CSPM Security Project Closing 3 — Questions and Answers
Question 1: Which metric is MOST relevant when evaluating the success of a security project during closing?
- Number of team members who worked on the project
- Reduction in identified security risks compared to baseline (Correct answer)
- Total budget spent on training
- Number of change requests submitted
Correct answer: Reduction in identified security risks compared to baseline
Measuring risk reduction against the baseline directly reflects whether the security project achieved its core objective.
Question 2: During project closure, a lessons learned session reveals that a critical security control was deployed two weeks late. This information should PRIMARILY be used to:
- Penalize the responsible team member
- Improve planning and scheduling in future security projects (Correct answer)
- Justify project cost overruns to the sponsor
- Update the current project's risk register
Correct answer: Improve planning and scheduling in future security projects
Lessons learned from delays are captured to refine scheduling practices and improve delivery in future projects.
Question 3: A security project manager is handing over an implemented SIEM system to the operations team. Which document is MOST critical to include in the handover package?
- Original project proposal
- Runbook detailing operational procedures and alert response steps (Correct answer)
- Meeting minutes from project kickoff
- Vendor marketing materials
Correct answer: Runbook detailing operational procedures and alert response steps
A runbook provides operations staff with the step-by-step procedures needed to effectively manage and respond to the SIEM system post-handover.
Question 4: What distinguishes project closure from phase closure in a security project?
- Phase closure requires stakeholder sign-off while project closure does not
- Project closure terminates all project activities permanently, while phase closure only ends one phase (Correct answer)
- Phase closure releases the entire project budget
- Project closure is optional for security projects
Correct answer: Project closure terminates all project activities permanently, while phase closure only ends one phase
Project closure permanently concludes the project, whereas phase closure marks the end of a specific phase while the project continues.
Question 5: A security PM discovers undocumented system access credentials during project closure. The BEST immediate action is to:
- Delete the credentials and move on
- Report the discovery to the information security team and follow the credential management policy (Correct answer)
- Store the credentials in the project archive without disclosure
- Share the credentials with the entire project team for awareness
Correct answer: Report the discovery to the information security team and follow the credential management policy
Undocumented credentials represent a security risk and must be reported to the security team immediately for proper handling per policy.
Question 6: Which of the following BEST describes 'scope verification' in the context of security project closing?
- Checking that the project budget was not exceeded
- Obtaining formal stakeholder acceptance that all security deliverables meet requirements (Correct answer)
- Reviewing the initial project charter for completeness
- Verifying that all team members completed their timesheets
Correct answer: Obtaining formal stakeholder acceptance that all security deliverables meet requirements
Scope verification in project closing is the process of formally obtaining stakeholder acceptance that deliverables meet the agreed security requirements.
Question 7: When a security project is terminated early due to organizational restructuring, what must the PM ensure during closure?
- All planned work is completed before closure
- Partially completed deliverables are documented and their security implications assessed (Correct answer)
- The project team is immediately disbanded without documentation
- All project budgets are returned to the sponsor without accounting
Correct answer: Partially completed deliverables are documented and their security implications assessed
Early termination requires documenting all partially completed work and assessing any residual security risks to prevent unmanaged vulnerabilities.
Which metric is MOST relevant when evaluating the success of a security project during closing?