PMP Risk Management: Practice Questions & Study Guide
Risk management on the PMP exam covers planning risk management, identifying risks, performing qualitative and quantitative analysis, planning risk responses, implementing responses, and monitoring risks. You need to know the sequence and the main outputs (e.g. risk register, risk report).
Risks are uncertain events that can have positive or negative effects on objectives. You identify them (with the team and others), analyze them (qualitative first—probability and impact—then quantitative if needed), and plan responses: avoid, mitigate, transfer, or accept for threats; exploit, enhance, share, or accept for opportunities. As the project runs you implement responses and monitor for new risks and triggers.
Common exam traps include mixing up “avoid” and “mitigate” (avoid = eliminate the cause; mitigate = reduce impact or probability) and forgetting that opportunities have response strategies too. Another trap is doing quantitative analysis before qualitative—you typically prioritize with qualitative first. Also watch for questions where the best “next” step is to update the risk register or communicate with stakeholders before taking action.
Practice risk questions in the Process domain on PMP Exam Lab. Focus on “what is the PM doing?” and “what should happen next?” to reinforce the flow of risk management.
Frequently Asked Questions
- What goes in the risk register?
- The risk register typically includes identified risks, potential responses, risk owners, and other details. It is updated throughout risk management—identification adds risks, analysis adds priority and details, and response planning adds response strategies.
- When do you use quantitative risk analysis?
- Quantitative analysis (e.g. Monte Carlo, expected monetary value) is used when you need numerical outputs—e.g. contingency reserves or prioritization of risks by impact on project objectives. It often follows qualitative analysis, which narrows the set of risks to analyze in depth.
- What’s the difference between avoid and mitigate?
- Avoid: eliminate the risk or its cause (e.g. change the approach so the risk no longer applies). Mitigate: reduce the probability and/or impact of the risk (e.g. add quality checks). Both are threat response strategies.
- What are the risk response strategies for threats and opportunities?
- For threats: avoid, mitigate, transfer, or accept. For opportunities: exploit, enhance, share, or accept. Avoid eliminates the cause; mitigate reduces probability or impact; transfer shifts impact to a third party. Exploit ensures the opportunity happens; enhance increases probability or impact; share involves a third party. Accept means no proactive action.
- What is the difference between qualitative and quantitative risk analysis?
- Qualitative analysis prioritizes risks using probability and impact (e.g. high/medium/low) and a probability-impact matrix. It is fast and often done first. Quantitative analysis uses numerical techniques (e.g. EMV, Monte Carlo) to model effects on objectives and estimate contingency reserves. Quantitative is used when you need numeric outputs and typically follows qualitative.
- How many risk management questions are on the PMP exam?
- PMI does not publish topic-specific counts. Risk management falls under the Process domain (41% of the active PMP Version 8 exam). Based on candidate reports, risk questions typically make up a significant portion of Process—often 10–15% of the exam. You should know the risk register, response strategies, and the order of processes: identify → qualitative → quantitative (if needed) → plan responses → implement → monitor.