Courseiva
mediumMultiple ChoiceObjective-mapped

PK0-005 A project manager is creating a risk register Practice Question

A project manager is creating a risk register. The team identifies a risk that could cause a data breach if a server is misconfigured. The probability is low, but impact is high. Which risk response strategy is most appropriate?

⚠ Common exam trap

CompTIA often tests the distinction between 'accepting' a risk because probability is low versus 'mitigating' it when a cost-effective control exists; the trap here is that candidates overlook the high impact and assume low probability alone justifies acceptance, ignoring the project manager's duty to implement reasonable safeguards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mitigate by implementing configuration management.

Implementing configuration management directly reduces the likelihood of a server misconfiguration, which is the root cause of the potential data breach. This is a classic risk mitigation strategy that proactively addresses the risk's probability by enforcing standardized, auditable server configurations (e.g., using tools like Ansible or Puppet with CIS benchmarks).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transfer the risk by purchasing cyber insurance.

    Why it's wrong here

    Insurance covers financial loss, not prevention.

  • Accept the risk because probability is low.

    Why it's wrong here

    High impact warrants proactive mitigation.

  • Mitigate by implementing configuration management.

    Why this is correct

    Reduces likelihood of misconfiguration.

  • Avoid the risk by not using that server.

    Why it's wrong here

    Avoidance may not be feasible.

About these practice questions

One of 980 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.