CSPM Security Project Planning 2 — Questions and Answers
Question 1: A security project manager needs to document the boundaries and deliverables of a new security initiative. Which planning artifact is most appropriate for this purpose?
- Risk register
- Project scope statement (Correct answer)
- Communication plan
- Stakeholder matrix
Correct answer: Project scope statement
A project scope statement defines boundaries, deliverables, exclusions, and acceptance criteria for the security project.
Question 2: During security project planning, the team identifies that a critical firewall upgrade depends on a network assessment being completed first. This relationship is best described as a:
- Lag dependency
- Finish-to-start dependency (Correct answer)
- Start-to-start dependency
- Resource conflict
Correct answer: Finish-to-start dependency
A finish-to-start dependency means the predecessor activity must finish before the successor activity can start.
Question 3: Which security planning document establishes the processes for managing changes to security controls during a project?
- Security baseline
- Change management plan (Correct answer)
- Configuration management plan
- Risk response plan
Correct answer: Change management plan
The change management plan defines procedures for submitting, reviewing, approving, and implementing changes throughout the project.
Question 4: A CSPM candidate is estimating security project costs using historical data from similar past projects. This technique is called:
- Bottom-up estimating
- Parametric estimating
- Analogous estimating (Correct answer)
- Three-point estimating
Correct answer: Analogous estimating
Analogous estimating uses historical information from similar projects to estimate duration or cost.
Question 5: Which of the following is the PRIMARY purpose of a security project kickoff meeting?
- Finalize the project budget
- Formally authorize the project start and align stakeholders (Correct answer)
- Complete the risk assessment
- Assign all project resources
Correct answer: Formally authorize the project start and align stakeholders
The kickoff meeting formally signals the start of execution and ensures all stakeholders share a common understanding of goals and expectations.
Question 6: When planning a security awareness training program project, the manager should capture both internal and external stakeholders using which tool?
- RACI chart
- Stakeholder register (Correct answer)
- Issue log
- Work breakdown structure
Correct answer: Stakeholder register
A stakeholder register documents all identified stakeholders, their roles, interests, and influence on the project.
Question 7: In security project planning, 'gold plating' refers to:
- Applying encryption to all data assets
- Adding features or functionality beyond what was agreed in scope (Correct answer)
- Using certified security tools only
- Documenting compliance evidence thoroughly
Correct answer: Adding features or functionality beyond what was agreed in scope
Gold plating is the practice of adding extras not requested by the customer, which can increase risk and cost without adding approved value.
A security project manager needs to document the boundaries and deliverables of a new security initiative.
Which planning artifact is most appropriate for this purpose?