Skip to content

PMI-RMP : Risk Response (Domain 4)

PMI – PMI-RMP : Certified Risk Management Professional - Domain 4 - Risk Response

30 questionsmedium

The management of project uncertainty reaches its most critical phase during the Risk Response domain. While identification and analysis provide the necessary data and prioritization, the risk response phase is where that information is transformed into actionable strategies intended to safeguard project value and ensure objectives are met. In the Project Management Institute (PMI) framework, Domain 4 accounts for 13% of the Risk Management Professional (PMI-RMP) examination and is concentrated into two primary tasks: planning risk responses and implementing those responses. This guide provides an exhaustive synthesis of the strategies, calculations, and execution methodologies required to master this domain.

Strategic Framework for Threat Response

When a project team identifies a negative risk—a threat—they must select a strategy that aligns with the organization’s risk appetite and the project’s specific thresholds. These strategies are not mutually exclusive and are often selected based on a cost-benefit analysis to determine which approach provides the most efficient use of resources.

Avoidance

The strategy of avoidance involves changing the project management plan to eliminate the threat entirely. This is the most proactive stance and usually involves altering the project scope, schedule, or technical approach. For example, if a specific technology is deemed too risky due to a lack of internal expertise, the project team may choose to use a proven, older technology. Avoidance effectively reduces the probability of the risk occurring to zero.

Mitigation

Mitigation focuses on reducing the probability of occurrence or the impact of a threat. Unlike avoidance, the risk is still present, but its potential for harm is lessened. This often involves implementing additional testing, selecting more stable suppliers, or simplifying processes. Mitigation requires an investment of resources (time or money) to create a “buffer” that protects the project objectives from the full weight of the threat.

Transfer

Transfer involves shifting the responsibility for the risk to a third party. This does not eliminate the risk but ensures that another entity bears the financial or operational consequences if the risk event occurs. Common methods of transfer include purchasing insurance, using performance bonds, or utilizing specific contract types like fixed-price contracts to shift cost risk to a vendor. It is important to note that transfer often involves the payment of a risk premium to the party taking on the risk.

Acceptance

Acceptance is a passive or active strategy used when it is not possible or cost-effective to address a risk through other means.

  • Passive Acceptance: The team takes no action other than periodically reviewing the risk to ensure it has not changed significantly.
  • Active Acceptance: The team establishes a contingency reserve (money or time) to handle the risk if it occurs. This is the primary method for managing “known-unknowns.”

Escalation

Escalation is used when a threat is outside the scope of the project or when the proposed response exceeds the project manager’s authority. The risk is moved to a higher level in the organization—such as a program manager, portfolio manager, or senior sponsor—to be managed at the appropriate governance level. Once escalated, the project manager typically no longer tracks the risk, although it may remain in the risk register for visibility.

Strategic Framework for Opportunity Response

Modern risk management emphasizes that uncertainty is not solely negative. Opportunities—positive risks—must be managed with the same level of discipline as threats to maximize organizational value and project success.

Exploit

The exploit strategy is the positive counterpart to avoidance. It seeks to ensure that the opportunity definitely happens. This might involve assigning the organization’s most talented resources to a task to ensure it is completed ahead of schedule or using a new technology that guarantees a significant reduction in costs. The goal is to eliminate the uncertainty associated with the opportunity to ensure a 100% probability of occurrence.

Enhance

Enhancement is the positive counterpart to mitigation. It aims to increase the probability of occurrence or the positive impact of the opportunity. By identifying the key drivers of the opportunity, the team can focus their efforts on strengthening those drivers. For example, adding resources to a task might increase the likelihood of finishing early, thereby capturing a performance bonus.

Share

Sharing is the positive counterpart to transfer. It involves allocating some or all of the ownership of the opportunity to a third party that is best able to capture the benefit for the project. This often involves joint ventures, risk-sharing partnerships, or incentive-based contracts where both the organization and the vendor benefit from the successful realization of the opportunity.

Acceptance

Similar to threat acceptance, opportunity acceptance involves taking no proactive action to capture the opportunity but being willing to take advantage of it if it occurs. This is often chosen when the cost of proactive exploitation or enhancement outweighs the potential benefit.

Escalation

Opportunity escalation occurs when an opportunity is identified that benefits the organization beyond the specific boundaries of the project. If a project team discovers a way to improve a process that could benefit the entire company, but the project manager lacks the authority to implement it company-wide, the opportunity is escalated to senior leadership.

Accountability and Action Ownership

A risk response plan is ineffective if it lacks clear accountability. Task 1 of Domain 4 explicitly requires the identification of action owners for each selected response.

The Role of the Risk Owner

The risk owner is the individual responsible for monitoring the risk and for the overall effectiveness of the response strategy. They are usually someone with the authority to ensure that the necessary resources are available.

