View Full PMI PMI-RMP Exam Dumps and Practice Test Dumps
Question: 341. A project team is identifying risks for a new initiative and wants to examine contracts, specifications, assumptions, and previous project documentation for potential sources of uncertainty. Which risk identification technique is most directly applicable?
- Decision tree analysis
2. Document analysis
3. Monte Carlo simulation
4. Risk transfer
Correct Answer: 2
Explanation:
Document analysis involves examining existing project documentation to identify inconsistencies, assumptions, constraints, dependencies, or other information that may reveal risks. Relevant documents can include contracts, requirements, specifications, schedules, estimates, assumptions, lessons learned, and other project records. This technique is particularly useful early in risk identification because important risks may already be reflected indirectly in the available documentation. Decision tree analysis and Monte Carlo simulation are primarily analytical techniques, while transfer is a risk response strategy. Therefore, systematically reviewing project documents is the most direct technique in this situation.
Question: 342. A project manager notices that a risk has a moderate probability and moderate impact, but the potential consequence could affect a critical regulatory milestone. What additional factor should be considered when prioritizing the risk?
- The risk’s urgency and proximity to the milestone
2. Only the number of risks already in the register
3. The color of the risk report
4. Whether the risk owner has completed training
Correct Answer: 1
Explanation:
Risk prioritization should consider more than probability and impact alone. Urgency, proximity, detectability, and the timing of potential consequences can influence how quickly a risk requires attention. A moderate risk that could affect a critical regulatory milestone may warrant closer monitoring or earlier response planning because there may be limited time to react if conditions deteriorate. The number of risks in the register, report formatting, and owner training status do not directly determine the urgency of this particular exposure. Considering timing helps ensure that significant risks are managed before response options become constrained.
Question: 343. A risk response is designed to reduce the probability of a threat from 40% to 15%, but the response introduces a new security vulnerability. What should the project team do?
- Declare the original response successful and stop monitoring
2. Ignore the vulnerability because it was not part of the original risk
3. Identify and assess the new secondary risk created by the response
4. Remove the original threat from the risk register immediately
Correct Answer: 3
Explanation:
A response can reduce an existing threat while simultaneously creating a new risk. The new security vulnerability is a secondary risk because it arises as a consequence of implementing the response. The team should identify, analyze, assign ownership, and determine an appropriate response for the new risk. Declaring the original response completely successful would overlook the broader effects of the action. The original risk may still require monitoring because residual exposure remains. Evaluating secondary risks helps ensure that a response does not simply replace one significant uncertainty with another.
Question: 344. A project manager needs to identify stakeholders who may have different risk tolerances and influence over risk decisions. Which activity is most relevant?
- Stakeholder analysis
2. Cost variance analysis
3. Schedule compression
4. Procurement closeout
Correct Answer: 1
Explanation:
Stakeholder analysis helps the project team understand stakeholders’ interests, influence, expectations, information needs, and attitudes toward project uncertainty. These factors can affect risk thresholds, response decisions, escalation requirements, and communication strategies. Different stakeholders may have different levels of tolerance for cost, schedule, quality, safety, regulatory, or reputational exposure. Understanding these differences helps the project team tailor risk management appropriately. Cost variance, schedule compression, and procurement closeout address other project concerns and do not directly provide insight into stakeholder risk attitudes or influence.
Question: 345. A project team has several possible response actions for a threat. One response removes the source of uncertainty entirely, while another reduces its probability but leaves the source in place. Which distinction is being evaluated?
- Acceptance versus escalation
2. Avoidance versus mitigation
3. Transfer versus sharing
4. Exploit versus enhance
Correct Answer: 2
Explanation:
Avoidance and mitigation are distinct threat response strategies. Avoidance changes the project approach, scope, requirement, technology, or other condition to eliminate the source of the threat or protect the project from its consequences. Mitigation reduces the probability or impact of the threat while allowing the underlying activity or condition to remain. The scenario explicitly contrasts removing the source with reducing its probability, which corresponds to avoidance versus mitigation. Acceptance and escalation concern other management choices, while exploit and enhance are primarily opportunity strategies.
