PMI PMP Compliance Security and Sustainability Practice Test

 

Topic 21 covers compliance security and sustainability for the PMI Project Management Professional (PMP) certification. These original scenarios apply the July 2026 exam objectives across predictive, agile and hybrid projects. Use the stated constraints to select one answer unless the question specifies otherwise. For broader preparation, visit the PMP Exam Dumps page. Each option has an explanation of its role in the decision.

Question 1

A predictive project will operate a service in two jurisdictions. A team member says the first location’s retention rule must apply everywhere, but the project has no confirmed requirements for the second location. Policy requires compliance review before design approval. What should the manager do?

  1. Delay compliance review until the service has real users in both locations.
  2. Leave retention decisions to individual developers during implementation.
  3. Apply the first location’s rule everywhere because the same company operates both services.
  4. Have qualified compliance specialists determine and document the applicable obligations.
  5. Choose the longest possible retention period to satisfy every potential rule.

Correct Answer: D

 

Correct Answer

Answer D is correct because the project lacks a verified basis for extending one location’s rule to another. Specialist review can establish the actual obligations and resolve their implications before retention is embedded in the design.

Incorrect Answers

Answer A is incorrect because design approval is the stated review point. Waiting until operation could require rework after the system has already collected data under unverified rules.

Answer B is incorrect because inconsistent local choices would bypass the required review and may be difficult to reverse. Applicability and design constraints need a documented project-level basis.

Answer C is incorrect because common ownership does not establish identical obligations across locations. The explicit review requirement exists to prevent assumptions from becoming unsupported design decisions.

Answer E is incorrect because longer retention is not inherently compliant and can conflict with limits on keeping data. The project needs applicable requirements, not a presumed universal conservative choice.

 

Question 2

A predictive project must prove that production access is reviewed every month. Internal policy requires evidence of the accounts examined, reviewer, review date and action on inappropriate access. The team supplies a signed statement saying reviews occur. What should the manager request?

  1. The configuration showing that the access-review tool sends monthly reminders.
  2. The monthly review records and tracked disposition of any inappropriate access.
  3. An export of the current production account list with active roles.
  4. A more senior signature on the same general statement.
  5. A copy of the access-review policy without operational records.

Correct Answer: B

 

Correct Answer

Answer B is correct because the policy requires evidence of a performed control, not a general assertion. Records showing scope, reviewer, timing and follow-up allow an assessor to verify both the review and its consequences.

Incorrect Answers

Answer A is incorrect because a configured reminder supports execution of the control, but does not prove a review occurred or that findings were resolved. The policy requires records of actual performance.

Answer C is incorrect because the export identifies accounts and permissions, but does not show that an authorized reviewer examined them during each required month or acted on inappropriate access.

Answer D is incorrect because seniority does not supply the missing account scope, dates or corrective actions. The evidence gap concerns what happened, not who endorses a broad claim.

Answer E is incorrect because policy describes expected behavior but does not prove that the monthly reviews took place. Design evidence and operating evidence serve different purposes.

 

Question 3

An adaptive team is preparing the first release of a service that will handle restricted data. Policy requires security requirements to be testable before release and an authorized owner for residual security risk. Which two planning actions implement these conditions? Choose TWO.

  1. Let a successful functional demonstration serve as the complete security assessment.
  2. Allow the team to accept residual risk by unanimous vote.
  3. Translate the applicable security requirements into acceptance checks with evidence owners.
  4. Defer all security acceptance discussion until customers report a concern.
  5. Identify who can accept residual security risk and when that decision is needed.
  6. Copy another product’s security checklist without checking its data or boundaries.

Correct Answers: C, E

 

Correct Answers

Answer C is correct because testable checks connect each requirement to something the team can demonstrate. Evidence ownership reduces the risk of discovering at release that no one collected the proof needed for approval.

Answer E is correct because residual exposure may remain after controls are tested. A named authorized decision route ensures the release is not approved by someone who lacks the required risk authority.

Incorrect Answers

Answer A is incorrect because functional success does not establish access, data or other security properties. Separate applicable checks are needed to substantiate the security requirements.

Answer B is incorrect because consensus does not create the authority required by policy. The team can supply evidence, but the designated risk owner must make the acceptance decision.

Answer D is incorrect because the policy places testability before release. Customer feedback cannot substitute for deciding how restricted data will be protected before it enters the service.

Answer F is incorrect because reuse can help, but a checklist must be applicable to this service. Different data and architecture may require different checks or expose gaps in the copied set.

