ASEP - Associate Systems Engineering Professional Risk and Opportunity Management Questions and Answers 1 — Questions and Answers
Question 1: A systems engineering team identifies a potential risk that a key supplier for a custom component might go out of business. After identifying this risk, what is the most critical next step in the risk management process?
- Immediately select an alternate supplier to start fabricating the part.
- Analyze the probability of the supplier failing and the impact on the project's cost and schedule. (Correct answer)
- Purchase insurance to cover the potential financial loss.
- Accept the risk and add extra time to the project schedule as a buffer.
Correct answer: Analyze the probability of the supplier failing and the impact on the project's cost and schedule.
The formal risk management process follows a sequence: Identification, Analysis, Response Planning, and Monitoring. After a risk is identified, it must be analyzed to determine its probability and impact. This analysis is essential for prioritizing the risk and selecting the most appropriate response. Acting on a response (like selecting a new supplier or buying insurance) before analysis is premature.
Question 2: A project team is using a graphical tool to prioritize a list of identified risks. They plot each risk on a grid where one axis represents the likelihood of occurrence and the other axis represents the severity of the consequence. What is this tool called?
- Fishbone Diagram
- Gantt Chart
- Work Breakdown Structure
- Risk Matrix (Correct answer)
Correct answer: Risk Matrix
A Risk Matrix, also known as a Probability-Impact Matrix, is a standard tool for qualitative risk analysis. It helps teams visually prioritize risks by mapping their probability against their potential impact, allowing for focused attention on the most significant threats.
Question 3: A project faces a significant risk of schedule delays if they develop a new, complex software module from scratch. The team decides to alter the project plan to instead integrate a commercially available, proven software component that meets the requirements. Which risk response strategy is being employed?
- Avoidance (Correct answer)
- Mitigation
- Transfer
- Acceptance
Correct answer: Avoidance
Risk avoidance is a strategy that involves changing the project plan to eliminate the threat entirely. By choosing to use a commercial component instead of developing a new one, the team has removed the risks associated with the new development, thus avoiding them. Mitigation would involve reducing the risk's probability or impact, not eliminating it.
Question 4: During system integration, an engineer discovers that a new, more efficient data compression algorithm is now available which was not an option during the design phase. Implementing it could significantly improve system performance, which is a key stakeholder desire. According to the principles of opportunity management, what is the most appropriate initial action?
- Immediately begin rewriting the software to include the new algorithm.
- Dismiss the finding to avoid scope creep and potential schedule delays.
- Analyze the potential benefits, costs, and any new risks associated with implementing the algorithm. (Correct answer)
- Document the finding in a 'lessons learned' report for future projects.
Correct answer: Analyze the potential benefits, costs, and any new risks associated with implementing the algorithm.
Opportunity management follows a process similar to risk management. Once an opportunity is identified, it must be analyzed to understand its potential benefits, costs, and any associated risks before a decision is made to pursue it. This ensures that the decision is based on a sound business case rather than impulse.
Question 5: Which of the following best describes the primary objective of the Risk and Opportunity Management process within systems engineering?
- To create a comprehensive list of all things that could possibly go wrong and assign blame if they do.
- To proactively identify, analyze, and treat uncertainties to increase the likelihood of meeting project objectives. (Correct answer)
- To secure additional budget and schedule margin from management to cover any unforeseen problems.
- To eliminate every potential negative event before the project begins.
Correct answer: To proactively identify, analyze, and treat uncertainties to increase the likelihood of meeting project objectives.
The core purpose of risk and opportunity management is to handle uncertainty in a proactive way. It involves a continuous process of identifying potential positive and negative events, understanding their potential impact, and planning actions to minimize threats and maximize opportunities, thereby improving the chances of project success.
Question 6: For a risk to be clearly understood and analyzed by all stakeholders, it should be documented in a well-formed risk statement. Which of the following components are essential for a complete risk statement?
- The mitigation plan, the person responsible, and the due date.
- The project name, the date identified, and the risk category.
- The potential, uncertain event or condition and the resulting consequence or impact on objectives. (Correct answer)
- The budget impact, the schedule impact, and the technical impact.
Correct answer: The potential, uncertain event or condition and the resulting consequence or impact on objectives.
A complete and effective risk statement clearly articulates the potential problem. This is best done by describing the uncertain event or condition that might occur and the specific consequence or impact it would have on the project's objectives (e.g., cost, schedule, performance). A common format is 'If [condition], then [consequence].'
A systems engineering team identifies a potential risk that a key supplier for a custom component might go out of business.
After identifying this risk, what is the most critical next step in the risk management process?