CPSM CSPM Quality, Risk & Procurement Management 4 — Questions and Answers
Question 1: A software project's risk probability-impact matrix categorizes a risk as 'High Probability / Low Impact.' What is the most appropriate response?
- Escalate immediately to the project sponsor
- Mitigate by reducing probability or accept with a contingency plan (Correct answer)
- Transfer the risk through insurance
- Avoid the risk by canceling the related deliverable
Correct answer: Mitigate by reducing probability or accept with a contingency plan
High-probability, low-impact risks are typically mitigated to reduce their frequency or accepted with a documented contingency plan since their impact is manageable.
Question 2: What is the purpose of a make-or-buy analysis in procurement management?
- To compare the cost of building software in-house versus outsourcing it (Correct answer)
- To determine which project risks should be bought down via insurance
- To assess vendor financial stability before contract award
- To create the project's cost baseline
Correct answer: To compare the cost of building software in-house versus outsourcing it
A make-or-buy analysis evaluates whether it is more cost-effective and strategically sound to develop a capability internally or procure it from an external vendor.
Question 3: Which quality management tool is best suited for identifying the few causes responsible for most defects?
- Control chart
- Pareto chart (Correct answer)
- Scatter diagram
- Check sheet
Correct answer: Pareto chart
A Pareto chart applies the 80/20 principle by displaying defect categories in descending frequency, highlighting the vital few causes driving most quality problems.
Question 4: A project team is performing risk monitoring. Which activity is most important to ensure the risk register stays accurate?
- Freezing the risk register after planning is complete
- Periodically reviewing and updating risks as the project progresses (Correct answer)
- Delegating all risk updates to the QA team
- Reporting only high-priority risks to stakeholders
Correct answer: Periodically reviewing and updating risks as the project progresses
Continuous review and updating of the risk register throughout the project lifecycle ensures emerging risks are captured and resolved risks are closed.
Question 5: In contract management, what does 'contract closure' involve?
- Terminating all vendor relationships permanently
- Verifying all deliverables are complete and formally accepting or settling the contract (Correct answer)
- Moving remaining funds to the next project
- Archiving only the financial records of the contract
Correct answer: Verifying all deliverables are complete and formally accepting or settling the contract
Contract closure involves confirming all contractual obligations have been met, resolving any open claims, and formally documenting the contract as complete.
Question 6: A risk response plan includes a 'fallback plan.' When is a fallback plan activated?
- Before the primary risk response is attempted
- When the primary risk response proves insufficient (Correct answer)
- During the risk identification phase
- Only if the risk probability exceeds 80%
Correct answer: When the primary risk response proves insufficient
A fallback plan is a secondary response strategy that is triggered when the primary mitigation or contingency measure fails to adequately address the risk.
Question 7: Which procurement document is used to invite vendors to propose solutions when requirements are not fully defined?
- Request for Quotation (RFQ)
- Request for Proposal (RFP) (Correct answer)
- Invitation for Bid (IFB)
- Purchase Order (PO)
Correct answer: Request for Proposal (RFP)
An RFP solicits vendor proposals including their approach, methodology, and pricing when the buyer needs innovative solutions rather than simple price quotes.
A software project's risk probability-impact matrix categorizes a risk as 'High Probability / Low Impact.' What is the most appropriate response?