CSPM Security Project Closing 2 — Questions and Answers
Question 1: During project closure, which document formally releases the project team from their security responsibilities?
- Risk register
- Project closure report (Correct answer)
- Security incident log
- Lessons learned register
Correct answer: Project closure report
The project closure report formally documents the completion of the project and releases team members from their assigned responsibilities.
Question 2: A security project manager is closing a network segmentation project. What is the FIRST step before handing over to operations?
- Archive all project documentation
- Conduct a final security assessment to verify deliverables meet requirements (Correct answer)
- Release the project budget
- Notify stakeholders of project completion
Correct answer: Conduct a final security assessment to verify deliverables meet requirements
Verifying that all deliverables meet the defined security requirements must occur before handover to ensure the project objectives were achieved.
Question 3: Which artifact captures unresolved security risks that the operations team must manage after project closure?
- Project charter
- Risk register transition document (Correct answer)
- Work breakdown structure
- Procurement closing report
Correct answer: Risk register transition document
A risk register transition document passes outstanding risks and their mitigation plans to the operational team responsible for ongoing management.
Question 4: What is the purpose of a post-implementation security review during project closing?
- To reassign team members to new projects
- To evaluate whether implemented security controls are functioning as intended (Correct answer)
- To negotiate final vendor contracts
- To update the project scope statement
Correct answer: To evaluate whether implemented security controls are functioning as intended
A post-implementation security review confirms that controls are operating effectively and meeting the security objectives defined at project initiation.
Question 5: When closing a security project, sensitive project records such as vulnerability assessments should be:
- Deleted immediately to prevent data exposure
- Transferred to the client without restrictions
- Archived according to the organization's data retention and classification policy (Correct answer)
- Shared publicly as part of transparency initiatives
Correct answer: Archived according to the organization's data retention and classification policy
Sensitive records must be archived following established data retention and classification policies to ensure compliance and controlled access.
Question 6: A CSPM is conducting final stakeholder acceptance for a firewall upgrade project. The client signs the acceptance form but notes a minor configuration issue. What should the PM do?
- Re-open the project to fix the issue before accepting sign-off
- Log the issue as a known deficiency, escalate to operations, and proceed with formal closure (Correct answer)
- Ignore the issue since the client signed acceptance
- Reject the sign-off and restart the project
Correct answer: Log the issue as a known deficiency, escalate to operations, and proceed with formal closure
Minor post-acceptance deficiencies are documented and transitioned to operations rather than re-opening the project, which would delay closure.
Question 7: Which of the following is a key component of the administrative closure process in a security project?
- Selecting new security vendors
- Confirming all contracts and procurement activities are closed (Correct answer)
- Designing new security architectures
- Initiating the next project phase
Correct answer: Confirming all contracts and procurement activities are closed
Administrative closure includes verifying that all procurement contracts are settled, payments finalized, and vendor obligations discharged.
During project closure, which document formally releases the project team from their security responsibilities?