CSPM Security Project Closing 4 β Questions and Answers
Question 1: Which of the following is the CORRECT order for closing a security project?
- Archive records β Obtain acceptance β Release team β Close contracts
- Obtain acceptance β Close contracts β Release team β Archive records (Correct answer)
- Release team β Close contracts β Archive records β Obtain acceptance
- Close contracts β Release team β Obtain acceptance β Archive records
Correct answer: Obtain acceptance β Close contracts β Release team β Archive records
Best practice dictates obtaining stakeholder acceptance first, then closing contracts, releasing the team, and finally archiving project records.
Question 2: A security project manager is asked to confirm that all penetration testing reports from the project have been properly handled. This is an example of:
- Risk avoidance
- Sensitive data handling compliance during administrative closure (Correct answer)
- Scope creep management
- Quality assurance testing
Correct answer: Sensitive data handling compliance during administrative closure
Ensuring penetration testing reports are properly classified, stored, or destroyed is part of sensitive data handling compliance during the administrative closure process.
Question 3: Which role is PRIMARILY responsible for formally accepting the security project deliverables during closure?
- Project sponsor or designated client representative (Correct answer)
- Project manager
- Lead security engineer
- External auditor
Correct answer: Project sponsor or designated client representative
The project sponsor or designated client representative holds authority to formally accept deliverables and authorize project closure.
Question 4: During closing, a security project manager identifies that a third-party vendor did not fulfill all contractual security obligations. The PM should:
- Close the contract anyway to avoid delays
- Document the deficiency, withhold final payment if applicable, and escalate to contract management (Correct answer)
- Ignore it since the project is ending
- Assign internal team members to complete the vendor's work without notification
Correct answer: Document the deficiency, withhold final payment if applicable, and escalate to contract management
Vendor non-compliance must be documented and escalated through formal contract management channels, including withholding payment if contractually appropriate.
Question 5: What is the purpose of a 'security handover checklist' when transitioning a completed project to operations?
- To track which team members are leaving the organization
- To ensure all security controls, documentation, and access credentials are properly transferred (Correct answer)
- To record the financial performance of the project
- To list future project ideas for the security team
Correct answer: To ensure all security controls, documentation, and access credentials are properly transferred
A security handover checklist ensures no critical security assets, documentation, or access information are missed during the transition to operations.
Question 6: A CSPM must ensure that user access provisioned specifically for the security project is revoked at closure. Failure to do this creates:
- A budget variance
- Orphaned accounts that increase the organization's attack surface (Correct answer)
- A scope change request
- A quality management issue
Correct answer: Orphaned accounts that increase the organization's attack surface
Orphaned accountsβactive credentials no longer tied to a legitimate business needβexpand the attack surface and are a common post-project security vulnerability.
Question 7: Which of the following BEST supports continuous improvement in future security projects?
- Skipping lessons learned to save time
- Formally documenting and storing lessons learned in an organizational knowledge base (Correct answer)
- Keeping lessons learned internal to the project team only
- Deleting lessons learned after the project sponsor reviews them
Correct answer: Formally documenting and storing lessons learned in an organizational knowledge base
Storing lessons learned in an accessible knowledge base ensures future project teams can benefit from past experiences and avoid repeating mistakes.
Which of the following is the CORRECT order for closing a security project?