Certified Records Manager (CRM) Exam — Questions and Answers
Question 1: A legal hold (litigation hold) requires an organization to do which of the following?
- Transfer all relevant records to outside legal counsel
- Encrypt all records associated with the legal matter
- Immediately destroy all records related to pending litigation
- Suspend normal disposition of records relevant to anticipated or active litigation (Correct answer)
Correct answer: Suspend normal disposition of records relevant to anticipated or active litigation
A legal hold suspends the normal retention and disposition schedule for records potentially relevant to litigation, investigations, or audits.
Question 2: Under California's CCPA, which of the following rights is granted to California consumers regarding their personal information?
- The right to unlimited data portability at no cost
- The right to demand a paper copy of all records
- The right to approve all marketing uses of their data in advance
- The right to know what personal data is collected and to opt out of its sale (Correct answer)
Correct answer: The right to know what personal data is collected and to opt out of its sale
The CCPA gives California consumers the right to know what personal information is collected, the right to delete it, and the right to opt out of its sale.
Question 3: What is 'cutoff' in the context of records retention?
- The point at which a record series stops accumulating and the retention period begins (Correct answer)
- The process of transferring records to off-site storage
- The maximum storage capacity for a records system
- The date a record is permanently destroyed
Correct answer: The point at which a record series stops accumulating and the retention period begins
Cutoff is the point—often end of calendar or fiscal year—at which a file or record series is closed and its retention period clock begins.
Question 4: What does residual risk mean in CRM practice?
- Risk remaining after all controls are implemented (Correct answer)
- Risk affecting waste materials
- Budget overrun risk
- Initial risk before assessment
Correct answer: Risk remaining after all controls are implemented
Residual risk is the level remaining after practical controls are applied. Some is usually accepted as eliminating all risk is rarely feasible.
Question 5: What is the role of a records manager in an organization's disaster recovery plan?
- To identify vital records, oversee their protection, and coordinate records recovery following a disaster (Correct answer)
- To select and purchase disaster recovery insurance policies
- To train all employees in emergency evacuation and safety procedures
- To manage financial recovery and insurance claims after a disaster
Correct answer: To identify vital records, oversee their protection, and coordinate records recovery following a disaster
Records managers identify vital records, ensure protection strategies are in place, and lead records recovery efforts as part of the broader disaster recovery plan.
Question 6: How frequently should an organization review and update its vital records inventory?
- Whenever a new employee joins the records management team
- Once every five years as part of a full records audit
- At least annually, or whenever significant changes occur to business functions or systems (Correct answer)
- Only when a disaster occurs
Correct answer: At least annually, or whenever significant changes occur to business functions or systems
Vital records inventories should be reviewed at least annually or when business functions change to ensure the inventory remains accurate and current.
Question 7: What is 'migration' as a digital preservation strategy in electronic records management?
- Deleting records that have exceeded their retention period
- Converting paper records to electronic format for the first time
- Transferring records from one technology to another to ensure continued access (Correct answer)
- Moving physical records between storage facilities
Correct answer: Transferring records from one technology to another to ensure continued access
Migration involves transferring electronic records from one technology platform or file format to another to ensure they remain accessible as the original technology becomes obsolete.
Question 8: What is the primary function of an audit trail in electronic records management?
- To automatically flag records for disposition
- To provide a chronological log of all system activities, accesses, and modifications (Correct answer)
- To speed up record retrieval times
- To reduce electronic storage costs
Correct answer: To provide a chronological log of all system activities, accesses, and modifications
An audit trail provides a chronological log of all activities, accesses, and changes made to electronic records, supporting accountability and legal admissibility.
Question 9: What are consequences of non-compliance in CRM practice?
- Fines, license revocation, legal liability, and reputation damage (Correct answer)
- A verbal warning only
- No consequences if not caught
- Automatic renewal
Correct answer: Fines, license revocation, legal liability, and reputation damage
Non-compliance can result in fines, license issues, legal liability, and lasting reputational damage.
Question 10: In the context of records security, 'chain of custody' refers to:
- The legal retention period for evidence records
- The hierarchy of employees authorized to approve records destruction
- The documented history of who has accessed, transferred, or handled a record (Correct answer)
- A process for encrypting records during transit
Correct answer: The documented history of who has accessed, transferred, or handled a record
Chain of custody tracks every person who has accessed or handled a record, ensuring its integrity and admissibility as evidence.
Question 11: Which ARMA International principle addresses the need for an organization to maintain complete and accurate records?
- Retention
- Integrity (Correct answer)
- Disposition
- Availability
Correct answer: Integrity
The Integrity principle in GARP® ensures records are complete, accurate, and protected from unauthorized modification throughout their lifecycle.
Question 12: What does ROI measure in CRM financial analysis?
- Employee headcount
- Total organizational revenue
- Gain or loss relative to the investment amount (Correct answer)
- Physical goods returns
Correct answer: Gain or loss relative to the investment amount
ROI compares net gain or loss to initial investment cost, helping compare profitability of different options.
Question 13: A records retention schedule primarily serves what purpose?
- To define how long records must be kept and when they should be disposed of (Correct answer)
- To classify records by their security level
- To identify the physical location of all records
- To document who created each record
Correct answer: To define how long records must be kept and when they should be disposed of
A retention schedule specifies mandatory retention periods for each records series and authorizes their disposition after those periods expire.
