure code only
- To reduce human-factor risk by ensuring all personnel understand their security responsibilities (Correct answer)
- To satisfy vendor due diligence questionnaires
- To replace technical security controls with behavioral ones
Correct answer: To reduce human-factor risk by ensuring all personnel understand their security responsibilities
Security awareness programs address the human element of risk by educating all staff on their roles and responsibilities, reducing susceptibility to phishing, social engineering, and policy violations.
Question 14: What distinguishes a Certified Security Project Manager certified professional from a non-certified practitioner?
- Certified professionals exclusively work in larger organizations
- There is no meaningful difference in competency
- Certified professionals always have more years of experience
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 15: When a security project involves international deployments, which voluntary framework from the Montreux Document addresses human rights obligations of private security companies operating in conflict zones?
- ASIS PSC.1
- Geneva Convention Protocol II
- ICoC (International Code of Conduct for Private Security Providers) (Correct answer)
- UN Guiding Principles on Business and Human Rights
Correct answer: ICoC (International Code of Conduct for Private Security Providers)
The ICoC is a multi-stakeholder initiative that establishes human rights and humanitarian law standards for private security providers operating internationally.
Question 16: A CSPM must ensure that incident response activities align with the project schedule. Which approach best balances security response with project continuity?
- Outsource incident response to avoid disrupting project timelines
- Pause all project activities until the incident is fully resolved
- Document the incident and address it during the next project phase
- Continue project work on unaffected systems while the IR team handles the incident in parallel (Correct answer)
Correct answer: Continue project work on unaffected systems while the IR team handles the incident in parallel
Isolating affected systems while continuing work on unaffected areas allows the project to maintain momentum while the IR team focuses on containment and resolution.
Question 17: Why is resource allocation important in project planning?
- It helps to cut costs
- It ensures efficiency and timely task completion (Correct answer)
- It reduces project quality
- It decreases the project’s scope
Correct answer: It ensures efficiency and timely task completion
Resource allocation is critical in project planning because it ensures that the necessary personnel, equipment, and materials are assigned to tasks efficiently and effectively. Proper allocation prevents bottlenecks, optimizes workload distribution, and ensures that tasks can be completed on time. This leads to greater productivity and helps maintain the project's schedule and budget.
Question 18: Which US law established the Federal Information Security Management Act, mandating cybersecurity programs for federal agencies?
- E-Government Act of 2002 (FISMA title) (Correct answer)
- Sarbanes-Oxley Act (SOX)
- Gramm-Leach-Bliley Act (GLBA)
- Computer Fraud and Abuse Act (CFAA)
Correct answer: E-Government Act of 2002 (FISMA title)
FISMA was enacted as Title III of the E-Government Act of 2002 and requires federal agencies to develop, document, and implement information security programs.
Question 19: What is the role of a project manager during the execution phase?
- To manage the project team and communicate with stakeholders (Correct answer)
- To handle customer complaints
- To assign all tasks to the team
- To focus on financial management only
Correct answer: To manage the project team and communicate with stakeholders
During the execution phase, the project manager's role is primarily to lead and manage the project team, ensuring tasks are completed according to the plan. They also serve as the central point of communication, regularly updating and engaging with stakeholders to manage expectations and gather feedback. This leadership and communication are crucial for keeping the project aligned and moving forward.
Question 20: What is the PRIMARY purpose of obtaining CSPM certification in Certified Security Project Manager?
- To guarantee employment in the field
- To bypass educational requirements
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To satisfy a personal achievement goal
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 21: A security project manager is overseeing deployment of an intrusion detection system at a financial institution. Which regulation most directly requires the institution to implement controls that detect unauthorized access to customer financial information?
- SOX Section 404
- Gramm-Leach-Bliley Act (GLBA) Safeguards Rule (Correct answer)
- HIPAA Security Rule
- PCI DSS
Correct answer: Gramm-Leach-Bliley Act (GLBA) Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement administrative, technical, and physical safeguards—including access detection—to protect customer financial data.
Question 22: A CSPM professional conducting a security program gap analysis compares the current state against:
- The number of open vulnerabilities in the SIEM
- Executive personal risk preferences
- A desired target state or recognized security standard (Correct answer)
- Competitor security budgets
Correct answer: A desired target state or recognized security standard
A gap analysis measures the difference between an organization's current security posture and a target framework or maturity level to identify areas requiring improvement.
Question 23: During security project planning, a project manager discovers that two compliance requirements conflict. The best immediate action is to:
- Remove both requirements from scope
- Implement the stricter requirement and document the decision (Correct answer)
- Ignore the lesser requirement to save cost
- Escalate both requirements to the project sponsor for direction
Correct answer: Implement the stricter requirement and document the decision
Applying the stricter control satisfies both requirements while the conflict is formally documented for stakeholder awareness and decisions.
Question 24: Which communication document is typically sent to stakeholders during a significant security incident to provide status updates?
- Incident After-Action Report
- Incident Situation Report (SitRep) (Correct answer)
- Security Risk Register Update
- Vulnerability Disclosure Notice
Correct answer: Incident Situation Report (SitRep)
A Situation Report (SitRep) provides stakeholders with timely, structured updates on incident status, current actions, and next steps during an active incident.
Question 25: A qualitative risk assessment differs from a quantitative risk assessment primarily because it:
- Uses numerical dollar values for all risks
- Is mandated by PCI-DSS v4.0
- Requires actuarial data and historical loss records
- Relies on descriptive ratings such as High, Medium, and Low (Correct answer)
Correct answer: Relies on descriptive ratings such as High, Medium, and Low
Qualitative risk assessments categorize risk using subjective descriptors rather than precise monetary figures, making them faster but less precise than quantitative methods.
Question 26: Which planning process group activity ensures that the security project's quality standards and metrics are defined before work begins?
- Quality assurance
- Quality control
- Quality auditing
- Plan quality management (Correct answer)
Correct answer: Plan quality management
Plan Quality Management identifies the relevant quality standards and determines how to satisfy them throughout the project.
Question 27: A security project is implementing multi-factor authentication (MFA) across 5,000 endpoints. Progress monitoring reveals 30% adoption after 60% of the timeline has elapsed. What should the project manager assess first?
- Whether to cancel the project
- Whether to reduce the MFA rollout scope permanently
- Whether stakeholders are satisfied with current adoption
- Schedule variance and its root cause to determine corrective action (Correct answer)
Correct answer: Schedule variance and its root cause to determine corrective action
The project manager should first calculate and analyze the schedule variance to understand the magnitude of the delay and identify root causes before selecting appropriate corrective actions.
Question 28: A CSPM professional facilitates a tabletop exercise. The primary goal of this activity is to:
- Simulate a crisis scenario to identify gaps in plans and team readiness without real-world disruption (Correct answer)
- Validate firewall rule configurations in a staging environment
- Measure individual employee security awareness scores
- Test live production systems for vulnerabilities
Correct answer: Simulate a crisis scenario to identify gaps in plans and team readiness without real-world disruption
Tabletop exercises use discussion-based simulations of security incidents to test plans, identify weaknesses in response procedures, and improve team coordination without impacting live systems.
Question 29: What is a risk assessment in a security project?
- A survey of past incidents
- An evaluation of existing security measures
- An analysis of potential threats and vulnerabilities (Correct answer)
- A budget analysis for the project
Correct answer: An analysis of potential threats and vulnerabilities
A risk assessment in a security project is a systematic process of identifying potential threats (e.g., theft, cyber-attacks) and vulnerabilities (e.g., weak access controls, outdated software) that could impact an organization's assets. It evaluates the likelihood and potential impact of these risks to inform the design and implementation of effective and proportionate security measures. This proactive analysis is foundational to robust security planning.
Question 30: Why is scope creep a challenge in project planning?
- It helps to finish the project early
- It leads to project expansion without proper adjustments (Correct answer)
- It reduces the scope of work
- It helps the project stay on time
Correct answer: It leads to project expansion without proper adjustments
Scope creep is a significant challenge in project planning because it refers to the uncontrolled expansion of a project's scope without corresponding adjustments to time, budget, or resources. This unplanned growth can lead to increased costs, missed deadlines, and a decline in project quality. Effectively managing scope creep requires careful change control processes to prevent projects from derailing.
Question 31: Which document serves as the formal agreement between the security project manager and the performing organization, authorizing the use of resources?
- Procurement contract
- Project management plan
- Project charter (Correct answer)
- Resource management plan
Correct answer: Project charter
The project charter formally authorizes the project and grants the project manager authority to apply organizational resources.
Question 32: What is the significance of a project schedule?
- It ensures tasks are completed within the set timelines (Correct answer)
- It helps monitor the project’s budget
- It allows for better communication with clients
- It reduces the scope of the project
Correct answer: It ensures tasks are completed within the set timelines
A project schedule is significant because it organizes all project tasks chronologically, assigning specific start and end dates. Its primary purpose is to ensure that all activities are completed within the set timelines, facilitating efficient workflow and preventing delays. By providing a clear sequence of operations, it helps keep the project on track and meet deadlines.
Question 33: Which foundational principle is MOST important for success in the Certified Security Project Manager profession?
- Maximizing financial returns on every engagement
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Specializing in only one narrow area of practice
- Maintaining the minimum requirements for certification
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 34: A CSPM is using a probability and impact matrix during risk planning. Which quadrant receives the highest priority for response planning?
- Low probability, low impact
- Low probability, high impact
- High probability, high impact (Correct answer)
- High probability, low impact
Correct answer: High probability, high impact
Risks with both high probability and high impact represent the greatest threat and require the most urgent response planning.
Question 35: What is the MOST effective way for new CSPM professionals to build competency in their field?
- Focusing solely on the most advanced topics
- Learning entirely through trial and error
- Studying certification materials exclusively
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 36: What is the MOST effective way for new CSPM professionals to build competency in their field?
- Learning entirely through trial and error
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Studying certification materials exclusively
- Focusing solely on the most advanced topics
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 37: What is the PRIMARY purpose of obtaining CSPM certification in Certified Security Project Manager?
- To satisfy a personal achievement goal
- To guarantee employment in the field
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To bypass educational requirements
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
Question 38: How should a CSPM professional manager address underperformance within their team?
- Provide timely, specific feedback with support and a clear improvement plan (Correct answer)
- Publicly address the issue in team meetings
- Immediately reassign the individual to a different role
- Ignore it until formal review periods
Correct answer: Provide timely, specific feedback with support and a clear improvement plan
Addressing underperformance requires timely intervention with specific, objective feedback about the performance gap. Providing support resources and a clear improvement plan with defined expectations and timelines gives the individual a fair opportunity to improve.
Question 39: Which security project execution practice BEST supports continuous compliance monitoring in a cloud environment?
- Quarterly stakeholder compliance reviews
- Automated compliance-as-code tools integrated into CI/CD pipelines (Correct answer)
- Annual manual compliance audits
- Storing compliance evidence in spreadsheets
Correct answer: Automated compliance-as-code tools integrated into CI/CD pipelines
Compliance-as-code tools embedded in CI/CD pipelines continuously evaluate infrastructure and application configurations against security policies, providing real-time compliance visibility.
Question 40: What is the role of resource management during project execution?
- It ensures efficient use of resources (Correct answer)
- It is irrelevant during execution
- It reduces team productivity
- It manages the project budget only
Correct answer: It ensures efficient use of resources
Resource management during project execution is vital for ensuring the efficient and effective utilization of all project resources, including personnel, equipment, and materials. It involves optimizing their deployment, monitoring their usage, and making adjustments as needed to avoid waste and maximize productivity. This ensures that tasks are completed efficiently and the project stays on schedule and within budget.
Question 41: What is the role of a budget in project planning?
- To reduce costs across the board
- To track personal expenses
- To avoid allocating resources
- To ensure financial feasibility and resource allocation (Correct answer)
Correct answer: To ensure financial feasibility and resource allocation
The role of a budget in project planning is to ensure the financial feasibility of the project and to guide resource allocation. It sets financial limits, estimates costs for all activities, and allocates funds to various project components. A well-managed budget helps control expenditures, prevents overspending, and ensures that the project has the necessary financial resources to achieve its objectives.
Question 42: Which foundational principle is MOST important for success in the Certified Security Project Manager profession?
- Maximizing financial returns on every engagement
- Specializing in only one narrow area of practice
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining the minimum requirements for certification
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 43: What does MTTR stand for in incident response metrics?
- Mean Threat and Response Ratio
- Minimum Time to Remediate
- Maximum Threat Tolerance Rating
- Mean Time to Recover (Correct answer)
Correct answer: Mean Time to Recover
MTTR stands for Mean Time to Recover (or Resolve), measuring the average time from incident detection to full system restoration.
Question 44: A security project manager is determining the critical path for an IDS deployment. What does identifying the critical path allow the manager to do?
- Allocate the entire budget to high-priority tasks
- Identify tasks where delays will directly delay the project finish date (Correct answer)
- Remove all float from non-critical activities
- Reassign resources from non-security tasks
Correct answer: Identify tasks where delays will directly delay the project finish date
The critical path represents the longest sequence of dependent tasks; any delay on it directly extends the overall project duration.
Question 45: Which document formally authorizes the project team to begin executing security project work packages?
- Work authorization system output (Correct answer)
- Issue log
- Lessons learned register
- Risk register
Correct answer: Work authorization system output
A work authorization system provides formal approval to begin specific work packages, ensuring security activities are executed in the correct sequence and by authorized resources.
Question 46: Which compliance requirement often mandates that security project records be retained for a minimum defined period after project closure?
- Project Management Body of Knowledge (PMBOK)
- ISO 9001 Quality Management
- Regulatory and industry standards such as HIPAA, PCI-DSS, or SOX (Correct answer)
- Agile Manifesto
Correct answer: Regulatory and industry standards such as HIPAA, PCI-DSS, or SOX
Regulatory frameworks like HIPAA, PCI-DSS, and SOX specify mandatory data retention periods for security-related records, which must be honored during project closure.
Question 47: What is the primary goal of obtaining formal 'sign-off' from stakeholders at the end of a security project?
- To create a legal and formal record that deliverables were accepted and project obligations fulfilled (Correct answer)
- To confirm the project was completed on time only
- To allow the PM to immediately start a new project
- To provide the PM with performance bonuses
Correct answer: To create a legal and formal record that deliverables were accepted and project obligations fulfilled
Formal sign-off creates an auditable record confirming stakeholders accepted the deliverables, which protects all parties and legally closes project obligations.
Question 48: Why is quality assurance critical in project execution?
- It ensures the project meets quality standards (Correct answer)
- It helps avoid project delays
- It ensures client dissatisfaction
- It reduces project costs
Correct answer: It ensures the project meets quality standards
Quality assurance is critical in project execution because it ensures that the project deliverables and processes meet predefined quality standards and client expectations. By implementing systematic activities to monitor and verify quality throughout the project, potential defects or deviations can be identified and corrected early. This proactive approach helps to deliver a high-quality security system that performs reliably and effectively.
Question 49: A security project manager is creating a network diagram and notices a lag of 5 days between two tasks. This means:
- The second task starts 5 days before the first task finishes
- There is a required wait of 5 days between the end of the predecessor and the start of the successor (Correct answer)
- Both tasks share 5 days of float
- The first task is 5 days behind schedule
Correct answer: There is a required wait of 5 days between the end of the predecessor and the start of the successor
Lag introduces a deliberate delay between the finish of a predecessor and the start of a successor activity.
Question 50: During the eradication phase of incident response, what is the primary goal?
- Removing all traces of the threat from the environment (Correct answer)
- Notifying affected customers and stakeholders
- Restoring systems to their pre-incident state
- Preventing the incident from affecting additional systems
Correct answer: Removing all traces of the threat from the environment
Eradication focuses on completely removing the threat — including malware, backdoors, and unauthorized accounts — from all affected systems.
Question 51: What is the BEST strategy for resource allocation in Certified Security Project Manager project management?
- Keep significant reserves without deployment
- Match resources to priorities based on assessment of needs, risks, and strategic goals (Correct answer)
- Allocate all resources equally regardless of need
- Focus resources only on the largest tasks
Correct answer: Match resources to priorities based on assessment of needs, risks, and strategic goals
Effective resource allocation requires matching available resources to priorities determined by assessment of needs, risk factors, and strategic goals. This ensures that critical areas receive appropriate support while maintaining overall efficiency.
Question 52: How does the CSPM body of knowledge relate to daily professional practice?
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
- It only applies during certification exams
- It is theoretical and has limited practical application
- It is relevant only for academic research
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 53: During project closure, which document formally releases the project team from their security responsibilities?
- Risk register
- Security incident log
- Project closure report (Correct answer)
- Lessons learned register
Correct answer: Project closure report
The project closure report formally documents the completion of the project and releases team members from their assigned responsibilities.
Question 54: When performing a risk heat map analysis, the axes typically represent:
- Likelihood vs. impact (Correct answer)
- Cost vs. implementation time
- Control effectiveness vs. residual risk
- Threat actors vs. asset value
Correct answer: Likelihood vs. impact
A risk heat map plots risks on a grid with likelihood (probability) on one axis and impact (severity) on the other to visually prioritize which risks need immediate attention.
Question 55: When designing an executive protection detail, which threat assessment model is most commonly applied to evaluate the credibility and capability of identified threats to a principal?
- STRIDE Threat Model
- TARA (Threat Agent Risk Assessment)
- Pathway to Violence model (Correct answer)
- CARVER Matrix
Correct answer: Pathway to Violence model
The Pathway to Violence model, developed by Calhoun and Weston, identifies behavioral indicators along the progression from grievance to targeted attack, widely used in EP threat assessment.
Question 56: A security project's schedule shows activities with float (slack). What does float indicate?
- The activity is on the critical path
- The number of resources available for the activity
- The amount of time an activity can be delayed without delaying the project (Correct answer)
- The budget reserved for schedule overruns
Correct answer: The amount of time an activity can be delayed without delaying the project
Float (or slack) is the amount of time an activity can be delayed without affecting the project's overall completion date.
Question 57: Which risk metric represents the maximum tolerable downtime for a system before business operations are critically impaired?
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time to Repair (MTTR)
- Recovery Point Objective (RPO)
- Mean Time Between Failures (MTBF)
Correct answer: Recovery Time Objective (RTO)
The Recovery Time Objective (RTO) defines the maximum acceptable length of time a system can be offline following a disruption before causing unacceptable business impact.
Question 58: Which statement BEST describes the relationship between Certified Security Project Manager certification requirements and industry evolution?
- Requirements become less stringent over time
- Certification requirements never change once established
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Changes only occur when government mandates new requirements
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 59: A project manager is applying the MoSCoW method during security requirements planning. What does 'W' stand for?
- Wanted
- Weighted
- Won't have this time (Correct answer)
- Work in progress
Correct answer: Won't have this time
In MoSCoW prioritization, 'W' stands for 'Won't have this time,' indicating requirements deferred to a future phase.
Question 60: What is the MOST important factor to consider when selecting assessment tools for CSPM certification work?
- Validity, reliability, and appropriateness for the specific context (Correct answer)
- The cost of the assessment tool
- How quickly the tool can be administered
- Personal familiarity with the tool
Correct answer: Validity, reliability, and appropriateness for the specific context
Assessment tools must be valid (measuring what they claim to measure), reliable (producing consistent results), and appropriate for the specific context and population. These psychometric properties ensure the quality of assessment outcomes.
Question 61: During planning of a zero-trust architecture project, the team decides to phase delivery into increments. This approach is associated with which project lifecycle?
- Predictive (waterfall)
- Event-driven
- Linear sequential
- Adaptive (agile/iterative) (Correct answer)
Correct answer: Adaptive (agile/iterative)
Adaptive lifecycles deliver work in iterations or increments, allowing feedback and adjustments after each phase.
Question 62: When planning a project in Certified Security Project Manager, which element should be established FIRST?
- The team member assignments
- Clear objectives, scope, and success criteria (Correct answer)
- The budget allocation
- The project timeline
Correct answer: Clear objectives, scope, and success criteria
Clear objectives, scope, and success criteria must be established first because they form the foundation for all other planning decisions. Without knowing what success looks like, it is impossible to properly allocate budget, assign personnel, or set timelines.
Question 63: Which stakeholder engagement strategy is MOST effective for CSPM professionals leading initiatives?
- Identify stakeholders early, understand their interests, and maintain regular communication (Correct answer)
- Limit engagement to senior leadership only
- Inform stakeholders only after decisions are made
- Engage stakeholders only when their approval is needed
Correct answer: Identify stakeholders early, understand their interests, and maintain regular communication
Early stakeholder identification, understanding their interests and concerns, and maintaining regular communication builds support, prevents surprises, and ensures diverse perspectives inform decision-making throughout the initiative.
Question 64: Which assessment method provides the MOST reliable data for CSPM professionals making critical decisions?
- Standardized tools combined with professional observation (Correct answer)
- Single-source data from one stakeholder
- Social media reviews and testimonials
- Informal verbal feedback alone
Correct answer: Standardized tools combined with professional observation
Combining standardized assessment tools with professional observation provides the most reliable and comprehensive data. Standardized tools ensure consistency and validity, while professional observation captures nuances that tools might miss.
Question 65: After closing a security project, a team member attempts to access project systems using credentials that were not revoked. This situation BEST illustrates the importance of:
- Timely access deprovisioning as part of the closure process (Correct answer)
- Project schedule management
- Resource leveling techniques
- Earned value management
Correct answer: Timely access deprovisioning as part of the closure process
Timely revocation of all project-specific access credentials is a critical closure task that prevents unauthorized post-project access to sensitive systems.
Question 66: Which metric BEST indicates whether a security project's cost performance is acceptable during monitoring?
- Number of change requests submitted
- Number of risks identified
- Cost Performance Index (CPI) (Correct answer)
- Resource utilization percentage
Correct answer: Cost Performance Index (CPI)
The Cost Performance Index (CPI = Earned Value ÷ Actual Cost) directly measures cost efficiency; a CPI ≥ 1.0 indicates the project is at or under budget.