The Role of the Risk Action Owner

While the risk owner oversees the risk, the risk action owner is the person tasked with the actual execution of the response activities. In some cases, the risk owner and action owner are the same person, but in complex projects, these roles are often separated to ensure technical expertise is applied to the response while management oversight remains centralized.

Mapping Responsibility (RACI and RAM)

To ensure human accountability, risk professionals utilize tools such as the Responsibility Assignment Matrix (RAM) or a RACI (Responsible, Accountable, Consulted, Informed) chart. These frameworks ensure that every risk in the register has a designated person who is accountable for its outcome and a designated person responsible for its execution. This prevents the “diffusion of responsibility” that often occurs in high-pressure project environments.

Analyzing Response Effectiveness

Selecting a strategy is only the first step; the project team must analyze the feasibility and effectiveness of that strategy before implementation. This involves a cost-benefit analysis where the cost of the response is weighed against the potential reduction in the monetary impact of the risk.

Cost-Benefit Analysis

If the cost of a mitigation strategy is $10,000, but it only reduces the Expected Monetary Value (EMV) of a risk by $5,000, the response is not economically viable. Practitioners must ensure that the “risk premium” or response cost is proportional to the protection it provides.

Risk Burndown Charts

In both traditional and agile environments, risk burndown charts serve as a vital visual tool for communicating the effectiveness of response strategies. A burndown chart tracks the cumulative risk exposure of the project over time. As responses are implemented and risks are mitigated or closed, the “heat” or total exposure level on the chart should decrease. If the burndown line remains flat or increases, it indicates that current response strategies are ineffective or that new risks are emerging faster than they can be managed.

Calculation of Reserves

One of the most technical aspects of Domain 4 is the calculation of reserves. Reserves are the financial and temporal buffers established to manage uncertainty.

Contingency Reserves

Contingency reserves are allocated for “known-unknowns”—risks that have been identified and analyzed. The amount of the contingency reserve is typically derived from the results of the quantitative risk analysis.

  • EMV-Based Calculation: By summing the Expected Monetary Value ($Probability \times Impact$) of all identified risks, a project manager can justify a specific dollar amount for the contingency reserve.
  • Three-Point Estimating: Using Beta or Triangular distributions (as outlined in Domain III), teams can determine a range of possible costs and set the reserve at a confidence level (e.g., P80) that aligns with stakeholder tolerance.

Contingency reserves are part of the project cost baseline and are under the direct control of the project manager.

Management Reserves

Management reserves are set aside for “unknown-unknowns”—unforeseen risks that could not have been identified during the planning phase. Unlike contingency reserves, management reserves are not included in the cost baseline. They are part of the total project budget but usually require senior management approval to access. They represent the organization’s strategic buffer for total project failure or major environmental shifts.

Reserve TypeTargetBaseline InclusionGovernance/Control
ContingencyIdentified Risks (Known-Unknowns)Yes (Part of Baseline)Project Manager
ManagementUnidentified Risks (Unknown-Unknowns)No (Part of Budget)Senior Management

Implementing Responses: Contingency and Fallback Plans

Implementation (Task 2 of Domain 4) involves executing the pre-planned actions when specific risk triggers are met.

Contingency Plans

A contingency plan is a specific set of actions that will be taken only if a predefined trigger occurs. For example, if a project schedule slips by more than five days (the trigger), the contingency plan might be to authorize overtime for the engineering team. These plans are proactive and are developed during the planning phase to ensure a rapid response.

Fallback Plans

A fallback plan, or “Plan B,” is implemented if the primary risk response or contingency plan fails to be effective. If the engineering overtime mentioned above does not recover the schedule, the fallback plan might be to reduce the project scope to meet the hard deadline. Fallback plans provide a secondary layer of protection for the project’s most critical objectives.

Workarounds

Workarounds are unplanned responses to risks that occur unexpectedly and were not previously identified or for which no contingency plan was created. Workarounds are reactive by nature and are often the result of “improvised” problem-solving when an unknown-unknown materializes.

Management of Residual and Secondary Risks

The implementation of a risk response often creates a new landscape of uncertainty. A sophisticated risk professional does not view a response as the end of the process but as the beginning of a new monitoring cycle.

Secondary Risks

A secondary risk is a risk that arises as a direct result of implementing a risk response. For instance, if the team decides to mitigate a technical risk by hiring an outside consultant (the response), a secondary risk might be that the consultant becomes unavailable or fails to integrate with the internal team. These risks must be identified and analyzed with the same rigor as the original risks.

Residual Risks

Residual risks are the “leftover” risks that remain after a response strategy has been implemented. No mitigation strategy is 100% effective (unless it is avoidance). If a team mitigates a risk, the remaining probability or impact is the residual risk. The project manager must ensure that the residual risk level is within the established stakeholder thresholds. If the residual risk is still too high, further response planning is required.

Risk Response in Agile and Hybrid Environments

In agile project lifecycles, risk response is not a one-time planning activity but a continuous, iterative process.

Iterative Implementation

Agile teams address risk responses through:

  • Backlog Refinement: High-risk items (technical debt, uncertain requirements) are prioritized in the backlog to be addressed early in the project.
  • Sprint Planning: Specific risk response actions can be included as tasks within a sprint.
  • Daily Standups: Teams discuss emerging impediments or risk triggers daily, allowing for immediate “micro-responses.”
  • Retrospectives: Teams evaluate the effectiveness of past responses and adjust their strategies for future iterations.

Visual Risk Tracking

Agile environments favor transparency. While a traditional project might use a complex risk register, an agile team might use a “risk wall” or integrate risk levels directly into their burndown charts. This ensures that the entire team—not just the project manager—is aware of and responsible for risk implementation.

Governance and Escalation Procedures

Effective risk response requires a clear governance structure. Project managers must understand the boundaries of their authority regarding reserve spending and strategy selection.

Threshold Alignment

Every response must be checked against the organizational risk appetite. If a project manager selects a “Transfer” strategy that involves a very high premium, this must be balanced against the project’s budget constraints.

The Escalation Path

Escalation is a formal process. When a risk exceeds project thresholds, it must be documented in the risk register as “Escalated,” and the project manager must communicate the transfer of responsibility to the relevant stakeholder. The project manager’s role then shifts from “Owner” to “Monitor,” ensuring that the higher-level manager is indeed addressing the risk so that it does not negatively impact the project from the outside.

Evaluative Exercises

Short-Answer Questions

  1. Question: What is the primary difference between the “Transfer” strategy and the “Escalate” strategy for a threat?

    • Answer: Transfer involves moving the risk to a third party (like an insurer or vendor) often for a fee, while Escalate moves the risk to a higher level of internal management because the risk is outside the project’s scope.
    • Logic: Transfer is a procurement or financial decision; Escalation is a governance and authority decision.
  2. Question: Why is a “Fallback Plan” developed if a “Contingency Plan” is already in place?

    • Answer: A Fallback Plan is used if the primary contingency response fails to effectively address the risk event, providing a secondary layer of protection.
    • Logic: It serves as the “Plan B” to ensure project objectives are not entirely compromised if the first response is insufficient.
  3. Question: How does a “Secondary Risk” differ from a “Residual Risk”?

    • Answer: A secondary risk is a new risk created by the response itself, whereas a residual risk is the remaining portion of the original risk that exists after mitigation.
    • Logic: Secondary risks are unintended consequences; residual risks are the expected “leftovers” of an imperfect response.
  4. Question: In the context of opportunities, what is the goal of the “Exploit” strategy?

    • Answer: To eliminate the uncertainty associated with a positive risk to ensure the opportunity definitely occurs (100% probability).
    • Logic: It is the positive equivalent of “Avoidance,” where the goal is to remove the element of “chance” entirely.
  5. Question: Which reserve is included in the project cost baseline: Contingency or Management?

    • Answer: Contingency Reserve.
    • Logic: Contingency reserves are for known-unknowns and are part of the project manager’s controlled budget; Management reserves are for unknown-unknowns and are outside the baseline.
  6. Question: What visual tool is specifically used to track the reduction of project risk exposure over the course of the project?

    • Answer: The Risk Burndown Chart.
    • Logic: It plots cumulative risk levels over time, showing whether responses are effectively “burning down” the project’s total risk heat.
  7. Question: If a project manager takes no action against a risk other than periodically reviewing its status, what strategy is being employed?

    • Answer: Passive Acceptance.
    • Logic: Active acceptance involves a reserve; passive acceptance involves only monitoring.
  8. Question: What is the specific purpose of a “Risk Action Owner”?

    • Answer: To execute the specific tasks associated with a risk response plan.
    • Logic: This separates the oversight responsibility (Risk Owner) from the practical implementation (Action Owner).
  9. Question: How does “Mitigation” affect the probability and impact of a risk?

    • Answer: It seeks to reduce either the probability of the risk occurring, the impact it would have, or both, to within acceptable thresholds.
    • Logic: It is an investment made to lower the risk’s “score” without necessarily eliminating the risk entirely.
  10. Question: What is a “Workaround,” and when is it typically used?

    • Answer: An unplanned response to a risk that was previously unidentified or for which no plan existed.
    • Logic: Workarounds are reactive and are used when an “unknown-unknown” occurs during the execution phase.