 

Question 4

A hybrid service encrypts its database, but a permission test shows that a support user can read every customer’s restricted record. Policy limits that role to assigned cases. The release lead argues that encryption satisfies the data-protection requirement. What should the manager recommend?

  1. Move the same permissions to a new database without repeating the test.
  2. Accept the release because encryption makes the stored records unreadable to everyone.
  3. Correct the role permissions and retest the restricted-record access.
  4. Ask support users to promise that they will open only assigned cases.
  5. Add a longer password requirement and treat the permission finding as resolved.

Correct Answer: C

 

Correct Answer

Answer C is correct because encryption protects data in certain storage or transmission contexts but does not prevent an authorized application session from reading too much. The observed role access violates the explicit assigned-case boundary.

Incorrect Answers

Answer A is incorrect because changing location does not address the overbroad role. Carrying the permission design forward would preserve the failure unless the access rules are corrected.

Answer B is incorrect because the application can decrypt data for authorized sessions, including this overprivileged role. The failed permission test directly shows that storage encryption did not enforce the required access boundary.

Answer D is incorrect because a behavioral promise does not enforce the stated role restriction. The demonstrated excessive access needs an effective permission control and verification.

Answer E is incorrect because stronger authentication helps establish who the user is, but it does not restrict which records that authenticated role can read. The authorization defect would remain.

 

Question 5

A predictive records project uses a policy that deletes routine records after three years but suspends deletion for records placed under a documented investigation hold. A batch scheduled for deletion includes held records. What should the project manager do?

  1. Copy held records to a personal drive and delete the controlled originals.
  2. Keep all organizational records indefinitely because one batch contains a hold.
  3. Exclude the held records and apply the hold process before deleting the eligible remainder.
  4. Delete the whole batch because the standard three-year period has elapsed.
  5. Ask the project sponsor to erase the hold entry to preserve the cleanup milestone.

Correct Answer: C

 

Correct Answer

Answer C is correct because the policy contains an explicit exception for held records. Applying it by record category respects both the routine disposal rule and the preservation requirement without assuming every record has the same status.

Incorrect Answers

Answer A is incorrect because an unmanaged copy may lose required access, integrity and custody controls. The hold should be implemented through the authorized preservation process, not an informal substitute.

Answer B is incorrect because the policy suspends deletion for the held records, not every record in the organization. Indefinite broad retention would discard the routine disposal rule without a stated basis.

Answer D is incorrect because the ordinary schedule is overridden for records under the documented hold. Age alone is not enough to determine deletion eligibility in this scenario.

Answer E is incorrect because the hold has its own documented process, and no sponsor authority to remove it is stated. Schedule pressure is not evidence that preservation is no longer required.

 

Question 6

A security assessment finds a moderate vulnerability in a hybrid release. Policy permits a 14-day exception only with validated compensating controls and written approval by the security risk owner naming remediation and expiry. The proposed control blocks the affected route. Which two actions are required before using the exception? Choose TWO.

  1. Test that the compensating control blocks the relevant exposure in the release environment.
  2. Wait for a customer incident to confirm whether the blocking rule works.
  3. Obtain the risk owner’s documented approval with remediation responsibility and expiry.
  4. Carry the exception forward automatically if remediation misses the deadline.
  5. Ask the product owner to accept the exception instead of the security risk owner.
  6. Mark the vulnerability permanently resolved as soon as the block is proposed.

Correct Answers: A, C

 

Correct Answers

Answer A is correct because a proposed block is not yet evidence of reduced exposure. Validation in the relevant environment establishes whether the temporary measure actually supports the requested exception.

Answer C is correct because the policy assigns acceptance authority and requires the exception to remain bounded. A recorded owner and end date prevent a temporary workaround from becoming an unreviewed permanent condition.

Incorrect Answers

Answer B is incorrect because the policy requires validation before using the exception. An incident is neither a safe test method nor timely evidence for the release decision.

Answer D is incorrect because the 14-day limit requires a new authorized decision or restoration of compliance. A missed deadline cannot extend its own permission.

Answer E is incorrect because product prioritization authority does not replace the explicit security acceptance role. The named owner must decide whether the residual exposure is acceptable.

Answer F is incorrect because the underlying vulnerability remains, and the control has not even been validated. Closure of the finding would misstate both remediation and evidence status.

 

Question 7

A contractor has completed an adaptive delivery assignment. Access policy requires individual production accounts to be disabled when assignments end, while service identities remain active under an internal owner. The contractor also created a service identity used by nightly processing. What should the manager coordinate?