Question 67: What is the main goal during the closing phase of a security project?
- To evaluate the security system performance (Correct answer)
- To complete the final project payments
- To review project documents only
- To ignore feedback from the client
Correct answer: To evaluate the security system performance
The main goal during the closing phase of a security project is to formally complete all project activities and ensure the successful handover of the security system. A critical part of this is evaluating the security system's performance to confirm it meets all specified requirements and operates effectively. This evaluation verifies that the project has delivered its intended value and achieved its objectives.
Question 68: What type of risk response strategy involves purchasing cyber insurance to offset potential financial losses?
- Risk avoidance
- Risk mitigation
- Risk acceptance
- Risk transfer (Correct answer)
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a risk to a third party, such as an insurer, rather than eliminating or reducing the underlying threat.
Question 69: What distinguishes a Certified Security Project Manager certified professional from a non-certified practitioner?
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
- Certified professionals always have more years of experience
- There is no meaningful difference in competency
- Certified professionals exclusively work in larger organizations
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 70: How frequently should ongoing assessments be conducted in Certified Security Project Manager practice?
- At regular intervals based on established protocols and as conditions change (Correct answer)
- Once annually regardless of circumstances
- Only when required by external auditors
- Only when problems are reported
Correct answer: At regular intervals based on established protocols and as conditions change
Ongoing assessments should follow established protocols for regular intervals and also be conducted when conditions change. This balanced approach ensures continuous monitoring while remaining responsive to new developments.
Question 71: What does project closing ensure?
- All budget approvals
- Assessment of project risks
- Completion of project objectives (Correct answer)
- Review of stakeholder feedback only
Correct answer: Completion of project objectives
Project closing is the formal process that ensures all activities required to complete the project or phase have been finalized. Its primary purpose is to confirm that all defined project objectives have been met, deliverables have been accepted, and all administrative tasks are concluded. This guarantees that the project has successfully delivered its intended outcomes.
Question 72: Which statement BEST describes the relationship between Certified Security Project Manager certification requirements and industry evolution?
- Changes only occur when government mandates new requirements
- Requirements become less stringent over time
- Certification requirements never change once established
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 73: Which statement BEST describes the relationship between Certified Security Project Manager certification requirements and industry evolution?
- Requirements become less stringent over time
- Certification requirements never change once established
- Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards (Correct answer)
- Changes only occur when government mandates new requirements
Correct answer: Requirements evolve periodically to reflect advances in knowledge, technology, and practice standards
Certification requirements evolve to keep pace with advances in professional knowledge, technological developments, and changes in practice standards. This ensures that certified professionals remain current and competent in a changing professional landscape.
Question 74: Which security metric is most useful for demonstrating a security program's effectiveness to senior leadership over time?
- Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends (Correct answer)
- Number of firewall rules in production
- Total lines of security policy documentation
- Number of security tools deployed
Correct answer: Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) trends
MTTD and MTTR are outcome-based metrics that directly reflect the security team's detection and response capabilities, making them meaningful indicators of program maturity for leadership.
Question 75: Which security planning document defines how project information will be distributed, to whom, and at what frequency?
- Risk register
- Quality management plan
- Stakeholder engagement plan
- Communications management plan (Correct answer)
Correct answer: Communications management plan
The communications management plan specifies information needs, formats, timing, and responsible parties for project communications.
Question 76: Which element of a risk register captures the actions taken to reduce a specific risk to an acceptable level?
- Risk owner
- Risk treatment plan (Correct answer)
- Risk appetite
- Inherent risk score
Correct answer: Risk treatment plan
The risk treatment plan within a risk register documents the specific controls, timelines, and responsibilities chosen to mitigate, transfer, avoid, or accept an identified risk.
Question 77: How does the CSPM body of knowledge relate to daily professional practice?
- It is theoretical and has limited practical application
- It only applies during certification exams
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
- It is relevant only for academic research
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 78: What distinguishes a Certified Security Project Manager certified professional from a non-certified practitioner?
- There is no meaningful difference in competency
- Certified professionals always have more years of experience
- Certified professionals exclusively work in larger organizations
- Certification validates competency through standardized assessment against established benchmarks (Correct answer)
Correct answer: Certification validates competency through standardized assessment against established benchmarks
Certification provides objective validation of competency through standardized assessment. While non-certified practitioners may be skilled, certification offers verified evidence that a professional meets established benchmarks for knowledge and performance.
Question 79: When planning a project in Certified Security Project Manager, which element should be established FIRST?
- The team member assignments
- The project timeline
- The budget allocation
- Clear objectives, scope, and success criteria (Correct answer)
Correct answer: Clear objectives, scope, and success criteria
Clear objectives, scope, and success criteria must be established first because they form the foundation for all other planning decisions. Without knowing what success looks like, it is impossible to properly allocate budget, assign personnel, or set timelines.
Question 80: A CSPM professional is reviewing a third-party vendor's security posture. This activity is best categorized as:
- Supply chain risk management (Correct answer)
- Threat modeling
- Business impact analysis
- Internal risk audit
Correct answer: Supply chain risk management
Evaluating vendor security controls is a core supply chain risk management activity, ensuring third-party relationships do not introduce unacceptable risk to the organization.
Question 81: During execution monitoring, which technique involves randomly sampling security work products to assess overall quality?
- Statistical sampling (Correct answer)
- Benchmarking
- Force field analysis
- Affinity diagramming
Correct answer: Statistical sampling
Statistical sampling selects a representative subset of deliverables for inspection, allowing quality conclusions to be drawn about the entire population without inspecting every item.
Question 82: Which monitoring control ensures that security project lessons are captured continuously rather than only at closure?
- The project charter review
- Monthly steering committee meetings
- A single post-project debrief report
- Retrospectives or lessons learned sessions held at milestone intervals (Correct answer)
Correct answer: Retrospectives or lessons learned sessions held at milestone intervals
Conducting retrospectives or lessons learned sessions at milestone intervals captures insights while they are fresh and allows the team to apply improvements during the current project.
Question 83: During project closure, a lessons learned session reveals that a critical security control was deployed two weeks late. This information should PRIMARILY be used to:
- Update the current project's risk register
- Improve planning and scheduling in future security projects (Correct answer)
- Penalize the responsible team member
- Justify project cost overruns to the sponsor
Correct answer: Improve planning and scheduling in future security projects
Lessons learned from delays are captured to refine scheduling practices and improve delivery in future projects.
Question 84: In Certified Security Project Manager, what is the PRIMARY purpose of conducting an initial assessment?
- To fulfill administrative paperwork requirements
- To generate documentation for billing purposes
- To demonstrate the assessor's expertise
- To establish a baseline and identify needs for appropriate action (Correct answer)
Correct answer: To establish a baseline and identify needs for appropriate action
The initial assessment establishes a baseline of current conditions and identifies specific needs. This foundational information guides all subsequent decisions, planning, and interventions.
Question 85: How frequently should ongoing assessments be conducted in Certified Security Project Manager practice?
- Only when problems are reported
- At regular intervals based on established protocols and as conditions change (Correct answer)
- Only when required by external auditors
- Once annually regardless of circumstances
Correct answer: At regular intervals based on established protocols and as conditions change
Ongoing assessments should follow established protocols for regular intervals and also be conducted when conditions change. This balanced approach ensures continuous monitoring while remaining responsive to new developments.
Question 86: Why is stakeholder engagement important in project planning?
- It improves communication and satisfaction (Correct answer)
- It guarantees project completion
- It delays the project
- It limits project scope
Correct answer: It improves communication and satisfaction
Stakeholder engagement is crucial in project planning because it fosters open communication and ensures that the needs and expectations of all involved parties are understood and addressed. By involving stakeholders early and continuously, project managers can gain valuable insights, build consensus, and manage expectations effectively. This leads to increased satisfaction and a higher likelihood of project success.
Question 87: Which security planning document establishes the processes for managing changes to security controls during a project?
- Configuration management plan
- Security baseline
- Change management plan (Correct answer)
- Risk response plan
Correct answer: Change management plan
The change management plan defines procedures for submitting, reviewing, approving, and implementing changes throughout the project.
Question 88: When documenting assessment findings in CSPM practice, which approach is MOST appropriate?
- Record objective findings, measurements, and professional observations factually (Correct answer)
- Use technical jargon that only experts can understand
- Summarize findings verbally without written documentation
- Include only positive findings to maintain optimism
Correct answer: Record objective findings, measurements, and professional observations factually
Assessment documentation must be objective, factual, and comprehensive. Recording measurements, observations, and findings without bias ensures that the documentation is useful for decision-making and withstands scrutiny.
Question 89: Which foundational principle is MOST important for success in the Certified Security Project Manager profession?
- Maximizing financial returns on every engagement
- Maintaining the minimum requirements for certification
- Specializing in only one narrow area of practice
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 90: In the context of supply chain security, what does the term 'counterfeit electronic part' most directly threaten in a security project?
- System integrity and mission assurance (Correct answer)
- Schedule delays due to vendor audits
- Budget overruns due to replacement costs
- Regulatory fines under ITAR
Correct answer: System integrity and mission assurance
Counterfeit parts can introduce hidden vulnerabilities or fail prematurely, directly threatening system integrity and mission assurance.
Question 91: In a CSPM context, a residual risk is best described as:
- The risk remaining after security controls have been implemented (Correct answer)
- The total risk before any controls are applied
- The risk transferred to a third-party vendor
- The risk accepted by executive leadership
Correct answer: The risk remaining after security controls have been implemented
Residual risk is the level of risk that persists after all planned security controls and mitigations have been put into place.
Question 92: During a penetration test phase of a security project, the tester discovers a critical finding outside the agreed scope. What should the project manager do?
- Ignore the finding as it is out of scope
- Raise a change request and notify relevant stakeholders before proceeding (Correct answer)
- Instruct the tester to exploit the finding immediately
- Expand scope unilaterally to include the finding
Correct answer: Raise a change request and notify relevant stakeholders before proceeding
Out-of-scope findings must be handled through formal change control; the project manager raises a change request and informs stakeholders before any work proceeds outside the agreed boundary.
Question 93: A CSPM is creating a responsibility assignment matrix. The 'A' in RACI stands for:
- Assigned
- Authorized
- Aware
- Accountable (Correct answer)
Correct answer: Accountable
Accountable (A) identifies the single person who owns the deliverable and is ultimately answerable for its completion.
Question 94: How does effective communication support project planning?
- It helps avoid misunderstandings
- It slows down the project
- It makes the planning process easier (Correct answer)
- It avoids resource allocation
Correct answer: It makes the planning process easier
Effective communication is vital in project planning as it ensures that all team members, stakeholders, and clients are on the same page regarding project goals, requirements, and progress. Clear and consistent communication helps to avoid misunderstandings, facilitates collaboration, and streamlines decision-making. This transparency and shared understanding ultimately make the entire planning process smoother and more efficient.
Question 95: Which metric measures the average time between when an incident is detected and when it is fully contained?
- Recovery Time Objective (RTO)
- Mean Time to Respond (MTTR)
- Mean Time to Contain (MTTC) (Correct answer)
- Mean Time to Detect (MTTD)
Correct answer: Mean Time to Contain (MTTC)
Mean Time to Contain (MTTC) specifically measures the time elapsed from detection to successful containment of the threat.
Question 96: A security project manager is calculating the Annual Loss Expectancy (ALE) for a threat. Which formula is correct?
- ALE = ARO + SLE
- ALE = ARO - SLE
- ALE = SLE Ă— ARO (Correct answer)
- ALE = SLE / ARO
Correct answer: ALE = SLE Ă— ARO
ALE equals Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), expressing the expected yearly financial loss from a specific threat.
Question 97: What is the MOST important leadership quality for a CSPM certified professional managing a team?
- Achieving the highest personal performance metrics
- Demonstrating integrity, clear communication, and ability to develop team members (Correct answer)
- Maintaining strict control over all decisions
- Avoiding all forms of conflict within the team
Correct answer: Demonstrating integrity, clear communication, and ability to develop team members
Effective leadership in professional settings requires integrity to build trust, clear communication to align the team, and the ability to develop team members' skills and capabilities. These qualities create a productive and engaged team.
Question 98: When assessment results for a Certified Security Project Manager evaluation are inconclusive, the BEST practice is to:
- Conduct additional assessment using alternative methods (Correct answer)
- Report the results as definitive anyway
- Delay reporting until results are favorable
- Discard the results and start over completely
Correct answer: Conduct additional assessment using alternative methods
Inconclusive results require additional assessment using alternative methods to gather more data. This triangulation approach helps clarify findings without compromising the integrity of the assessment process.
Question 99: Which stakeholder engagement strategy is MOST effective for CSPM professionals leading initiatives?
- Limit engagement to senior leadership only
- Identify stakeholders early, understand their interests, and maintain regular communication (Correct answer)
- Engage stakeholders only when their approval is needed
- Inform stakeholders only after decisions are made
Correct answer: Identify stakeholders early, understand their interests, and maintain regular communication
Early stakeholder identification, understanding their interests and concerns, and maintaining regular communication builds support, prevents surprises, and ensures diverse perspectives inform decision-making throughout the initiative.
Question 100: When documenting assessment findings in CSPM practice, which approach is MOST appropriate?
- Include only positive findings to maintain optimism
- Use technical jargon that only experts can understand
- Summarize findings verbally without written documentation
- Record objective findings, measurements, and professional observations factually (Correct answer)
Correct answer: Record objective findings, measurements, and professional observations factually
Assessment documentation must be objective, factual, and comprehensive. Recording measurements, observations, and findings without bias ensures that the documentation is useful for decision-making and withstands scrutiny.
Question 101: A CSPM must ensure that user access provisioned specifically for the security project is revoked at closure. Failure to do this creates:
- A budget variance
- Orphaned accounts that increase the organization's attack surface (Correct answer)
- A scope change request
- A quality management issue
Correct answer: Orphaned accounts that increase the organization's attack surface
Orphaned accounts—active credentials no longer tied to a legitimate business need—expand the attack surface and are a common post-project security vulnerability.
Question 102: When a security project is terminated early due to organizational restructuring, what must the PM ensure during closure?
- Partially completed deliverables are documented and their security implications assessed (Correct answer)
- All planned work is completed before closure
- The project team is immediately disbanded without documentation
- All project budgets are returned to the sponsor without accounting
Correct answer: Partially completed deliverables are documented and their security implications assessed
Early termination requires documenting all partially completed work and assessing any residual security risks to prevent unmanaged vulnerabilities.
Question 103: In Certified Security Project Manager, what is the PRIMARY purpose of conducting an initial assessment?
