Hard1 markMultiple Choice
Task 1: Plan and manage project complianceBusiness EnvironmentComplianceTask 1

PMP · Question 11 · Task 1: Plan and manage project compliance

A project manager is leading a project to update the organization's HR systems. The organization has a strict policy regarding 'Zero Trust' security architecture. The vendor selected for the project proposes a solution that relies on VPN-based trust, which conflicts with the policy. The vendor argues their solution is industry standard and cheaper.<br/><br/>What should the project manager do?

Answer options:

A.

Accept the vendor's solution to save costs and update the risk register.

B.

Change the organizational policy to match the vendor's industry-standard solution.

C.

Work with the vendor to identify a compliant solution or escalate to the governance board for a decision.

D.

Proceed with the vendor's solution but implement additional firewalls as a workaround.

How to approach this question

Conflict between Vendor and Policy. PM cannot break policy. PM cannot change policy. PM must Negotiate or Escalate.

Full Answer

C.Work with the vendor to identify a compliant solution or escalate to the governance board for a decision.✓ Correct
C
Organizational security policies are compliance requirements. The PM cannot ignore them (A) or change them (B). The correct path is to try to align the vendor to the policy or escalate to the governance body (C) that owns the policy to see if an exception is possible.

Common mistakes

Assuming the PM has authority to override security policy for cost savings (A).

Practice the full PMP Business Environment Domain Practice Exam

60 questions · hints · full answers · grading

More questions from this exam