The organization plans for implementing an information security management system (ISMS).
By doing so, what is the main objective?
Answer : C
An Information Security Management System (ISMS) is designed to protect information assets through structured controls, policies, and risk management practices.
EPI aligns with globally accepted security frameworks (e.g., ISO/IEC 27001), where the foundation of an ISMS is the CIA triad:
C --- Confidentiality
Ensures information is accessible only to authorized persons.
I --- Integrity
Ensures information is accurate, complete, protected from unauthorized modification.
A --- Availability
Ensures information and systems are accessible when required.
Implementing an ISMS aims to safeguard these three fundamental information security objectives.
Why the other options are incorrect:
A --- This focuses only on records retention, not information security as a whole.
B --- Omits integrity and availability, which are essential ISMS elements.
D --- Too narrow; ISMS covers all information assets, not just customer records.
Thus, the correct answer is C, which fully represents the CIA triad.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
ISMS is responsible for protecting confidentiality, integrity, and availability of all information assets.
The CIA triad forms the basis of information security objectives.
Management wants to receive a monthly report on data center cost breakdown per business unit without transferring the actual cost to the users.
Which model should you apply?
Answer : B
EPI's financial management guidance distinguishes between several internal cost transparency models. Chargeback occurs when costs are formally billed to internal departments or customers. However, in this scenario, management wants visibility of cost distribution without making business units financially responsible. This aligns directly with the Show Back model.
Show Back is a non-billing mechanism that reports how much each business unit would hypothetically be charged if costs were allocated proportionally. It improves cost awareness, encourages responsible consumption, and helps management understand operational cost drivers without generating friction associated with real billing. Show Back is commonly used in organizations where financial culture, policy constraints, or strategic choices prevent the use of formal chargeback.
Options A (Chargeback) does not meet the requirement because it transfers costs. Options C and D are not recognized cost transparency models within EPI or general IT financial management practices.
Therefore, the most suitable model for cost transparency without financial transfer is B -- Show Back.
Key Performance Objectives (KPOs) need to be defined.
What is a suitable time period for KPOs?
Answer : D
KPOs are strategic and operational performance objectives that must support:
Daily operations
Weekly operational control
Monthly service reporting
Quarterly reviews
Annual strategic planning
EPI emphasizes that performance objectives must be measurable across multiple timeframes, depending on the operational layer:
Weekly short-term operational checks
Monthly service-level analysis and trend review
Yearly strategic improvement and long-term performance planning
Therefore, weekly, monthly, and yearly intervals are all suitable for KPOs.
Thus, D is correct.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
Performance measurement occurs across multiple time horizons.
KPOs must be aligned to operational, tactical, and strategic levels.
The needs analysis is completed, and services have been defined.
What makes a good service definition?
Answer : B
In the context of defining services (after needs analysis) in the EPI framework, a good service definition should be SMART --- Specific, Measurable, Achievable, Relevant, Time-bound. This ensures that the service can be consistently delivered, measured, controlled, and improved.
Specific: clearly defined service features and scope
Measurable: metrics and KPIs are defined
Achievable: realistic given resources and capabilities
Relevant: aligns with business/customer needs
Time-bound: has defined timelines for delivery and review
While following PDCA (Plan-Do-Check-Act) (option A) is good practice for continuous improvement, it is not what characterises a service definition. Meeting ROI (option C) is business-case oriented, not a service definition criterion. Having an underlying SLA (option D) is related but not the core characteristic of a well-defined service itself.
Thus, the correct answer is B.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
Service definitions should be clear, measurable, and aligned with business/customer needs.
A SMART definition supports service design, delivery, monitoring, and improvement.
During lock-out/tag-out, which of the below is the most recommended procedure?
Answer : D
In the EPI Facilities Operations Manager body of knowledge, the Lock-Out/Tag-Out (LOTO) procedure is a mandatory safety control to ensure that electrical or mechanical equipment cannot be energized while work is being performed. A core principle emphasized in EPI safety training is:
''The person who applies the lock must be the same person who removes it.''
This aligns with international best practices for occupational health and safety, where LOTO ensures that the individual performing maintenance or repair has full control of the energy isolation device.
Why this is required:
Personal Safety Responsibility
The lock identifies the technician directly working on the equipment. Only they can confirm whether work is complete and the area is safe for re-energizing.
Risk Prevention
If someone else removes the lock (another operator, safety manager, or facilities manager), they may incorrectly assume that the equipment is ready to be restored, which can lead to severe injury or fatality.
Compliance With EPI Safety Guidelines
EPI emphasizes the principle of ''single-person control'' over hazardous energy. No supervisor or colleague may remove another technician's lock unless a formal, documented emergency override procedure is followed --- which is not considered standard practice.
Clear Accountability Chain
LOTO prevents ambiguity or miscommunication. The technician who placed the lock is the only one with full knowledge of the work status and hazards involved.
Why other options are incorrect:
A, B, and C violate the fundamental LOTO rule because they involve someone other than the applying operator removing the lock.
Oversight personnel (safety manager, facilities manager) monitor and audit the process, but they should not remove another person's lock except under rare, emergency, escalation-approved situations.
EPI DCFOM-Aligned Reference Concepts (Paraphrased, Not Verbatim)
LOTO must ensure the isolation device is locked and tagged by the person performing the work.
Only the same individual may remove their own lock.
Removal by another party is only permitted under controlled, documented emergency protocols.
The process prevents accidental energization and protects worker safety.
Training programs need to be selected.
Of the below, which is the first activity to start with?
Answer : C
Training must be aligned with actual operational needs and competency gaps.
The skills matrix is the tool that provides:
Current skill levels of staff
Required skill levels per role
Identified gaps
Training needs based on operational requirements
Therefore, the first step is to review the skills matrix to determine what training is actually needed.
Why other options are incorrect:
A: Service catalog inventory is part of SLM, not training selection.
B: Contacting vendors is premature without knowing training needs.
D: Price comparison should occur later, after training needs are defined.
Thus, C is correct.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
Skills matrix is the foundation for determining training needs.
Training selection must be based on capability gaps, not brochures or pricing.
A recent cooling equipment failure resulted in a sudden shutdown of IT systems. Although the service provider was quickly on-site, it eventually took more than 12 hours for the cooling equipment to be repaired. Management wants to prevent this from happening again.
What is the best response?
Answer : C
EPI defines several maintenance contract models, each offering different levels of service and support. In the scenario described, long repair time caused unacceptable downtime. To reduce risk, the organization needs a contract that provides:
Faster response
Faster repair time
Better availability of spare parts
Preventive and corrective coverage
Minimum downtime guarantees
A comprehensive maintenance contract provides:
Full service coverage
Labor + parts
Priority response levels
Faster restoration times
Predictable maintenance costs
Better uptime assurance
Increased provider accountability
Why the other options are incorrect:
A (Time & Material): Slowest and most unpredictable; not suitable for critical cooling systems.
B (Basic contract): Limited coverage; still leaves long repair times.
D (Exclusive contract): Typically refers to dedicated on-site or embedded teams, but not the standard EPI contract step-up for improved uptime.
Thus, C -- Comprehensive contract is the best option.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
Comprehensive contracts provide enhanced support, faster repairs, and full coverage.
Suitable for critical infrastructure like cooling systems.