- To generate documentation for billing purposes
- To demonstrate the assessor's expertise
- To fulfill administrative paperwork requirements
- To establish a baseline and identify needs for appropriate action (Correct answer)
Correct answer: To establish a baseline and identify needs for appropriate action
The initial assessment establishes a baseline of current conditions and identifies specific needs. This foundational information guides all subsequent decisions, planning, and interventions.
Question 104: During security project closing, which activity specifically addresses ensuring that security tools and licenses are properly transferred or decommissioned?
- Asset disposition (Correct answer)
- Stakeholder engagement
- Schedule compression
- Risk response planning
Correct answer: Asset disposition
Asset disposition covers the proper transfer, reassignment, or decommissioning of hardware, software, and licenses at the end of a security project.
Question 105: Which assessment method provides the MOST reliable data for CSPM professionals making critical decisions?
- Social media reviews and testimonials
- Informal verbal feedback alone
- Single-source data from one stakeholder
- Standardized tools combined with professional observation (Correct answer)
Correct answer: Standardized tools combined with professional observation
Combining standardized assessment tools with professional observation provides the most reliable and comprehensive data. Standardized tools ensure consistency and validity, while professional observation captures nuances that tools might miss.
Question 106: A security project team is performing planning poker to estimate story points for security user stories. This technique is used in which type of project approach?
- PMBOK predictive projects
- Agile/Scrum projects (Correct answer)
- PRINCE2 projects
- Waterfall projects
Correct answer: Agile/Scrum projects
Planning poker is a consensus-based agile estimation technique where team members use cards to provide individual estimates before discussion.
Question 107: When planning vendor selection for a security tool procurement, which document formally describes the requirements that vendors must address in their proposals?
- Request for Proposal (RFP) (Correct answer)
- Memorandum of Understanding (MOU)
- Service Level Agreement (SLA)
- Statement of Work (SOW)
Correct answer: Request for Proposal (RFP)
An RFP solicits detailed proposals from vendors, specifying requirements, evaluation criteria, and submission instructions.
Question 108: What is the MOST important leadership quality for a CSPM certified professional managing a team?
- Demonstrating integrity, clear communication, and ability to develop team members (Correct answer)
- Avoiding all forms of conflict within the team
- Achieving the highest personal performance metrics
- Maintaining strict control over all decisions
Correct answer: Demonstrating integrity, clear communication, and ability to develop team members
Effective leadership in professional settings requires integrity to build trust, clear communication to align the team, and the ability to develop team members' skills and capabilities. These qualities create a productive and engaged team.
Question 109: A security project manager is asked to confirm that all penetration testing reports from the project have been properly handled. This is an example of:
- Risk avoidance
- Scope creep management
- Sensitive data handling compliance during administrative closure (Correct answer)
- Quality assurance testing
Correct answer: Sensitive data handling compliance during administrative closure
Ensuring penetration testing reports are properly classified, stored, or destroyed is part of sensitive data handling compliance during the administrative closure process.
Question 110: A security project manager notices the Schedule Performance Index (SPI) is 0.82. What does this indicate?
- The project is 18% under budget
- The project is ahead of schedule by 18%
- The project is behind schedule — only 82% of planned work is complete (Correct answer)
- The project has consumed 82% of its float
Correct answer: The project is behind schedule — only 82% of planned work is complete
An SPI below 1.0 means the project is behind schedule; an SPI of 0.82 means only 82 cents of planned work has been accomplished for every dollar of scheduled work.
Question 111: Which monitoring technique involves comparing planned security deliverables against actual completions using a cumulative S-curve?
- Monte Carlo simulation
- Earned Value Management (EVM) (Correct answer)
- Critical path method
- Variance analysis
Correct answer: Earned Value Management (EVM)
Earned Value Management uses S-curves to plot cumulative planned value against earned value and actual cost, enabling performance assessment of security deliverables.
Question 112: During which incident response phase is forensic evidence collected and analyzed?
- Detection & Analysis (Correct answer)
- Containment
- Post-Incident Activity
- Preparation
Correct answer: Detection & Analysis
The Detection & Analysis phase involves collecting, preserving, and analyzing evidence to understand the nature, scope, and impact of the incident.
Question 113: What is a project charter?
- A financial plan for the project
- A list of resources needed
- A plan to track progress
- A document outlining project scope and objectives (Correct answer)
Correct answer: A document outlining project scope and objectives
A project charter is a formal document that officially authorizes the existence of a project and provides the project manager with the authority to apply organizational resources to project activities. It outlines the high-level project scope, objectives, key stakeholders, and overall vision. This document serves as a foundational agreement, ensuring everyone understands the project's purpose and initial parameters.
Question 114: How does the CSPM body of knowledge relate to daily professional practice?
- It is theoretical and has limited practical application
- It only applies during certification exams
- It is relevant only for academic research
- It provides the foundational framework that guides decision-making and standard practices (Correct answer)
Correct answer: It provides the foundational framework that guides decision-making and standard practices
The body of knowledge provides the foundational framework of principles, standards, and best practices that professionals use to guide their daily decision-making, ensure consistent quality, and maintain alignment with industry standards.
Question 115: What is the distinction between a security 'event' and a security 'incident'?
- Events are external threats while incidents are internal threats
- An event is any observable occurrence; an incident is an event that negatively impacts security (Correct answer)
- Events are logged automatically while incidents require manual detection
- An incident is a potential threat while an event is a confirmed breach
Correct answer: An event is any observable occurrence; an incident is an event that negatively impacts security
A security event is any observable system occurrence, while an incident is specifically an event that threatens or violates security policies, AUPs, or standard security practices.
Question 116: A security project manager plans to use earned value management (EVM). If the project's EV is $80,000 and PV is $100,000, what does this indicate?
- The project is behind schedule (Correct answer)
- The project is ahead of schedule
- The project is under budget
- The project has exceeded scope
Correct answer: The project is behind schedule
A Schedule Performance Index (SPI) below 1.0 (EV/PV = 0.8) indicates the project is behind its planned schedule.
Question 117: A security project manager uses Estimate at Completion (EAC) to forecast final project cost. If the CPI is 0.90 and Budget at Completion (BAC) is $500,000, what is the EAC (assuming current performance continues)?
- $555,556 (Correct answer)
- $500,000
- $450,000
- $510,000
Correct answer: $555,556
EAC = BAC Ă· CPI = $500,000 Ă· 0.90 = $555,556, meaning the project is forecast to overrun budget if current cost efficiency continues.
Question 118: Under OSHA 29 CFR 1910.119, what type of security and safety management program is required for facilities that handle highly hazardous chemicals above threshold quantities?
- Process Safety Management (PSM) Program (Correct answer)
- Integrated Safety Management System (ISMS)
- Hazardous Materials Emergency Response Plan
- Chemical Security Assessment (CSA)
Correct answer: Process Safety Management (PSM) Program
OSHA's Process Safety Management (PSM) standard requires a comprehensive program—including hazard analysis, operating procedures, and incident investigation—for facilities with threshold quantities of highly hazardous chemicals.
Question 119: Which foundational principle is MOST important for success in the Certified Security Project Manager profession?
- Specializing in only one narrow area of practice
- Commitment to continuous learning, ethical practice, and quality outcomes (Correct answer)
- Maintaining the minimum requirements for certification
- Maximizing financial returns on every engagement
Correct answer: Commitment to continuous learning, ethical practice, and quality outcomes
Success in any professional field requires a commitment to continuous learning to stay current, ethical practice to maintain trust and integrity, and a focus on quality outcomes that serve stakeholders and the public interest.