Question: 346. A project manager wants to determine whether several risk events are likely to occur together because they depend on the same external economic factor. What should the manager examine?
- Risk correlation and dependencies
2. Only individual risk scores
3. The project’s communication format
4. Closed project issues
Correct Answer: 1
Explanation:
When multiple risks depend on the same external factor, their occurrences may be correlated rather than independent. Examining correlation and dependencies helps the team understand whether a single external condition could cause multiple risks to materialize simultaneously. This is important for both qualitative prioritization and quantitative modeling because treating correlated risks as independent can distort the estimated aggregate exposure. Individual risk scores alone may not reveal these relationships. Communication formats and closed issues do not directly address the statistical or causal relationships among current risks.
Question: 347. A project manager receives a risk report showing that the number of high-priority risks has decreased from 12 to 7. However, the remaining risks have larger potential impacts than before. What should the manager do?
- Conclude that overall exposure has definitely improved
2. Focus only on the reduction in risk count
3. Reassess the current risk profile, including aggregate exposure and potential impact
4. Close the remaining risks because their number is smaller
Correct Answer: 3
Explanation:
The number of high-priority risks alone does not fully describe a project’s risk profile. A reduction from 12 risks to 7 could coincide with increased potential impact, greater correlation, or other changes that leave overall exposure significant or even increase it. The manager should review current probability, impact, residual exposure, emerging risks, correlations, thresholds, and trends rather than relying solely on the count of high-priority risks. This provides stakeholders with a more complete understanding of current exposure. Risk reporting should reflect meaningful changes in risk conditions, not simply the number of entries.
Question: 348. A project team identifies an opportunity that could provide a major benefit, but the project lacks the expertise required to pursue it effectively. Another organization has the required expertise and is willing to participate. Which strategy could allow the project to pursue the opportunity collaboratively?
- Share
2. Avoid
3. Accept
4. Mitigate
Correct Answer: 1
Explanation:
Sharing is an opportunity response strategy in which the project works with another party to pursue and realize a potential benefit. It is particularly relevant when an external organization has capabilities, expertise, resources, or access that the project does not possess. A collaborative arrangement can allow both parties to contribute toward realizing the opportunity and potentially share the resulting benefits. Avoidance and mitigation are primarily threat-oriented strategies, while acceptance means taking advantage of an opportunity without proactively pursuing it. Therefore, sharing fits the scenario where external expertise is needed to realize the opportunity.
Question: 349. A project manager wants to identify risks associated with a complex process by asking participants to examine how people, equipment, procedures, materials, and environmental conditions could contribute to failure. Which technique is most appropriate?
- Fishbone or cause-and-effect analysis
2. Monte Carlo simulation
3. Decision tree analysis
4. Risk transfer
Correct Answer: 1
Explanation:
A fishbone, or cause-and-effect diagram, helps teams systematically explore possible causes contributing to a problem or uncertain event. Categories such as people, equipment, methods, materials, and environment can help participants identify root causes and relationships that might otherwise be overlooked. Monte Carlo simulation is used to model uncertainty quantitatively, decision trees compare alternatives and uncertain outcomes, and risk transfer is a response strategy. Because the scenario asks the team to explore multiple categories of potential causes of failure, cause-and-effect analysis is the most appropriate technique.
Question: 350. A project manager is reviewing a quantitative risk model and discovers that the model assumes activity durations are independent even though several activities depend on the same supplier. What should the manager consider?
- Whether the independence assumption is valid and whether dependencies should be represented in the model
2. Increasing every activity duration by exactly one day
3. Removing supplier-related activities from the model
4. Treating the model output as fully reliable
Correct Answer: 1
Explanation:
Quantitative risk models depend on assumptions about relationships among uncertain variables. If several activity durations depend on the same supplier, treating them as independent may underestimate the likelihood of combined delays. The team should validate the independence assumption and determine whether the supplier dependency or correlation should be represented in the model. Arbitrarily adding one day does not accurately represent the relationship, while removing relevant activities would reduce the model’s usefulness. Model assumptions should be validated before decision-makers rely heavily on the resulting probability distributions or forecasts.
