Courseiva
Process — Managing Technical AspectsmediumMultiple SelectObjective-mapped

PMP Process — Managing Technical Aspects Practice Question

You are managing a software upgrade project using a hybrid approach. During execution, the team discovers a critical security vulnerability that was not identified during risk planning. The vulnerability requires immediate patching to avoid a potential data breach. Which TWO actions should you take NEXT?

⚠ Common exam trap

Candidates often confuse the urgency of a security vulnerability with the need to bypass formal processes, but the PMP exam emphasizes that even critical issues must follow the change control process to ensure proper documentation and stakeholder communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Assess the impact of the vulnerability on the project scope, schedule, and cost

Upon discovering an unplanned critical security vulnerability, the immediate next step is to assess its impact on the project's scope, schedule, and cost. This assessment provides the necessary data to determine the appropriate response and informs the subsequent change request. Without this impact analysis, any action taken could be misaligned with project constraints and stakeholder expectations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Assess the impact of the vulnerability on the project scope, schedule, and cost

    Why this is correct

    Before any action, a thorough impact analysis is crucial. This involves evaluating how the vulnerability affects the project's defined deliverables (scope), the timeline for completion (schedule), and the allocated budget (cost). This assessment provides the data needed to make informed decisions about the appropriate response, ensuring that any proposed solution is proportionate to the threat and its potential consequences. It is a foundational step in integrated change control.

  • Submit a change request to address the vulnerability through the appropriate change control process

    Why this is correct

    Once the impact is understood, addressing a significant vulnerability typically requires a formal change request. This ensures that any proposed solution, whether it is a scope modification, schedule adjustment, or budget reallocation, is documented, reviewed by the Change Control Board (CCB), and formally approved. Adhering to the change control process maintains project governance, transparency, and traceability for all project modifications, especially in a hybrid environment.

  • Immediately assign the team to fix the vulnerability without formal approval

    Why it's wrong here

    Assigning the team to fix a vulnerability without formal approval, even if urgent, bypasses established project governance and the integrated change control process. This action can lead to unauthorized scope creep, unbudgeted expenses, and unapproved schedule deviations, potentially disrupting other project activities and stakeholder expectations. While speed is sometimes critical, proper documentation and approval are essential for maintaining control and accountability.

  • Add the vulnerability to the risk register and continue with the current sprint as planned

    Why it's wrong here

    Simply adding a newly discovered vulnerability to the risk register and continuing as planned is an inadequate response, especially if the vulnerability poses an immediate or significant threat to the project or its deliverables. While risk identification is important, this approach fails to address the identified issue proactively or reactively. It neglects the need for a proper impact assessment and a planned response, potentially leading to greater problems down the line.

  • Implement a temporary workaround to reduce the risk and monitor the situation

    Why it's wrong here

    Implementing a temporary workaround might mitigate immediate risk, but it is typically an unplanned response to an emergent issue, not a substitute for a formal resolution. While useful in a crisis, relying solely on a workaround without pursuing a permanent fix through the change control process leaves the underlying problem unresolved and can introduce technical debt or new risks. A permanent solution, once identified, must be formally managed.

About these practice questions

One of 800 original PMP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.