Question 14: What is the primary purpose of a file plan?
- To schedule records for destruction
- To document the chain of custody for legal records
- To establish access controls for sensitive records
- To provide a framework for classifying and organizing records (Correct answer)
Correct answer: To provide a framework for classifying and organizing records
A file plan is a structured scheme for organizing, classifying, and filing records to ensure consistency and retrievability across an organization.
Question 15: What is the primary purpose of a vital records protection program?
- To ensure critical records are protected and accessible to maintain operations during and after a disaster (Correct answer)
- To comply with copyright and intellectual property laws
- To reduce storage costs for all organizational records
- To standardize the format of all organizational records
Correct answer: To ensure critical records are protected and accessible to maintain operations during and after a disaster
A vital records protection program ensures that records essential for business continuity, legal rights, and obligations are protected and recoverable in a disaster.
Question 16: What is the first step in establishing a vital records protection program?
- Purchasing or contracting for off-site storage facilities
- Installing fireproof storage cabinets throughout the facility
- Training all employees in emergency response procedures
- Conducting an inventory and risk assessment to identify which records are vital and the threats they face (Correct answer)
Correct answer: Conducting an inventory and risk assessment to identify which records are vital and the threats they face
Identifying vital records through inventory and assessing risks is the foundational step, as you must know what to protect and from what threats before implementing protection measures.
Question 17: Which US law specifically requires federal agencies to obtain NARA approval before destroying federal records?
- Privacy Act of 1974
- E-Government Act of 2002
- Federal Records Act (FRA) (Correct answer)
- Freedom of Information Act (FOIA)
Correct answer: Federal Records Act (FRA)
The Federal Records Act requires federal agencies to obtain disposition authority from the National Archives and Records Administration (NARA) before destroying federal records.
Question 18: What is 'data normalization' in the context of records management databases?
- Converting all records to a standard file size
- Adjusting database performance speed settings
- Encrypting personal data to meet privacy regulations
- Organizing data to reduce redundancy and improve data integrity across tables (Correct answer)
Correct answer: Organizing data to reduce redundancy and improve data integrity across tables
Data normalization organizes data in a database to reduce redundancy and improve data integrity by structuring tables to minimize duplication.
Question 19: What does disposition refer to in records management?
- Moving records to a new folder.
- Archiving or securely destroying records. (Correct answer)
- Changing font styles.
- Scanning all papers.
Correct answer: Archiving or securely destroying records.
In records management, disposition refers to the final phase of a record's lifecycle, which occurs after its active and inactive retention periods have expired. This involves either archiving records of enduring value for historical or permanent preservation or securely destroying records that are no longer needed and have met all legal and business retention requirements. Proper disposition is crucial for compliance and risk mitigation.
Question 20: What is an Electronic Document and Records Management System (EDRMS) primarily designed to do?
- Generate financial reports for auditors
- Automate payroll processing
- Capture, store, manage, and provide access to records throughout their lifecycle (Correct answer)
- Replace all paper-based communication
Correct answer: Capture, store, manage, and provide access to records throughout their lifecycle
An EDRMS is designed to capture, store, manage, and provide access to records throughout their entire lifecycle in a digital environment.
Question 21: Which security framework provides a voluntary set of guidelines for managing cybersecurity risk and is widely used by US organizations to protect information assets?
- NIST Cybersecurity Framework (CSF) (Correct answer)
- ISO 27001
- SOC 2 Type II
- PCI DSS
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF is a voluntary framework of best practices for managing and reducing cybersecurity risk, widely adopted by US public and private sector organizations.
Question 22: What is the primary purpose of a data classification policy in records management?
- To assign retention schedules to all records
- To index records for faster retrieval
- To categorize information by sensitivity and apply appropriate controls (Correct answer)
- To determine the physical storage location of records
Correct answer: To categorize information by sensitivity and apply appropriate controls
Data classification policies categorize records by sensitivity level so that appropriate security controls can be applied to each category.
Question 23: Which ISO standard provides international guidelines for records management?
- ISO 15489 (Correct answer)
- ISO 27001
- ISO 14001
- ISO 9001
Correct answer: ISO 15489
ISO 15489 is the international standard that provides principles and implementation guidance for records management in both public and private organizations.
Question 24: What concept describes the chain of custody and ownership history of a record from creation to final disposition?
- Provenance
- Records lifecycle
- Archival bond
- Custodial history (Correct answer)
Correct answer: Custodial history
Custodial history tracks who has had custody of a record over time, which is important for establishing authenticity and evidentiary value.
Question 25: What is 'least privilege' in access control?
- Limiting access to only necessary data. (Correct answer)
- Allowing full access to all users.
- Giving access based on age.
- Revoking admin rights for IT staff.
Correct answer: Limiting access to only necessary data.
The principle of 'least privilege' in access control dictates that users, programs, or processes should be granted only the minimum level of access permissions necessary to perform their specific tasks. This minimizes the potential damage from accidental errors, misuse, or malicious activity, as it restricts what an unauthorized individual or compromised account can access or alter.
Question 26: What is a 'born-digital' record?
- A record created in digital format from its inception without a physical original (Correct answer)
- A paper record that has been scanned into digital format
- A record about digital technology topics
- A handwritten record stored on a digital device
Correct answer: A record created in digital format from its inception without a physical original
A born-digital record is one that was originally created in digital format, as opposed to a digitized record which was converted from a physical source.