  1. Ask the contractor to keep managing the service identity without a contract.
  2. Leave both identities active until the contractor’s next possible assignment.
  3. Disable every identity the contractor created, including the nightly service identity.
  4. Disable the individual’s access and transfer control of the service identity to its internal owner.
  5. Rename the contractor’s personal account as the service account.

Correct Answer: D

 

Correct Answer

Answer D is correct because the policy distinguishes human access from an operating dependency. Removing the contractor’s access while preserving and controlling the needed service identity meets both security and continuity requirements.

Incorrect Answers

Answer A is incorrect because this creates continuing privileged dependence on someone whose authorized assignment has ended. The policy explicitly requires an internal owner for service identities.

Answer B is incorrect because a speculative future need does not justify continuing personal production access. The policy requires disablement when the current assignment ends.

Answer C is incorrect because this treats service and personal identities as equivalent and could stop required processing. The service identity needs accepted internal ownership rather than indiscriminate removal.

Answer E is incorrect because renaming does not establish the proper ownership and controls for distinct identity purposes. It can also undermine traceability of prior individual activity.

 

Question 8

A predictive project outsources document processing. Policy says the organization retains accountability for its data controls and requires the vendor agreement to specify access, incident reporting and evidence rights. The supplier states that outsourcing transfers all accountability to it. What should the manager do?

  1. Confirm the required controls and evidence rights in the agreement before approval.
  2. Assign the project administrator personal responsibility for all supplier failures.
  3. Require only a general confidentiality statement because technical controls are the supplier’s concern.
  4. Remove the processing activity from the project’s compliance assessment.
  5. Accept the supplier’s statement as a replacement for the internal policy.

Correct Answer: A

 

Correct Answer

Answer A is correct because the organization’s policy retains accountability even when work is outsourced. Explicit obligations and evidence rights let the project manage the supplier’s contribution and verify the agreed controls.

Incorrect Answers

Answer B is incorrect because accountability needs a workable governance and contractual arrangement, not an unsupported transfer to one administrative role. The required controls would still be unspecified.

Answer C is incorrect because confidentiality language alone does not specify incident timing, access boundaries or evidence rights. The policy calls for those operationally meaningful terms.

Answer D is incorrect because outsourced processing still affects the organization’s data obligations under the stated policy. Excluding it would create a blind spot precisely where third-party coordination is needed.

Answer E is incorrect because a supplier assertion does not amend the organization’s accountability rule. The required access, reporting and evidence terms remain unresolved.

 

Question 9

An incremental service rollout stores primary data in an approved region. The recovery design copies nightly backups to another region. Company policy requires both primary copies and backups to remain in the approved region unless a specific exception is authorized. No exception exists. What is the correct assessment?

  1. The location requirement applies only after a recovery event restores the backup.
  2. The design passes if backup files are encrypted before transfer.
  3. The design passes because users interact only with the approved primary region.
  4. Delete the recovery requirement so the primary architecture can be approved unchanged.
  5. The backup design fails the location requirement and needs correction or authorized exception.

Correct Answer: E

 

Correct Answer

Answer E is correct because the policy explicitly includes backups, so a compliant primary location is insufficient. The known secondary copy must be brought within the requirement or handled through the stated exception route.

Incorrect Answers

Answer A is incorrect because the backup is already a stored copy in another region. Waiting for restoration would ignore the policy’s explicit treatment of backup storage.

Answer B is incorrect because encryption may reduce exposure but does not satisfy the separate location condition. No encrypted-backup exception is stated.

Answer C is incorrect because user interaction does not change where the backups are stored. The policy applies to data copies, not merely the endpoint customers see.

Answer D is incorrect because removing a resilience requirement is a separate decision and may harm continuity. The appropriate task is to reconcile both requirements, not silently discard recovery.

 

Question 10

During a hybrid pilot, logs suggest an unauthorized export of restricted records. The incident policy requires immediate notification to the response team and preservation of relevant evidence; that team directs containment. Which two actions should the project manager take now? Choose TWO.

  1. Erase the export logs after taking an informal screenshot for the project report.
  2. Wait until the next steering meeting to avoid interrupting the pilot.
  3. Notify the incident response team with the observed facts and current uncertainties.
  4. Disconnect all corporate systems without coordinating with the response team.
  5. Email the suspected records to the entire team so everyone can investigate.
  6. Preserve relevant logs and records using the approved evidence-handling process.

