PMP Process — Managing Technical Aspects Practice Question
You are managing a software development project using a hybrid approach. During a daily standup, one developer mentions he has identified a potential security flaw in the current build that could significantly impact the release. The fix will require at least two days of additional work. What should you do FIRST?
⚠ Common exam trap
Many exam-takers confuse 'immediate action' with 'immediate fix' (Option C) or 'defer to backlog' (Option A), failing to recognize that the PM's first duty is to log and assess the issue before any action, as per the issue management process in the PMBOK Guide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log the issue in the issue log, assess the impact on scope and schedule, and then determine the next steps
In a hybrid project, when a security flaw is discovered during a daily standup, the first action must be to log the issue and assess its impact on scope and schedule before deciding on a response. Option B follows the correct risk management process: capture the issue, evaluate its severity, and then determine the appropriate fix strategy. This ensures that the fix is prioritized based on technical risk and business impact, not rushed or deferred without analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add the fix to the product backlog and address it in the next sprint planning
Why it's wrong here
Deferring a critical security flaw to the product backlog for future sprint planning is generally inappropriate for issues demanding immediate attention. Security vulnerabilities represent a significant risk that could lead to data breaches, system compromise, or reputational damage, often requiring a more urgent and structured response than simply queuing it for a later cycle. This approach fails to acknowledge the potential severity and immediate impact of such a defect.
- ✓
Log the issue in the issue log, assess the impact on scope and schedule, and then determine the next steps
Why this is correct
This is the most appropriate first step for a project manager encountering a significant issue like a security flaw. Logging the issue formally initiates the issue management process, ensuring documentation and visibility. Subsequently, assessing its impact on project scope, schedule, cost, and quality is crucial for understanding its severity and developing an informed response, aligning with integrated change control processes before any action is taken.
- ✗
Instruct the developer to fix the security flaw immediately
Why it's wrong here
Directing an immediate fix without prior assessment is a reactive approach that bypasses proper project management protocols. Such an action could lead to unmanaged scope changes, resource reallocations that disrupt other planned work, or even introduce new defects without a comprehensive understanding of the root cause or potential side effects. A structured analysis is essential to ensure the fix is effective, efficient, and integrated appropriately.
- ✗
Escalate the issue to the project sponsor for a decision
Why it's wrong here
Escalating the issue directly to the project sponsor without first performing an initial assessment and analysis is premature. Project managers are expected to manage issues within their authority and provide informed recommendations. Escalation should occur only after the project team has evaluated the issue's impact, explored potential solutions, and determined that the issue exceeds the project manager's decision-making authority or significantly impacts strategic objectives.
Go deeper
Related to this question
About these practice questions
One of 800 original PMP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.