PMI-RMP : Risk Response (Domain 4)
PMI – PMI-RMP : Certified Risk Management Professional - Domain 4 - Risk Response
The management of project uncertainty reaches its most critical phase during the Risk Response domain. While identification and analysis provide the necessary data and prioritization, the risk response phase is where that information is transformed into actionable strategies intended to safeguard project value and ensure objectives are met. In the Project Management Institute (PMI) framework, Domain 4 accounts for 13% of the Risk Management Professional (PMI-RMP) examination and is concentrated into two primary tasks: planning risk responses and implementing those responses. This guide provides an exhaustive synthesis of the strategies, calculations, and execution methodologies required to master this domain.
Strategic Framework for Threat Response
When a project team identifies a negative risk—a threat—they must select a strategy that aligns with the organization’s risk appetite and the project’s specific thresholds. These strategies are not mutually exclusive and are often selected based on a cost-benefit analysis to determine which approach provides the most efficient use of resources.
Avoidance
The strategy of avoidance involves changing the project management plan to eliminate the threat entirely. This is the most proactive stance and usually involves altering the project scope, schedule, or technical approach. For example, if a specific technology is deemed too risky due to a lack of internal expertise, the project team may choose to use a proven, older technology. Avoidance effectively reduces the probability of the risk occurring to zero.
Mitigation
Mitigation focuses on reducing the probability of occurrence or the impact of a threat. Unlike avoidance, the risk is still present, but its potential for harm is lessened. This often involves implementing additional testing, selecting more stable suppliers, or simplifying processes. Mitigation requires an investment of resources (time or money) to create a “buffer” that protects the project objectives from the full weight of the threat.
Transfer
Transfer involves shifting the responsibility for the risk to a third party. This does not eliminate the risk but ensures that another entity bears the financial or operational consequences if the risk event occurs. Common methods of transfer include purchasing insurance, using performance bonds, or utilizing specific contract types like fixed-price contracts to shift cost risk to a vendor. It is important to note that transfer often involves the payment of a risk premium to the party taking on the risk.
Acceptance
Acceptance is a passive or active strategy used when it is not possible or cost-effective to address a risk through other means.
- Passive Acceptance: The team takes no action other than periodically reviewing the risk to ensure it has not changed significantly.
- Active Acceptance: The team establishes a contingency reserve (money or time) to handle the risk if it occurs. This is the primary method for managing “known-unknowns.”
Escalation
Escalation is used when a threat is outside the scope of the project or when the proposed response exceeds the project manager’s authority. The risk is moved to a higher level in the organization—such as a program manager, portfolio manager, or senior sponsor—to be managed at the appropriate governance level. Once escalated, the project manager typically no longer tracks the risk, although it may remain in the risk register for visibility.
Strategic Framework for Opportunity Response
Modern risk management emphasizes that uncertainty is not solely negative. Opportunities—positive risks—must be managed with the same level of discipline as threats to maximize organizational value and project success.
Exploit
The exploit strategy is the positive counterpart to avoidance. It seeks to ensure that the opportunity definitely happens. This might involve assigning the organization’s most talented resources to a task to ensure it is completed ahead of schedule or using a new technology that guarantees a significant reduction in costs. The goal is to eliminate the uncertainty associated with the opportunity to ensure a 100% probability of occurrence.
Enhance
Enhancement is the positive counterpart to mitigation. It aims to increase the probability of occurrence or the positive impact of the opportunity. By identifying the key drivers of the opportunity, the team can focus their efforts on strengthening those drivers. For example, adding resources to a task might increase the likelihood of finishing early, thereby capturing a performance bonus.
Share
Sharing is the positive counterpart to transfer. It involves allocating some or all of the ownership of the opportunity to a third party that is best able to capture the benefit for the project. This often involves joint ventures, risk-sharing partnerships, or incentive-based contracts where both the organization and the vendor benefit from the successful realization of the opportunity.
Acceptance
Similar to threat acceptance, opportunity acceptance involves taking no proactive action to capture the opportunity but being willing to take advantage of it if it occurs. This is often chosen when the cost of proactive exploitation or enhancement outweighs the potential benefit.
Escalation
Opportunity escalation occurs when an opportunity is identified that benefits the organization beyond the specific boundaries of the project. If a project team discovers a way to improve a process that could benefit the entire company, but the project manager lacks the authority to implement it company-wide, the opportunity is escalated to senior leadership.
Accountability and Action Ownership
A risk response plan is ineffective if it lacks clear accountability. Task 1 of Domain 4 explicitly requires the identification of action owners for each selected response.
The Role of the Risk Owner
The risk owner is the individual responsible for monitoring the risk and for the overall effectiveness of the response strategy. They are usually someone with the authority to ensure that the necessary resources are available.