Correct Answers: C, F

 

Correct Answers

Answer C is correct because the specialist team has the authority to direct containment and needs prompt, factual information. Reporting uncertainty honestly avoids delaying the response until the project can prove the entire event.

Answer F is correct because the policy requires evidence that can support investigation and response. Controlled preservation reduces the chance that routine rotation or ad hoc editing destroys information about the suspected export.

Incorrect Answers

Answer A is incorrect because deletion loses evidence and the screenshot may omit relevant context or integrity information. The policy calls for approved preservation, not a self-selected replacement.

Answer B is incorrect because immediate notification is required because delayed response can extend harm or lose evidence. Routine governance timing is not the incident reporting route.

Answer D is incorrect because broad containment could damage unaffected services and exceed the manager’s stated role. The incident team directs containment based on the evidence and service dependencies.

Answer E is incorrect because broad redistribution could create another exposure and bypass the authorized response process. The response team should direct access to sensitive evidence.

 

Question 11

A predictive project’s compliance matrix lists 40 applicable obligations and shows each as complete. An auditor cannot trace the entries to tests, approvals or records. What should the project manager request before relying on the matrix?

  1. Replace the matrix with a signed project charter.
  2. A summary showing that the compliance risk register has no open high-rated risks.
  3. Send the auditor a full repository dump without identifying which records apply.
  4. Ask every team member to initial the existing completion column.
  5. Trace each obligation to its control, accountable owner and verifiable evidence.

Correct Answer: E

 

Correct Answer

Answer E is correct because a completion mark is a conclusion, not its basis. Linking obligation, control and evidence allows reviewers to test whether the stated requirement was actually met and who is responsible for any gap.

Incorrect Answers

Answer A is incorrect because the charter can authorize work but does not prove compliance with each specific obligation. It would lose rather than establish the requested evidence links.

Answer B is incorrect because a low reported risk position does not trace the 40 obligations to evidence of satisfaction. Risk classification and proof that a required control operated answer different questions.

Answer C is incorrect because unstructured volume makes relevance and completeness difficult to assess. A traceable mapping is needed so each obligation can be checked against appropriate evidence.

Answer D is incorrect because additional initials do not identify tests, approval scope or records. The assessor still could not reproduce the basis of any completion judgment.

 

Question 12

An adaptive team must meet a release policy requiring tested restricted-data permissions, separate approval of production deployment, and an auditable record of the exact version released. Which three actions directly satisfy those conditions? Choose THREE.

  1. Use last quarter’s permission test because the product has the same name.
  2. Obtain deployment approval from the authorized role separate from the implementer.
  3. Run the permission tests against the candidate release and retain the results.
  4. Record only the release date because the repository keeps many versions.
  5. Record the deployed version and its associated approval and test evidence.
  6. Let the implementer approve under a second username.

Correct Answers: B, C, E

 

Correct Answers

Answer B is correct because the policy calls for separation in the release decision. A distinct authorized approver provides that control rather than allowing the implementer to self-approve.

Answer C is correct because the tests must demonstrate the relevant control in the version proposed for release. Retained results provide evidence that the restricted-data boundary was actually checked.

Answer E is correct because an auditable release record must identify which artifact the evidence and decision covered. This connection prevents a later reviewer from mistaking evidence for another version as proof of this deployment.

Incorrect Answers

Answer A is incorrect because a shared name does not demonstrate that the candidate’s permissions match the previously tested version. The current release needs relevant evidence.

Answer D is incorrect because the date alone may not identify the exact deployed artifact or the matching evidence. The explicit version requirement remains unmet.

Answer F is incorrect because separate credentials do not create a separate decision maker. The same person would still implement and authorize the deployment.

 

Question 13

A predictive project compares two devices delivering the same service for five years. Its approved carbon model includes manufacturing and annual operation only; end-of-life impacts are equal and excluded from this comparison. Device R emits 100 units in manufacturing and 10 per year in use. Device S emits 40 initially and 30 per year. Which statement follows the model?

  1. R has 100 fewer units because only the difference in annual operation matters.
  2. R has 150 units over five years, 40 fewer than S.
  3. S is preferable because all operating emissions should be assigned to operations after project closure.
  4. S has 70 units against R’s 110, so select S using first-year totals.
  5. S has 60 fewer units because its manufacturing emissions are lower.

