PK0-005 Project Management Concepts Practice Question
A project manager is closing out a customer portal project when a key vendor reports that a delivered component fails security acceptance criteria. The component is already installed in the production environment, and the customer has begun using it. The project manager must decide how to handle the situation before final sign-off. Which TWO actions are MOST appropriate? (Choose two.)
⚠ Common exam trap
The trap here is treating a late-discovered defect as a documentation-only matter, when it actually requires formal issue tracking, change control, and authorized replanning before closure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Reopen the project, replan the remaining work, and obtain approval from the change control board or sponsor for the revised baseline
A failed acceptance criterion found during closure must be captured, analyzed, and dispositioned through formal channels. Logging the issue and routing it through change control creates the record and impact analysis, while reopening and replanning with change control board or sponsor approval authorizes any remediation against a revised baseline. Together these actions keep the project's status truthful and ensure the customer accepts verified results rather than an unresolved security failure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the component as-is and note the security exception only in the lessons learned register
Why it's wrong here
Recording an exception solely in the lessons learned register does not constitute a formal acceptance of risk or a decision by the authorized approver. Acceptance criteria were not met, so the component cannot simply be deemed complete without documented risk acceptance from the customer or sponsor. Lessons learned capture process improvements for future projects; they are not a substitute for change control and formal sign-off on a known defect.
- ✓
Reopen the project, replan the remaining work, and obtain approval from the change control board or sponsor for the revised baseline
Why this is correct
Because the component is already in production and the defect blocks acceptance, the work required to remediate it must be authorized rather than performed informally. Reopening the project, replanning the affected work, and securing change control board or sponsor approval for the revised baseline restores legitimate control over scope, schedule, and cost. This keeps the project's records accurate and ensures the customer's acceptance decision is based on verified results.
- ✓
Document the defect in the issue log, assess the impact on scope and schedule, and route it through the change control process
Why this is correct
A failed acceptance criterion discovered during closure is a defect that must be captured and evaluated, not hidden. Logging it as an issue, analyzing its effect on scope, schedule, and cost, and submitting it to change control gives the governance body the information needed to approve remediation, adjust the baseline, or formally accept the risk. This preserves the audit trail and prevents uncontrolled rework after sign-off.
- ✗
Sign off on the project and open a separate follow-up project to fix the component later
Why it's wrong here
Signing off while a known security acceptance failure remains unresolved transfers an unquantified risk to operations and misrepresents completion. The defect affects a component already in production, so closing the project first would bypass the change control and acceptance processes that exist to prevent this. A follow-up project might eventually address it, but only after the current project has formally documented and dispositioned the failure.
- ✗
Instruct the vendor to fix the component without notifying the customer until remediation is complete
Why it's wrong here
Directing the vendor to remediate silently withholds material information from the customer, who is already using the affected component and must make informed acceptance decisions. It also bypasses change control, so the added effort has no approved baseline and no documented impact on schedule or cost. Transparency with the customer and formal disposition of the defect are required, even if the vendor ultimately performs the corrective work.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 954 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.