The Role of the Risk Action Owner
While the risk owner oversees the risk, the risk action owner is the person tasked with the actual execution of the response activities. In some cases, the risk owner and action owner are the same person, but in complex projects, these roles are often separated to ensure technical expertise is applied to the response while management oversight remains centralized.
Mapping Responsibility (RACI and RAM)
To ensure human accountability, risk professionals utilize tools such as the Responsibility Assignment Matrix (RAM) or a RACI (Responsible, Accountable, Consulted, Informed) chart. These frameworks ensure that every risk in the register has a designated person who is accountable for its outcome and a designated person responsible for its execution. This prevents the “diffusion of responsibility” that often occurs in high-pressure project environments.
Analyzing Response Effectiveness
Selecting a strategy is only the first step; the project team must analyze the feasibility and effectiveness of that strategy before implementation. This involves a cost-benefit analysis where the cost of the response is weighed against the potential reduction in the monetary impact of the risk.
Cost-Benefit Analysis
If the cost of a mitigation strategy is $10,000, but it only reduces the Expected Monetary Value (EMV) of a risk by $5,000, the response is not economically viable. Practitioners must ensure that the “risk premium” or response cost is proportional to the protection it provides.
Risk Burndown Charts
In both traditional and agile environments, risk burndown charts serve as a vital visual tool for communicating the effectiveness of response strategies. A burndown chart tracks the cumulative risk exposure of the project over time. As responses are implemented and risks are mitigated or closed, the “heat” or total exposure level on the chart should decrease. If the burndown line remains flat or increases, it indicates that current response strategies are ineffective or that new risks are emerging faster than they can be managed.
Calculation of Reserves
One of the most technical aspects of Domain 4 is the calculation of reserves. Reserves are the financial and temporal buffers established to manage uncertainty.
Contingency Reserves
Contingency reserves are allocated for “known-unknowns”—risks that have been identified and analyzed. The amount of the contingency reserve is typically derived from the results of the quantitative risk analysis.
- EMV-Based Calculation: By summing the Expected Monetary Value ($Probability \times Impact$) of all identified risks, a project manager can justify a specific dollar amount for the contingency reserve.
- Three-Point Estimating: Using Beta or Triangular distributions (as outlined in Domain III), teams can determine a range of possible costs and set the reserve at a confidence level (e.g., P80) that aligns with stakeholder tolerance.
Contingency reserves are part of the project cost baseline and are under the direct control of the project manager.
Management Reserves
Management reserves are set aside for “unknown-unknowns”—unforeseen risks that could not have been identified during the planning phase. Unlike contingency reserves, management reserves are not included in the cost baseline. They are part of the total project budget but usually require senior management approval to access. They represent the organization’s strategic buffer for total project failure or major environmental shifts.
| Reserve Type | Target | Baseline Inclusion | Governance/Control |
|---|---|---|---|
| Contingency | Identified Risks (Known-Unknowns) | Yes (Part of Baseline) | Project Manager |
| Management | Unidentified Risks (Unknown-Unknowns) | No (Part of Budget) | Senior Management |
Implementing Responses: Contingency and Fallback Plans
Implementation (Task 2 of Domain 4) involves executing the pre-planned actions when specific risk triggers are met.
Contingency Plans
A contingency plan is a specific set of actions that will be taken only if a predefined trigger occurs. For example, if a project schedule slips by more than five days (the trigger), the contingency plan might be to authorize overtime for the engineering team. These plans are proactive and are developed during the planning phase to ensure a rapid response.
Fallback Plans
A fallback plan, or “Plan B,” is implemented if the primary risk response or contingency plan fails to be effective. If the engineering overtime mentioned above does not recover the schedule, the fallback plan might be to reduce the project scope to meet the hard deadline. Fallback plans provide a secondary layer of protection for the project’s most critical objectives.
Workarounds
Workarounds are unplanned responses to risks that occur unexpectedly and were not previously identified or for which no contingency plan was created. Workarounds are reactive by nature and are often the result of “improvised” problem-solving when an unknown-unknown materializes.
Management of Residual and Secondary Risks
The implementation of a risk response often creates a new landscape of uncertainty. A sophisticated risk professional does not view a response as the end of the process but as the beginning of a new monitoring cycle.
Secondary Risks
A secondary risk is a risk that arises as a direct result of implementing a risk response. For instance, if the team decides to mitigate a technical risk by hiring an outside consultant (the response), a secondary risk might be that the consultant becomes unavailable or fails to integrate with the internal team. These risks must be identified and analyzed with the same rigor as the original risks.
Residual Risks
Residual risks are the “leftover” risks that remain after a response strategy has been implemented. No mitigation strategy is 100% effective (unless it is avoidance). If a team mitigates a risk, the remaining probability or impact is the residual risk. The project manager must ensure that the residual risk level is within the established stakeholder thresholds. If the residual risk is still too high, further response planning is required.