Correct Answer: B

 

Correct Answer

Answer B is correct because device R totals 100 + 5 x 10 = 150, while S totals 40 + 5 x 30 = 190. The lower operating emissions offset R’s greater manufacturing impact within the specified horizon.

Incorrect Answers

Answer A is incorrect because the annual difference is 20, totaling 100 over five years, but R begins with 60 more manufacturing units. Ignoring that initial difference overstates the net benefit.

Answer C is incorrect because organizational cost or ownership boundaries do not remove emissions from the approved life-cycle comparison. The model explicitly includes annual operation for the five-year service.

Answer D is incorrect because those totals describe only the first year. The approved five-year horizon includes later operating impacts, which reverse the initial ranking; selecting on year one would answer a different decision question.

Answer E is incorrect because this compares only the initial phase. Over five years, S’s additional operating emissions exceed that 60-unit initial advantage.

 

Question 14

A hybrid project compares suppliers’ carbon estimates for equivalent equipment. One estimate includes manufacturing only; another includes manufacturing, use and disposal. Policy requires a common functional service, life span and boundary for comparison. Which two actions are appropriate? Choose TWO.

  1. Combine the two estimates into a single average for both suppliers.
  2. Obtain the underlying assumptions and document material data uncertainty.
  3. Reject any supplier that reports a complete life-cycle estimate as too complex.
  4. Multiply every manufacturing estimate by the same arbitrary factor.
  5. Align the estimates to the same service, assumed life span and life-cycle stages.
  6. Select the smallest published number without adjusting the boundary.

Correct Answers: B, E

 

Correct Answers

Answer B is correct because consistent boundaries still need credible inputs. Knowing assumptions and uncertainty allows the team to judge whether the apparent difference is robust or needs further evidence.

Answer E is correct because differences in coverage can dominate the apparent ranking. A common basis makes the numbers answer the same decision question rather than rewarding whichever supplier omitted more stages.

Incorrect Answers

Answer A is incorrect because averaging unlike product estimates removes the distinction the procurement decision needs. It does not correct boundary differences or preserve supplier-specific evidence.

Answer C is incorrect because broader disclosure is not evidence of worse performance. Rejecting it would discourage the information needed for the required comparison.

Answer D is incorrect because an unsupported multiplier does not establish the omitted stages for each product. Their operating life and disposal impacts may differ materially.

Answer F is incorrect because a manufacturing-only total may look lower because it omits use and disposal. The policy prohibits treating unlike estimates as directly comparable.

 

Question 15

A predictive facility project can choose cooling design L with lower energy use but higher water use, or design M with the opposite profile. Both meet mandatory limits. The approved sustainability plan requires the board to consider local water stress and operating emissions together. What should the manager present?

  1. Recommend L solely because energy efficiency is the only sustainability criterion.
  2. Treat the designs as equally sustainable because both meet mandatory limits.
  3. A whole-life comparison of both impacts with local conditions and tradeoffs.
  4. Ask construction to choose the faster installation and omit operating effects.
  5. Recommend M solely because water use is always more important than emissions.

Correct Answer: C

 

Correct Answer

Answer C is correct because the decision involves two relevant environmental dimensions, and both designs are feasible. Showing their operating context and life-cycle effects lets the board apply its stated priorities rather than silently optimizing one measure.

Incorrect Answers

Answer A is incorrect because the plan explicitly includes local water stress. Treating energy as the only criterion would omit a potentially material harm even though both designs pass minimum limits.

Answer B is incorrect because minimum compliance establishes eligibility, not equivalence of environmental outcomes. The board still needs the comparative effects specified by the plan.

Answer D is incorrect because installation speed does not answer the required sustainability comparison. Significant water and energy effects occur throughout operation and need to remain visible.

Answer E is incorrect because no universal priority between these impacts is established. The approved plan calls for a contextual joint assessment rather than a blanket ranking.

 

Question 16

A predictive project considers replacing working equipment solely to reduce emissions during its remaining two-year service period. Under the agreed comparison, keeping it adds no new manufacturing emissions. Replacement adds 80 units upfront and saves 15 units per year in operation. All other impacts are equal. What should the manager recommend on this criterion?

  1. Extend the service period in the calculation without changing the operating plan.
  2. Keep the equipment because replacement adds a net 50 units over the remaining period.
  3. Declare the alternatives equal after subtracting only one year of savings.
  4. Replace it because any annual efficiency improvement reduces total emissions.
  5. Replace it because the 80-unit addition is already a sunk cost.

