CSPM CSPM Security Governance & Leadership 2 — Questions and Answers
Question 1: A CSPM professional conducting a security program gap analysis compares the current state against:
- Competitor security budgets
- A desired target state or recognized security standard (Correct answer)
- The number of open vulnerabilities in the SIEM
- Executive personal risk preferences
Correct answer: A desired target state or recognized security standard
A gap analysis measures the difference between an organization's current security posture and a target framework or maturity level to identify areas requiring improvement.
Question 2: Which leadership model focuses on inspiring teams through vision, motivation, and transformational change — particularly relevant in driving security culture shifts?
- Transactional leadership
- Transformational leadership (Correct answer)
- Autocratic leadership
- Laissez-faire leadership
Correct answer: Transformational leadership
Transformational leaders motivate teams by articulating a compelling vision and inspiring change, making this style especially effective for embedding security culture across an organization.
Question 3: In a security project, a RACI matrix is used to clarify:
- Risk scores for each identified threat
- Roles and responsibilities for project tasks and decisions (Correct answer)
- The ranking of security controls by cost-effectiveness
- Audit findings and remediation owners
Correct answer: Roles and responsibilities for project tasks and decisions
A RACI matrix defines who is Responsible, Accountable, Consulted, and Informed for each project activity, preventing confusion and gaps in ownership.
Question 4: What is the key difference between a security policy and a security standard?
- Policies are technical; standards are strategic
- Policies state high-level intent and requirements; standards specify mandatory controls to meet those requirements (Correct answer)
- Standards are optional guidelines; policies are strictly enforced
- Policies apply only to IT staff; standards apply organization-wide
Correct answer: Policies state high-level intent and requirements; standards specify mandatory controls to meet those requirements
Security policies establish the 'what and why' at a high level, while standards define the specific, mandatory 'how' — the measurable requirements that satisfy the policy.
Question 5: Which stakeholder communication approach is most effective when presenting security risk findings to a non-technical executive board?
- Detailed technical CVE lists and CVSS scores
- Business-impact-focused summaries tied to financial and operational risk (Correct answer)
- Raw SIEM log exports and packet captures
- Full penetration test technical appendices
Correct answer: Business-impact-focused summaries tied to financial and operational risk
Executives make decisions based on business impact and financial risk, so security findings must be translated into organizational risk language — not raw technical detail.
Question 6: In security governance, 'due care' refers to:
- Hiring certified security professionals for all roles
- Taking reasonable and prudent steps to protect assets and meet one's legal obligations (Correct answer)
- Documenting all security incidents within 72 hours
- Purchasing the most advanced security technologies available
Correct answer: Taking reasonable and prudent steps to protect assets and meet one's legal obligations
Due care means an organization has taken the steps a reasonable and prudent person would take to protect assets, demonstrating legal and ethical responsibility for security.
A CSPM professional conducting a security program gap analysis compares the current state against: