nerdexam
RSA

050-SEPROGRC-01 · Question #25

When testing the Proof-of-Concept, which three items should you focus on? (Choose three)

The correct answer is B. Step through the business process flow(s) given to you by the customer. C. Refer to the success criteria as defined by the customer; verify all criteria is accounted for. D. Login with each user you created and verify each user sees only the data he has been. When testing an RSA Archer PoC, the three critical focus areas are walking through business process flows, verifying success criteria are met, and confirming each user's data access is correctly restricted by role.

Solution Design and Best Practices for GRC

Question

When testing the Proof-of-Concept, which three items should you focus on? (Choose three)

Options

  • AConfirm all fields in any demo records contain values.
  • BStep through the business process flow(s) given to you by the customer.
  • CRefer to the success criteria as defined by the customer; verify all criteria is accounted for.
  • DLogin with each user you created and verify each user sees only the data he has been
  • EVerify all other workspaces display correctly, in case you need to perform some ad-hoc

How the community answered

(28 responses)
  • A
    11% (3)
  • B
    82% (23)
  • E
    7% (2)

Why each option

When testing an RSA Archer PoC, the three critical focus areas are walking through business process flows, verifying success criteria are met, and confirming each user's data access is correctly restricted by role.

AConfirm all fields in any demo records contain values.

Confirming every demo record field has a value is a data quality task but not a primary testing objective - empty fields may be intentional and do not validate functional or security requirements.

BStep through the business process flow(s) given to you by the customer.Correct

Stepping through the business process flows validates that the configured workflows and data relationships match the customer's actual operational requirements as scoped for the PoC.

CRefer to the success criteria as defined by the customer; verify all criteria is accounted for.Correct

Referencing the customer-defined success criteria ensures every agreed-upon requirement is demonstrably functional before the PoC is presented, directly tying testing to contractual expectations.

DLogin with each user you created and verify each user sees only the data he has beenCorrect

Logging in as each user to verify data visibility confirms that access control configurations - roles, groups, and field permissions - are correctly enforced, which is a core security function of RSA Archer.

EVerify all other workspaces display correctly, in case you need to perform some ad-hoc

Verifying unrelated workspaces for potential ad-hoc needs is out of scope for PoC testing, which should remain focused on the agreed-upon success criteria rather than exploratory coverage.

Concept tested: RSA Archer PoC testing scope and validation criteria

Source: https://community.rsa.com/t5/archer-platform-documentation/tkb-p/product-documentation

Topics

#proof of concept#testing#success criteria#access control

Community Discussion

No community discussion yet for this question.

Full 050-SEPROGRC-01 Practice