Question 27: How can organizations ensure legal compliance?
- Only follow local policies.
- Develop clear policies and provide training. (Correct answer)
- Wait for violations to occur.
- Ignore outdated laws.
Correct answer: Develop clear policies and provide training.
Ensuring legal compliance requires a proactive and systematic approach within an organization. Developing clear, comprehensive policies and procedures for records management establishes the framework for compliant behavior. Regular training for all employees is crucial to ensure they understand these policies and their individual responsibilities in adhering to legal and regulatory requirements.
Question 28: In the OAIS model, what is a 'Submission Information Package' (SIP)?
- A management report summarizing current records status
- An encrypted package of highly sensitive records
- A compressed backup package sent to external auditors
- The information package delivered by the producer to the archive for ingest and preservation (Correct answer)
Correct answer: The information package delivered by the producer to the archive for ingest and preservation
In the OAIS model, a Submission Information Package (SIP) is the information package delivered by the producer (record creator) to the archive for ingest and long-term preservation.
Question 29: A records manager is building a retention schedule and must balance two state laws with different retention periods for the same record type. Which approach is correct?
- Seek a court ruling before establishing the retention period
- Apply the shorter period to reduce storage costs
- Apply the period that matches federal law only
- Apply the longer period to ensure compliance with both laws (Correct answer)
Correct answer: Apply the longer period to ensure compliance with both laws
When multiple laws apply, the records manager must retain records for the longer period to ensure compliance with all applicable legal requirements simultaneously.
Question 30: What is the role of a 'taxonomy' in a records management system?
- To automate the destruction of expired records
- To provide a hierarchical structure for organizing and classifying records consistently (Correct answer)
- To measure system performance metrics
- To encrypt sensitive records during transmission
Correct answer: To provide a hierarchical structure for organizing and classifying records consistently
A taxonomy provides a hierarchical structure for organizing and classifying records consistently, enabling systematic retrieval and management.
Question 31: What is 'vital records dispersal' as a protection strategy?
- Distributing access rights to vital records among multiple system administrators
- Sending records to different storage vendors for competitive pricing
- Spreading copies of vital records across multiple geographically separate locations to reduce the risk of total loss (Correct answer)
- Distributing records among multiple internal departments
Correct answer: Spreading copies of vital records across multiple geographically separate locations to reduce the risk of total loss
Vital records dispersal reduces the risk of total loss by maintaining copies at multiple locations, ensuring at least one copy survives any single disaster.
Question 32: Why is written communication important in CRM practice?
- Eliminated by technology
- Only for legal disputes
- It creates permanent records and ensures clarity for future reference (Correct answer)
- Less effective than verbal always
Correct answer: It creates permanent records and ensures clarity for future reference
Written communication creates documented records, provides clarity, and serves as reference material for decisions and actions.
Question 33: What factor determines how long a record is retained?
- Applicable laws and business needs. (Correct answer)
- Number of employees.
- Availability of storage boxes.
- Manager preference.
Correct answer: Applicable laws and business needs.
The retention period for a record is primarily determined by a combination of legal, regulatory, and operational requirements. Laws and regulations often mandate minimum retention periods for specific record types, while business needs dictate how long records are useful for operational, historical, or financial purposes. Balancing these factors ensures both compliance and efficient information management.
Question 34: Under the Sarbanes-Oxley Act (SOX), public companies must retain audit work papers and related records for a minimum of:
- 10 years
- 7 years (Correct answer)
- 3 years
- 5 years
Correct answer: 7 years
SOX Section 802 requires retention of audit and review work papers for at least 7 years from the end of the fiscal period covered.
Question 35: Which file format is most widely recommended for the long-term preservation of text-based electronic records?
- DOCX
- PDF/A (Correct answer)
- HTML
- RTF
Correct answer: PDF/A
PDF/A (PDF for Archiving) is an ISO-standardized version of PDF (ISO 19005) specifically designed for long-term preservation of electronic documents.
Question 36: Under the Generally Accepted Recordkeeping Principles® (GARP®), which principle emphasizes that records must be complete and unaltered?
- Compliance
- Integrity (Correct answer)
- Availability
- Protection
Correct answer: Integrity
The Integrity principle under GARP® requires that records be complete, accurate, and protected against unauthorized alteration.
Question 37: What does the term 'trustworthy digital repository' (TDR) refer to in records management?
- A firewall-protected on-premise records server
- Any cloud storage service with a financially guaranteed uptime SLA
- A digital archive that reliably and sustainably provides long-term access to managed digital resources to its designated community (Correct answer)
- Any records system certified for use by a government agency
Correct answer: A digital archive that reliably and sustainably provides long-term access to managed digital resources to its designated community
A trustworthy digital repository is a system that reliably and sustainably provides access to managed digital resources to a designated community, meeting established criteria for long-term preservation such as those in ISO 16363.
Question 38: Under US federal regulations, employer payroll records must generally be retained for a minimum of how many years?
- 7 years
- 1 year
- 10 years
- 3 years (Correct answer)
Correct answer: 3 years
The Fair Labor Standards Act (FLSA) requires employers to retain payroll records for at least 3 years.
Question 39: What is a Records Management Application (RMA)?
