Courseiva
Question 42 of 980
mediumMultiple ChoiceObjective-mapped

PK0-005 Practice Question: A project manager is leading a software…

A project manager is leading a software development project that has a fixed budget and strict deadline. During the execution phase, the development team identifies a critical security vulnerability that requires immediate remediation, which will add two weeks to the schedule and increase costs by 10%. What is the BEST course of action for the project manager?

⚠ Common exam trap

A common mix-up: candidates choose Option D, thinking immediate action is always best, but CompTIA emphasizes the formal change management process where any deviation from the baseline requires prior approval, even for urgent security fixes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Escalate the issue to the project sponsor with a trade-off analysis of cost, schedule, and scope impacts.

The project manager must balance the triple constraint (cost, schedule, scope) when an unplanned security vulnerability emerges. Escalating to the sponsor with a trade-off analysis allows informed decision-making, as the fixed budget and strict deadline mean any change requires stakeholder approval. This aligns with PMI's best practices for managing change requests in a constrained environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Escalate the issue to the project sponsor with a trade-off analysis of cost, schedule, and scope impacts.

    Why this is correct

    Escalation with trade-off analysis allows the sponsor to make an informed decision on how to proceed.

  • Reduce the scope by removing one feature to compensate for the additional work.

    Why it's wrong here

    Removing a feature may not directly address the vulnerability and could impact project objectives.

  • Proceed with the original plan and document the vulnerability as a known risk.

    Why it's wrong here

    Ignoring a critical vulnerability is not acceptable and could lead to major issues.

  • Instruct the team to fix the vulnerability immediately and then inform the sponsor of the changes.

    Why it's wrong here

    Proceeding without approval exceeds the project manager's authority and may violate the project baseline.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Last reviewed: Jun 11, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.