Question 120: How does monitoring contribute to project success?
- By tracking progress and resolving issues (Correct answer)
- By reducing team morale
- By delaying project delivery
- By increasing project costs
Correct answer: By tracking progress and resolving issues
Monitoring significantly contributes to project success by continuously tracking progress against the project plan and identifying any deviations or potential issues. This ongoing oversight allows the project manager to detect problems early, implement corrective actions, and resolve obstacles promptly. By staying informed about the project's status, monitoring helps keep the project on schedule and within budget.
Question 121: Which role is PRIMARILY responsible for formally accepting the security project deliverables during closure?
- Project sponsor or designated client representative (Correct answer)
- Lead security engineer
- Project manager
- External auditor
Correct answer: Project sponsor or designated client representative
The project sponsor or designated client representative holds authority to formally accept deliverables and authorize project closure.
Question 122: Which of the following is the PRIMARY purpose of a security project kickoff meeting?
- Finalize the project budget
- Assign all project resources
- Complete the risk assessment
- Formally authorize the project start and align stakeholders (Correct answer)
Correct answer: Formally authorize the project start and align stakeholders
The kickoff meeting formally signals the start of execution and ensures all stakeholders share a common understanding of goals and expectations.
Question 123: How should a CSPM professional manager address underperformance within their team?
- Publicly address the issue in team meetings
- Provide timely, specific feedback with support and a clear improvement plan (Correct answer)
- Immediately reassign the individual to a different role
- Ignore it until formal review periods
Correct answer: Provide timely, specific feedback with support and a clear improvement plan
Addressing underperformance requires timely intervention with specific, objective feedback about the performance gap. Providing support resources and a clear improvement plan with defined expectations and timelines gives the individual a fair opportunity to improve.
Question 124: What is the BEST strategy for resource allocation in Certified Security Project Manager project management?
- Focus resources only on the largest tasks
- Match resources to priorities based on assessment of needs, risks, and strategic goals (Correct answer)
- Keep significant reserves without deployment
- Allocate all resources equally regardless of need
Correct answer: Match resources to priorities based on assessment of needs, risks, and strategic goals
Effective resource allocation requires matching available resources to priorities determined by assessment of needs, risk factors, and strategic goals. This ensures that critical areas receive appropriate support while maintaining overall efficiency.
Question 125: Which of the following is a key component of the administrative closure process in a security project?
- Designing new security architectures
- Initiating the next project phase
- Selecting new security vendors
- Confirming all contracts and procurement activities are closed (Correct answer)
Correct answer: Confirming all contracts and procurement activities are closed
Administrative closure includes verifying that all procurement contracts are settled, payments finalized, and vendor obligations discharged.
Question 126: A security project plan includes a cost baseline. What is the cost baseline used for?
- Calculating team member bonuses
- Approving vendor invoices
- Measuring and monitoring project cost performance (Correct answer)
- Setting the security budget ceiling
Correct answer: Measuring and monitoring project cost performance
The cost baseline is the approved, time-phased budget used as a benchmark for measuring and comparing actual cost performance.
Question 127: During execution of a security project, a critical vulnerability is discovered in a third-party library used by the system under development. What is the BEST immediate action?
- Continue development and patch in the next sprint
- Remove the library and rewrite the functionality
- Raise a risk event, assess impact, and escalate per the risk management plan (Correct answer)
- Halt all development until the vendor releases a patch
Correct answer: Raise a risk event, assess impact, and escalate per the risk management plan
Discovering a vulnerability during execution requires raising a risk event, assessing its impact on project scope and timeline, and escalating according to the pre-defined risk management plan.
Question 128: What distinguishes project closure from phase closure in a security project?
- Project closure terminates all project activities permanently, while phase closure only ends one phase (Correct answer)
- Phase closure requires stakeholder sign-off while project closure does not
- Phase closure releases the entire project budget
- Project closure is optional for security projects
Correct answer: Project closure terminates all project activities permanently, while phase closure only ends one phase
Project closure permanently concludes the project, whereas phase closure marks the end of a specific phase while the project continues.
Question 129: What is the PRIMARY benefit of using data-driven decision making in Certified Security Project Manager management?
- It provides objective evidence to support decisions, reduce bias, and track outcomes (Correct answer)
- It eliminates the need for professional judgment
- It simplifies the decision-making process to one approach
- It guarantees positive results for every decision
Correct answer: It provides objective evidence to support decisions, reduce bias, and track outcomes
Data-driven decision making provides objective evidence that supports more informed decisions, helps reduce personal bias, and enables tracking of outcomes to evaluate effectiveness. It complements, rather than replaces, professional judgment.
Question 130: A security project's risk register shows a previously low-probability threat has increased to high probability due to a new regulatory announcement. What is the CORRECT response?
- Transfer the risk to a different project
- Reassess the risk, update the register, and trigger response planning for the escalated risk (Correct answer)
- Remove the risk as it is now a certainty
- Wait until the regulation is published before acting
Correct answer: Reassess the risk, update the register, and trigger response planning for the escalated risk
When a risk's probability changes materially, the project manager must reassess its rating, update the risk register, and invoke or revise response strategies accordingly.
Question 131: What role does documentation play during project closing?
- It provides information for audits
- It limits stakeholder involvement
- It serves as a reference for future projects (Correct answer)
- It reduces the quality of work
Correct answer: It serves as a reference for future projects
Comprehensive documentation during project closing is vital as it captures all project details, decisions, and outcomes. This repository of information acts as a valuable reference for future projects, allowing teams to learn from past experiences, avoid repeating mistakes, and leverage successful strategies. It also supports knowledge transfer within the organization.
Question 132: Which role is typically responsible for declaring a security incident and initiating the formal response process in a large organization?
- Security Analyst
- Help Desk Technician
- Incident Response Manager or CISO (Correct answer)
- Network Administrator
Correct answer: Incident Response Manager or CISO
The Incident Response Manager or CISO typically holds the authority to formally declare an incident and activate the full IR plan, ensuring appropriate resources are mobilized.
Question 133: Which risk response strategy involves transferring financial consequences of a security risk to a third party, such as through cyber insurance?
- Accept
- Mitigate
- Avoid
- Transfer (Correct answer)
Correct answer: Transfer
Risk transfer shifts the financial impact of a risk to another party, typically through contracts, warranties, or insurance.
Question 134: What is the primary purpose of a Statement of Applicability (SoA) in an ISO 27001 compliance project?
- To record penetration testing findings for auditors
- To define the project charter and scope boundaries
- To document which Annex A controls are applicable and whether they are implemented (Correct answer)
- To list all identified vulnerabilities in the environment
Correct answer: To document which Annex A controls are applicable and whether they are implemented
The SoA is an ISO 27001 requirement that maps each Annex A control to the organization, stating applicability, implementation status, and justification for exclusions.
Question 135: Under the NIST Cybersecurity Framework (CSF), which function addresses identifying the steps to contain and eradicate a security event?
- Protect
- Recover
- Identify
- Respond (Correct answer)
Correct answer: Respond
The Respond function of the NIST CSF encompasses activities including response planning, communications, analysis, mitigation, and improvements after a cybersecurity event.
Question 136: What is the MOST important factor to consider when selecting assessment tools for CSPM certification work?
- Validity, reliability, and appropriateness for the specific context (Correct answer)
- How quickly the tool can be administered
- The cost of the assessment tool
- Personal familiarity with the tool
Correct answer: Validity, reliability, and appropriateness for the specific context
Assessment tools must be valid (measuring what they claim to measure), reliable (producing consistent results), and appropriate for the specific context and population. These psychometric properties ensure the quality of assessment outcomes.
