PMP · Question #420
A company has decided to implement a new archiving system. A data breach occurred during the implementation of the project. What should the project manager do first?
The correct answer is A. Implement the planned risk response to handle the issue. You could ask the team to fix it first, however that might not be the FIRST thing you have to do. You may have to notify supervisors/security, notify customers, work with authorities of some kind, there's plenty of things that will likely be in the risk response before asking the
Question
A company has decided to implement a new archiving system. A data breach occurred during the implementation of the project. What should the project manager do first?
Options
- AImplement the planned risk response to handle the issue
- BReview possible alternative documentation methods with team
- CUpdate the risk register with the risk and proposed impact
- DAsk the team to fix the system to resolve the issue
How the community answered
(53 responses)- A75% (40)
- B4% (2)
- C8% (4)
- D13% (7)
Explanation
You could ask the team to fix it first, however that might not be the FIRST thing you have to do. You may have to notify supervisors/security, notify customers, work with authorities of some kind, there's plenty of things that will likely be in the risk response before asking the team to fix it.
Topics
Community Discussion
5A is correct because a data breach is a risk that materialized, and if your risk register and response plan were done right, you already have a documented action to execute first. C and D come after you trigger the planned response, not before.
Our group landed on C because a data breach is a risk that has now materialized, so the PM needs to capture it in the risk register with the actual impact before taking any further action. A few folks pushed back saying A is the move since you should execute the planned response, but our consensus was that you document first so there is a clear record, then respond.
A is correct because once a risk has materialized it becomes an issue, and you execute the planned response rather than treating it as a fresh risk to document. The risk register already captured this scenario during planning, so now you act on it.
D is the right call here because a data breach is a live security incident, not just a theoretical risk anymore. The word first in the stem means you contain the damage immediately, so asking the team to fix the system is the only option that actually stops the bleeding.
A is correct because the first step in responding to a confirmed data breach is activating the incident response plan, not jumping straight to remediation. You contain and investigate through the established process before anyone starts fixing systems, otherwise you risk destroying evidence and missing the full scope of the compromise.