CSPM Security Project Closing 5 — Questions and Answers
Question 1: During security project closing, which activity specifically addresses ensuring that security tools and licenses are properly transferred or decommissioned?
- Risk response planning
- Asset disposition (Correct answer)
- Stakeholder engagement
- Schedule compression
Correct answer: Asset disposition
Asset disposition covers the proper transfer, reassignment, or decommissioning of hardware, software, and licenses at the end of a security project.
Question 2: A project sponsor requests the closure of a security project before all planned controls are implemented due to budget cuts. The PM's FIRST action should be:
- Immediately disband the team
- Document the incomplete controls, assess residual risk, and obtain sponsor sign-off acknowledging the risk acceptance (Correct answer)
- Proceed without documenting incomplete work
- Implement controls using team members' personal time
Correct answer: Document the incomplete controls, assess residual risk, and obtain sponsor sign-off acknowledging the risk acceptance
When closing before completion, the PM must document all gaps, assess the resulting residual risk, and formally obtain sponsor acknowledgment of accepted risk.
Question 3: Which compliance requirement often mandates that security project records be retained for a minimum defined period after project closure?
- Agile Manifesto
- Regulatory and industry standards such as HIPAA, PCI-DSS, or SOX (Correct answer)
- Project Management Body of Knowledge (PMBOK)
- ISO 9001 Quality Management
Correct answer: Regulatory and industry standards such as HIPAA, PCI-DSS, or SOX
Regulatory frameworks like HIPAA, PCI-DSS, and SOX specify mandatory data retention periods for security-related records, which must be honored during project closure.
Question 4: A final security audit conducted at project closure reveals that one control objective was not fully met. The PM should:
- Falsify the audit report to reflect full compliance
- Document the finding, create a remediation plan, and transfer it to the operations team (Correct answer)
- Proceed with closure and ignore the finding
- Re-scope the project to extend until the control is fully implemented regardless of budget
Correct answer: Document the finding, create a remediation plan, and transfer it to the operations team
Unmet control objectives must be honestly documented with a remediation plan that is handed off to operations, ensuring accountability without falsifying records.
Question 5: What is the primary goal of obtaining formal 'sign-off' from stakeholders at the end of a security project?
- To provide the PM with performance bonuses
- To create a legal and formal record that deliverables were accepted and project obligations fulfilled (Correct answer)
- To allow the PM to immediately start a new project
- To confirm the project was completed on time only
Correct answer: To create a legal and formal record that deliverables were accepted and project obligations fulfilled
Formal sign-off creates an auditable record confirming stakeholders accepted the deliverables, which protects all parties and legally closes project obligations.
Question 6: Which of the following represents a security-specific risk during project closure that is NOT typically present in non-security projects?
- Budget overruns
- Exposure of vulnerability data contained in project artifacts if not properly secured (Correct answer)
- Team member turnover
- Schedule delays
Correct answer: Exposure of vulnerability data contained in project artifacts if not properly secured
Security project artifacts such as vulnerability assessments and penetration test reports contain sensitive data that, if improperly handled during closure, can expose the organization to exploitation.
Question 7: After closing a security project, a team member attempts to access project systems using credentials that were not revoked. This situation BEST illustrates the importance of:
- Project schedule management
- Timely access deprovisioning as part of the closure process (Correct answer)
- Resource leveling techniques
- Earned value management
Correct answer: Timely access deprovisioning as part of the closure process
Timely revocation of all project-specific access credentials is a critical closure task that prevents unauthorized post-project access to sensitive systems.
During security project closing, which activity specifically addresses ensuring that security tools and licenses are properly transferred or decommissioned?