mediumMultiple Choice
PK0-005 Practice Question: A project manager is leading a software…
A project manager is leading a software development project that has a fixed budget and strict deadline. During the execution phase, the development team identifies a critical security vulnerability that requires immediate remediation, which will add two weeks to the schedule and increase costs by 10%. What is the BEST course of action for the project manager?
⚠ Common exam trap
A common mix-up: candidates choose Option D, thinking immediate action is always best, but CompTIA emphasizes the formal change management process where any deviation from the baseline requires prior approval, even for urgent security fixes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the issue to the project sponsor with a trade-off analysis of cost, schedule, and scope impacts.
The project manager must balance the triple constraint (cost, schedule, scope) when an unplanned security vulnerability emerges. Escalating to the sponsor with a trade-off analysis allows informed decision-making, as the fixed budget and strict deadline mean any change requires stakeholder approval. This aligns with PMI's best practices for managing change requests in a constrained environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Escalate the issue to the project sponsor with a trade-off analysis of cost, schedule, and scope impacts.
Why this is correct
The security fix breaches the fixed budget and strict deadline, so the project manager lacks authority to absorb a ten per cent cost increase and two-week slip. Escalating to the sponsor with a trade-off analysis lets the accountable owner decide on scope, schedule or funding.
- ✗
Reduce the scope by removing one feature to compensate for the additional work.
Why it's wrong here
Removing a feature to absorb the remediation effort alters agreed scope without sponsor authorisation, and the dropped feature may itself be contractually required. It is tempting because scope reduction is a recognised way to recover schedule, but on a fixed-budget project the sponsor must approve any baseline change first.
- ✗
Proceed with the original plan and document the vulnerability as a known risk.
Why it's wrong here
Documenting a critical vulnerability as a known risk leaves the flaw exploitable in production, which no fixed-budget trade-off justifies. It is tempting because risk registers legitimately track accepted risks, but acceptance suits low-impact issues; here the project manager must escalate the cost and schedule impact to the sponsor for a decision.
- ✗
Instruct the team to fix the vulnerability immediately and then inform the sponsor of the changes.
Why it's wrong here
Committing the extra two weeks and 10% cost before notifying the sponsor breaches change control on a fixed-budget project, since only the sponsor can authorise baseline changes. It is tempting because remediation urgency feels overriding, yet the project manager must first raise a change request and obtain approval before instructing the team.
Go deeper
Related to this question
About these practice questions
One of 954 original PK0-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.