Project Management Risk Management and Mitigation 5 — Questions and Answers
Question 1: In the context of risk management, what is a 'trigger' (also called a risk symptom or warning sign)?
- The root cause of a risk event
- An indication that a risk event is about to occur or has occurred (Correct answer)
- The monetary value assigned to a risk
- The action that causes a risk to be transferred
Correct answer: An indication that a risk event is about to occur or has occurred
A risk trigger is an early warning signal or condition that indicates a risk event is imminent or has already been activated.
Question 2: A project manager implements additional testing phases to reduce the probability that software defects reach production. Which risk response is being applied?
- Transfer
- Avoid
- Mitigate (Correct answer)
- Accept
Correct answer: Mitigate
Mitigation reduces the probability or impact of a negative risk, such as adding testing phases to lower the chance of defects reaching users.
Question 3: What is the MAIN purpose of conducting a risk audit during project execution?
- To identify new risks for the first time
- To evaluate the effectiveness of risk responses and the risk management process (Correct answer)
- To reassign risk owners to different team members
- To calculate updated EMV values for all risks
Correct answer: To evaluate the effectiveness of risk responses and the risk management process
Risk audits examine whether risk responses are effective and whether the overall risk management process is being followed as planned.
Question 4: A project manager calculates a risk's Expected Monetary Value (EMV) as -$30,000. What does this negative value indicate?
- The risk is an opportunity worth $30,000
- The risk is a threat with a negative expected impact of $30,000 (Correct answer)
- The risk should be immediately avoided
- The project is over budget by $30,000
Correct answer: The risk is a threat with a negative expected impact of $30,000
A negative EMV indicates a threat—the expected financial impact of the risk on the project is a loss of $30,000.
Question 5: Which risk management process involves determining which risks may affect the project and documenting their characteristics?
- Plan Risk Management
- Identify Risks (Correct answer)
- Perform Qualitative Risk Analysis
- Monitor Risks
Correct answer: Identify Risks
The Identify Risks process focuses on finding, recognizing, and documenting all possible risks that could affect project objectives.
Question 6: A high-priority risk on a software project has been mitigated, but a small residual risk remains. What should the project manager do?
- Remove the risk from the register since the mitigation was successful
- Document the residual risk and accept or monitor it (Correct answer)
- Escalate the residual risk to senior management
- Perform a new quantitative analysis on the residual risk
Correct answer: Document the residual risk and accept or monitor it
Residual risks are risks that remain after mitigation and should be documented in the risk register with an acceptance or monitoring plan.
Question 7: A project manager is conducting a risk review and finds that a supplier's financial instability could threaten on-time delivery. She negotiates a backup supplier agreement as a precaution. This is an example of:
- Passive acceptance
- Contingency planning (Correct answer)
- Risk avoidance
- Risk enhancement
Correct answer: Contingency planning
Arranging a backup supplier is a contingency plan—a predefined response that will be activated if the primary risk event (supplier failure) occurs.
In the context of risk management, what is a 'trigger' (also called a risk symptom or warning sign)?