CDFOM Exam - Free Sample Questions & Answers
Preparing for the CDFOM exam is simple with Certs Blitz. We offer easy-to-understand study materials that help you learn the most important exam topics. You can study using our PDF questions, practice online with a real exam-style test, or use the desktop practice software. Choose the study method that works best for you and prepare at your own pace.
At Certs Blitz, we keep our CDFOM practice questions up to date. Whenever the exam syllabus or objectives change, we update our study materials so you always learn the latest topics. This helps you save time, avoid outdated content, and feel more confident when you take your exam.
Heavy equipment needs to be moved to another side of the computer room so that the three (3) workers can continue their drilling and cutting off the wall for a new cable tray. Four (4) staff members are required to move the equipmentso there is one extra staff member required to assist. The safety manager who is overseeing the works is asked to help moving the equipment. Is the safety manager allowed to step in and assist with the move?
Correct Answer: A
In EPI’s safety and statutory requirements framework, the Safety Manager’s role is strictly
supervisory during ongoing work activities. They are responsible for monitoring, verifying
compliance, ensuring safe practices, and intervening only to correct unsafe conditions—not to
physically participate in the hazardous task.
Key safety principles include:
Independence of the Safety Function
The Safety Manager must remain impartial and fully observant.
If they participate directly in labor activities (such as lifting equipment), they can no longer maintain
oversight of:
ongoing safety compliance
worker actions
environmental hazards
risk escalation
Conflict of Responsibilities
By physically engaging in the task, the Safety Manager becomes distracted and loses supervisory
visibility, which introduces risk to the entire operation.
Competency and Authorization Requirements
Personnel assigned to physically move heavy equipment must:
be authorized workers
be trained in manual handling
have been briefed for the specific PTW-controlled activity
The Safety Manager is not part of the operational lifting team unless specifically assigned
beforehand, which is not the case here.
EPI’s Supervisory Separation Principle
The safety oversight role must remain dedicated and unbroken during all hazardous or controlled
work activities.
Therefore, the Safety Manager must notstep in to replace orsupplement labor resources.
Correct answer: A — No.
EPI DCFOM-Aligned Reference Concepts(Paraphrased, Not Verbatim)
Safety oversight must remain independent and uninterrupted.
Safety Manager responsibilities do not include participating in physical hazardous activities.
Supervisory personnel cannot assume operational roles during high-risk work.
When is the right moment to label assets?
Correct Answer: B
EPI guidelines on asset management state that assets should be tagged and entered into the asset management database as early as possible, specifically:
At the moment of unpacking.
Reasons:
Prevents loss or misplacement
Ensures traceability during staging, testing, and installation
Supports lifecycle tracking from the earliest stage
Ensures accurate configuration and inventory management
Why other options are incorrect:
A: Contract activation is unrelated to labeling.
C: Testing occurs after unpacking; labeling must precede it.
D: Commissioning is too late; the asset must already be tracked.
Thus, B is correct.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
Asset labeling begins as soon as equipment is unpacked.
Early tagging ensures full lifecycle traceability and compliance.
During lock-out/tag-out, which of the below is the most recommended procedure?
Correct Answer: D
In the EPI Facilities Operations Manager body of knowledge, the Lock-Out/Tag-Out (LOTO) procedure is a mandatory safety control to ensure that electrical or mechanical equipment cannot be energized while work is being performed. A core principle emphasized in EPI safety training is: “The person who applies the lock must be the same person who removes it.” This aligns with international best practices for occupational health and safety, where LOTO ensures that the individual performing maintenance or repair has full control of the energy isolation device. Why this is required: Personal Safety Responsibility The lock identifies the technician directly working on the equipment. Only they can confirm whether work is complete and the area is safe for re-energizing. Risk Prevention Ifsomeone else removes the lock (another operator, safety manager, or facilities manager), they may incorrectly assume that the equipment is ready to be restored, which can lead to severe injury or fatality. Compliance With EPI Safety Guidelines EPI emphasizes the principle of “single-person control” over hazardous energy. No supervisor or colleague may remove another technician’s lock unless a formal, documented emergency override procedure is followed — which is not considered standard practice. Clear Accountability Chain LOTO prevents ambiguity or miscommunication. The technician who placed the lock is the only one with full knowledge of the work status and hazards involved. Why other options are incorrect: A, B, and C violate the fundamental LOTO rule because they involve someone other than the applying operator removing the lock. Oversight personnel (safety manager, facilities manager) monitor and audit the process, but they should not remove another person’s lock except under rare, emergency, escalation-approved situations. EPI DCFOM-Aligned Reference Concepts(Paraphrased, Not Verbatim) LOTO must ensure the isolation device is locked and tagged by the person performing the work. Only the same individual may remove their own lock. Removal by another party is only permitted under controlled, documented emergency protocols. The process prevents accidental energization and protects worker safety
The data center service provider has decided that maintenance of the data center facilities infrastructure will be outsourced.
Is it still involved in the risk management process of data center maintenance?
Correct Answer: A
EPI's governance and risk management principles clearly state:
When a data center outsources maintenance, operational work can be outsourced, but risk cannot be transferred.
Risk may be shared, mitigated, or reduced through contractual arrangements, but ownership remains with the data center service provider.
The data center operator is still responsible for ensuring compliance, operational continuity, and safety---even if another party performs the maintenance tasks.
Therefore:
The service provider must remain involved in risk evaluation, risk treatment, and ongoing monitoring.
Oversight responsibilities cannot be delegated.
Options C and D are incorrect because outsourcing the activity does not outsource risk accountability.
Option B is irrelevant because risk responsibility does not depend on provider expertise.
Thus, A is correct.
EPI DCFOM-Aligned Reference Concepts (Paraphrased)
Risk ownership remains with the organization even when maintenance is outsourced.
Outsourcing shares risk but does not transfer it.
The data center must maintain involvement in the risk management process.
When creating a compliance document register, which categories should at least be included?
Correct Answer: A
A compliance document register ensures that the organization maintains oversight and traceability of all documents required to meet regulatory, legal, and service-related obligations. The register is essential for audits, governance, risk management, and operational continuity. According to EPI's GRC framework, the minimum categories that must be included are legal and service compliance documents.
Legal documents include regulatory requirements, statutory obligations, contracts, permits, safety regulations, environmental compliance mandates, and jurisdictional requirements. Service documents include SLAs, OLAs, underpinning contracts, service catalogs, and operational procedures required to fulfill service commitments. These categories represent the core compliance landscape affecting the organization's ability to operate legally and deliver services contractually.
Options B, C, and D list other organizational elements that may appear in broader documentation sets but are not fundamental compliance categories. Marketing, budgeting, staffing policies, and business culture documents do not constitute mandatory compliance obligations and are not required for inclusion in a compliance register.
Thus, the correct answer is A -- Legal and service.