Risk Response in Agile and Hybrid Environments
In agile project lifecycles, risk response is not a one-time planning activity but a continuous, iterative process.
Iterative Implementation
Agile teams address risk responses through:
- Backlog Refinement: High-risk items (technical debt, uncertain requirements) are prioritized in the backlog to be addressed early in the project.
- Sprint Planning: Specific risk response actions can be included as tasks within a sprint.
- Daily Standups: Teams discuss emerging impediments or risk triggers daily, allowing for immediate “micro-responses.”
- Retrospectives: Teams evaluate the effectiveness of past responses and adjust their strategies for future iterations.
Visual Risk Tracking
Agile environments favor transparency. While a traditional project might use a complex risk register, an agile team might use a “risk wall” or integrate risk levels directly into their burndown charts. This ensures that the entire team—not just the project manager—is aware of and responsible for risk implementation.
Governance and Escalation Procedures
Effective risk response requires a clear governance structure. Project managers must understand the boundaries of their authority regarding reserve spending and strategy selection.
Threshold Alignment
Every response must be checked against the organizational risk appetite. If a project manager selects a “Transfer” strategy that involves a very high premium, this must be balanced against the project’s budget constraints.
The Escalation Path
Escalation is a formal process. When a risk exceeds project thresholds, it must be documented in the risk register as “Escalated,” and the project manager must communicate the transfer of responsibility to the relevant stakeholder. The project manager’s role then shifts from “Owner” to “Monitor,” ensuring that the higher-level manager is indeed addressing the risk so that it does not negatively impact the project from the outside.
Evaluative Exercises
Short-Answer Questions
-
Question: What is the primary difference between the “Transfer” strategy and the “Escalate” strategy for a threat?
- Answer: Transfer involves moving the risk to a third party (like an insurer or vendor) often for a fee, while Escalate moves the risk to a higher level of internal management because the risk is outside the project’s scope.
- Logic: Transfer is a procurement or financial decision; Escalation is a governance and authority decision.
-
Question: Why is a “Fallback Plan” developed if a “Contingency Plan” is already in place?
- Answer: A Fallback Plan is used if the primary contingency response fails to effectively address the risk event, providing a secondary layer of protection.
- Logic: It serves as the “Plan B” to ensure project objectives are not entirely compromised if the first response is insufficient.
-
Question: How does a “Secondary Risk” differ from a “Residual Risk”?
- Answer: A secondary risk is a new risk created by the response itself, whereas a residual risk is the remaining portion of the original risk that exists after mitigation.
- Logic: Secondary risks are unintended consequences; residual risks are the expected “leftovers” of an imperfect response.
-
Question: In the context of opportunities, what is the goal of the “Exploit” strategy?
- Answer: To eliminate the uncertainty associated with a positive risk to ensure the opportunity definitely occurs (100% probability).
- Logic: It is the positive equivalent of “Avoidance,” where the goal is to remove the element of “chance” entirely.
-
Question: Which reserve is included in the project cost baseline: Contingency or Management?
- Answer: Contingency Reserve.
- Logic: Contingency reserves are for known-unknowns and are part of the project manager’s controlled budget; Management reserves are for unknown-unknowns and are outside the baseline.
-
Question: What visual tool is specifically used to track the reduction of project risk exposure over the course of the project?
- Answer: The Risk Burndown Chart.
- Logic: It plots cumulative risk levels over time, showing whether responses are effectively “burning down” the project’s total risk heat.
-
Question: If a project manager takes no action against a risk other than periodically reviewing its status, what strategy is being employed?
- Answer: Passive Acceptance.
- Logic: Active acceptance involves a reserve; passive acceptance involves only monitoring.
-
Question: What is the specific purpose of a “Risk Action Owner”?
- Answer: To execute the specific tasks associated with a risk response plan.
- Logic: This separates the oversight responsibility (Risk Owner) from the practical implementation (Action Owner).
-
Question: How does “Mitigation” affect the probability and impact of a risk?
- Answer: It seeks to reduce either the probability of the risk occurring, the impact it would have, or both, to within acceptable thresholds.
- Logic: It is an investment made to lower the risk’s “score” without necessarily eliminating the risk entirely.
-
Question: What is a “Workaround,” and when is it typically used?
- Answer: An unplanned response to a risk that was previously unidentified or for which no plan existed.
- Logic: Workarounds are reactive and are used when an “unknown-unknown” occurs during the execution phase.
Scenario Design Questions (No Answers)
-
Scenario: You are managing a hybrid software development project. During a sprint retrospective, the team identifies that a third-party API is consistently failing under high load. This was a known risk, and the primary mitigation strategy (using a load balancer) has failed to stabilize the system. Design a response strategy that incorporates a Fallback Plan and identify the necessary secondary risks that might arise.
-
Scenario: An organization is highly risk-averse but has discovered an opportunity to enter a new market six months ahead of schedule if they use an unproven AI tool. The project manager does not have the authority to increase the budget for the necessary “Exploit” strategy. Outline the formal steps for Escalating this opportunity, including what information must be provided to the portfolio manager.
-
Scenario: During the implementation of a mitigation response for a construction project (hiring a backup crane operator), the team realizes that the cost of the backup operator is 50% higher than the Expected Monetary Value (EMV) of the potential schedule delay they are trying to prevent. Critique this response plan using cost-benefit analysis principles and suggest an alternative strategy.
-
Scenario: A project has a total cost baseline of $1,000,000. Quantitative analysis shows a cumulative EMV of $150,000 for identified threats. The sponsor has insisted on a total budget of $1,100,000. Calculate the required contingency reserve and determine if the management reserve provided by the sponsor is sufficient based on standard risk governance.
-
Scenario: Imagine a project using a risk burndown chart. Halfway through the project, the burndown line shows a sharp upward spike despite several successful response implementations. Analyze what this spike might represent regarding the project environment and the effectiveness of the Risk Identification and Response processes.
Glossary of Key Terms
- Avoidance: A threat response strategy that changes the project plan to eliminate the risk entirely.
- Contingency Plan: A pre-planned response that is executed only when a specific trigger occurs.
- Contingency Reserve: Funds or time set aside within the cost baseline to manage identified risks (known-unknowns).
- EMV (Expected Monetary Value): A statistical calculation ($Probability \times Impact$) used to quantify risk for reserve determination.
- Enhance: An opportunity response strategy intended to increase the probability or impact of a positive risk.
- Escalation: Moving a risk to a higher management level because it is outside the project’s scope or authority.
- Exploit: An opportunity response strategy that ensures the positive risk will definitely occur.
- Fallback Plan: A secondary response plan implemented if the primary contingency plan is ineffective.
- Management Reserve: Funds set aside for unforeseen risks (unknown-unknowns), held outside the project cost baseline.
- Mitigation: A threat response strategy that reduces the probability or impact of a risk.
- Passive Acceptance: A strategy where the team does nothing about a risk except monitor it.
- Residual Risk: The remaining risk exposure that exists after a response strategy has been implemented.
- Risk Action Owner: The person responsible for the actual execution of a risk response.
- Risk Burndown Chart: A visual tool showing the cumulative risk exposure of a project over time.
- Risk Owner: The individual accountable for monitoring a risk and ensuring the effectiveness of its response.
- Secondary Risk: A new risk that arises as a direct result of implementing a risk response.
- Share: An opportunity response strategy that involves partnering with a third party to capture a benefit.
- Transfer: A threat response strategy that shifts the impact and ownership of a risk to a third party.
- Trigger: A specific event or indicator that signals a risk is about to occur or has occurred, initiating a response.
- Workaround: A reactive, unplanned response to an unexpected risk event.
Leaderboard
No scores saved yet. Be the first!
30 Questions — PMI – PMI-RMP : Certified Risk Management Professional - Domain 4 - Risk Response
Expand any question to reveal the correct answer and explanation.
-
1 A project manager is overseeing a high-priority software deployment. A risk was identified where a specific legacy module might fail under load. To address this, the team decides to re-architect the system to bypass the legacy module entirely. Which risk response strategy was employed?
Consider whether the threat still exists in the new project architecture.
Avoid
By changing the project management plan or scope to eliminate the threat entirely, the project manager has successfully avoided the risk.
-
✗ Mitigate
Mitigation focuses on reducing the probability or impact of a risk rather than removing the threat altogether.
-
✗ Transfer
Transferring a risk involves shifting the impact and ownership to a third party, such as through insurance or a fixed-price contract.
-
✗ Accept
Acceptance involves acknowledging the risk and potentially establishing a contingency, but not taking proactive steps to remove it.
-
-
2 During the implementation of a mitigation strategy involving the installation of a new high-speed cooling system, the project team discovers that the system's power requirements exceed the facility's current electrical capacity. This new uncertainty is best classified as which of the following?
Focus on the cause-and-effect relationship between the chosen response and the new risk.
Secondary risk
A secondary risk is a risk that arises as a direct consequence of implementing a risk response.
-
✗ Residual risk
Residual risk refers to the remaining risk exposure that exists after a response has been implemented.
-
✗ Trigger condition
A trigger condition is an event or situation that indicates a risk is about to occur or has occurred.
