CSPM Security Project Execution & Monitoring 4 — Questions and Answers
Question 1: A security project is implementing multi-factor authentication (MFA) across 5,000 endpoints. Progress monitoring reveals 30% adoption after 60% of the timeline has elapsed. What should the project manager assess first?
- Whether to cancel the project
- Schedule variance and its root cause to determine corrective action (Correct answer)
- Whether to reduce the MFA rollout scope permanently
- Whether stakeholders are satisfied with current adoption
Correct answer: Schedule variance and its root cause to determine corrective action
The project manager should first calculate and analyze the schedule variance to understand the magnitude of the delay and identify root causes before selecting appropriate corrective actions.
Question 2: During execution monitoring, which technique involves randomly sampling security work products to assess overall quality?
- Benchmarking
- Statistical sampling (Correct answer)
- Affinity diagramming
- Force field analysis
Correct answer: Statistical sampling
Statistical sampling selects a representative subset of deliverables for inspection, allowing quality conclusions to be drawn about the entire population without inspecting every item.
Question 3: A project manager is monitoring a security awareness training rollout. Which KPI MOST directly measures the effectiveness of the training?
- Number of training modules delivered
- Phishing simulation click-rate before and after training (Correct answer)
- Total training hours logged
- Number of employees enrolled
Correct answer: Phishing simulation click-rate before and after training
Phishing simulation click-rate comparison before and after training directly measures behavioral change, which is the ultimate goal of security awareness training.
Question 4: What is the role of the change control board (CCB) during security project execution?
- To approve or reject changes to project baselines (Correct answer)
- To perform daily stand-up coordination
- To write the project's risk management plan
- To conduct penetration testing
Correct answer: To approve or reject changes to project baselines
The CCB reviews submitted change requests and decides whether to approve, reject, or defer changes to the project's scope, schedule, cost, or quality baselines.
Question 5: A security project team is behind schedule on firewall rule implementation. The project manager proposes fast-tracking. What is a key risk of this approach?
- Increased project documentation requirements
- Increased rework risk due to overlapping dependent activities (Correct answer)
- Reduced stakeholder communication frequency
- Higher chance of scope creep
Correct answer: Increased rework risk due to overlapping dependent activities
Fast-tracking overlaps activities that would normally be sequential, which can increase rework risk if upstream work must change after downstream work has already begun.
Question 6: Which monitoring output provides a formal record of project performance data at a specific point in time?
- Risk register update
- Work performance report (Correct answer)
- Project charter
- Responsibility assignment matrix
Correct answer: Work performance report
A work performance report compiles and presents work performance data and information in a structured format at a specific point in time for decision-making and communication.
Question 7: During security project execution, a team member raises a concern that a newly implemented control conflicts with an existing regulatory requirement. How should this be handled?
- Dismiss the concern as outside the team member's role
- Log it as an issue, investigate the conflict, and escalate if needed (Correct answer)
- Implement a workaround without documentation
- Close the project immediately
Correct answer: Log it as an issue, investigate the conflict, and escalate if needed
Regulatory conflicts must be formally logged in the issue register, investigated to confirm their validity, and escalated to compliance or legal stakeholders if confirmed.
A security project is implementing multi-factor authentication (MFA) across 5,000 endpoints.
Progress monitoring reveals 30% adoption after 60% of the timeline has elapsed.
What should the project manager assess first?