CSPM Security Project Planning 4 — Questions and Answers
Question 1: During security project planning, a project manager discovers that two compliance requirements conflict. The best immediate action is to:
- Implement the stricter requirement and document the decision (Correct answer)
- Ignore the lesser requirement to save cost
- Escalate both requirements to the project sponsor for direction
- Remove both requirements from scope
Correct answer: Implement the stricter requirement and document the decision
Applying the stricter control satisfies both requirements while the conflict is formally documented for stakeholder awareness and decisions.
Question 2: A security project plan includes a cost baseline. What is the cost baseline used for?
- Approving vendor invoices
- Measuring and monitoring project cost performance (Correct answer)
- Calculating team member bonuses
- Setting the security budget ceiling
Correct answer: Measuring and monitoring project cost performance
The cost baseline is the approved, time-phased budget used as a benchmark for measuring and comparing actual cost performance.
Question 3: A security project manager plans to use earned value management (EVM). If the project's EV is $80,000 and PV is $100,000, what does this indicate?
- The project is ahead of schedule
- The project is behind schedule (Correct answer)
- The project is under budget
- The project has exceeded scope
Correct answer: The project is behind schedule
A Schedule Performance Index (SPI) below 1.0 (EV/PV = 0.8) indicates the project is behind its planned schedule.
Question 4: Which security planning document defines how project information will be distributed, to whom, and at what frequency?
- Stakeholder engagement plan
- Communications management plan (Correct answer)
- Quality management plan
- Risk register
Correct answer: Communications management plan
The communications management plan specifies information needs, formats, timing, and responsible parties for project communications.
Question 5: A project manager is applying the MoSCoW method during security requirements planning. What does 'W' stand for?
- Wanted
- Won't have this time (Correct answer)
- Weighted
- Work in progress
Correct answer: Won't have this time
In MoSCoW prioritization, 'W' stands for 'Won't have this time,' indicating requirements deferred to a future phase.
Question 6: Which risk response strategy involves transferring financial consequences of a security risk to a third party, such as through cyber insurance?
- Avoid
- Mitigate
- Transfer (Correct answer)
- Accept
Correct answer: Transfer
Risk transfer shifts the financial impact of a risk to another party, typically through contracts, warranties, or insurance.
Question 7: A security project manager is building the WBS for a SOC implementation. What is the LOWEST level of the WBS called?
- Activity
- Milestone
- Work package (Correct answer)
- Deliverable
Correct answer: Work package
Work packages are the lowest level of the WBS and represent deliverables that can be scheduled, cost-estimated, monitored, and controlled.
During security project planning, a project manager discovers that two compliance requirements conflict.
The best immediate action is to: