Chapter 10 – Project Risk Planning
TRUE/FALSE
1. It is impossible to remove all sources of risk on a project.
2. A risk is anything that may impact the project team’s ability to achieve the general project success
measures and the specific project stakeholder priorities.
3. When the impact of an event is negative, it is considered a risk; when the impact is positive, the event
is considered an opportunity.
4. The process of deciding how to approach, plan and execute risk management activities for a project is
known as Project Risk Absorption Methodology (PRAM).
5. The risk management plan is a component of the project management plan that describes how risk
management activities will be structured and performed on a project.
6. A risk management plan should define who has responsibility for causing each risk and hold the
responsible party directly accountable for developing an appropriate solution.
7. The cost per risk for risks discovered early in the project is often more than the cost per risk for risks
discovered late because there is more opportunity for the risk to impact several dimensions of the
project.
8. The primary output of risk identification is the Risk Identification Matrix (RIM).
9. The risk register is a living document and new risks can be added as they are discovered.
10. When complete, the risk register presents the results of both qualitative and quantitative risk analysis
as well as risk response planning.
11. In agile projects, early risk planning is done at a detail level.
12. Perform Quantitative Risk Analysis is the process of prioritizing risks for subsequent further analysis
or action by assessing and combining their probability and impact.
13. The primary questions project teams use in qualitative risk analysis are “how likely is this risk to
happen?”, and “if it does happen, how big will the impact be?”
14. Perform Quantitative Risk Analysis is the process of numerically analyzing the effect of identified
risks on overall project objectives.
15. Once risks have been identified and analyzed, the project team decides how they will handle each risk.
16. Plan Risk Responses is the process of developing options to enhance opportunities and reduce threats
for every risk that has been identified.
17. In some cases, project teams will elect to reduce a threat to a level that a sponsor and other
stakeholders deem acceptable, rather than eliminate it completely.
18. Risk response strategies such as acceptance and conducting further research apply to both threats and
opportunities.
19. Risk response strategy decisions should reflect a thorough understanding of the priorities that key
stakeholders have for cost, schedule, scope, and quality.
20. Sometimes the risks posed by a project are so great that an appropriate risk response is to not perform
the project at all.
21. Risk response strategies such as mitigation and exploitation apply to both threats and opportunities.
MULTIPLE CHOICE
1. All of the following are benefits that can be attributed to the effective use of a risk management plan
EXCEPT:
a.
It enables project managers to eliminate or reduce the impact of some threats.
b.
It enables the project manager to identify and eliminate all risks
c.
It facilitates communication with various project stakeholders.
d.
It enables project managers to capitalize on some opportunities.
2. Risk is often considered in terms of impact to project success. Which of the following is NOT a valid
measure of project success?
a.
meeting specifications
b.
customer related measures such as customer satisfaction
c.
achieving efficiencies in ongoing operations
d.
measures related to the firm’s objectives including market share or new products
3. Which of the following accurately describes risk in project management?
a.
A risk may impact the project in a positive or negative way.
b.
Some projects have no risks.
c.
Risk assessment should remain objective and uninfluenced by stakeholder priorities.
d.
Project managers should always be risk averse
4. On agile projects, detailed risk management activities may occur during all of the following times
EXCEPT:
a.
While planning each subsequent iteration.
b.
During early risk planning at the start of the project.
c.
In daily stand-up meetings.
d.
During retrospectives at the end of each iteration.
5. All of the following criteria can be used to categorize project risks EXCEPT:
a.
whether the risk is a known known
b.
the project objective that may be impacted by the risk
c.
whether the risk is internal or external to the performing organization
d.
the project life cycle phase
6. All of the following methods have proven to be useful techniques to help project teams identify the
risks that might impact the project EXCEPT:
a.
reviewing project documents
b.
documenting lessons learned
c.
interviewing stakeholders
d.
brainstorming among team members and subject matter experts
7. Project managers can identify risks by learning and understanding the cause and effect relationships
that bear on risk events. All of the following approaches rely upon an understanding of cause and
effect relationships to identify risks EXCEPT:
a.
develop a flow chart that shows how people, materials or data flow from one person or
location to another
b.
conduct a root cause analysis
c.
understand trigger conditions that indicate a risk is about to occur
d.
list all risks in a risk register
8. Project teams can often identify risks by conducting any of several types of reviews. Which of the
following illustrates a valuable type of risk review?
a.
review the project schedule to determine if certain people are overloaded
b.
review previous projects to verify that each current assumption is correct
c.
review the communication plan to determine where poor communications could cause a
problem
d.
review sunk costs to determine project continuance
9. Which of the following describes the activities appropriately performed by the project team during
Perform Qualitative Risk Analysis?
a.
Team members assess the probability of occurrence and severity of impact for identified
risks.
b.
