CAPM Business Analysis Frameworks Practice Question
A business analyst is defining the requirements for a new online banking feature that allows customers to transfer funds between accounts. The security team insists that the feature must comply with multi-factor authentication (MFA) regulations. The marketing team wants to minimize steps to improve user experience. Which type of requirement best describes the MFA compliance mandate?
⚠ Common exam trap
The trap here is misclassifying a security constraint as a functional requirement because it involves authentication, but functional requirements describe behaviors, not constraints.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Non-functional requirement
Non-functional requirements specify constraints or quality attributes, such as security, that the system must satisfy. The MFA compliance mandate is a regulatory security constraint, so it is correctly classified as a non-functional requirement. This classification helps the BA ensure that the solution meets compliance while addressing the marketing team's usability concerns separately as other non-functional requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Business requirement
Why it's wrong here
Business requirements define high-level goals or objectives of the organization, such as increasing customer satisfaction or complying with regulations. While the MFA mandate stems from a regulatory obligation, it is a specific constraint on the solution, not a high-level business goal. In requirements classification, it is better categorized as a non-functional requirement because it describes a quality or constraint the system must adhere to.
- ✓
Non-functional requirement
Why this is correct
Non-functional requirements describe constraints or quality attributes that the system must meet, such as security, performance, or usability. The MFA compliance mandate is a security constraint imposed by regulations, so it is a non-functional requirement. It defines a condition the system must satisfy rather than a specific behavior like transferring funds. In this scenario, the BA must document it as a non-functional requirement to ensure compliance while balancing user experience.
- ✗
Functional requirement
Why it's wrong here
Functional requirements describe what the system should do, such as allowing customers to transfer funds. The MFA mandate does not specify a behavior of the system; instead, it imposes a security constraint on how the transfer is performed. Therefore, it is not a functional requirement. The BA should classify it as non-functional to correctly capture its nature.
- ✗
Transition requirement
Why it's wrong here
Transition requirements describe temporary capabilities needed to migrate from the current state to the future state, such as data conversion or training. The MFA mandate is an ongoing security constraint, not a temporary transition need. Therefore, it does not fit this category. The BA should recognize it as a non-functional requirement that applies to the operational system.
Go deeper
Related to this question
About these practice questions
This CAPM question is part of Courseiva's 451-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official PMI exam blueprint
This CAPM practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAPM exam.