PMI PMP Compliance Security and Sustainability Practice Test
Topic 21 covers compliance security and sustainability for the PMI Project Management Professional (PMP) certification. These original scenarios apply the July 2026 exam objectives across predictive, agile and hybrid projects. Use the stated constraints to select one answer unless the question specifies otherwise. For broader preparation, visit the PMP Exam Dumps page. Each option has an explanation of its role in the decision.
Question 1
A predictive project will operate a service in two jurisdictions. A team member says the first location’s retention rule must apply everywhere, but the project has no confirmed requirements for the second location. Policy requires compliance review before design approval. What should the manager do?
Correct Answer: D
Correct Answer
Answer D is correct because the project lacks a verified basis for extending one location’s rule to another. Specialist review can establish the actual obligations and resolve their implications before retention is embedded in the design.
Incorrect Answers
Answer A is incorrect because design approval is the stated review point. Waiting until operation could require rework after the system has already collected data under unverified rules.
Answer B is incorrect because inconsistent local choices would bypass the required review and may be difficult to reverse. Applicability and design constraints need a documented project-level basis.
Answer C is incorrect because common ownership does not establish identical obligations across locations. The explicit review requirement exists to prevent assumptions from becoming unsupported design decisions.
Answer E is incorrect because longer retention is not inherently compliant and can conflict with limits on keeping data. The project needs applicable requirements, not a presumed universal conservative choice.
Question 2
A predictive project must prove that production access is reviewed every month. Internal policy requires evidence of the accounts examined, reviewer, review date and action on inappropriate access. The team supplies a signed statement saying reviews occur. What should the manager request?
Correct Answer: B
Correct Answer
Answer B is correct because the policy requires evidence of a performed control, not a general assertion. Records showing scope, reviewer, timing and follow-up allow an assessor to verify both the review and its consequences.
Incorrect Answers
Answer A is incorrect because a configured reminder supports execution of the control, but does not prove a review occurred or that findings were resolved. The policy requires records of actual performance.
Answer C is incorrect because the export identifies accounts and permissions, but does not show that an authorized reviewer examined them during each required month or acted on inappropriate access.
Answer D is incorrect because seniority does not supply the missing account scope, dates or corrective actions. The evidence gap concerns what happened, not who endorses a broad claim.
Answer E is incorrect because policy describes expected behavior but does not prove that the monthly reviews took place. Design evidence and operating evidence serve different purposes.
Question 3
An adaptive team is preparing the first release of a service that will handle restricted data. Policy requires security requirements to be testable before release and an authorized owner for residual security risk. Which two planning actions implement these conditions? Choose TWO.
Correct Answers: C, E
Correct Answers
Answer C is correct because testable checks connect each requirement to something the team can demonstrate. Evidence ownership reduces the risk of discovering at release that no one collected the proof needed for approval.
Answer E is correct because residual exposure may remain after controls are tested. A named authorized decision route ensures the release is not approved by someone who lacks the required risk authority.
Incorrect Answers
Answer A is incorrect because functional success does not establish access, data or other security properties. Separate applicable checks are needed to substantiate the security requirements.
Answer B is incorrect because consensus does not create the authority required by policy. The team can supply evidence, but the designated risk owner must make the acceptance decision.
Answer D is incorrect because the policy places testability before release. Customer feedback cannot substitute for deciding how restricted data will be protected before it enters the service.
Answer F is incorrect because reuse can help, but a checklist must be applicable to this service. Different data and architecture may require different checks or expose gaps in the copied set.
Question 4
A hybrid service encrypts its database, but a permission test shows that a support user can read every customer’s restricted record. Policy limits that role to assigned cases. The release lead argues that encryption satisfies the data-protection requirement. What should the manager recommend?
Correct Answer: C
Correct Answer
Answer C is correct because encryption protects data in certain storage or transmission contexts but does not prevent an authorized application session from reading too much. The observed role access violates the explicit assigned-case boundary.
Incorrect Answers
Answer A is incorrect because changing location does not address the overbroad role. Carrying the permission design forward would preserve the failure unless the access rules are corrected.
Answer B is incorrect because the application can decrypt data for authorized sessions, including this overprivileged role. The failed permission test directly shows that storage encryption did not enforce the required access boundary.
Answer D is incorrect because a behavioral promise does not enforce the stated role restriction. The demonstrated excessive access needs an effective permission control and verification.
Answer E is incorrect because stronger authentication helps establish who the user is, but it does not restrict which records that authenticated role can read. The authorization defect would remain.
Question 5
A predictive records project uses a policy that deletes routine records after three years but suspends deletion for records placed under a documented investigation hold. A batch scheduled for deletion includes held records. What should the project manager do?
Correct Answer: C
Correct Answer
Answer C is correct because the policy contains an explicit exception for held records. Applying it by record category respects both the routine disposal rule and the preservation requirement without assuming every record has the same status.
Incorrect Answers
Answer A is incorrect because an unmanaged copy may lose required access, integrity and custody controls. The hold should be implemented through the authorized preservation process, not an informal substitute.
Answer B is incorrect because the policy suspends deletion for the held records, not every record in the organization. Indefinite broad retention would discard the routine disposal rule without a stated basis.
Answer D is incorrect because the ordinary schedule is overridden for records under the documented hold. Age alone is not enough to determine deletion eligibility in this scenario.
Answer E is incorrect because the hold has its own documented process, and no sponsor authority to remove it is stated. Schedule pressure is not evidence that preservation is no longer required.
Question 6
A security assessment finds a moderate vulnerability in a hybrid release. Policy permits a 14-day exception only with validated compensating controls and written approval by the security risk owner naming remediation and expiry. The proposed control blocks the affected route. Which two actions are required before using the exception? Choose TWO.
Correct Answers: A, C
Correct Answers
Answer A is correct because a proposed block is not yet evidence of reduced exposure. Validation in the relevant environment establishes whether the temporary measure actually supports the requested exception.
Answer C is correct because the policy assigns acceptance authority and requires the exception to remain bounded. A recorded owner and end date prevent a temporary workaround from becoming an unreviewed permanent condition.
Incorrect Answers
Answer B is incorrect because the policy requires validation before using the exception. An incident is neither a safe test method nor timely evidence for the release decision.
Answer D is incorrect because the 14-day limit requires a new authorized decision or restoration of compliance. A missed deadline cannot extend its own permission.
Answer E is incorrect because product prioritization authority does not replace the explicit security acceptance role. The named owner must decide whether the residual exposure is acceptable.
Answer F is incorrect because the underlying vulnerability remains, and the control has not even been validated. Closure of the finding would misstate both remediation and evidence status.
Question 7
A contractor has completed an adaptive delivery assignment. Access policy requires individual production accounts to be disabled when assignments end, while service identities remain active under an internal owner. The contractor also created a service identity used by nightly processing. What should the manager coordinate?
Correct Answer: D
Correct Answer
Answer D is correct because the policy distinguishes human access from an operating dependency. Removing the contractor’s access while preserving and controlling the needed service identity meets both security and continuity requirements.
Incorrect Answers
Answer A is incorrect because this creates continuing privileged dependence on someone whose authorized assignment has ended. The policy explicitly requires an internal owner for service identities.
Answer B is incorrect because a speculative future need does not justify continuing personal production access. The policy requires disablement when the current assignment ends.
Answer C is incorrect because this treats service and personal identities as equivalent and could stop required processing. The service identity needs accepted internal ownership rather than indiscriminate removal.
Answer E is incorrect because renaming does not establish the proper ownership and controls for distinct identity purposes. It can also undermine traceability of prior individual activity.
Question 8
A predictive project outsources document processing. Policy says the organization retains accountability for its data controls and requires the vendor agreement to specify access, incident reporting and evidence rights. The supplier states that outsourcing transfers all accountability to it. What should the manager do?
Correct Answer: A
Correct Answer
Answer A is correct because the organization’s policy retains accountability even when work is outsourced. Explicit obligations and evidence rights let the project manage the supplier’s contribution and verify the agreed controls.
Incorrect Answers
Answer B is incorrect because accountability needs a workable governance and contractual arrangement, not an unsupported transfer to one administrative role. The required controls would still be unspecified.
Answer C is incorrect because confidentiality language alone does not specify incident timing, access boundaries or evidence rights. The policy calls for those operationally meaningful terms.
Answer D is incorrect because outsourced processing still affects the organization’s data obligations under the stated policy. Excluding it would create a blind spot precisely where third-party coordination is needed.
Answer E is incorrect because a supplier assertion does not amend the organization’s accountability rule. The required access, reporting and evidence terms remain unresolved.
Question 9
An incremental service rollout stores primary data in an approved region. The recovery design copies nightly backups to another region. Company policy requires both primary copies and backups to remain in the approved region unless a specific exception is authorized. No exception exists. What is the correct assessment?
Correct Answer: E
Correct Answer
Answer E is correct because the policy explicitly includes backups, so a compliant primary location is insufficient. The known secondary copy must be brought within the requirement or handled through the stated exception route.
Incorrect Answers
Answer A is incorrect because the backup is already a stored copy in another region. Waiting for restoration would ignore the policy’s explicit treatment of backup storage.
Answer B is incorrect because encryption may reduce exposure but does not satisfy the separate location condition. No encrypted-backup exception is stated.
Answer C is incorrect because user interaction does not change where the backups are stored. The policy applies to data copies, not merely the endpoint customers see.
Answer D is incorrect because removing a resilience requirement is a separate decision and may harm continuity. The appropriate task is to reconcile both requirements, not silently discard recovery.
Question 10
During a hybrid pilot, logs suggest an unauthorized export of restricted records. The incident policy requires immediate notification to the response team and preservation of relevant evidence; that team directs containment. Which two actions should the project manager take now? Choose TWO.
Correct Answers: C, F
Correct Answers
Answer C is correct because the specialist team has the authority to direct containment and needs prompt, factual information. Reporting uncertainty honestly avoids delaying the response until the project can prove the entire event.
Answer F is correct because the policy requires evidence that can support investigation and response. Controlled preservation reduces the chance that routine rotation or ad hoc editing destroys information about the suspected export.
Incorrect Answers
Answer A is incorrect because deletion loses evidence and the screenshot may omit relevant context or integrity information. The policy calls for approved preservation, not a self-selected replacement.
Answer B is incorrect because immediate notification is required because delayed response can extend harm or lose evidence. Routine governance timing is not the incident reporting route.
Answer D is incorrect because broad containment could damage unaffected services and exceed the manager’s stated role. The incident team directs containment based on the evidence and service dependencies.
Answer E is incorrect because broad redistribution could create another exposure and bypass the authorized response process. The response team should direct access to sensitive evidence.
Question 11
A predictive project’s compliance matrix lists 40 applicable obligations and shows each as complete. An auditor cannot trace the entries to tests, approvals or records. What should the project manager request before relying on the matrix?
Correct Answer: E
Correct Answer
Answer E is correct because a completion mark is a conclusion, not its basis. Linking obligation, control and evidence allows reviewers to test whether the stated requirement was actually met and who is responsible for any gap.
Incorrect Answers
Answer A is incorrect because the charter can authorize work but does not prove compliance with each specific obligation. It would lose rather than establish the requested evidence links.
Answer B is incorrect because a low reported risk position does not trace the 40 obligations to evidence of satisfaction. Risk classification and proof that a required control operated answer different questions.
Answer C is incorrect because unstructured volume makes relevance and completeness difficult to assess. A traceable mapping is needed so each obligation can be checked against appropriate evidence.
Answer D is incorrect because additional initials do not identify tests, approval scope or records. The assessor still could not reproduce the basis of any completion judgment.
Question 12
An adaptive team must meet a release policy requiring tested restricted-data permissions, separate approval of production deployment, and an auditable record of the exact version released. Which three actions directly satisfy those conditions? Choose THREE.
Correct Answers: B, C, E
Correct Answers
Answer B is correct because the policy calls for separation in the release decision. A distinct authorized approver provides that control rather than allowing the implementer to self-approve.
Answer C is correct because the tests must demonstrate the relevant control in the version proposed for release. Retained results provide evidence that the restricted-data boundary was actually checked.
Answer E is correct because an auditable release record must identify which artifact the evidence and decision covered. This connection prevents a later reviewer from mistaking evidence for another version as proof of this deployment.
Incorrect Answers
Answer A is incorrect because a shared name does not demonstrate that the candidate’s permissions match the previously tested version. The current release needs relevant evidence.
Answer D is incorrect because the date alone may not identify the exact deployed artifact or the matching evidence. The explicit version requirement remains unmet.
Answer F is incorrect because separate credentials do not create a separate decision maker. The same person would still implement and authorize the deployment.
Question 13
A predictive project compares two devices delivering the same service for five years. Its approved carbon model includes manufacturing and annual operation only; end-of-life impacts are equal and excluded from this comparison. Device R emits 100 units in manufacturing and 10 per year in use. Device S emits 40 initially and 30 per year. Which statement follows the model?
Correct Answer: B
Correct Answer
Answer B is correct because device R totals 100 + 5 x 10 = 150, while S totals 40 + 5 x 30 = 190. The lower operating emissions offset R’s greater manufacturing impact within the specified horizon.
Incorrect Answers
Answer A is incorrect because the annual difference is 20, totaling 100 over five years, but R begins with 60 more manufacturing units. Ignoring that initial difference overstates the net benefit.
Answer C is incorrect because organizational cost or ownership boundaries do not remove emissions from the approved life-cycle comparison. The model explicitly includes annual operation for the five-year service.
Answer D is incorrect because those totals describe only the first year. The approved five-year horizon includes later operating impacts, which reverse the initial ranking; selecting on year one would answer a different decision question.
Answer E is incorrect because this compares only the initial phase. Over five years, S’s additional operating emissions exceed that 60-unit initial advantage.
Question 14
A hybrid project compares suppliers’ carbon estimates for equivalent equipment. One estimate includes manufacturing only; another includes manufacturing, use and disposal. Policy requires a common functional service, life span and boundary for comparison. Which two actions are appropriate? Choose TWO.
Correct Answers: B, E
Correct Answers
Answer B is correct because consistent boundaries still need credible inputs. Knowing assumptions and uncertainty allows the team to judge whether the apparent difference is robust or needs further evidence.
Answer E is correct because differences in coverage can dominate the apparent ranking. A common basis makes the numbers answer the same decision question rather than rewarding whichever supplier omitted more stages.
Incorrect Answers
Answer A is incorrect because averaging unlike product estimates removes the distinction the procurement decision needs. It does not correct boundary differences or preserve supplier-specific evidence.
Answer C is incorrect because broader disclosure is not evidence of worse performance. Rejecting it would discourage the information needed for the required comparison.
Answer D is incorrect because an unsupported multiplier does not establish the omitted stages for each product. Their operating life and disposal impacts may differ materially.
Answer F is incorrect because a manufacturing-only total may look lower because it omits use and disposal. The policy prohibits treating unlike estimates as directly comparable.
Question 15
A predictive facility project can choose cooling design L with lower energy use but higher water use, or design M with the opposite profile. Both meet mandatory limits. The approved sustainability plan requires the board to consider local water stress and operating emissions together. What should the manager present?
Correct Answer: C
Correct Answer
Answer C is correct because the decision involves two relevant environmental dimensions, and both designs are feasible. Showing their operating context and life-cycle effects lets the board apply its stated priorities rather than silently optimizing one measure.
Incorrect Answers
Answer A is incorrect because the plan explicitly includes local water stress. Treating energy as the only criterion would omit a potentially material harm even though both designs pass minimum limits.
Answer B is incorrect because minimum compliance establishes eligibility, not equivalence of environmental outcomes. The board still needs the comparative effects specified by the plan.
Answer D is incorrect because installation speed does not answer the required sustainability comparison. Significant water and energy effects occur throughout operation and need to remain visible.
Answer E is incorrect because no universal priority between these impacts is established. The approved plan calls for a contextual joint assessment rather than a blanket ranking.
Question 16
A predictive project considers replacing working equipment solely to reduce emissions during its remaining two-year service period. Under the agreed comparison, keeping it adds no new manufacturing emissions. Replacement adds 80 units upfront and saves 15 units per year in operation. All other impacts are equal. What should the manager recommend on this criterion?
Correct Answer: B
Correct Answer
Answer B is correct because the two-year operating saving is 2 x 15 = 30 units, which does not offset the 80-unit manufacturing addition. Under the stated equal-impact assumptions, replacement increases the total by 50.
Incorrect Answers
Answer A is incorrect because a longer horizon could change the ranking, but it must reflect a credible authorized service plan. Altering only the spreadsheet assumption would not support this decision.
Answer C is incorrect because one year provides 15 units of savings and leaves 65 additional units, not equality. The approved comparison covers two remaining years.
Answer D is incorrect because efficiency affects the operating phase but does not erase the new manufacturing burden. The short remaining life prevents the savings from offsetting that addition.
Answer E is incorrect because that manufacturing impact would occur only if replacement is chosen, so it is a prospective consequence. Treating it as sunk would remove a decision-relevant impact.
Question 17
A hybrid replacement project uses a disposal supplier for retired devices. Policy requires asset-specific custody records, verified data sanitization and evidence of the approved recovery or disposal route. The supplier provides only a certificate saying it is environmentally responsible. What should the manager request?
Correct Answer: B
Correct Answer
Answer B is correct because the policy requires evidence of what happened to the actual assets. A general supplier statement cannot establish that specific devices were sanitized or followed the approved disposal route.
Incorrect Answers
Answer A is incorrect because collection is only one custody event and says nothing about sanitization or final destination. The photo does not complete the required chain of evidence.
Answer C is incorrect because values may inform supplier selection, but they do not prove execution of the three required controls for these assets. The project still lacks device-level evidence.
Answer D is incorrect because aggregate quantities may inform environmental reporting, but cannot establish which registered devices were sanitized or where each went. The policy requires evidence linked to the actual assets.
Answer E is incorrect because payment proves a financial transaction, not the actual handling of every asset. The stated policy requires operational evidence tied to the devices.
Question 18
An adaptive hardware initiative learns that a component supplier may be violating the organization’s worker-safety requirements. Policy requires a qualified assessment, documented corrective action and follow-up verification before the supplier can be classified compliant. No imminent hazard has been reported. Which two actions follow the policy? Choose TWO.
Correct Answers: A, E
Correct Answers
Answer A is correct because the reported concern needs evidence establishing what conditions exist and which requirements are affected. A qualified review avoids both dismissing the report and treating unverified allegations as a final finding.
Answer E is correct because a promise of improvement is not proof that the conditions changed. Ownership, action tracking and verification connect the supplier’s response to the policy’s explicit compliance decision.
Incorrect Answers
Answer B is incorrect because absence of an imminent hazard does not show that all worker-safety requirements are met. The policy still requires assessment and verified corrective action.
Answer C is incorrect because the stated process calls for assessment and correction, and no emergency condition is given. Automatic termination is not established as the required or proportionate response here.
Answer D is incorrect because a broad assurance does not meet the required qualified assessment or corrective-action evidence. Intent is not enough to classify the supplier compliant.
Answer F is incorrect because the organization’s policy explicitly includes worker safety in supplier compliance. A narrow environmental interpretation cannot remove that stated social requirement.
Question 19
A predictive procurement includes an internal accessibility standard as a mandatory acceptance condition. The chosen product passes functional demonstrations but has not been tested against that standard. The supplier says its other customers have accepted it. What should the manager do?
Correct Answer: C
Correct Answer
Answer C is correct because other customers may have different conditions, and functional demonstrations do not establish the specified accessibility properties. The project’s own mandatory standard needs relevant evidence before its acceptance gate can pass.
Incorrect Answers
Answer A is incorrect because market use can provide context but does not prove that this version meets the project’s stated standard. The specific evidence gap remains.
Answer B is incorrect because the scenario establishes an internal requirement regardless of project type. Inventing a legal-scope exception would ignore the actual governing condition.
Answer D is incorrect because the procurement expressly makes it mandatory. Reclassifying it after selection would change the acceptance basis without authorization.
Answer E is incorrect because a broad assurance may guide further inquiry, but it does not establish that this product and configuration meet the mandatory internal standard. Applicable evidence is still needed.
Question 20
A cloud supplier provides an independent security report. Its scope lists the core hosting service but excludes the new analytics add-on that will process the project’s restricted records. Policy requires assurance covering the actual service and data flow. What should the project manager conclude?
Correct Answer: C
Correct Answer
Answer C is correct because assurance applies to the services and boundaries actually assessed. The add-on processing restricted records needs relevant additional evidence or an authorized design decision before the policy condition is satisfied.
Incorrect Answers
Answer A is incorrect because it may still support assurance of the core hosting service within its scope. The right response is to identify the uncovered component, not discard all valid evidence.
Answer B is incorrect because a sales assurance does not provide the independent or otherwise required evidence for the actual data flow. The documented exclusion remains unresolved.
Answer D is incorrect because common branding does not expand the documented assessment scope. The explicit exclusion is decisive for the planned processing path.
Answer E is incorrect because changing the diagram would misrepresent the system being assessed. Accurate scope is essential to discovering, rather than concealing, assurance gaps.
Question 21
An adaptive release passed an access-control test. After the test, a configuration change broadens a service role, and that changed version is now the release candidate. Policy requires evidence matching the deployed configuration. What should the manager request?
Correct Answer: B
Correct Answer
Answer B is correct because the change touches the control that was tested, so the earlier result cannot by itself establish the new behavior. Targeted reassessment restores the connection between evidence and the release candidate.
Incorrect Answers
Answer A is incorrect because the stated risk concerns a changed permission boundary. Impact assessment should identify affected evidence; blanket rework is not justified by the facts given.
Answer C is incorrect because configuration can alter access independently of application code. The policy applies to what is deployed, including the changed service role.
Answer D is incorrect because a successful login checks authentication for that account, while the change broadens a service role’s authorization. The affected permission behavior must be tested with relevant role and access cases.
Answer E is incorrect because relabeling evidence does not change which configuration was tested. It would obscure the mismatch instead of resolving it.
Question 22
A hybrid project plans to announce that a new process is carbon-free because direct fuel use is zero. Its approved reporting policy includes purchased electricity and material supply impacts and requires estimates to disclose important uncertainty. Which two changes make the claim supportable? Choose TWO.
Correct Answers: B, F
Correct Answers
Answer B is correct because readers need to know what was counted and how reliable the estimate is. A bounded, evidence-based statement can communicate improvement without implying more certainty or coverage than the analysis supports.
Answer F is correct because zero direct fuel use covers only one part of the required assessment. Including the other specified stages prevents an incomplete boundary from being presented as total absence of emissions.
Incorrect Answers
Answer A is incorrect because the approved policy already defines relevant impacts. Choosing a boundary to fit a desired statement reverses the evidence-based reporting process.
Answer C is incorrect because onsite fuel and electricity supply are distinct sources in the stated policy. One being zero does not establish the other as zero.
Answer D is incorrect because a public absolute would remain misleading when required impacts are omitted. Private documentation does not cure the scope of the outward claim.
Answer E is incorrect because selective timing can misrepresent annual performance and uncertainty. The reporting basis needs to match the period claimed.
Question 23
A predictive installation’s commissioning policy requires a signed safety inspection for the installed equipment configuration before energization. The available certificate covers an earlier design, and the installed protective device was changed afterward. What should the project manager do?
Correct Answer: A
Correct Answer
Answer A is correct because the protective-device change makes the certificate’s scope materially different from the equipment to be used. The stated commissioning condition requires evidence covering the actual installed arrangement.
Incorrect Answers
Answer B is incorrect because changing the team performing the action does not remove the stated precondition. The equipment still needs inspection before energization.
Answer C is incorrect because a limited operating trial is not the signed inspection required by policy. It may also expose people or equipment before the protective arrangement has been accepted.
Answer D is incorrect because an annotation cannot establish that the changed protective device was assessed. The required approval must follow the applicable inspection process.
Answer E is incorrect because a signature does not extend evidence to an unassessed configuration. The policy specifically names the installed equipment as the inspection subject.
Question 24
An adaptive team wants realistic test data for a prototype. Policy prohibits uploading identifiable customer records to unapproved external tools, while an approved synthetic-data generator can provide the necessary field types. No real customer identity is needed for the test. What should the manager recommend?
Correct Answer: E
Correct Answer
Answer E is correct because the stated testing need concerns field behavior rather than actual identity. Approved synthetic data satisfies that need while avoiding the prohibited transfer of identifiable records.
Incorrect Answers
Answer A is incorrect because other fields may still identify customers, and no approved de-identification assessment is stated. Removing one field does not establish compliance with the external-tool restriction.
Answer B is incorrect because personal trust does not replace the organization’s tool approval. The available approved generator already meets the stated test need.
Answer C is incorrect because the restriction concerns where identifiable data is sent, not whether the receiving application is a prototype. Development status does not create an exception.
Answer D is incorrect because the restriction can be met without abandoning verification. Synthetic data permits relevant tests and avoids the unnecessary loss of quality evidence.
Question 25
A hybrid service must remain compliant as its configuration and supplier chain change. Its operating policy requires monitoring of control effectiveness, reassessment after material changes and retained evidence for periodic review. Which three arrangements support continuing compliance? Choose THREE.
Correct Answers: A, B, C
Correct Answers
Answer A is correct because configuration and supplier changes can alter which requirements apply or whether existing controls still work. Explicit triggers keep the assessment connected to the service as it evolves.
Answer B is correct because periodic reviewers need to identify when a control was tested and which operating state the result supports. Version-linked records prevent an old pass from being treated as timeless proof.
Answer C is correct because ongoing effectiveness can deteriorate after initial approval. Named owners and exception follow-up turn monitoring into action rather than collecting metrics that nobody is accountable to use.
Incorrect Answers
Answer D is incorrect because that would erase the history required for periodic review and make earlier decisions difficult to audit. Retention should follow the approved evidence policy rather than automatic version replacement.
Answer E is incorrect because the policy expressly anticipates change. An initial assessment cannot demonstrate that later suppliers or technical arrangements preserve the same controls.
Answer F is incorrect because document production does not show whether the controls operate effectively. The required monitoring concerns results and exceptions in the live service.
Popular posts
Recent Posts