Team members develop contingency plans for all risks to avoid adverse impacts to project
objectives.
c.
Team members identify potential risk events.
d.
Team members define how to conduct risk management activities for the project.
10. Which of the following describes the appropriate use of a cause-and-effect diagram to support project
risk analysis?
a.
The project team begins by identifying strengths, weaknesses, opportunities and threats.
b.
Assumptions and constraints are organized in a fishbone pattern.
c.
Although effects are more visible, it is often easier to alter the effect by changing the
underlying cause.
d.
Team members are encouraged to keep asking “when?” to break down risks into more
detailed causes.
11. All of the following describe the appropriate application of Perform Quantitative Risk Analysis in
project management EXCEPT:
a.
Large, complex and expensive projects stand to benefit from the additional rigor of
quantitative risk analysis techniques.
b.
Quantitative techniques are used when it is critical to predict the probability of completing
a project on time or within budget with confidence.
c.
Brainstorming techniques are used by the team and other stakeholders to identify as many
project risks as possible.
d.
Decision Tree Analysis and Simulation techniques such as Monte Carlo Analysis are
examples of useful quantitative risk analysis techniques.
ID
Risk Event
Likelihood
A
Project requires new technology and support structure
Medium
B
Web infrastructure lacks sufficient transaction capacity
Medium
C
IS resources are spread too thin
High
D
The intranet site suffers a security breach
Low
Figure 10-1 Excerpt from Internet Project Risk Register
12. Consider the excerpt of the Internet Project risk register presented in Figure 10-1. Which of the
following risk events should receive the highest priority for the development of risk responses?
a.
A – project requires new technology and support structure
b.
B – web infrastructure lacks sufficient transaction capacity
c.
C – IS resources are spread too thin
d.
D – The intranet site suffers a security breach
13. Which of the following quantitative risk analysis techniques is used to determine which risks have the
most powerful impact on the project, with results displayed in the form of a tornado diagram?
a.
Failure Mode and Effects Analysis (FMEA)
b.
Expected Monetary Value
c.
Sensitivity Analysis
d.
Simulation Techniques such as Monte Carlo Analysis
14. All of these describe contemporary methods of risk prioritization in project management EXCEPT:
a.
Risk prioritization is generally based on the probability of occurrence and severity of
impact of each identified risk.
b.
Some organizations place a higher priority on risks that are likely to happen soon.
c.
Some organizations call attention to the risks that are difficult to detect.
d.
Results of quantitative risk analysis are used for clarification purposes and are typically
not documented in the risk register.
15. All of the following describe an appropriate application of Plan Risk Responses in project
management EXCEPT:
a.
Risk response planning should address both opportunities and threats.
b.
Responses should be created for every identified project risk.
c.
The expectations of the sponsor and key stakeholders should influence the risk responses
that are developed.
d.
Often multiple strategies are identified for a single risk.
16. All of the following are among the classic risk response strategies EXCEPT:
a.
share a threat
b.
transfer a threat
c.
enhance an opportunity
d.
avoid a threat
17. When a project team elects to purchase insurance, or adopts a fixed price contract with a vendor, or
hires an expert, it is demonstrating which of the following risk response strategies?
a.
avoid a threat
b.
transfer a threat
c.
mitigate a threat
d.
assume a threat
18. Which of the following activities illustrates a risk response strategy designed to mitigate a threat?
a.
adopt a fixed price type contract
b.
train a team member to cover for a potentially unavailable key resource
c.
change the project plan or scope
d.
develop change control procedures
19. Which of the following activities illustrates a risk response strategy designed to research a threat or an
opportunity?
a.
establish triggers and update them frequently
b.
establish time or cost contingencies
c.
construct a prototype to learn more about a candidate solution
d.
identify a risk owner to each high priority risk
20. All of the following activities illustrate a risk response strategy designed to exploit an opportunity
EXCEPT:
a.
identify trigger condition
b.
assign more or better resources
c.
purchase insurance
d.
give the project more visibility
21. All of the following activities are appropriate upon completion of risk response planning EXCEPT:
a.
The risk register should be updated to reflect the risk response strategies.
b.
The risk register should be baselined after planning is completed, and should not be
updated once the project is in flight.
c.
The project plan should be updated to reflect any changes to the project schedule, budget
or resource assignments.
d.
A single person should be assigned as the owner of each risk.
ESSAY
1. Identify and describe three risk identification techniques. What are some of the benefits of each
technique?
2. How might you approach the prioritization of the risk events identified by your project team and
subject matter experts? How would you use the results of this prioritization effort to guide the
development of risk responses?
3. Identify five common project risk strategies employed to address threats that your project may face.
Give an example of each.
ANS:
Key concepts to be covered in the response could include, but are not limited to: