Courseiva

CAPM Business Analysis Frameworks Practice Question

You are the business analyst for a project developing a mobile banking application. The project is in the requirements elicitation phase. One of the key stakeholders, the head of security, is on an extended leave and will not be available for three weeks. The project timeline is aggressive, and the project manager insists on completing requirements gathering within two weeks to stay on schedule. You have held initial interviews with other stakeholders, but the security requirements are critical because the app will handle sensitive financial data. The quality assurance lead suggests using a survey to collect security requirements from the security team, but the security team members are reluctant to provide input without their manager's approval. What should you do?

⚠ Common exam trap

CAPM often tests the balance between project constraints and stakeholder availability, leading candidates to choose extreme options like delaying everything or proceeding without validation, rather than a balanced approach with assumptions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document assumptions about the security requirements and proceed with the rest of the elicitation, planning to validate with the head of security upon their return.

The best course of action is to document assumptions about the security requirements and proceed with the rest of the elicitation, planning to validate with the head of security upon their return. This balances the project timeline constraints with the need for security requirements. By documenting assumptions, the business analyst acknowledges the gap and creates a plan to validate later, reducing the risk of rework. It also allows other elicitation activities to continue, keeping the project on schedule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delay all requirements elicitation until the head of security returns to ensure complete and accurate security requirements.

    Why it's wrong here

    Halting all elicitation for three weeks breaches the two-week deadline and stalls unrelated requirement areas that other stakeholders can already address. It is tempting because waiting guarantees the security lead's authoritative input, and would be correct if the schedule were flexible and security were the only outstanding requirement domain.

  • ✗

    Use existing security policies and industry standards as a proxy for the security requirements without further elicitation.

    Why it's wrong here

    Policies and standards describe generic controls, not this application's specific data flows, so they cannot substitute for eliciting the security team's actual requirements. It is tempting because standards are legitimate inputs for compliance baselines, and would be correct when defining minimum control frameworks rather than project-specific requirements.

  • ✓

    Document assumptions about the security requirements and proceed with the rest of the elicitation, planning to validate with the head of security upon their return.

    Why this is correct

    Recording assumptions preserves momentum on the aggressive timeline while flagging the security gap explicitly. The assumptions log documents that security requirements remain unvalidated, and the head of security reviews them on return, satisfying both the two-week deadline and the need for authoritative sign-off on sensitive financial data controls.

  • ✗

    Conduct a survey of the security team members to gather their requirements despite their reluctance.

    Why it's wrong here

    Surveying reluctant team members without their manager's approval yields unreliable, incomplete security requirements for sensitive financial data. It is tempting because surveys efficiently reach many dispersed stakeholders, and would be correct where respondents are willing and the topic is not politically sensitive or approval-dependent.

About these practice questions

This CAPM question is part of Courseiva's 451-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official PMI exam blueprint

This CAPM practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAPM exam.