正解:A
This violates the need-to-know principle because employees in the sales department should only have access to information required to perform their job responsibilities. Granting broad access to project files-especially files containing employee personal information-is an access control failure: permissions are too open and not aligned to role-based necessity. CompTIA Project+ emphasizes compliance and information security considerations that affect projects, including the expectation that sensitive information is protected through appropriate controls and access restrictions.
"Intellectual property" (B) concerns ownership and protection of creations (designs, trademarks, code, patents), not role-based access to personal data. "Multifactor authentication" (C) is an authentication mechanism that strengthens login security, but the scenario is about authorization/permissions (who is allowed to access what) rather than proving identity. "Facility access" (D) relates to physical security of locations, not digital file permissions.
In practice, the PM would coordinate with security/IT to correct access groups, implement least-privilege and role-based access control, and ensure sensitive data (like employee PII) is stored and shared with stricter controls-consistent with Project+ governance expectations around handling sensitive information appropriately.