nerdexam
PMI

PMP · Question #1368

A team needs to follow defined cybersecurity compliance that is mandatory for a customer project. What should the project manager do to monitor compliance in the project?

The correct answer is D. Schedule regular project audits.. A project requires adherence to defined cybersecurity compliance for a customer project.

Submitted by kim_seoul· Apr 18, 2026Process

Question

A team needs to follow defined cybersecurity compliance that is mandatory for a customer project. What should the project manager do to monitor compliance in the project?

Options

  • AConfer with team members.
  • BDiscuss with the customer.
  • CReview with security experts.
  • DSchedule regular project audits.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    10% (4)
  • C
    3% (1)
  • D
    82% (32)

Why each option

A project requires adherence to defined cybersecurity compliance for a customer project.

AConfer with team members.

Conferring with team members is good for ongoing communication but does not provide formal, independent verification of compliance.

BDiscuss with the customer.

Discussing with the customer confirms their expectations but doesn't independently monitor the team's internal adherence to compliance.

CReview with security experts.

Reviewing with security experts is valuable for guidance and assessment but is typically part of an audit process or a specific expert review, not a continuous monitoring mechanism by itself.

DSchedule regular project audits.Correct

Scheduling regular project audits, specifically compliance audits, is the most robust and systematic way for a project manager to monitor adherence to mandatory cybersecurity compliance requirements. Audits provide formal verification that processes, procedures, and deliverables meet the specified standards and identify any deviations or areas needing corrective action.

Concept tested: Project compliance monitoring and auditing

Source: https://www.pmi.org/learning/library/project-management-audit-1250

Topics

#Compliance Monitoring#Project Audits#Monitoring & Controlling#Cybersecurity

Community Discussion

5
Viktor S.Viktor S.Nov 3, 2025

D is correct. Regular project audits are the tool specifically designed to verify ongoing compliance with mandatory requirements like cybersecurity standards. The other options are information-gathering or collaboration moves, not monitoring mechanisms. Audits give you the structured, repeatable check that compliance actually happened, which is what the question is really asking for.

17
Anjali D.Anjali D.Nov 11, 2025

I first leaned toward C since security experts seem like the right people for cybersecurity questions, but the key word is monitor, which points to ongoing verification, not consultation. Our group landed on D because regular project audits are the structured mechanism for confirming compliance over the life of the project.

4
Nina C.Nina C.Nov 13, 2025

D is right, and just to add, audits also create the paper trail you need for the exam's favorite follow-up question about stakeholder communication.

0
Nina C.Nina C.Nov 17, 2025

I first leaned toward C because I figured security experts would know the compliance requirements best. But the key word in the question is monitor, which means ongoing checking throughout the project, not just a one-time consultation. Regular project audits, option D, are the structured way to verify compliance continues to be met at intervals. That is the tool designed specifically for this kind of recurring oversight.

1
Viktor S.Viktor S.Nov 19, 2025

D is right but the reason it works is that audits produce documented evidence of compliance, not just the act of checking, which matters when regulators come asking.

0
Full PMP Practice