Courseiva
Process — Managing Technical AspectshardMultiple ChoiceObjective-mapped

PMP Process — Managing Technical Aspects Practice Question

You are managing a project using a hybrid approach. During a sprint, the development team discovers a critical security vulnerability that was not identified during risk planning. The fix will require significant rework and will cause the sprint goal to be missed. What should the project manager do FIRST?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform an impact analysis and submit a change request to address the vulnerability

The project manager should first assess the impact of the security vulnerability on scope, schedule, and cost, then submit a change request to formally address the issue. Option B is incorrect because bypassing change control violates project governance, especially in a hybrid approach where change management processes are defined. Option C is incorrect because requiring overtime to achieve the sprint goal ignores the rework impact and could lead to burnout and quality issues. Option D is incorrect because delaying the fix leaves the vulnerability unaddressed, which is unacceptable for a critical security issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Perform an impact analysis and submit a change request to address the vulnerability

    Why this is correct

    Performing an impact analysis is the critical first step to understand the full ramifications of the security vulnerability across scope, schedule, cost, and quality. Subsequently, submitting a formal change request ensures that the proposed solution is properly reviewed, approved by the Change Control Board (CCB) or relevant stakeholders, and formally integrated into the project baselines. This structured approach maintains project governance and transparency, even within a hybrid framework, ensuring all implications are considered before implementation.

  • Instruct the team to fix the vulnerability immediately without formal change control

    Why it's wrong here

    Instructing the team to fix the vulnerability immediately without formal change control is a significant deviation from proper project governance. This approach bypasses necessary stakeholder review and approval, potentially leading to unmanaged scope creep, resource conflicts, and undocumented changes that can destabilize the project baseline. Even for urgent issues, a streamlined change process is essential to maintain control and ensure proper integration and communication.

  • Ask the team to work overtime to fix the vulnerability while still achieving the sprint goal

    Why it's wrong here

    Asking the team to work unplanned overtime to address the vulnerability while simultaneously achieving the original sprint goal is an unsustainable and potentially harmful approach. This action ignores realistic capacity planning, risks team burnout, and compromises the quality of both the fix and other sprint deliverables due to rushed work. It also fails to formally acknowledge the new work as a change, which impacts the sprint backlog and overall project plan.

  • Allow the team to continue with the sprint and address the vulnerability in a future sprint

    Why it's wrong here

    Allowing the team to continue with the current sprint and defer a critical security vulnerability to a future sprint is an unacceptable risk management strategy. Delaying a known critical vulnerability significantly increases the project's exposure to potential data breaches, system failures, reputational damage, and regulatory non-compliance. A PMP must prioritize addressing such high-impact risks immediately, even if it means adjusting current sprint objectives.

About these practice questions

One of 800 original PMP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.