Bootstrap Risk Assessment & Management 4 — Questions and Answers
Question 1: During risk monitoring, what is the primary purpose of conducting periodic risk reviews?
- To reassign risk owners to reduce workload
- To assess whether existing risks have changed and identify new ones (Correct answer)
- To close out the risk register at phase gates
- To report risk costs to stakeholders
Correct answer: To assess whether existing risks have changed and identify new ones
Periodic risk reviews evaluate changes in risk probability or impact, check trigger conditions, and surface newly emerging risks throughout the project.
Question 2: Which risk response is most appropriate when a risk's probability and impact are both too low to justify active treatment?
- Exploit
- Mitigate
- Passive acceptance (Correct answer)
- Active acceptance
Correct answer: Passive acceptance
Passive acceptance means acknowledging the risk with no proactive action — appropriate when the cost of response exceeds the potential loss.
Question 3: A risk owner's primary responsibility is to:
- Fund the contingency reserve for the risk
- Execute and monitor the assigned risk response plan (Correct answer)
- Report all risks to the project sponsor
- Update the project charter when risks materialize
Correct answer: Execute and monitor the assigned risk response plan
The risk owner is accountable for ensuring the designated risk response is carried out and for monitoring trigger conditions for their assigned risk.
Question 4: When assessing risk velocity, a project manager is evaluating:
- The speed at which a risk is expected to impact the project if it occurs (Correct answer)
- The rate of cost increase due to identified risks
- The frequency of risk review meetings
- How quickly risk owners must respond to triggers
Correct answer: The speed at which a risk is expected to impact the project if it occurs
Risk velocity (or speed of onset) describes how quickly a risk will transition from identification to impact, affecting how much warning time exists.
Question 5: The FMEA (Failure Mode and Effects Analysis) technique is used primarily to:
- Prioritize risks using a probability-impact grid
- Identify ways a product or process can fail and assess the effects (Correct answer)
- Calculate EMV for each risk scenario
- Document risk lessons learned after project closure
Correct answer: Identify ways a product or process can fail and assess the effects
FMEA systematically examines each component or process step for potential failure modes, their causes, and downstream effects on the overall system.
Question 6: Which of the following is an example of a 'positive risk' (opportunity) response strategy?
- Mitigate
- Avoid
- Exploit (Correct answer)
- Transfer
Correct answer: Exploit
Exploit is the opportunity counterpart to avoidance — it seeks to ensure the opportunity definitely occurs by removing uncertainty around capturing it.
Question 7: A watchlist in risk management typically contains risks that are:
- High priority requiring immediate action
- Too significant to document informally
- Low priority and monitored periodically for changes (Correct answer)
- Risks that have already been transferred
Correct answer: Low priority and monitored periodically for changes
The watchlist holds low-priority risks that do not currently warrant active responses but should be reviewed at regular intervals in case their status changes.
During risk monitoring, what is the primary purpose of conducting periodic risk reviews?