Correct Answer: B

 

Correct Answer

Answer B is correct because the two-year operating saving is 2 x 15 = 30 units, which does not offset the 80-unit manufacturing addition. Under the stated equal-impact assumptions, replacement increases the total by 50.

Incorrect Answers

Answer A is incorrect because a longer horizon could change the ranking, but it must reflect a credible authorized service plan. Altering only the spreadsheet assumption would not support this decision.

Answer C is incorrect because one year provides 15 units of savings and leaves 65 additional units, not equality. The approved comparison covers two remaining years.

Answer D is incorrect because efficiency affects the operating phase but does not erase the new manufacturing burden. The short remaining life prevents the savings from offsetting that addition.

Answer E is incorrect because that manufacturing impact would occur only if replacement is chosen, so it is a prospective consequence. Treating it as sunk would remove a decision-relevant impact.

 

Question 17

A hybrid replacement project uses a disposal supplier for retired devices. Policy requires asset-specific custody records, verified data sanitization and evidence of the approved recovery or disposal route. The supplier provides only a certificate saying it is environmentally responsible. What should the manager request?

  1. Photograph the collection truck and close the disposal activity.
  2. Records linking each device to sanitization, custody and final disposition.
  3. Accept the statement because it describes the supplier’s corporate values.
  4. The total weight of devices collected and the supplier’s overall recycling rate.
  5. Treat payment of the disposal invoice as proof that all devices were recovered correctly.

Correct Answer: B

 

Correct Answer

Answer B is correct because the policy requires evidence of what happened to the actual assets. A general supplier statement cannot establish that specific devices were sanitized or followed the approved disposal route.

Incorrect Answers

Answer A is incorrect because collection is only one custody event and says nothing about sanitization or final destination. The photo does not complete the required chain of evidence.

Answer C is incorrect because values may inform supplier selection, but they do not prove execution of the three required controls for these assets. The project still lacks device-level evidence.

Answer D is incorrect because aggregate quantities may inform environmental reporting, but cannot establish which registered devices were sanitized or where each went. The policy requires evidence linked to the actual assets.

Answer E is incorrect because payment proves a financial transaction, not the actual handling of every asset. The stated policy requires operational evidence tied to the devices.

 

Question 18

An adaptive hardware initiative learns that a component supplier may be violating the organization’s worker-safety requirements. Policy requires a qualified assessment, documented corrective action and follow-up verification before the supplier can be classified compliant. No imminent hazard has been reported. Which two actions follow the policy? Choose TWO.

  1. Commission the qualified assessment and record the specific findings.
  2. Classify the supplier compliant because no imminent hazard was reported.
  3. Terminate the supplier immediately without assessing the reported conditions.
  4. Accept the supplier’s assurance that its managers support worker safety.
  5. Track an accountable corrective plan and verify its completion before a compliant rating.
  6. Exclude worker safety because sustainability concerns only carbon emissions.

Correct Answers: A, E

 

Correct Answers

Answer A is correct because the reported concern needs evidence establishing what conditions exist and which requirements are affected. A qualified review avoids both dismissing the report and treating unverified allegations as a final finding.

Answer E is correct because a promise of improvement is not proof that the conditions changed. Ownership, action tracking and verification connect the supplier’s response to the policy’s explicit compliance decision.

Incorrect Answers

Answer B is incorrect because absence of an imminent hazard does not show that all worker-safety requirements are met. The policy still requires assessment and verified corrective action.

Answer C is incorrect because the stated process calls for assessment and correction, and no emergency condition is given. Automatic termination is not established as the required or proportionate response here.

Answer D is incorrect because a broad assurance does not meet the required qualified assessment or corrective-action evidence. Intent is not enough to classify the supplier compliant.

Answer F is incorrect because the organization’s policy explicitly includes worker safety in supplier compliance. A narrow environmental interpretation cannot remove that stated social requirement.

 

Question 19

A predictive procurement includes an internal accessibility standard as a mandatory acceptance condition. The chosen product passes functional demonstrations but has not been tested against that standard. The supplier says its other customers have accepted it. What should the manager do?

  1. Accept the product based on its use by other customers.
  2. Assume the standard applies only to public projects and waive it here.
  3. Obtain applicable accessibility test evidence before approving acceptance.
  4. Treat accessibility as an optional enhancement because functionality is complete.
  5. A general accessibility assurance covering the supplier’s product family.

Correct Answer: C

 

Correct Answer

Answer C is correct because other customers may have different conditions, and functional demonstrations do not establish the specified accessibility properties. The project’s own mandatory standard needs relevant evidence before its acceptance gate can pass.

