mediumMultiple ChoiceObjective-mapped
PK0-005 A project manager is creating a risk register Practice Question
A project manager is creating a risk register. The team identifies a risk that could cause a data breach if a server is misconfigured. The probability is low, but impact is high. Which risk response strategy is most appropriate?
⚠ Common exam trap
CompTIA often tests the distinction between 'accepting' a risk because probability is low versus 'mitigating' it when a cost-effective control exists; the trap here is that candidates overlook the high impact and assume low probability alone justifies acceptance, ignoring the project manager's duty to implement reasonable safeguards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate by implementing configuration management.
Implementing configuration management directly reduces the likelihood of a server misconfiguration, which is the root cause of the potential data breach. This is a classic risk mitigation strategy that proactively addresses the risk's probability by enforcing standardized, auditable server configurations (e.g., using tools like Ansible or Puppet with CIS benchmarks).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk by purchasing cyber insurance.
Why it's wrong here
Insurance covers financial loss, not prevention.
- ✗
Accept the risk because probability is low.
Why it's wrong here
High impact warrants proactive mitigation.
- ✓
Mitigate by implementing configuration management.
Why this is correct
Reduces likelihood of misconfiguration.
- ✗
Avoid the risk by not using that server.
Why it's wrong here
Avoidance may not be feasible.
Go deeper
Related to this question
About these practice questions
One of 980 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.