Risk Assessment & Management Flashcards
7 cards from real Software Testing practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
Which quantitative technique uses repeated random sampling to model the probability distribution of overall project risk?
Answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of iterations with random variable inputs to produce a probability distribution of outcomes such as schedule or cost.
Failure Mode and Effects Analysis (FMEA) produces a Risk Priority Number (RPN). Which three factors are multiplied to calculate RPN?
Answer: Severity, Occurrence, Detection
RPN = Severity × Occurrence × Detection; higher RPNs indicate failure modes that most urgently require corrective action.
A software team applies risk-based testing and decides NOT to test a low-risk feature to save time. This decision must be recorded because it represents:
Answer: An accepted risk that increases residual risk
Skipping tests for low-risk features is an explicit risk acceptance decision that raises residual risk, and it must be logged in the risk register.
In Agile testing, product backlog items are often risk-ordered. What criterion makes an item 'high risk' in this context?
Answer: Items with unclear requirements and high customer value
Unclear requirements combined with high business value create both high probability of defects and high impact if those defects reach users.
A contingency reserve in a test project budget specifically covers:
Answer: The cost of known risks that are expected to occur
Contingency reserves are allocated for identified risks with a quantified probability, whereas management reserves cover truly unknown risks.
Which activity marks the formal closure of a risk in the risk register?
Answer: The risk's trigger date passes without incident or the risk is fully resolved
A risk is closed when it can no longer occur (trigger window has passed) or when it has been fully resolved and no longer poses a threat.
Which risk category specifically covers the danger that third-party components or APIs used by the software under test may introduce defects?
Answer: Dependency risk
Dependency risk arises from reliance on external parties (vendors, APIs, libraries) whose quality or availability is outside the team's direct control.