-
✗ Unknown unknown
This risk was generated by a specific action taken by the team, making it a direct result of the response rather than a purely unforeseen event.
-
-
3 A project team identifies an opportunity where a new regulatory change might allow them to fast-track their product launch. The project manager decides to hire an external consulting firm that specializes in these regulations to ensure the project qualifies for the fast-track process. What is the name of this response strategy?
Think about the goal of hiring specialists to ensure a specific outcome is achieved.
Exploit
Exploiting an opportunity involves taking action to ensure the opportunity is realized (reducing uncertainty to zero).
-
✗ Enhance
Enhancing focuses on increasing the probability or positive impact of an opportunity rather than guaranteeing it.
-
✗ Share
Sharing involves allocating ownership of the opportunity to a third party to best capture the benefit for the project.
-
✗ Accept
Acceptance of an opportunity means taking no proactive action and merely taking advantage of the benefit if it happens.
-
-
4 The project manager has implemented a sophisticated encryption protocol to mitigate the threat of data breaches. Despite this, a small possibility remains that a zero-day vulnerability could still be exploited. This remaining exposure is known as:
Consider the term for the 'leftover' risk after mitigation.
Residual risk
Residual risk is the risk that remains after a response plan has been executed to address the primary threat.
-
✗ Secondary risk
This is not a new risk created by the encryption, but rather a portion of the original threat that was not fully eliminated.
-
✗ Workaround
A workaround is an unplanned response to an issue that has already occurred, not a classification of risk exposure.
-
✗ Management reserve
Management reserves are funds for unknown unknowns, not a term for the leftover portion of a known risk.
-
-
5 A project manager is calculating the budget for a risk response. The strategy involves a 40% probability of a $50,000 impact. What is the Expected Monetary Value (EMV) that should be considered when justifying the cost of this response?
Apply the standard formula for calculating the statistical average of a risk event.
$20,000
EMV is calculated as Probability $\times$ Impact, which in this case is $0.40 \times 50,000 = 20,000$.
-
✗ $50,000
This represents the total impact if the risk occurs, not the statistical average or EMV.
-
✗ $30,000
This value does not reflect the standard EMV calculation based on the provided probability and impact.
-
✗ $12,500
This would be the result of an incorrect division rather than the standard multiplication used for EMV.
-
-
6 If a primary risk response strategy fails to perform as expected, the project manager initiates a pre-planned set of actions to minimize further damage. This secondary plan is known as a:
Identify the term for a 'Plan B' in risk management.
Fallback plan
A fallback plan is a plan used when the primary response is found to be ineffective or fails.
-
✗ Contingency plan
Contingency plans are used if a risk actually occurs; a fallback plan is the alternative if that first contingency doesn't work.
-
✗ Workaround
Workarounds are reactive and unplanned, whereas the scenario specifies that these actions were pre-planned.
-
✗ Corrective action
Corrective actions bring project performance back in line with the plan, but 'fallback plan' is the specific risk management term for an alternative response.
-
-
7 A project manager identifies that a critical path activity is at risk of delay. They decide to allocate additional staff to the task to ensure it finishes on time, potentially even earlier. This is an example of which opportunity strategy?
Focus on the objective of increasing the chance of a positive outcome.
Enhance
Enhancing involves increasing the probability and/or the positive impact of an opportunity.
-
✗ Exploit
Exploit would imply a 100% guarantee that the benefit is captured, whereas adding staff only increases the likelihood.
-
✗ Accept
Acceptance would mean taking no action and hoping the activity finishes early on its own.
-
✗ Mitigate
Mitigate is a strategy for threats, while finishing a task early is considered an opportunity.
-
-
8 During a project audit, it is noted that the project manager is using a specific fund to manage 'unknown unknowns'—risks that were never identified during the planning phase. Which fund is being utilized?
Differentiate between reserves managed by the PM and those requiring higher approval for unforeseen events.
Management reserve
Management reserves are specifically set aside for unforeseen risks that were not included in the risk register.
-
✗ Contingency reserve
Contingency reserves are for 'known unknowns'—risks that were identified and included in the risk baseline.
-
✗ Operational budget
The operational budget covers standard project costs, not specific reserves for managing uncertainty.
-
✗ Secondary fund
There is no formal risk management term called a 'secondary fund' for unknown risks.
-
-
9 An agile team uses a specific visual tool to track the effectiveness of their risk responses over time, showing a downward trend in total risk exposure. What is the name of this tool?
Think of a chart that shows how the 'inventory' of risk is decreasing.
Risk burndown chart
A risk burndown chart tracks the remaining risk exposure over time, ideally showing a 'burn down' as responses are implemented.
-
✗ Sprint backlog
The sprint backlog contains tasks and user stories to be completed in an iteration, not specifically the trend of risk exposure.
-
✗ Ishikawa diagram
Ishikawa diagrams are used for root cause analysis during risk identification, not for tracking response effectiveness over time.
-
✗ Tornado diagram
A tornado diagram is a sensitivity analysis tool used during quantitative analysis to compare the relative importance of variables.
-
-
10 A project manager is facing a risk that could significantly impact the project's reputation. The organization's threshold for reputational risk is zero. Which strategy is the most appropriate?
Consider the necessary action when 'zero' exposure is the requirement.
Avoid
When a threshold is zero, the organization has no appetite for the risk, necessitating its complete elimination (avoidance).
-
✗ Transfer
Transferring the risk still leaves a residual reputational impact that the organization may not be willing to accept.
-
✗ Mitigate
Mitigation implies some level of residual risk, which is unacceptable if the threshold is strictly zero.
-
✗ Accept
Acceptance is the opposite of what is required when an organization has a zero-tolerance policy for a specific risk category.
-
-
11 Which document is primarily updated to reflect the selection of risk owners and the specific actions to be taken during the 'Plan Risk Response' process?
Identify the central tracking document for all risk-related metadata.
Risk register
The risk register is the central repository where response strategies, action owners, and timelines are documented.
-
✗ Project charter
The project charter is a high-level document that authorizes the project and does not contain tactical risk response details.
-
✗ Work breakdown structure
The WBS decomposes project work into deliverables; while it may eventually include risk activities, the primary repository for risk data is the register.
-
✗ Stakeholder engagement plan
This plan outlines how to manage stakeholder expectations but is not the primary location for documenting specific risk response actions.
-
-
12 In a situational scenario, a risk event occurs that was not in the risk register. The project manager must take immediate action to address the problem. This is known as a:
Determine the term for an 'impromptu' response to an unforeseen issue.
Workaround
A workaround is a reactive, unplanned response to a risk event that was not previously identified or planned for.
-
✗ Fallback plan
Fallback plans are pre-planned for risks that were already identified in the register.
-
✗ Contingency response
Contingency responses are pre-planned 'known unknowns'; this scenario specifies the risk was not identified.
-
✗ Corrective action
While it is an action taken to correct a situation, 'workaround' is the specific term for responding to an unidentified risk event.
-
-
13 A project manager decides to use a fixed-price contract with a vendor to address the risk of fluctuating material costs. This is an example of which strategy?
Identify the strategy that involves shifting risk ownership via contract.
Transfer
A fixed-price contract shifts the financial risk of cost fluctuations from the buyer to the seller.
-
✗ Mitigate
Mitigation would involve reducing the probability of cost changes, whereas this contract shifts the ownership of the impact.
-
✗ Avoid
The threat of cost fluctuation still exists; the PM has simply changed who is responsible for paying if it happens.
-
✗ Active acceptance
Active acceptance involves setting aside a reserve, not entering into a legal agreement to shift the risk to another party.
-
-
14 The project's contingency reserve is being depleted faster than expected due to several low-probability, high-impact risks occurring early. What should the project manager do first?
What is the most logical analytical step when a resource is running low?
Re-evaluate remaining risks and reserves
The PM must first analyze the current risk status and determine if the remaining reserves are sufficient for the rest of the project.
-
✗ Request an immediate increase in management reserve
A request for more funds should be based on a detailed analysis of need, not done immediately without data.
-
✗ Stop all risk response activities to save costs
Stopping risk responses would increase overall project vulnerability and exposure to further threats.
-
✗ Use the management reserve for the next identified risk
Management reserves are for unknown risks and typically require formal approval from senior leadership.
-
-
15 A project manager is debating between two strategies. Strategy A costs $10,000 and reduces a $100,000 threat by 50%. Strategy B costs $15,000 and reduces the same threat by 80%. Based solely on cost-benefit analysis of the risk reduction, which is better?
Calculate the net benefit (Impact Reduction - Implementation Cost) for each.
Strategy B
Strategy B provides $80,000 of risk reduction for $15,000 (benefit of $65k), while Strategy A provides $50,000 reduction for $10,000 (benefit of $40k).
-
✗ Strategy A
While Strategy A has a lower upfront cost, its net benefit in terms of risk reduction is lower than Strategy B.
-
✗ Neither is acceptable
Both strategies provide a benefit that far exceeds their implementation cost.
-
✗ They are equal
The net financial benefit of Strategy B is clearly higher than that of Strategy A ($65,000 vs $40,000).
-
-
16 An organization has a very high risk appetite for innovation. For a new R&D project, the project manager identifies a potential technology breakthrough. Which strategy is most aligned with the organizational culture?
Consider the most aggressive way to capture a positive outcome.
Exploit
High risk appetite for innovation suggests an 'exploit' strategy to ensure the capture of high-value opportunities.