- An application for designing record templates and forms
- Software that manages the full lifecycle of records according to defined organizational policies (Correct answer)
- A mobile app for photographing physical records
- A database used exclusively for storing employee contact information
Correct answer: Software that manages the full lifecycle of records according to defined organizational policies
An RMA is specialized software designed to manage records according to organizational policies, including retention scheduling, disposition, and access controls throughout the records lifecycle.
Question 40: How are 'vital records' defined in records management?
- Any record classified as confidential or sensitive
- Records older than 25 years that require permanent preservation
- All records created by senior management
- Records essential to resume or continue operations, protect legal rights, or fulfill obligations during or after a disaster (Correct answer)
Correct answer: Records essential to resume or continue operations, protect legal rights, or fulfill obligations during or after a disaster
Vital records are those essential for an organization to resume operations, protect rights, and meet legal obligations following a disaster or emergency.
Question 41: A records manager receives a legal hold notice. What action regarding information security should be taken IMMEDIATELY?
- Transfer all records to legal counsel's office
- Apply the standard retention schedule and document the decision
- Encrypt all organizational records enterprise-wide
- Suspend normal disposition and ensure all potentially relevant records are preserved and protected from alteration (Correct answer)
Correct answer: Suspend normal disposition and ensure all potentially relevant records are preserved and protected from alteration
A legal hold supersedes normal retention schedules, requiring immediate preservation and protection of relevant records from any deletion or modification.
Question 42: What is 'records reconstruction' in the context of disaster recovery?
- Converting surviving paper records to digital format after a disaster
- Reorganizing and reclassifying records after a system migration
- Rebuilding destroyed physical folders and filing cabinets
- The process of recreating records lost in a disaster using secondary sources such as copies, backups, or related documents (Correct answer)
Correct answer: The process of recreating records lost in a disaster using secondary sources such as copies, backups, or related documents
Records reconstruction involves recreating lost or damaged records using alternate sources—backups, partner records, or related documents—when originals cannot be recovered.
Question 43: What is a 'Recovery Point Objective' (RPO) in disaster recovery planning?
- The number of backup copies required for all vital records
- The priority ranking assigned to records for recovery sequencing
- The geographic location designated as the primary records recovery site
- The maximum age of the most recent backup from which data can be recovered after a disaster (Correct answer)
Correct answer: The maximum age of the most recent backup from which data can be recovered after a disaster
RPO defines the maximum acceptable data loss measured in time, determining how frequently backups must be made to meet recovery requirements.
Question 44: Which electronic records management approach maintains records in their original business systems rather than transferring them to a separate repository?
- Archive migration approach
- Digital vault consolidation strategy
- Centralized repository approach
- In-place records management (Correct answer)
Correct answer: In-place records management
In-place records management applies records management policies to records where they reside in their original business systems without physically relocating them to a separate repository.
Question 45: What are 'emergency operating records' in a vital records program?
- Records documenting past emergency incidents and their outcomes
- Personnel files for designated emergency response staff
- Records required for annual regulatory audits
- Records needed to continue or resume essential operations immediately following a disaster (Correct answer)
Correct answer: Records needed to continue or resume essential operations immediately following a disaster
Emergency operating records include those needed to immediately resume essential business functions after a disaster, such as contact lists, system documentation, and operational procedures.
Question 46: When should records be reviewed for disposition?
- During holidays.
- Every 10 years only.
- Before retention periods expire. (Correct answer)
- When staff have time.
Correct answer: Before retention periods expire.
Records should be reviewed for disposition proactively, ideally before their designated retention periods expire. This allows organizations to plan and execute the secure destruction or archiving of records in a timely manner, preventing the accumulation of unnecessary data and reducing storage costs and legal liabilities associated with over-retention. Timely review ensures continuous compliance.
Question 47: What role does HIPAA play in records compliance?
- Controls banking disclosures.
- Regulates tax records.
- Protects patient health information. (Correct answer)
- Restricts military records.
Correct answer: Protects patient health information.
HIPAA, the Health Insurance Portability and Accountability Act, is a U.S. federal law that establishes national standards to protect sensitive patient health information. It governs how healthcare providers, health plans, and healthcare clearinghouses handle and secure Protected Health Information (PHI). Compliance with HIPAA is crucial for organizations dealing with medical records to avoid significant penalties.
Question 48: Why is metadata important in records management?
- It replaces records.
- It assists with indexing, searching, and managing records. (Correct answer)
- It encrypts data automatically.
- It stores passwords.
Correct answer: It assists with indexing, searching, and managing records.
Metadata, or 'data about data,' is crucial in records management because it provides essential contextual information about each record. This includes details like creation date, author, keywords, and retention period, which greatly enhance a record's discoverability and usability. Metadata enables efficient indexing, precise searching, and automated management of records throughout their lifecycle, ensuring they can be found and understood when needed.
Question 49: What does the OAIS reference model stand for in digital preservation?
- Online Archive Indexing System
- Organizational Archiving and Information Standards
- Official Archive Integration Schema
- Open Archival Information System (Correct answer)
Correct answer: Open Archival Information System
The Open Archival Information System (OAIS) is an ISO standard reference model (ISO 14721) describing the components and functions required of a trustworthy digital archive.
Question 50: What is an internal control in CRM financial management?
- A process providing assurance about financial reporting reliability (Correct answer)
- Temperature control
- A remote control device
- Controlling employee behavior
Correct answer: A process providing assurance about financial reporting reliability
Internal controls safeguard assets, ensure accurate reporting, promote efficiency, and ensure compliance.
