Courseiva

CAPM Business Analysis Frameworks Practice Question

A business analyst is preparing a requirements traceability matrix for a regulatory compliance program at a bank. The matrix must link business needs to solution components across the project life cycle. Which two relationships should the traceability matrix capture to support both scope verification and impact analysis of future change requests? (Choose two.)

⚠ Common exam trap

The trap here is treating any plausible metadata column, such as requester name or funding code, as equivalent to the directional requirement-to-need and requirement-to-artifact links that actually drive scope verification and impact analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Links from each requirement to the design, code, and test artifacts that implement and verify it.

A robust traceability matrix connects requirements upward to the business needs they satisfy and downward to the design, code, and test artifacts that realize and verify them. Upward links enable scope verification by exposing requirements with no business justification, while downward links enable impact analysis by pinpointing the artifacts and tests a change would disturb. Together they form the compliance evidence chain auditors expect.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Links from each requirement to the design, code, and test artifacts that implement and verify it.

    Why this is correct

    Downward traceability to design, build, and test artifacts enables verification that every requirement is implemented and validated, and it supports impact analysis by revealing exactly which components and test cases a change would touch. In a regulated bank, auditors rely on this chain to demonstrate that each mandated control was built and independently tested before release.

  • ✗

    Links between requirements and the risk register entries that could threaten their delivery.

    Why it's wrong here

    Connecting requirements to risks is valuable for risk management, but it is not one of the two relationships that together enable scope verification and impact analysis. Risk linkage does not prove a requirement traces to a business objective, nor does it identify the design and test artifacts a change would affect. It therefore cannot fulfill the dual purpose described in the compliance scenario.

  • ✗

    Links from each requirement to the individual stakeholder who originally requested it.

    Why it's wrong here

    Attributing a requirement to its originating stakeholder is useful context, but it is not one of the two traceability relationships that jointly support scope verification and change impact analysis. Knowing who asked does not prove the requirement satisfies a business need or show which artifacts would be affected by a change, so it cannot substitute for upward or downward traceability in this compliance program.

  • ✓

    Links from each business requirement to the higher-level business need or objective it satisfies.

    Why this is correct

    Tracing each requirement upward to its business need proves that the requirement delivers value and lets the team detect scope creep when a requirement has no parent objective. During impact analysis, this upward link shows which business goals a proposed change would affect, which is essential in a compliance program where every requirement must map to a regulatory obligation that the bank must satisfy.

  • ✗

    Links from each requirement to the budget code and cost center that funds its delivery.

    Why it's wrong here

    Financial coding helps with cost accounting but does not establish the requirement-to-need or requirement-to-artifact relationships needed for scope verification and impact analysis. A change request's impact is assessed through affected needs and affected artifacts, not through funding codes. Including cost centers in the matrix adds administrative overhead without strengthening compliance evidence or change control.

About these practice questions

This CAPM question is part of Courseiva's 451-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PMI exam blueprint

This CAPM practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAPM exam.