Question: 351. A risk owner notices that a response trigger has been reached, but the planned response can no longer be implemented because the supplier has changed its contractual terms. What should the risk owner do?
- Activate the obsolete response anyway
2. Reassess the risk and determine an alternative response or escalation path
3. Close the risk because the trigger occurred
4. Ignore the change until the risk becomes an issue
Correct Answer: 2
Explanation:
A trigger indicates that predefined conditions requiring attention have occurred, but the associated response must still be feasible under current circumstances. If the supplier’s changed contractual terms make the planned response impossible, the risk owner should reassess the current exposure and determine an alternative response. Escalation may also be necessary if the required decision or resources exceed the owner’s authority. Activating an obsolete response could create additional problems, while closing the risk would remove visibility without addressing the exposure. Effective risk management requires adapting responses when conditions change.
Question: 352. A project manager wants to identify risks that may arise because a new project phase will introduce different stakeholders, technologies, and dependencies. When should the team perform this assessment?
- Only after the new phase has ended
2. At the transition into the new phase and as conditions evolve
3. Only when an issue is reported
4. Never, because risks were already identified at project initiation
Correct Answer: 2
Explanation:
Risk profiles can change significantly when a project enters a new phase. New technologies, stakeholders, interfaces, assumptions, constraints, and dependencies may create risks that were not relevant earlier. Reassessing risks at a phase transition helps the team identify these changes before significant work begins and allows existing risks and responses to be updated. Risk assessment should also continue as conditions evolve. Waiting until the phase ends or until an issue occurs would reduce the opportunity for proactive management. Initial risk identification is not sufficient for a changing project environment.
Question: 353. A project team is deciding whether to accept a risk because the cost of further response would exceed the expected benefit of reducing the exposure. What should the team also verify?
- That the remaining exposure is within applicable thresholds and stakeholder tolerance
2. That all risks have identical probability
3. That the risk owner has no further responsibilities
4. That the risk can be removed from all reports
Correct Answer: 1
Explanation:
Acceptance can be appropriate when further response is not justified by cost, feasibility, or expected benefit, but the decision should still be consistent with applicable risk thresholds, stakeholder tolerance, and governance requirements. If residual exposure exceeds an established threshold or violates a mandatory requirement, cost alone may not justify acceptance. The team should also define how the accepted risk will be monitored and what conditions would trigger reconsideration. Risk ownership does not disappear after acceptance. Therefore, verifying that the remaining exposure is within acceptable boundaries is essential.
Question: 354. A project manager is preparing a risk report for a technical team and an executive steering committee. Which approach is most appropriate?
- Use exactly the same level of technical detail for both audiences
2. Provide only financial data to both audiences
3. Tailor the content and level of detail to each audience while maintaining consistent underlying risk information
4. Send no report to the technical team
Correct Answer: 3
Explanation:
Risk communication should be tailored to stakeholder needs while remaining consistent and accurate. A technical team may require detailed information about technical causes, triggers, dependencies, response actions, and indicators. An executive steering committee may need concise information about major exposures, trends, decisions, escalations, and effects on strategic objectives. Tailoring the presentation does not mean changing the underlying facts. Providing identical technical detail to all audiences can reduce effectiveness, while limiting all communication to financial information may omit important risk dimensions. Appropriate tailoring improves understanding and decision-making.
Question: 355. A project manager identifies a threat that cannot be avoided because it is inherent in a mandatory regulatory requirement. The team can reduce the probability of noncompliance through additional testing. Which response is represented?
- Transfer
2. Mitigation
3. Exploit
4. Share
Correct Answer: 2
Explanation:
When a threat cannot reasonably be eliminated because the underlying condition is mandatory, the team may reduce its probability or impact through mitigation. Additional testing can reduce the probability that defects or noncompliance will remain undetected before the regulatory milestone. Transfer would shift responsibility or consequences to another party, while exploit and share are opportunity strategies. The response should be evaluated for cost, feasibility, residual exposure, and effects on other objectives. Mitigation does not guarantee that the threat will disappear; it aims to reduce its likelihood or consequences.
Question: 356. A project manager finds that an important risk is repeatedly discussed in meetings but is not reflected in the formal risk report. What should the manager examine?
- Whether risk communication and reporting requirements are being followed
2. Whether the project should stop
3. Whether the risk should automatically be accepted
4. Whether the risk owner should be removed
Correct Answer: 1
Explanation:
If important risk information is discussed but not reflected in formal reporting, the project manager should review the established risk communication and reporting requirements. The risk management plan may define what information should be reported, to whom, in what format, and at what frequency. The manager should determine whether the risk meets reporting criteria and whether the current reporting process is functioning effectively. Automatically accepting the risk or removing its owner would not address the communication gap. Consistent reporting helps ensure that decision-makers have access to relevant current risk information.
Question: 357. A project team wants to determine whether a risk response has caused the project’s overall risk exposure to shift from one objective to another. Which assessment is most useful?
- Cross-objective impact analysis
2. Project naming analysis
3. Procurement closeout
4. Team attendance tracking
Correct Answer: 1
Explanation:
A response can reduce exposure for one project objective while increasing exposure for another. Cross-objective impact analysis helps the team examine whether an action that improves cost risk, for example, creates schedule, quality, safety, or scope concerns. This broader view is important because project risk management should consider the interactions among objectives rather than optimizing one objective in isolation. Attendance tracking and procurement closeout do not provide this insight. Evaluating cross-objective effects can reveal trade-offs, secondary risks, and the need for a different or more balanced response.
Question: 358. A risk manager wants to determine whether a project’s risk assessment process is being performed consistently and according to established procedures. Which activity is most appropriate?
- Risk audit
2. Opportunity exploitation
3. Schedule compression
4. Scope validation
Correct Answer: 1
Explanation:
A risk audit examines the effectiveness and implementation of risk-management processes, including whether established procedures are being followed and whether risk responses are effective. It can identify process weaknesses, opportunities for improvement, and lessons that can strengthen future risk management. Opportunity exploitation is a response strategy, schedule compression concerns project scheduling, and scope validation concerns deliverables and acceptance. Therefore, when the objective is to evaluate whether the risk-management process is consistently implemented according to established procedures, a risk audit is appropriate.
Question: 359. A project manager is reviewing a risk with an uncertain event that has a 30% probability of causing a $120,000 loss. If loss magnitude is used for the calculation, what is the risk’s expected monetary value magnitude?
- $36,000
2. $84,000
3. $90,000
4. $120,000
Correct Answer: 1
Explanation:
Expected monetary value can be calculated by multiplying the probability of the uncertain event by the monetary consequence. Here, the probability is 30%, or 0.30, and the loss magnitude is $120,000. Therefore, 0.30 × $120,000 = $36,000. If threats are represented using a signed convention, the EMV could be shown as negative $36,000 because it represents an expected loss. The question explicitly asks for the loss magnitude, so the answer is $36,000. EMV is useful for comparing expected financial effects but should not be the only decision criterion.
Question: 360. At project closeout, the risk team wants to preserve knowledge about which risk responses were effective, which assumptions proved incorrect, and which monitoring indicators provided useful warnings. What should the team do?
- Delete the historical risk information
2. Capture the information as lessons learned and update relevant organizational knowledge
3. Transfer all closed risks to the next project automatically
4. Keep the information only in individual team members’ memories
Correct Answer: 2
Explanation:
Project closeout provides an important opportunity to capture lessons learned from risk management. Effective responses, incorrect assumptions, useful leading indicators, unsuccessful approaches, and process improvements can provide valuable organizational knowledge for future projects. The information should be documented in an accessible form according to organizational practices so that future teams can benefit from it. Automatically transferring every closed risk would not account for differences between projects, while relying on individual memory risks losing valuable knowledge. Capturing lessons learned supports continuous improvement and strengthens future risk identification, analysis, response planning, and monitoring.