Question 51: What is conflict resolution in CRM leadership?
- Addressing disagreements constructively to find acceptable solutions (Correct answer)
- Ignoring problems
- Avoiding all conflicts
- Making all decisions unilaterally
Correct answer: Addressing disagreements constructively to find acceptable solutions
Conflict resolution addresses disagreements promptly using listening, empathy, and collaborative problem-solving.
Question 52: Which method of destruction is most appropriate for confidential paper records containing personally identifiable information (PII)?
- Tearing by hand before disposal
- Cross-cut or micro-cut shredding (Correct answer)
- Burning in an open fire
- Recycling in standard bins
Correct answer: Cross-cut or micro-cut shredding
Cross-cut or micro-cut shredding renders PII unreadable and unrecoverable, meeting most regulatory standards for secure destruction.
Question 53: Which document formally authorizes the destruction of records that have met their retention requirements?
- Certificate of destruction
- Records inventory form
- Legal hold notice
- Disposition authorization form (Correct answer)
Correct answer: Disposition authorization form
A disposition authorization form (or records destruction authorization) must be approved before any eligible records can be destroyed.
Question 54: Which type of record should be retained permanently?
- Corporate bylaws or founding charters. (Correct answer)
- Lunch menus.
- Financial reports under $100.
- Weekly timesheets.
Correct answer: Corporate bylaws or founding charters.
Corporate bylaws or founding charters are fundamental legal documents that define the structure, purpose, and governance of an organization. These records establish the legal existence and operational framework of the entity. As such, they possess enduring legal and historical value and must be retained permanently to document the organization's foundational principles and legal standing.
Question 55: What is the triple constraint in CRM project management?
- Three mandatory approvals
- The interdependent relationship between scope, time, and cost (Correct answer)
- Three required team members
- Three completion phases
Correct answer: The interdependent relationship between scope, time, and cost
Scope, time, and cost are interdependent: changing one affects the others. Managers must balance all three.
Question 56: What is the primary distinction between a record and a non-record?
- Records require a retention period; non-records are filed alphabetically
- Records are created externally; non-records are created internally
- Records are always stored digitally; non-records are paper-based
- Records document business transactions or decisions; non-records do not have ongoing value (Correct answer)
Correct answer: Records document business transactions or decisions; non-records do not have ongoing value
A record documents official business activity and has value requiring retention, while a non-record (such as a draft or convenience copy) does not meet this threshold.
Question 57: Which principle of information security ensures that data is not disclosed to unauthorized individuals?
- Authenticity
- Integrity
- Availability
- Confidentiality (Correct answer)
Correct answer: Confidentiality
Confidentiality is the CIA triad principle that restricts information access to authorized parties only.
Question 58: What is a 'Recovery Time Objective' (RTO) in business continuity planning?
- The scheduled date for the next disaster recovery drill or test
- The time required to complete the annual vital records review
- The maximum amount of data loss an organization can tolerate measured in time
- The maximum acceptable time to restore a business function after a disruption (Correct answer)
Correct answer: The maximum acceptable time to restore a business function after a disruption
RTO defines the maximum tolerable downtime before a business function must be restored, guiding recovery planning and resource allocation.
Question 59: Why must organizations follow industry-specific regulations?
- To avoid hiring lawyers.
- To increase paperwork.
- To compete in the market.
- To meet legal obligations and reduce liability. (Correct answer)
Correct answer: To meet legal obligations and reduce liability.
Industry-specific regulations are designed to address unique risks and requirements within particular sectors, such as finance, healthcare, or energy. By adhering to these regulations, organizations ensure they meet their specific legal obligations, maintain operational integrity, and significantly reduce their exposure to fines, lawsuits, and reputational harm. Compliance is a critical component of risk management.
Question 60: What is the purpose of a 'records inventory'?
- To classify records under Freedom of Information exemptions
- To identify and document all records held by an organization (Correct answer)
- To rank records by their monetary value
- To assign retention periods without reviewing content
Correct answer: To identify and document all records held by an organization
A records inventory systematically identifies, describes, and locates all records within an organization, forming the foundation for developing a retention schedule.
Question 61: What is the primary purpose of an Electronic Document Management System (EDMS)?
- To print documents automatically
- To capture, store, manage, and retrieve electronic records throughout their lifecycle (Correct answer)
- To replace physical filing systems exclusively
- To encrypt all organizational communications
Correct answer: To capture, store, manage, and retrieve electronic records throughout their lifecycle
An EDMS is designed to capture, store, manage, and retrieve electronic documents and records throughout their entire lifecycle.
Question 62: Under HIPAA, which of the following is considered Protected Health Information (PHI)?
- A patient's name combined with their diagnosis (Correct answer)
- Aggregated hospital admission counts
- Anonymized patient statistics
- General public health research data
Correct answer: A patient's name combined with their diagnosis
PHI includes any individually identifiable health information, such as a patient's name linked to their medical condition.
Question 63: Which encryption standard is currently recommended by NIST for protecting sensitive federal records at rest?
- RC4
- MD5
- AES-256 (Advanced Encryption Standard) (Correct answer)
- DES (Data Encryption Standard)
Correct answer: AES-256 (Advanced Encryption Standard)
NIST recommends AES-256 as the current standard for strong encryption of sensitive data at rest.
Question 64: In records management, what is an 'enterprise content management' (ECM) system?
- A financial reporting platform for large corporations
- A tool used only for scanning physical documents
- A system exclusively for managing email communications
- A comprehensive platform for capturing, managing, storing, preserving, and delivering content across an organization (Correct answer)
Correct answer: A comprehensive platform for capturing, managing, storing, preserving, and delivering content across an organization
An ECM system is a comprehensive platform that captures, manages, stores, preserves, and delivers content and records across an entire organization.
Question 65: Which protection method provides the highest level of safeguard for vital records against physical disaster?
- Using acid-free archival storage materials for paper records
- Storing records in fireproof cabinets located on-site
- Encrypting all digital records with strong encryption
- Maintaining duplicate copies at a geographically remote off-site location (Correct answer)
Correct answer: Maintaining duplicate copies at a geographically remote off-site location
Geographically remote off-site duplication protects vital records from site-specific disasters—fires, floods, earthquakes—that could destroy on-site storage entirely.
Question 66: What is a compliance audit in CRM practice?
- A systematic review verifying adherence to requirements and policies (Correct answer)
- A profit assessment
- An employee review
- A customer survey
Correct answer: A systematic review verifying adherence to requirements and policies
A compliance audit examines adherence to regulations, policies, and standards, identifying gaps and recommending corrective actions.
Question 67: Which concept describes the legally recognized principle that organizations must not destroy records once they are aware that litigation or investigation is reasonably anticipated?
- Appraisal
- Spoliation (Correct answer)
- Cutoff
- Accession
Correct answer: Spoliation
Spoliation refers to the destruction or alteration of evidence once litigation is reasonably anticipated; it can result in severe legal sanctions including adverse inference instructions.
Question 68: A 'privacy impact assessment' (PIA) is conducted to:
- Evaluate the financial cost of a data breach
- Train employees on data handling procedures
- Archive records that contain personal information
- Identify privacy risks before implementing a new system or process involving personal data (Correct answer)
Correct answer: Identify privacy risks before implementing a new system or process involving personal data
A PIA is a proactive analysis performed before deploying new systems or processes to identify and mitigate privacy risks.
Question 69: A legal hold is lifted after litigation concludes. What should the records manager do next regarding affected records?
- Extend all hold records' retention by 5 additional years automatically
- Immediately destroy all records that were on hold
- Resume normal retention schedules and destroy records that have met their retention period (Correct answer)
- Transfer all held records to permanent archives
Correct answer: Resume normal retention schedules and destroy records that have met their retention period
Once a legal hold is lifted, the records manager should evaluate each record against the retention schedule and dispose of any that have already met their retention period.
Question 70: What is the primary purpose of a records retention schedule?
- To document how long each record series must be kept and its final disposition (Correct answer)
- To categorize records by their physical format
- To establish backup procedures for electronic records
- To list all employees who have access to records
Correct answer: To document how long each record series must be kept and its final disposition
A retention schedule identifies each record series, specifies its retention period, and defines the final disposition action (destroy, transfer, archive).
Question 71: How should sensitive paper records be disposed?
- Recycled without review.
- Shredded or destroyed securely. (Correct answer)
- Thrown in public bins.
- Stored in unlocked cabinets.
Correct answer: Shredded or destroyed securely.
Sensitive paper records contain confidential or personal information that, if exposed, could lead to privacy breaches or identity theft. Therefore, they must be disposed of securely, typically through shredding, pulping, or incineration, to render the information unreadable and irrecoverable. This prevents unauthorized access and ensures compliance with data protection regulations.
Question 72: What does 'chain of custody' mean in the context of electronic records?
- A method for encrypting records during electronic transfer
- The documented chronological sequence of possession and control of a record (Correct answer)
- The process of converting records between different file formats
- A series of legal regulations governing records retention
Correct answer: The documented chronological sequence of possession and control of a record
Chain of custody documents the chronological sequence of possession and handling of a record, which is essential for establishing authenticity and legal admissibility in court.
Question 73: Which document provides proof of compliance?
- Audit logs or trails. (Correct answer)
- Email threads.
- Handwritten notes.
- Employee surveys.
Correct answer: Audit logs or trails.
Audit logs or trails provide a chronological record of activities, such as who accessed a record, when, and what changes were made. These logs serve as irrefutable evidence of compliance with data access, security, and retention policies. They are essential for demonstrating accountability and transparency during internal or external audits.
Question 74: In an Electronic Document and Records Management System (EDRMS), what is the role of a 'disposition authority'?
- Official approval that authorizes the destruction or transfer of records (Correct answer)
- An audit log that tracks all record modifications
- A user role that grants access to restricted records
- A software module that automatically encrypts records at rest
Correct answer: Official approval that authorizes the destruction or transfer of records
A disposition authority is the official legal sanction that permits an organization to destroy or transfer records at the end of their retention period.
Question 75: The 'appraisal' process in records management is primarily used to determine:
- The physical condition of aging paper records
- The cost of off-site storage contracts
- Which records have sufficient value to warrant permanent preservation (Correct answer)
- The monetary value of archival records
Correct answer: Which records have sufficient value to warrant permanent preservation
Appraisal evaluates the long-term value of records—administrative, legal, fiscal, or historical—to determine which warrant permanent archival preservation.
Question 76: A records manager is implementing a 'clean desk policy.' What is the PRIMARY security goal of this policy?
- Prevent unauthorized access to physical records and sensitive information left unattended (Correct answer)
- Reduce office clutter to meet fire codes
- Improve employee productivity
- Ensure employees take regular breaks from screens
Correct answer: Prevent unauthorized access to physical records and sensitive information left unattended
A clean desk policy requires employees to secure physical records and devices when not in use, preventing unauthorized viewing or theft.
Question 77: What is the primary purpose of a 'records management policy'?
- To list every record series and its retention period
- To provide step-by-step filing instructions for clerical staff
- To define the technical specifications for an EDRMS system
- To establish organizational commitment, responsibilities, and principles for managing records (Correct answer)
Correct answer: To establish organizational commitment, responsibilities, and principles for managing records
A records management policy is a high-level document that defines organizational commitment, assigns responsibilities, and sets principles that guide the entire records management program.
Question 78: What is a communication plan in CRM project management?
- Eliminating meetings
- Restricting who can communicate
- Defining what information is shared, with whom, when, and how (Correct answer)
- Reducing total communication
Correct answer: Defining what information is shared, with whom, when, and how
A communication plan establishes content, audience, frequency, channels, and responsibilities for project communications.
Question 79: When records are transferred to a third-party vendor for storage or processing, which document BEST protects the organization's privacy obligations?
- A records destruction certificate
- An internal retention schedule
- A service level agreement (SLA) for uptime
- A data processing agreement (DPA) specifying security and privacy requirements (Correct answer)
Correct answer: A data processing agreement (DPA) specifying security and privacy requirements
A DPA contractually obligates third-party vendors to uphold the organization's data protection standards when handling personal information.
Question 80: What is scope creep in CRM project management?
- Incremental feature addition technique
- Reducing deliverables
- Uncontrolled scope expansion without adjusting time, cost, or resources (Correct answer)
- Natural planned growth
Correct answer: Uncontrolled scope expansion without adjusting time, cost, or resources
Scope creep adds requirements without formal evaluation, causing schedule delays and budget overruns.
Question 81: What is 'off-site storage' in the context of vital records protection?
- Storing copies of vital records at a geographically separate location to protect against site-specific disasters (Correct answer)
- Keeping records in a locked safe within the primary facility
- Storing records in a different department within the same building
- Archiving records exclusively in a cloud-based system
Correct answer: Storing copies of vital records at a geographically separate location to protect against site-specific disasters
Off-site storage places copies of vital records at a geographically separate facility, protecting them from disasters that could destroy the primary location.
Question 82: Which ARMA International principle addresses the requirement that records be accessible and usable when needed, including during and after a disaster?
- The Availability Principle (Correct answer)
- The Retention Principle
- The Compliance Principle
- The Integrity Principle
Correct answer: The Availability Principle
ARMA's Availability Principle within the Generally Accepted Recordkeeping Principles (GARP) requires that records be accessible and usable when needed, which encompasses vital records protection.
Question 83: What is cash flow management in CRM practice?
- Managing coins and currency
- Only tracking income
- Investing everything in stocks
- Optimizing the timing of money coming in and going out (Correct answer)
Correct answer: Optimizing the timing of money coming in and going out
Cash flow management tracks and optimizes the timing of inflows and outflows to ensure sufficient funds.
Question 84: What is a 'disposition authority' in the context of electronic records management?
- A person authorized to create new record categories
- Software that automatically deletes records upon schedule expiration
- The access rights granted to view classified records
- Official approval authorizing a specific records disposition action such as transfer or destruction (Correct answer)
Correct answer: Official approval authorizing a specific records disposition action such as transfer or destruction
A disposition authority is the official authorization that permits the transfer, destruction, or other disposition of records in accordance with the approved records retention schedule.
Question 85: How should CRM professionals handle difficult conversations?
- Avoid entirely
- Prepare key points, remain calm, focus on facts, seek solutions (Correct answer)
- Use aggressive language
- Delegate to management
Correct answer: Prepare key points, remain calm, focus on facts, seek solutions
Difficult conversations require preparation, emotional control, fact-based discussion, and collaborative problem-solving.
Question 86: What is the primary purpose of conducting regular tests of a vital records program?
- To generate documentation that justifies the budget for off-site storage
- To verify that protection measures work, recovery procedures are effective, and that the vital records inventory remains accurate (Correct answer)
- To provide hands-on training for newly hired records management staff
- To satisfy annual regulatory audit requirements only
Correct answer: To verify that protection measures work, recovery procedures are effective, and that the vital records inventory remains accurate
Regular testing confirms that vital records can actually be retrieved and used when needed and reveals any gaps in protection or recovery procedures.
Question 87: What is financial forecasting in CRM practice?
- Predicting future conditions based on historical data and trends (Correct answer)
- Determining compensation
- Guaranteeing exact outcomes
- Documenting past transactions only
Correct answer: Predicting future conditions based on historical data and trends
Forecasting uses historical data and trends to project future financial conditions, supporting strategic planning.
Question 88: Why is data visualization important in CRM reporting?
- Replaces written analysis
- It makes complex patterns easier to understand and communicate (Correct answer)
- Purely decorative
- Required by law
Correct answer: It makes complex patterns easier to understand and communicate
Visualization translates complex data into visual formats highlighting patterns and outliers for diverse audiences.
Question 89: How does records management support a 'business continuity plan' (BCP)?