-
✗ Accept
Acceptance is passive and does not align with a proactive, innovative culture.
-
✗ Share
Sharing would give away part of the benefit, which might not be desired if the organization wants to own the breakthrough.
-
✗ Avoid
Avoid is a threat strategy and is irrelevant to capturing technology breakthroughs.
-
-
17 A project manager implements a response that involves outsourcing a project component. They later realize this introduces a new risk that the vendor may go bankrupt. This new risk is:
Identify the term for a risk created by a response.
A secondary risk
Risks that are introduced by the implementation of a risk response are secondary risks.
-
✗ A residual risk
This is a new risk category (vendor stability), not a leftover part of the original technical risk.
-
✗ An identified risk
While it is now identified, the specific term describing its origin from a response is 'secondary risk'.
-
✗ A workaround
A workaround is a response to an issue, not a classification of a risk itself.
-
-
18 Which of the following describes 'Active Acceptance' of a threat?
Think about the role of 'reserves' in proactive risk planning.
Establishing a contingency reserve of time or money
Active acceptance involves acknowledging the risk and creating a plan (like a reserve) to handle it if it occurs.
-
✗ Doing nothing and dealing with the risk if it happens
This describes passive acceptance, not active acceptance.
-
✗ Changing the project plan to eliminate the threat
This describes avoidance, not acceptance.
-
✗ Buying an insurance policy to cover the potential loss
This describes transfer, not acceptance.
-
-
19 The project manager is reviewing the risk register and notes that a risk owner has not been assigned to a high-priority threat. Why is this a major concern in Domain 4?
Consider the link between ownership and execution.
Without an owner, there is no accountability for monitoring or executing the response
Risk owners are responsible for monitoring the risk and ensuring the response strategy is implemented if needed.
-
✗ The risk register is considered invalid without owners for every line item
While poor practice, a register is not 'invalid', but it is functionally ineffective for high-priority risks.
-
✗ Risk owners are required for quantitative analysis calculations
Quantitative analysis focuses on math and modeling, which doesn't strictly require an owner to be performed.
-
✗ The risk management plan cannot be approved by the sponsor
The plan is the high-level strategy; the register is the tactical list where owners are assigned.
-
-
20 A project manager is using a decision tree to choose between two responses. Response 1 has a 30% chance of success (saving $100k) and a 70% chance of failure (costing $20k). What is the EMV of Response 1?
Sum the weighted values of both the positive and negative outcomes.
$16,000
EMV = $(0.30 \times 100,000) + (0.70 \times -20,000) = 30,000 - 14,000 = 16,000$.
-
✗ $30,000
This only calculates the positive side of the decision and ignores the potential cost of failure.
-
✗ $44,000
This would be the result if the 'cost' of failure was incorrectly added rather than subtracted.
-
✗ $10,000
This does not match the mathematical calculation for EMV based on the provided probabilities.
-
-
21 You are managing a hybrid project. To ensure the team realizes the benefit of a technical opportunity, you add it to the product backlog and prioritize it for the next sprint. Which strategy are you using?
Identify the strategy that increases the likelihood of a positive event in an agile context.
Enhance
By moving it into a sprint, you are increasing the probability of realizing the opportunity, which is the definition of enhancing.
-
✗ Avoid
Avoid is a strategy for threats, not opportunities.
-
✗ Exploit
Exploiting would imply that you have definitely made the opportunity happen, whereas prioritizing in a backlog still carries sprint-level uncertainty.
-
✗ Mitigate
Mitigate is used for threats; opportunities are enhanced or exploited.
-
-
22 A project team decides to 'Share' a positive risk by forming a joint venture with another company. What is the primary benefit of this strategy?
Think about why you would bring in a partner for an opportunity.
It leverages the specialized skills of the partner to better capture the opportunity
Sharing involves partnering with a third party who is better able to capture the opportunity's benefit for the project.
-
✗ It removes all responsibility from the project manager
Sharing involves joint ownership, meaning the PM still maintains some level of involvement and responsibility.
-
✗ It turns the opportunity into a guaranteed success
Sharing only increases the probability of capturing the benefit; it does not guarantee it (which would be 'exploit').
-
✗ It saves the project from having to spend any of its own budget
A joint venture or sharing agreement often involves shared costs as well as shared benefits.
-
-
23 While implementing a response to avoid a regulatory threat, the team discovers that the new process significantly slows down production. This performance degradation is an example of:
Consider the origin of this new production delay.
A secondary risk
The slowdown is a new risk (to the schedule/efficiency) that was created directly by the chosen regulatory response.
-
✗ A residual risk
Residual risk would be the remaining regulatory exposure, not a new problem introduced by the solution.
-
✗ An opportunity
A slowdown in production is a negative impact, thus it cannot be an opportunity.
-
✗ A management reserve item
While it might require reserve funds to fix, the term for the risk itself is 'secondary risk'.
-
-
24 The project manager is implementing a 'Transfer' strategy for a data loss risk. Which of the following is a common tool for this?
Identify a standard financial instrument for shifting risk.
Insurance policies
Insurance is a classic risk transfer tool, moving the financial impact of the risk to an insurance company.
-
✗ Sensitivity analysis
Sensitivity analysis is used to identify which risks have the most potential impact, not to transfer them.
-
✗ Prototypes
Prototyping is a mitigation technique used to reduce uncertainty and technical risk probability.
-
✗ Risk audits
Risk audits are monitoring tools used to evaluate the effectiveness of the risk management process.
-
-
25 A project manager is choosing a risk strategy for an event with a 10% probability and a $1,000 impact. The cost of a mitigation response is $2,000. What is the most logical strategy?
Compare the cost of the response to the expected monetary value of the risk.
Accept
If the cost to mitigate ($2,000) is higher than the EMV of the risk ($100), the most economically rational choice is to accept the risk.
-
✗ Mitigate
Spending $2,000 to reduce a risk that only averages $100 in potential loss is not a sound financial decision.
-
✗ Transfer
Transferring would likely still cost more than the $100 average impact of the risk itself.
-
✗ Avoid
Avoidance usually involves significant scope or plan changes that likely cost more than the $100 risk impact.
-
-
26 Which strategy for an opportunity involves taking no proactive measures but taking advantage of the benefit if it arises naturally?
Think of the most 'laid-back' way to handle a positive risk.
Passive acceptance
Passive acceptance of an opportunity means taking no action and simply enjoying the benefit if it happens.
-
✗ Active acceptance
Active acceptance would involve setting aside a contingency to *use* the opportunity if it triggers, which implies more preparation than passive.
-
✗ Enhance
Enhancing involves taking steps to make the opportunity more likely, which is proactive.
-
✗ Exploit
Exploiting is highly proactive, aiming to guarantee that the opportunity is captured.
-
-
27 An agile project team uses 'Risk Burndown Charts'. If the line on the chart is moving upward during a specific sprint, what does this indicate to the project manager?
Consider what 'upward' movement means on a chart intended to show things 'burning down'.
Total project risk exposure is increasing
A burndown chart should trend toward zero; an upward movement indicates that new risks have been identified or existing risks have increased in severity.
-
✗ The team is successfully mitigating risks
Successful mitigation would cause the line to move downward, not upward.
-
✗ The project is ahead of schedule
Risk burndown charts track risk exposure, not schedule progress (which would be a standard task burndown chart).
-
✗ The contingency reserve is being replenished
Risk burndown charts show exposure, not the status of the financial reserves themselves.
-
-
28 You have identified a risk that a new software feature may be rejected by users. You decide to release a small pilot version to a subset of users first to gather feedback. Which strategy is this?
Identify the strategy that involves 'testing the waters' to reduce uncertainty.
Mitigate
A pilot reduces the impact and probability of total project failure by testing and refining the feature before a full launch.
-
✗ Avoid
Avoidance would mean not developing or releasing the feature at all to remove the risk of rejection.
-
✗ Transfer
Transfer would involve having a third party take on the risk of user rejection, which is not what a pilot does.
-
✗ Accept
Acceptance would mean releasing the full feature to all users and hoping for the best, without the pilot stage.
-
-
29 In a RACI matrix for a risk response action, which role is strictly assigned to only one person to ensure clear accountability for the completion of the action?
Focus on the role that represents the 'buck stops here' person.
Accountable
In a RACI matrix, only one person should be 'Accountable' (the 'A') to ensure clear decision-making and responsibility.
-
✗ Responsible
Multiple people can be 'Responsible' for performing the work, but only one is held accountable for the outcome.
-
✗ Consulted
The 'Consulted' role can include many subject matter experts whose opinions are sought.
-
✗ Informed
The 'Informed' role includes all stakeholders who need to be kept up-to-date on progress.
-
-
30 A risk that was accepted passively has now occurred, becoming an issue. Since no contingency plan was developed, what must the project manager do?
Consider the specific term for an unplanned response to an emergent issue.
Develop and implement a workaround
When an accepted risk with no pre-planned response occurs, the resulting action is a workaround.
-
✗ Trigger the fallback plan
Fallback plans are for identified risks where the primary response failed; here, there was no primary response to begin with.
-
✗ Immediately request management reserve
The PM should first attempt to solve the issue; management reserve is for risks that were unknown, not those that were identified and accepted.
-
✗ Update the risk register to 'closed'
The risk is now an issue that must be managed; closing it without action would ignore the problem.
-