Courseiva
mediumMultiple Choice

PK0-005 Practice Question: The project manager for a cloud migration project…

You are the project manager for a cloud migration project at a mid-sized company. The project team consists of internal IT staff and a third-party vendor responsible for data transfer. During a weekly status meeting, you discover that the vendor has been using an unauthorized tool to accelerate data transfer, which violates the security policy outlined in the project charter. The vendor claims the tool is necessary to meet the aggressive timeline. The project sponsor is concerned about security but also about schedule delays. You need to take the most appropriate action to address this issue while maintaining project control. Which action should you take?

⚠ Common exam trap

Test-takers frequently choose Option C, thinking daily reports mitigate the risk, but they overlook that the unauthorized tool itself violates the security policy and requires formal authorization before continued use.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the issue in the issue log, then submit a change request to evaluate the tool's security and potentially update the security policy.

It follows the proper project management workflow: documenting the unauthorized tool in the issue log and submitting a change request to formally evaluate the tool's security compliance. This allows the project to assess the risk without bypassing governance, maintaining control over security policy while addressing schedule concerns. The change request process ensures that any policy update is reviewed and approved by the appropriate stakeholders, preserving the integrity of the project charter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the issue in the issue log, then submit a change request to evaluate the tool's security and potentially update the security policy.

    Why this is correct

    Logging the violation in the issue log preserves the audit trail, and the change request routes the security-policy question through formal change control, letting the sponsor weigh risk against schedule without the vendor's unauthorised tool silently bypassing governance.

  • ✗

    Update the project charter to allow the use of the tool since it helps meet the timeline.

    Why it's wrong here

    Amending the charter to legitimise a policy-violating tool bypasses change control and the security baseline, so the violation persists. It is tempting because charter updates are a genuine mechanism when scope or constraints change, but only through formal approval, not to excuse a breach.

  • ✗

    Instruct the vendor to continue using the tool but require daily reports on security incidents.

    Why it's wrong here

    Permitting continued use with daily reports leaves the security violation in place and transfers risk acceptance to the project manager. It is tempting because monitoring is a valid control for known risks, but it cannot authorise a tool the charter explicitly prohibits.

  • ✗

    Escalate the issue to the vendor's management and request a replacement team.

    Why it's wrong here

    Escalating to the vendor's management and demanding a replacement team is disproportionate and abandons corrective action within the existing contract. It is tempting because escalation is legitimate for persistent non-compliance, but here it skips documenting the breach and directing the vendor to stop.

About these practice questions

This PK0-005 question is part of Courseiva's 954-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.