CSPM Security Project Planning 3 — Questions and Answers
Question 1: A security project manager is determining the critical path for an IDS deployment. What does identifying the critical path allow the manager to do?
- Allocate the entire budget to high-priority tasks
- Identify tasks where delays will directly delay the project finish date (Correct answer)
- Remove all float from non-critical activities
- Reassign resources from non-security tasks
Correct answer: Identify tasks where delays will directly delay the project finish date
The critical path represents the longest sequence of dependent tasks; any delay on it directly extends the overall project duration.
Question 2: During planning of a zero-trust architecture project, the team decides to phase delivery into increments. This approach is associated with which project lifecycle?
- Predictive (waterfall)
- Adaptive (agile/iterative) (Correct answer)
- Linear sequential
- Event-driven
Correct answer: Adaptive (agile/iterative)
Adaptive lifecycles deliver work in iterations or increments, allowing feedback and adjustments after each phase.
Question 3: Which document serves as the formal agreement between the security project manager and the performing organization, authorizing the use of resources?
- Project charter (Correct answer)
- Project management plan
- Resource management plan
- Procurement contract
Correct answer: Project charter
The project charter formally authorizes the project and grants the project manager authority to apply organizational resources.
Question 4: A security project manager is using a bottom-up cost estimate for a penetration testing engagement. What is the PRIMARY advantage of this approach?
- It requires the least time to produce
- It is most accurate because it sums individual component estimates (Correct answer)
- It relies on historical data for speed
- It avoids the need for a work breakdown structure
Correct answer: It is most accurate because it sums individual component estimates
Bottom-up estimating aggregates estimates for each work package, producing a highly detailed and accurate overall estimate.
Question 5: A security project team is performing planning poker to estimate story points for security user stories. This technique is used in which type of project approach?
- Waterfall projects
- Agile/Scrum projects (Correct answer)
- PRINCE2 projects
- PMBOK predictive projects
Correct answer: Agile/Scrum projects
Planning poker is a consensus-based agile estimation technique where team members use cards to provide individual estimates before discussion.
Question 6: Which scheduling technique uses optimistic, pessimistic, and most likely estimates to calculate expected activity duration?
- Critical Path Method (CPM)
- Program Evaluation and Review Technique (PERT) (Correct answer)
- Resource leveling
- Monte Carlo simulation
Correct answer: Program Evaluation and Review Technique (PERT)
PERT uses a weighted average of three time estimates (optimistic, most likely, pessimistic) to calculate expected durations under uncertainty.
Question 7: A CSPM is creating a responsibility assignment matrix. The 'A' in RACI stands for:
- Authorized
- Accountable (Correct answer)
- Assigned
- Aware
Correct answer: Accountable
Accountable (A) identifies the single person who owns the deliverable and is ultimately answerable for its completion.
A security project manager is determining the critical path for an IDS deployment.
What does identifying the critical path allow the manager to do?