- By creating financial plans for operating during economic downturns
- By ensuring vital records are identified, protected, and accessible so essential functions can be maintained during disruptions (Correct answer)
- By developing marketing strategies for business growth after a disaster
- By creating succession plans for leadership transitions during emergencies
Correct answer: By ensuring vital records are identified, protected, and accessible so essential functions can be maintained during disruptions
Records management supports the BCP by ensuring vital records are protected and accessible, providing the information foundation needed to maintain essential operations during disruptions.
Question 90: What is effective delegation in CRM management?
- Doing everything yourself
- Assigning authority and tasks while maintaining accountability (Correct answer)
- Giving unpleasant tasks to newcomers
- Passing off all responsibility
Correct answer: Assigning authority and tasks while maintaining accountability
Delegation assigns tasks and authority based on skills while the leader maintains ultimate accountability.
Question 91: How does a 'warm site' differ from both hot and cold sites in disaster recovery?
- A warm site is always located in a temperate climate zone
- A warm site is partially equipped with hardware and communications, requiring less setup time than a cold site but not immediately operational like a hot site (Correct answer)
- A warm site stores only paper records while hot and cold sites store digital records
- A warm site is shared with other organizations while hot and cold sites are dedicated facilities
Correct answer: A warm site is partially equipped with hardware and communications, requiring less setup time than a cold site but not immediately operational like a hot site
A warm site provides a middle ground—partial infrastructure reduces recovery time compared to a cold site, but at lower cost than a fully operational hot site.
Question 92: What is a milestone in CRM project management?
- A physical construction marker
- A significant event marking progress at a key point in the timeline (Correct answer)
- An optional checkpoint
- A daily required task
Correct answer: A significant event marking progress at a key point in the timeline
Milestones are significant checkpoints marking completion of major deliverables or phase transitions.
Question 93: How do regulations differ from standards in CRM practice?
- Regulations are legally binding; standards are typically voluntary (Correct answer)
- Regulations only apply to individuals
- They are the same
- Standards are always stricter
Correct answer: Regulations are legally binding; standards are typically voluntary
Regulations are legally enforceable government rules; standards are industry-developed guidelines that may become requirements through adoption.
Question 94: Why is multi-factor authentication important?
- It eliminates passwords completely.
- It increases login errors.
- It enhances account protection with multiple verification methods. (Correct answer)
- It slows down users.
Correct answer: It enhances account protection with multiple verification methods.
Multi-factor authentication (MFA) significantly enhances security by requiring users to provide two or more verification factors to gain access to an account or system. These factors typically include something the user knows (like a password), something the user has (like a phone or token), and something the user is (like a fingerprint). This layered approach makes it much harder for unauthorized individuals to compromise accounts, even if they steal a password.
Question 95: What is the critical path in CRM project scheduling?
- Tasks that can be skipped
- The shortest route to complete cheaply
- The most expensive phase
- The longest sequence of dependent tasks determining minimum duration (Correct answer)
Correct answer: The longest sequence of dependent tasks determining minimum duration
The critical path identifies the longest chain of dependent tasks; delays on these directly delay project completion.
Question 96: What is the purpose of a data breach response plan?
- To increase data collection.
- To address and mitigate data breach incidents. (Correct answer)
- To delay breach reporting.
- To notify competitors.
Correct answer: To address and mitigate data breach incidents.
A data breach response plan is a critical component of an organization's information security strategy. Its purpose is to provide a structured, pre-defined set of actions to be taken immediately following a data breach incident. This plan helps an organization quickly contain the breach, assess its impact, notify affected parties, and implement remediation steps to minimize damage and restore security.
Question 97: What is the difference between a 'hot site' and a 'cold site' in disaster recovery?
- A hot site is in a warm climate; a cold site is in a cold climate
- A hot site is fully equipped and immediately operational; a cold site provides only basic infrastructure requiring significant setup time (Correct answer)
- A hot site is on-site backup; a cold site is an off-site backup
- A hot site stores physical records; a cold site stores only digital records
Correct answer: A hot site is fully equipped and immediately operational; a cold site provides only basic infrastructure requiring significant setup time
A hot site is fully configured and ready for immediate use, while a cold site provides only physical space and basic utilities requiring significant setup before operations can resume.
Question 98: What is stakeholder mapping in CRM practice?
- Identifying parties with project interest and assessing their influence (Correct answer)
- Creating geographical maps
- Tracking competitor locations
- Mapping demographics
Correct answer: Identifying parties with project interest and assessing their influence
Stakeholder mapping identifies everyone affected by a project, categorizing them by influence and expectations for targeted engagement.
Question 99: What is transformational leadership in CRM practice?
- Inspiring followers to exceed expectations through vision and empowerment (Correct answer)
- Maintaining existing processes only
- Relying on punishment
- Avoiding all decisions
Correct answer: Inspiring followers to exceed expectations through vision and empowerment
Transformational leadership inspires team members to transcend self-interest for collective goals through vision and empowerment.
Question 100: Which type of attack involves an attacker intercepting communication between two parties to steal or alter records in transit?
- Denial-of-service attack
- Man-in-the-middle (MITM) attack (Correct answer)
- Phishing attack
- SQL injection
Correct answer: Man-in-the-middle (MITM) attack
A MITM attack positions the attacker between sender and receiver, enabling interception or manipulation of data in transit.
Certified Records Manager (CRM) Exam
The CRM certification validates expertise in managing records and information, from creation to disposition.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds