mediumMultiple ChoiceObjective-mapped
PK0-005 Practice Question: The project manager for a cloud migration project…
You are the project manager for a cloud migration project at a mid-sized company. The project team consists of internal IT staff and a third-party vendor responsible for data transfer. During a weekly status meeting, you discover that the vendor has been using an unauthorized tool to accelerate data transfer, which violates the security policy outlined in the project charter. The vendor claims the tool is necessary to meet the aggressive timeline. The project sponsor is concerned about security but also about schedule delays. You need to take the most appropriate action to address this issue while maintaining project control. Which action should you take?
⚠ Common exam trap
Test-takers frequently choose Option C, thinking daily reports mitigate the risk, but they overlook that the unauthorized tool itself violates the security policy and requires formal authorization before continued use.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the issue in the issue log, then submit a change request to evaluate the tool's security and potentially update the security policy.
It follows the proper project management workflow: documenting the unauthorized tool in the issue log and submitting a change request to formally evaluate the tool's security compliance. This allows the project to assess the risk without bypassing governance, maintaining control over security policy while addressing schedule concerns. The change request process ensures that any policy update is reviewed and approved by the appropriate stakeholders, preserving the integrity of the project charter.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Document the issue in the issue log, then submit a change request to evaluate the tool's security and potentially update the security policy.
Why this is correct
This follows proper issue management and change control processes.
- ✗
Update the project charter to allow the use of the tool since it helps meet the timeline.
Why it's wrong here
Changing the charter without formal change control is inappropriate.
- ✗
Instruct the vendor to continue using the tool but require daily reports on security incidents.
Why it's wrong here
This tolerates a policy violation without formal approval.
- ✗
Escalate the issue to the vendor's management and request a replacement team.
Why it's wrong here
Escalation may be needed, but the immediate action should address the non-compliance through proper channels.
Go deeper
Related to this question
About these practice questions
This PK0-005 question is part of Courseiva's 980-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.