Scenario Design Questions (No Answers)

  1. Scenario: You are managing a hybrid software development project. During a sprint retrospective, the team identifies that a third-party API is consistently failing under high load. This was a known risk, and the primary mitigation strategy (using a load balancer) has failed to stabilize the system. Design a response strategy that incorporates a Fallback Plan and identify the necessary secondary risks that might arise.

  2. Scenario: An organization is highly risk-averse but has discovered an opportunity to enter a new market six months ahead of schedule if they use an unproven AI tool. The project manager does not have the authority to increase the budget for the necessary “Exploit” strategy. Outline the formal steps for Escalating this opportunity, including what information must be provided to the portfolio manager.

  3. Scenario: During the implementation of a mitigation response for a construction project (hiring a backup crane operator), the team realizes that the cost of the backup operator is 50% higher than the Expected Monetary Value (EMV) of the potential schedule delay they are trying to prevent. Critique this response plan using cost-benefit analysis principles and suggest an alternative strategy.

  4. Scenario: A project has a total cost baseline of $1,000,000. Quantitative analysis shows a cumulative EMV of $150,000 for identified threats. The sponsor has insisted on a total budget of $1,100,000. Calculate the required contingency reserve and determine if the management reserve provided by the sponsor is sufficient based on standard risk governance.

  5. Scenario: Imagine a project using a risk burndown chart. Halfway through the project, the burndown line shows a sharp upward spike despite several successful response implementations. Analyze what this spike might represent regarding the project environment and the effectiveness of the Risk Identification and Response processes.

Glossary of Key Terms

  1. Avoidance: A threat response strategy that changes the project plan to eliminate the risk entirely.
  2. Contingency Plan: A pre-planned response that is executed only when a specific trigger occurs.
  3. Contingency Reserve: Funds or time set aside within the cost baseline to manage identified risks (known-unknowns).
  4. EMV (Expected Monetary Value): A statistical calculation ($Probability \times Impact$) used to quantify risk for reserve determination.
  5. Enhance: An opportunity response strategy intended to increase the probability or impact of a positive risk.
  6. Escalation: Moving a risk to a higher management level because it is outside the project’s scope or authority.
  7. Exploit: An opportunity response strategy that ensures the positive risk will definitely occur.
  8. Fallback Plan: A secondary response plan implemented if the primary contingency plan is ineffective.
  9. Management Reserve: Funds set aside for unforeseen risks (unknown-unknowns), held outside the project cost baseline.
  10. Mitigation: A threat response strategy that reduces the probability or impact of a risk.
  11. Passive Acceptance: A strategy where the team does nothing about a risk except monitor it.
  12. Residual Risk: The remaining risk exposure that exists after a response strategy has been implemented.
  13. Risk Action Owner: The person responsible for the actual execution of a risk response.
  14. Risk Burndown Chart: A visual tool showing the cumulative risk exposure of a project over time.
  15. Risk Owner: The individual accountable for monitoring a risk and ensuring the effectiveness of its response.
  16. Secondary Risk: A new risk that arises as a direct result of implementing a risk response.
  17. Share: An opportunity response strategy that involves partnering with a third party to capture a benefit.
  18. Transfer: A threat response strategy that shifts the impact and ownership of a risk to a third party.
  19. Trigger: A specific event or indicator that signals a risk is about to occur or has occurred, initiating a response.
  20. Workaround: A reactive, unplanned response to an unexpected risk event.

Leaderboard

No scores saved yet. Be the first!

30 Questions — PMI – PMI-RMP : Certified Risk Management Professional - Domain 4 - Risk Response

Expand any question to reveal the correct answer and explanation.

  1. 1 A project manager is overseeing a high-priority software deployment. A risk was identified where a specific legacy module might fail under load. To address this, the team decides to re-architect the system to bypass the legacy module entirely. Which risk response strategy was employed?

    Consider whether the threat still exists in the new project architecture.

    Avoid

    By changing the project management plan or scope to eliminate the threat entirely, the project manager has successfully avoided the risk.

    • Mitigate

      Mitigation focuses on reducing the probability or impact of a risk rather than removing the threat altogether.

    • Transfer

      Transferring a risk involves shifting the impact and ownership to a third party, such as through insurance or a fixed-price contract.

    • Accept

      Acceptance involves acknowledging the risk and potentially establishing a contingency, but not taking proactive steps to remove it.

  2. 2 During the implementation of a mitigation strategy involving the installation of a new high-speed cooling system, the project team discovers that the system's power requirements exceed the facility's current electrical capacity. This new uncertainty is best classified as which of the following?

    Focus on the cause-and-effect relationship between the chosen response and the new risk.

    Secondary risk

    A secondary risk is a risk that arises as a direct consequence of implementing a risk response.

    • Residual risk

      Residual risk refers to the remaining risk exposure that exists after a response has been implemented.

    • Trigger condition

      A trigger condition is an event or situation that indicates a risk is about to occur or has occurred.

    • Unknown unknown

      This risk was generated by a specific action taken by the team, making it a direct result of the response rather than a purely unforeseen event.

  3. 3 A project team identifies an opportunity where a new regulatory change might allow them to fast-track their product launch. The project manager decides to hire an external consulting firm that specializes in these regulations to ensure the project qualifies for the fast-track process. What is the name of this response strategy?

    Think about the goal of hiring specialists to ensure a specific outcome is achieved.

    Exploit

    Exploiting an opportunity involves taking action to ensure the opportunity is realized (reducing uncertainty to zero).

    • Enhance

      Enhancing focuses on increasing the probability or positive impact of an opportunity rather than guaranteeing it.

    • Share

      Sharing involves allocating ownership of the opportunity to a third party to best capture the benefit for the project.

    • Accept

      Acceptance of an opportunity means taking no proactive action and merely taking advantage of the benefit if it happens.

  4. 4 The project manager has implemented a sophisticated encryption protocol to mitigate the threat of data breaches. Despite this, a small possibility remains that a zero-day vulnerability could still be exploited. This remaining exposure is known as:

    Consider the term for the 'leftover' risk after mitigation.

    Residual risk

    Residual risk is the risk that remains after a response plan has been executed to address the primary threat.

    • Secondary risk

      This is not a new risk created by the encryption, but rather a portion of the original threat that was not fully eliminated.

    • Workaround

      A workaround is an unplanned response to an issue that has already occurred, not a classification of risk exposure.

    • Management reserve

      Management reserves are funds for unknown unknowns, not a term for the leftover portion of a known risk.

  5. 5 A project manager is calculating the budget for a risk response. The strategy involves a 40% probability of a $50,000 impact. What is the Expected Monetary Value (EMV) that should be considered when justifying the cost of this response?

    Apply the standard formula for calculating the statistical average of a risk event.

    $20,000

    EMV is calculated as Probability $\times$ Impact, which in this case is $0.40 \times 50,000 = 20,000$.

    • $50,000

      This represents the total impact if the risk occurs, not the statistical average or EMV.

    • $30,000

      This value does not reflect the standard EMV calculation based on the provided probability and impact.

    • $12,500

      This would be the result of an incorrect division rather than the standard multiplication used for EMV.

  6. 6 If a primary risk response strategy fails to perform as expected, the project manager initiates a pre-planned set of actions to minimize further damage. This secondary plan is known as a:

    Identify the term for a 'Plan B' in risk management.

    Fallback plan

    A fallback plan is a plan used when the primary response is found to be ineffective or fails.

    • Contingency plan

      Contingency plans are used if a risk actually occurs; a fallback plan is the alternative if that first contingency doesn't work.

    • Workaround

      Workarounds are reactive and unplanned, whereas the scenario specifies that these actions were pre-planned.

    • Corrective action

      Corrective actions bring project performance back in line with the plan, but 'fallback plan' is the specific risk management term for an alternative response.

  7. 7 A project manager identifies that a critical path activity is at risk of delay. They decide to allocate additional staff to the task to ensure it finishes on time, potentially even earlier. This is an example of which opportunity strategy?

    Focus on the objective of increasing the chance of a positive outcome.

    Enhance

    Enhancing involves increasing the probability and/or the positive impact of an opportunity.

    • Exploit

      Exploit would imply a 100% guarantee that the benefit is captured, whereas adding staff only increases the likelihood.

    • Accept

      Acceptance would mean taking no action and hoping the activity finishes early on its own.

    • Mitigate

      Mitigate is a strategy for threats, while finishing a task early is considered an opportunity.

  8. 8 During a project audit, it is noted that the project manager is using a specific fund to manage 'unknown unknowns'—risks that were never identified during the planning phase. Which fund is being utilized?

    Differentiate between reserves managed by the PM and those requiring higher approval for unforeseen events.

    Management reserve

    Management reserves are specifically set aside for unforeseen risks that were not included in the risk register.

    • Contingency reserve

      Contingency reserves are for 'known unknowns'—risks that were identified and included in the risk baseline.

    • Operational budget

      The operational budget covers standard project costs, not specific reserves for managing uncertainty.

    • Secondary fund

      There is no formal risk management term called a 'secondary fund' for unknown risks.

  9. 9 An agile team uses a specific visual tool to track the effectiveness of their risk responses over time, showing a downward trend in total risk exposure. What is the name of this tool?

    Think of a chart that shows how the 'inventory' of risk is decreasing.

    Risk burndown chart

    A risk burndown chart tracks the remaining risk exposure over time, ideally showing a 'burn down' as responses are implemented.

    • Sprint backlog

      The sprint backlog contains tasks and user stories to be completed in an iteration, not specifically the trend of risk exposure.

    • Ishikawa diagram

      Ishikawa diagrams are used for root cause analysis during risk identification, not for tracking response effectiveness over time.

    • Tornado diagram

      A tornado diagram is a sensitivity analysis tool used during quantitative analysis to compare the relative importance of variables.

  10. 10 A project manager is facing a risk that could significantly impact the project's reputation. The organization's threshold for reputational risk is zero. Which strategy is the most appropriate?

    Consider the necessary action when 'zero' exposure is the requirement.

    Avoid

    When a threshold is zero, the organization has no appetite for the risk, necessitating its complete elimination (avoidance).

    • Transfer

      Transferring the risk still leaves a residual reputational impact that the organization may not be willing to accept.

    • Mitigate

      Mitigation implies some level of residual risk, which is unacceptable if the threshold is strictly zero.

    • Accept

      Acceptance is the opposite of what is required when an organization has a zero-tolerance policy for a specific risk category.

  11. 11 Which document is primarily updated to reflect the selection of risk owners and the specific actions to be taken during the 'Plan Risk Response' process?

    Identify the central tracking document for all risk-related metadata.

    Risk register

    The risk register is the central repository where response strategies, action owners, and timelines are documented.

    • Project charter

      The project charter is a high-level document that authorizes the project and does not contain tactical risk response details.

    • Work breakdown structure

      The WBS decomposes project work into deliverables; while it may eventually include risk activities, the primary repository for risk data is the register.

    • Stakeholder engagement plan

      This plan outlines how to manage stakeholder expectations but is not the primary location for documenting specific risk response actions.

  12. 12 In a situational scenario, a risk event occurs that was not in the risk register. The project manager must take immediate action to address the problem. This is known as a:

    Determine the term for an 'impromptu' response to an unforeseen issue.

    Workaround

    A workaround is a reactive, unplanned response to a risk event that was not previously identified or planned for.

    • Fallback plan

      Fallback plans are pre-planned for risks that were already identified in the register.

    • Contingency response

      Contingency responses are pre-planned 'known unknowns'; this scenario specifies the risk was not identified.

    • Corrective action

      While it is an action taken to correct a situation, 'workaround' is the specific term for responding to an unidentified risk event.

  13. 13 A project manager decides to use a fixed-price contract with a vendor to address the risk of fluctuating material costs. This is an example of which strategy?

    Identify the strategy that involves shifting risk ownership via contract.

    Transfer

    A fixed-price contract shifts the financial risk of cost fluctuations from the buyer to the seller.

    • Mitigate

      Mitigation would involve reducing the probability of cost changes, whereas this contract shifts the ownership of the impact.

    • Avoid

      The threat of cost fluctuation still exists; the PM has simply changed who is responsible for paying if it happens.

    • Active acceptance

      Active acceptance involves setting aside a reserve, not entering into a legal agreement to shift the risk to another party.

  14. 14 The project's contingency reserve is being depleted faster than expected due to several low-probability, high-impact risks occurring early. What should the project manager do first?

    What is the most logical analytical step when a resource is running low?

    Re-evaluate remaining risks and reserves

    The PM must first analyze the current risk status and determine if the remaining reserves are sufficient for the rest of the project.

    • Request an immediate increase in management reserve

      A request for more funds should be based on a detailed analysis of need, not done immediately without data.

    • Stop all risk response activities to save costs

      Stopping risk responses would increase overall project vulnerability and exposure to further threats.

    • Use the management reserve for the next identified risk

      Management reserves are for unknown risks and typically require formal approval from senior leadership.

  15. 15 A project manager is debating between two strategies. Strategy A costs $10,000 and reduces a $100,000 threat by 50%. Strategy B costs $15,000 and reduces the same threat by 80%. Based solely on cost-benefit analysis of the risk reduction, which is better?

    Calculate the net benefit (Impact Reduction - Implementation Cost) for each.

    Strategy B

    Strategy B provides $80,000 of risk reduction for $15,000 (benefit of $65k), while Strategy A provides $50,000 reduction for $10,000 (benefit of $40k).

    • Strategy A

      While Strategy A has a lower upfront cost, its net benefit in terms of risk reduction is lower than Strategy B.

    • Neither is acceptable

      Both strategies provide a benefit that far exceeds their implementation cost.

    • They are equal

      The net financial benefit of Strategy B is clearly higher than that of Strategy A ($65,000 vs $40,000).

  16. 16 An organization has a very high risk appetite for innovation. For a new R&D project, the project manager identifies a potential technology breakthrough. Which strategy is most aligned with the organizational culture?

    Consider the most aggressive way to capture a positive outcome.

    Exploit

    High risk appetite for innovation suggests an 'exploit' strategy to ensure the capture of high-value opportunities.

    • Accept

      Acceptance is passive and does not align with a proactive, innovative culture.

    • Share

      Sharing would give away part of the benefit, which might not be desired if the organization wants to own the breakthrough.

    • Avoid

      Avoid is a threat strategy and is irrelevant to capturing technology breakthroughs.

  17. 17 A project manager implements a response that involves outsourcing a project component. They later realize this introduces a new risk that the vendor may go bankrupt. This new risk is:

    Identify the term for a risk created by a response.

    A secondary risk

    Risks that are introduced by the implementation of a risk response are secondary risks.

    • A residual risk

      This is a new risk category (vendor stability), not a leftover part of the original technical risk.

    • An identified risk

      While it is now identified, the specific term describing its origin from a response is 'secondary risk'.

    • A workaround

      A workaround is a response to an issue, not a classification of a risk itself.

  18. 18 Which of the following describes 'Active Acceptance' of a threat?

    Think about the role of 'reserves' in proactive risk planning.

    Establishing a contingency reserve of time or money

    Active acceptance involves acknowledging the risk and creating a plan (like a reserve) to handle it if it occurs.

    • Doing nothing and dealing with the risk if it happens

      This describes passive acceptance, not active acceptance.

    • Changing the project plan to eliminate the threat

      This describes avoidance, not acceptance.

    • Buying an insurance policy to cover the potential loss

      This describes transfer, not acceptance.

  19. 19 The project manager is reviewing the risk register and notes that a risk owner has not been assigned to a high-priority threat. Why is this a major concern in Domain 4?

    Consider the link between ownership and execution.

    Without an owner, there is no accountability for monitoring or executing the response

    Risk owners are responsible for monitoring the risk and ensuring the response strategy is implemented if needed.

    • The risk register is considered invalid without owners for every line item

      While poor practice, a register is not 'invalid', but it is functionally ineffective for high-priority risks.

    • Risk owners are required for quantitative analysis calculations

      Quantitative analysis focuses on math and modeling, which doesn't strictly require an owner to be performed.

    • The risk management plan cannot be approved by the sponsor

      The plan is the high-level strategy; the register is the tactical list where owners are assigned.

  20. 20 A project manager is using a decision tree to choose between two responses. Response 1 has a 30% chance of success (saving $100k) and a 70% chance of failure (costing $20k). What is the EMV of Response 1?

    Sum the weighted values of both the positive and negative outcomes.

    $16,000

    EMV = $(0.30 \times 100,000) + (0.70 \times -20,000) = 30,000 - 14,000 = 16,000$.

    • $30,000

      This only calculates the positive side of the decision and ignores the potential cost of failure.

    • $44,000

      This would be the result if the 'cost' of failure was incorrectly added rather than subtracted.

    • $10,000

      This does not match the mathematical calculation for EMV based on the provided probabilities.

  21. 21 You are managing a hybrid project. To ensure the team realizes the benefit of a technical opportunity, you add it to the product backlog and prioritize it for the next sprint. Which strategy are you using?

    Identify the strategy that increases the likelihood of a positive event in an agile context.

    Enhance

    By moving it into a sprint, you are increasing the probability of realizing the opportunity, which is the definition of enhancing.

    • Avoid

      Avoid is a strategy for threats, not opportunities.

    • Exploit

      Exploiting would imply that you have definitely made the opportunity happen, whereas prioritizing in a backlog still carries sprint-level uncertainty.

    • Mitigate

      Mitigate is used for threats; opportunities are enhanced or exploited.

  22. 22 A project team decides to 'Share' a positive risk by forming a joint venture with another company. What is the primary benefit of this strategy?

    Think about why you would bring in a partner for an opportunity.

    It leverages the specialized skills of the partner to better capture the opportunity

    Sharing involves partnering with a third party who is better able to capture the opportunity's benefit for the project.

    • It removes all responsibility from the project manager

      Sharing involves joint ownership, meaning the PM still maintains some level of involvement and responsibility.

    • It turns the opportunity into a guaranteed success

      Sharing only increases the probability of capturing the benefit; it does not guarantee it (which would be 'exploit').

    • It saves the project from having to spend any of its own budget

      A joint venture or sharing agreement often involves shared costs as well as shared benefits.

  23. 23 While implementing a response to avoid a regulatory threat, the team discovers that the new process significantly slows down production. This performance degradation is an example of:

    Consider the origin of this new production delay.

    A secondary risk

    The slowdown is a new risk (to the schedule/efficiency) that was created directly by the chosen regulatory response.

    • A residual risk

      Residual risk would be the remaining regulatory exposure, not a new problem introduced by the solution.

    • An opportunity

      A slowdown in production is a negative impact, thus it cannot be an opportunity.

    • A management reserve item

      While it might require reserve funds to fix, the term for the risk itself is 'secondary risk'.

  24. 24 The project manager is implementing a 'Transfer' strategy for a data loss risk. Which of the following is a common tool for this?

    Identify a standard financial instrument for shifting risk.

    Insurance policies

    Insurance is a classic risk transfer tool, moving the financial impact of the risk to an insurance company.

    • Sensitivity analysis

      Sensitivity analysis is used to identify which risks have the most potential impact, not to transfer them.

    • Prototypes

      Prototyping is a mitigation technique used to reduce uncertainty and technical risk probability.

    • Risk audits

      Risk audits are monitoring tools used to evaluate the effectiveness of the risk management process.

  25. 25 A project manager is choosing a risk strategy for an event with a 10% probability and a $1,000 impact. The cost of a mitigation response is $2,000. What is the most logical strategy?

    Compare the cost of the response to the expected monetary value of the risk.

    Accept

    If the cost to mitigate ($2,000) is higher than the EMV of the risk ($100), the most economically rational choice is to accept the risk.

    • Mitigate

      Spending $2,000 to reduce a risk that only averages $100 in potential loss is not a sound financial decision.

    • Transfer

      Transferring would likely still cost more than the $100 average impact of the risk itself.

    • Avoid

      Avoidance usually involves significant scope or plan changes that likely cost more than the $100 risk impact.

  26. 26 Which strategy for an opportunity involves taking no proactive measures but taking advantage of the benefit if it arises naturally?

    Think of the most 'laid-back' way to handle a positive risk.

    Passive acceptance

    Passive acceptance of an opportunity means taking no action and simply enjoying the benefit if it happens.

    • Active acceptance

      Active acceptance would involve setting aside a contingency to *use* the opportunity if it triggers, which implies more preparation than passive.

    • Enhance

      Enhancing involves taking steps to make the opportunity more likely, which is proactive.

    • Exploit

      Exploiting is highly proactive, aiming to guarantee that the opportunity is captured.

  27. 27 An agile project team uses 'Risk Burndown Charts'. If the line on the chart is moving upward during a specific sprint, what does this indicate to the project manager?

    Consider what 'upward' movement means on a chart intended to show things 'burning down'.

    Total project risk exposure is increasing

    A burndown chart should trend toward zero; an upward movement indicates that new risks have been identified or existing risks have increased in severity.

    • The team is successfully mitigating risks

      Successful mitigation would cause the line to move downward, not upward.

    • The project is ahead of schedule

      Risk burndown charts track risk exposure, not schedule progress (which would be a standard task burndown chart).

    • The contingency reserve is being replenished

      Risk burndown charts show exposure, not the status of the financial reserves themselves.

  28. 28 You have identified a risk that a new software feature may be rejected by users. You decide to release a small pilot version to a subset of users first to gather feedback. Which strategy is this?

    Identify the strategy that involves 'testing the waters' to reduce uncertainty.

    Mitigate

    A pilot reduces the impact and probability of total project failure by testing and refining the feature before a full launch.

    • Avoid

      Avoidance would mean not developing or releasing the feature at all to remove the risk of rejection.

    • Transfer

      Transfer would involve having a third party take on the risk of user rejection, which is not what a pilot does.

    • Accept

      Acceptance would mean releasing the full feature to all users and hoping for the best, without the pilot stage.

  29. 29 In a RACI matrix for a risk response action, which role is strictly assigned to only one person to ensure clear accountability for the completion of the action?

    Focus on the role that represents the 'buck stops here' person.

    Accountable

    In a RACI matrix, only one person should be 'Accountable' (the 'A') to ensure clear decision-making and responsibility.

    • Responsible

      Multiple people can be 'Responsible' for performing the work, but only one is held accountable for the outcome.

    • Consulted

      The 'Consulted' role can include many subject matter experts whose opinions are sought.

    • Informed

      The 'Informed' role includes all stakeholders who need to be kept up-to-date on progress.

  30. 30 A risk that was accepted passively has now occurred, becoming an issue. Since no contingency plan was developed, what must the project manager do?

    Consider the specific term for an unplanned response to an emergent issue.

    Develop and implement a workaround

    When an accepted risk with no pre-planned response occurs, the resulting action is a workaround.

    • Trigger the fallback plan

      Fallback plans are for identified risks where the primary response failed; here, there was no primary response to begin with.

    • Immediately request management reserve

      The PM should first attempt to solve the issue; management reserve is for risks that were unknown, not those that were identified and accepted.

    • Update the risk register to 'closed'

      The risk is now an issue that must be managed; closing it without action would ignore the problem.