Incorrect Answers

Answer A is incorrect because market use can provide context but does not prove that this version meets the project’s stated standard. The specific evidence gap remains.

Answer B is incorrect because the scenario establishes an internal requirement regardless of project type. Inventing a legal-scope exception would ignore the actual governing condition.

Answer D is incorrect because the procurement expressly makes it mandatory. Reclassifying it after selection would change the acceptance basis without authorization.

Answer E is incorrect because a broad assurance may guide further inquiry, but it does not establish that this product and configuration meet the mandatory internal standard. Applicable evidence is still needed.

 

Question 20

A cloud supplier provides an independent security report. Its scope lists the core hosting service but excludes the new analytics add-on that will process the project’s restricted records. Policy requires assurance covering the actual service and data flow. What should the project manager conclude?

  1. The report is irrelevant to every service because one add-on is excluded.
  2. Accept the add-on if the supplier’s sales representative confirms it uses secure technology.
  3. The report is useful but does not establish assurance for the excluded add-on.
  4. The report covers the add-on because both services have the same supplier logo.
  5. Remove the add-on from the data-flow diagram while retaining it in production.

Correct Answer: C

 

Correct Answer

Answer C is correct because assurance applies to the services and boundaries actually assessed. The add-on processing restricted records needs relevant additional evidence or an authorized design decision before the policy condition is satisfied.

Incorrect Answers

Answer A is incorrect because it may still support assurance of the core hosting service within its scope. The right response is to identify the uncovered component, not discard all valid evidence.

Answer B is incorrect because a sales assurance does not provide the independent or otherwise required evidence for the actual data flow. The documented exclusion remains unresolved.

Answer D is incorrect because common branding does not expand the documented assessment scope. The explicit exclusion is decisive for the planned processing path.

Answer E is incorrect because changing the diagram would misrepresent the system being assessed. Accurate scope is essential to discovering, rather than concealing, assurance gaps.

 

Question 21

An adaptive release passed an access-control test. After the test, a configuration change broadens a service role, and that changed version is now the release candidate. Policy requires evidence matching the deployed configuration. What should the manager request?

  1. Reject every prior test result and rebuild the entire product from the beginning.
  2. Assess and retest the affected permission behavior on the final configuration.
  3. Reuse the original pass because the application code is unchanged.
  4. Repeat the successful login test using the standard user account.
  5. Remove the date from the original test report so it appears current.

Correct Answer: B

 

Correct Answer

Answer B is correct because the change touches the control that was tested, so the earlier result cannot by itself establish the new behavior. Targeted reassessment restores the connection between evidence and the release candidate.

Incorrect Answers

Answer A is incorrect because the stated risk concerns a changed permission boundary. Impact assessment should identify affected evidence; blanket rework is not justified by the facts given.

Answer C is incorrect because configuration can alter access independently of application code. The policy applies to what is deployed, including the changed service role.

Answer D is incorrect because a successful login checks authentication for that account, while the change broadens a service role’s authorization. The affected permission behavior must be tested with relevant role and access cases.

Answer E is incorrect because relabeling evidence does not change which configuration was tested. It would obscure the mismatch instead of resolving it.

 

Question 22

A hybrid project plans to announce that a new process is carbon-free because direct fuel use is zero. Its approved reporting policy includes purchased electricity and material supply impacts and requires estimates to disclose important uncertainty. Which two changes make the claim supportable? Choose TWO.

  1. Ask marketing to define the boundary after the preferred headline is chosen.
  2. Use a qualified claim that states the calculation boundary and material uncertainty.
  3. Assume purchased electricity has zero impact whenever the process uses no fuel onsite.
  4. Keep the carbon-free claim and place the excluded impacts in an internal appendix only.
  5. Report only the most favorable month and present it as the full operating year.
  6. Calculate the relevant electricity and material impacts within the approved boundary.

Correct Answers: B, F

 

Correct Answers

Answer B is correct because readers need to know what was counted and how reliable the estimate is. A bounded, evidence-based statement can communicate improvement without implying more certainty or coverage than the analysis supports.

Answer F is correct because zero direct fuel use covers only one part of the required assessment. Including the other specified stages prevents an incomplete boundary from being presented as total absence of emissions.

Incorrect Answers

Answer A is incorrect because the approved policy already defines relevant impacts. Choosing a boundary to fit a desired statement reverses the evidence-based reporting process.