Question 137: A security project manager needs to verify that encryption standards are being applied consistently across all system components. Which monitoring activity is MOST appropriate?
- Updating the stakeholder engagement plan
- Performing a lessons learned session
- Conducting a security compliance audit against defined standards (Correct answer)
- Reviewing the project charter
Correct answer: Conducting a security compliance audit against defined standards
A compliance audit compares actual implementation against defined encryption standards, providing systematic verification that controls are applied consistently across all components.
Question 138: In the US, which sector-specific regulation requires annual independent security assessments for payment card processing environments?
- PCI-DSS (Correct answer)
- GLBA
- FISMA
- SOX
Correct answer: PCI-DSS
PCI-DSS (Payment Card Industry Data Security Standard) requires organizations processing cardholder data to undergo annual assessments by a Qualified Security Assessor (QSA) or complete a self-assessment questionnaire.
Question 139: A security project manager is asked to fast-track a compliance remediation project. What does fast-tracking involve?
- Adding more resources to compress duration
- Outsourcing tasks to speed delivery
- Performing activities in parallel that were originally planned sequentially (Correct answer)
- Cutting scope to meet the deadline
Correct answer: Performing activities in parallel that were originally planned sequentially
Fast-tracking overlaps activities that were originally planned in sequence, reducing overall duration but increasing risk.
Question 140: What is 'digital forensics' as applied in a security incident context?
- The scientific collection, preservation, and analysis of digital evidence for investigation (Correct answer)
- Real-time monitoring of network traffic during an active attack
- The use of automated tools to patch vulnerabilities after an incident
- The process of backing up data before restoring affected systems
Correct answer: The scientific collection, preservation, and analysis of digital evidence for investigation
Digital forensics involves the rigorous, scientifically sound collection and analysis of digital evidence to reconstruct events, identify threat actors, and support legal or disciplinary proceedings.
Question 141: A security project manager sets the organization's risk appetite. Risk appetite is best defined as:
- The residual risk remaining after all mitigations
- The minimum security controls required by law
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The total financial loss an organization can survive
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the overarching statement of the level of risk an organization is prepared to accept while pursuing its goals, guiding risk management decisions at all levels.
Question 142: What are security project deliverables?
- Reports and analysis
- Payments and invoices
- Physical and technical assets of the security system (Correct answer)
- Design ideas and proposals
Correct answer: Physical and technical assets of the security system
Security project deliverables refer to the tangible outputs and results produced throughout the project lifecycle. These primarily include the physical and technical assets of the security system itself, such as installed cameras, access control devices, servers, and software configurations. Additionally, deliverables can encompass documentation like design plans, user manuals, and training materials.
Question 143: Under the ICD 705 standard, what is the primary purpose of a Sensitive Compartmented Information Facility (SCIF) accreditation?
- To validate that TEMPEST countermeasures have been applied to all equipment
- To certify the facility's cybersecurity posture under NIST 800-53
- To certify that the facility meets physical and technical construction standards for handling classified SCI (Correct answer)
- To authorize personnel to receive SCI briefings
Correct answer: To certify that the facility meets physical and technical construction standards for handling classified SCI
ICD 705 accreditation confirms the SCIF meets the physical, technical, and administrative construction standards required to protect SCI from unauthorized disclosure.
Question 144: In security governance, 'due care' refers to:
- Hiring certified security professionals for all roles
- Taking reasonable and prudent steps to protect assets and meet one's legal obligations (Correct answer)
- Documenting all security incidents within 72 hours
- Purchasing the most advanced security technologies available
Correct answer: Taking reasonable and prudent steps to protect assets and meet one's legal obligations
Due care means an organization has taken the steps a reasonable and prudent person would take to protect assets, demonstrating legal and ethical responsibility for security.
Question 145: Which of the following represents a security-specific risk during project closure that is NOT typically present in non-security projects?
- Schedule delays
- Budget overruns
- Team member turnover
- Exposure of vulnerability data contained in project artifacts if not properly secured (Correct answer)
Correct answer: Exposure of vulnerability data contained in project artifacts if not properly secured
Security project artifacts such as vulnerability assessments and penetration test reports contain sensitive data that, if improperly handled during closure, can expose the organization to exploitation.
Question 146: A final security audit conducted at project closure reveals that one control objective was not fully met. The PM should:
- Proceed with closure and ignore the finding
- Document the finding, create a remediation plan, and transfer it to the operations team (Correct answer)
- Re-scope the project to extend until the control is fully implemented regardless of budget
- Falsify the audit report to reflect full compliance
Correct answer: Document the finding, create a remediation plan, and transfer it to the operations team
Unmet control objectives must be honestly documented with a remediation plan that is handed off to operations, ensuring accountability without falsifying records.
Question 147: Under SOX Section 404, which of the following is a key security project management responsibility?
- Maintaining HIPAA-compliant audit logs
- Encrypting all customer credit card data
- Documenting and testing internal controls over financial reporting (Correct answer)
- Conducting annual penetration tests on web applications
Correct answer: Documenting and testing internal controls over financial reporting
SOX Section 404 requires management and external auditors to assess and report on the effectiveness of internal controls over financial reporting, including IT general controls.
Question 148: A security project manager is deploying video surveillance at a transportation hub. Which concept describes the minimum video resolution and frame rate needed to positively identify a person's face from a recorded image?
- Evidential Quality Specification
- Operational Requirement
- Minimum Image Quality Standard (MIQS) (Correct answer)
- Forensic-Grade Imaging Standard
Correct answer: Minimum Image Quality Standard (MIQS)
Minimum Image Quality Standards define the resolution, frame rate, and lighting thresholds required for video to be useful for identification and evidential purposes.
Question 149: What is the MOST effective way for new CSPM professionals to build competency in their field?
- Focusing solely on the most advanced topics
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Studying certification materials exclusively
- Learning entirely through trial and error
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 150: What is the MOST effective way for new CSPM professionals to build competency in their field?
- Combining formal education, mentored practice, and ongoing professional development (Correct answer)
- Focusing solely on the most advanced topics
- Studying certification materials exclusively
- Learning entirely through trial and error
Correct answer: Combining formal education, mentored practice, and ongoing professional development
Building professional competency requires a multi-faceted approach: formal education provides foundational knowledge, mentored practice develops applied skills under guidance, and ongoing professional development ensures continuous growth and currency in the field.
Question 151: What is the PRIMARY purpose of obtaining CSPM certification in Certified Security Project Manager?
- To satisfy a personal achievement goal
- To demonstrate verified competency and adherence to professional standards (Correct answer)
- To guarantee employment in the field
- To bypass educational requirements
Correct answer: To demonstrate verified competency and adherence to professional standards
Professional certification demonstrates that an individual has met established competency standards through verified assessment. It provides assurance to employers, clients, and the public that the certified professional possesses the knowledge and skills required for competent practice.
CSPM (Certified Security Project Manager) Exam
The CSPM exam is administered by the Security Industry Association (SIA). The exam consists of 150 multiple-choice questions with a 2-hour time limit. A scaled passing score of 700 out of 1000 is required. The exam covers six domains of the Security Project Management Body of Knowledge (SPMBOK): Security Industry Knowledge and Initiation (>25%), Project Planning, Project Execution and Monitoring, Project Closing, Network Security Fundamentals, and Risk Management and Compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds