CSPM Security Project Execution & Monitoring 3 โ Questions and Answers
Question 1: During a penetration test phase of a security project, the tester discovers a critical finding outside the agreed scope. What should the project manager do?
- Instruct the tester to exploit the finding immediately
- Ignore the finding as it is out of scope
- Raise a change request and notify relevant stakeholders before proceeding (Correct answer)
- Expand scope unilaterally to include the finding
Correct answer: Raise a change request and notify relevant stakeholders before proceeding
Out-of-scope findings must be handled through formal change control; the project manager raises a change request and informs stakeholders before any work proceeds outside the agreed boundary.
Question 2: What is the MAIN purpose of a security project's daily stand-up during the execution phase?
- To review and sign off on completed deliverables
- To identify blockers, synchronize team activities, and track short-term progress (Correct answer)
- To update the project risk register
- To conduct a formal cost variance analysis
Correct answer: To identify blockers, synchronize team activities, and track short-term progress
Daily stand-ups are brief synchronization meetings to surface blockers, align on priorities, and ensure team members are on track with short-term tasks.
Question 3: Which metric BEST indicates whether a security project's cost performance is acceptable during monitoring?
- Number of risks identified
- Cost Performance Index (CPI) (Correct answer)
- Number of change requests submitted
- Resource utilization percentage
Correct answer: Cost Performance Index (CPI)
The Cost Performance Index (CPI = Earned Value รท Actual Cost) directly measures cost efficiency; a CPI โฅ 1.0 indicates the project is at or under budget.
Question 4: A security project manager needs to verify that encryption standards are being applied consistently across all system components. Which monitoring activity is MOST appropriate?
- Reviewing the project charter
- Conducting a security compliance audit against defined standards (Correct answer)
- Updating the stakeholder engagement plan
- Performing a lessons learned session
Correct answer: Conducting a security compliance audit against defined standards
A compliance audit compares actual implementation against defined encryption standards, providing systematic verification that controls are applied consistently across all components.
Question 5: During project execution, a key security engineer unexpectedly resigns. Which response BEST maintains project continuity?
- Halt the project until a replacement is hired
- Activate the resource management plan's contingency for critical roles (Correct answer)
- Reassign all tasks to remaining team members without adjustment
- Remove the engineer's tasks from scope
Correct answer: Activate the resource management plan's contingency for critical roles
The resource management plan should include contingency procedures for critical role vacancies, which may involve cross-training, contractor engagement, or workload rebalancing.
Question 6: What does a burn-down chart track in an agile-based security project execution?
- Cumulative budget expenditure over time
- Remaining work versus time to detect schedule slippage (Correct answer)
- Number of security vulnerabilities found per sprint
- Stakeholder satisfaction scores
Correct answer: Remaining work versus time to detect schedule slippage
A burn-down chart plots remaining work (story points or tasks) against elapsed time, allowing the team to see whether they are on track to complete the sprint or release.
Question 7: Which action BEST supports quality assurance of security deliverables during execution?
- Waiting until project closure to review deliverables
- Performing continuous process reviews and audits throughout execution (Correct answer)
- Delegating quality checks entirely to the client
- Relying only on automated code scanning
Correct answer: Performing continuous process reviews and audits throughout execution
Quality assurance involves ongoing process reviews and audits during execution to ensure processes used to create deliverables conform to defined quality standards.
During a penetration test phase of a security project, the tester discovers a critical finding outside the agreed scope.
What should the project manager do?