Answer C is incorrect because onsite fuel and electricity supply are distinct sources in the stated policy. One being zero does not establish the other as zero.

Answer D is incorrect because a public absolute would remain misleading when required impacts are omitted. Private documentation does not cure the scope of the outward claim.

Answer E is incorrect because selective timing can misrepresent annual performance and uncertainty. The reporting basis needs to match the period claimed.

 

Question 23

A predictive installation’s commissioning policy requires a signed safety inspection for the installed equipment configuration before energization. The available certificate covers an earlier design, and the installed protective device was changed afterward. What should the project manager do?

  1. Obtain the required inspection for the installed configuration before energization.
  2. Transfer energization to operations so the project no longer owns the condition.
  3. Energize at reduced load and treat that as formal inspection evidence.
  4. Ask the installer to annotate the old certificate without an authorized inspection.
  5. Proceed because any signed safety certificate satisfies the policy.

Correct Answer: A

 

Correct Answer

Answer A is correct because the protective-device change makes the certificate’s scope materially different from the equipment to be used. The stated commissioning condition requires evidence covering the actual installed arrangement.

Incorrect Answers

Answer B is incorrect because changing the team performing the action does not remove the stated precondition. The equipment still needs inspection before energization.

Answer C is incorrect because a limited operating trial is not the signed inspection required by policy. It may also expose people or equipment before the protective arrangement has been accepted.

Answer D is incorrect because an annotation cannot establish that the changed protective device was assessed. The required approval must follow the applicable inspection process.

Answer E is incorrect because a signature does not extend evidence to an unassessed configuration. The policy specifically names the installed equipment as the inspection subject.

 

Question 24

An adaptive team wants realistic test data for a prototype. Policy prohibits uploading identifiable customer records to unapproved external tools, while an approved synthetic-data generator can provide the necessary field types. No real customer identity is needed for the test. What should the manager recommend?

  1. Upload the records after deleting only customer names.
  2. Ask each developer to choose the external tool they personally trust.
  3. Upload the real records because the prototype is not yet in production.
  4. Skip all data tests to avoid handling any records.
  5. Use the approved synthetic data for the prototype tests.

Correct Answer: E

 

Correct Answer

Answer E is correct because the stated testing need concerns field behavior rather than actual identity. Approved synthetic data satisfies that need while avoiding the prohibited transfer of identifiable records.

Incorrect Answers

Answer A is incorrect because other fields may still identify customers, and no approved de-identification assessment is stated. Removing one field does not establish compliance with the external-tool restriction.

Answer B is incorrect because personal trust does not replace the organization’s tool approval. The available approved generator already meets the stated test need.

Answer C is incorrect because the restriction concerns where identifiable data is sent, not whether the receiving application is a prototype. Development status does not create an exception.

Answer D is incorrect because the restriction can be met without abandoning verification. Synthetic data permits relevant tests and avoids the unnecessary loss of quality evidence.

 

Question 25

A hybrid service must remain compliant as its configuration and supplier chain change. Its operating policy requires monitoring of control effectiveness, reassessment after material changes and retained evidence for periodic review. Which three arrangements support continuing compliance? Choose THREE.

  1. Define material-change triggers that initiate an obligation and control reassessment.
  2. Retain dated evidence linked to the service versions covered by each review.
  3. Assign owners to monitor control results and follow up exceptions.
  4. Delete prior review evidence whenever a new version is released.
  5. Treat the first compliance approval as valid for every future configuration.
  6. Monitor only the count of policies published by the service team.

Correct Answers: A, B, C

 

Correct Answers

Answer A is correct because configuration and supplier changes can alter which requirements apply or whether existing controls still work. Explicit triggers keep the assessment connected to the service as it evolves.

Answer B is correct because periodic reviewers need to identify when a control was tested and which operating state the result supports. Version-linked records prevent an old pass from being treated as timeless proof.

Answer C is correct because ongoing effectiveness can deteriorate after initial approval. Named owners and exception follow-up turn monitoring into action rather than collecting metrics that nobody is accountable to use.

Incorrect Answers

Answer D is incorrect because that would erase the history required for periodic review and make earlier decisions difficult to audit. Retention should follow the approved evidence policy rather than automatic version replacement.

Answer E is incorrect because the policy expressly anticipates change. An initial assessment cannot demonstrate that later suppliers or technical arrangements preserve the same controls.

Answer F is incorrect because document production does not show whether the controls operate effectively. The required monitoring concerns results and exceptions in the live service.

img