CSM Risk Assessment & Mitigation 3 โ Questions and Answers
Question 1: When calculating a risk's Expected Monetary Value (EMV), which formula is used?
- EMV = Impact + Probability
- EMV = Impact ร Probability (Correct answer)
- EMV = Impact รท Probability
- EMV = Impact โ Probability
Correct answer: EMV = Impact ร Probability
Expected Monetary Value is calculated by multiplying the monetary impact of a risk by its probability of occurrence.
Question 2: A software manager purchases cybersecurity insurance to cover losses from a potential data breach. This is an example of:
- Risk mitigation
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
Correct answer: Risk transference
Purchasing insurance transfers the financial consequences of a risk to a third party (the insurer).
Question 3: Which of the following best describes a 'residual risk'?
- A risk that has already materialized into an issue
- The remaining risk after mitigation actions have been applied (Correct answer)
- A risk identified after project closure
- A risk that was intentionally ignored
Correct answer: The remaining risk after mitigation actions have been applied
Residual risk is the level of risk that remains after mitigation strategies have been implemented.
Question 4: A software manager identifies a risk but decides to watch it closely over the next two weeks before taking action. This approach is called:
- Active acceptance
- Passive acceptance
- Risk monitoring (watchlist) (Correct answer)
- Risk avoidance
Correct answer: Risk monitoring (watchlist)
Placing a risk on a watchlist means actively monitoring it without immediately allocating resources, pending further information.
Question 5: In a risk register, which field records the planned actions to reduce a risk's probability or impact?
- Risk owner
- Risk trigger
- Mitigation plan (Correct answer)
- Risk status
Correct answer: Mitigation plan
The mitigation plan field documents the specific actions planned to reduce the probability or impact of the identified risk.
Question 6: A software project is 60% complete when a key integration risk the team accepted earlier actually occurs. What should the manager do first?
- Update the project charter
- Activate the contingency plan (Correct answer)
- Escalate to executive management immediately
- Close the project
Correct answer: Activate the contingency plan
When an accepted risk occurs, the first step is to activate any pre-defined contingency plan to manage the impact.
Question 7: Which technique uses optimistic, pessimistic, and most likely estimates to model schedule risk?
- Critical Path Method (CPM)
- PERT (Program Evaluation and Review Technique) (Correct answer)
- Agile velocity tracking
- Earned Value Analysis
Correct answer: PERT (Program Evaluation and Review Technique)
PERT uses three-point estimates (optimistic, pessimistic, most likely) to account for schedule uncertainty and risk.
When calculating a risk's Expected Monetary Value (EMV), which formula is used?