Risk Assessment & Management Flashcards
7 cards from real Software Testing practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
Which risk metric is calculated by multiplying the probability of a defect escaping to production by the cost of fixing it post-release?
Answer: Risk exposure
Risk exposure = probability × impact, giving a monetary or weighted measure of expected loss.
During risk-based testing, a module has HIGH consequence but LOW likelihood. Which priority level should it receive?
Answer: Medium
High consequence combined with low likelihood typically places a risk in the medium priority band on a risk matrix.
A tester identifies a risk that is outside the project scope to mitigate. What is the correct response strategy?
Answer: Accept the risk
When mitigation is outside scope, the project formally accepts the risk and documents it in the risk register.
What does 'residual risk' mean in a software testing context?
Answer: Risk remaining after mitigation actions have been applied
Residual risk is the level of risk that remains after all planned risk responses and controls have been implemented.
Which technique uses structured brainstorming guided by category prompts (e.g., People, Process, Technology) to identify software risks?
Answer: Ishikawa (fishbone) diagram
The Ishikawa diagram organizes potential causes of failure into branches that map to risk categories like process or technology.
A QA manager decides to purchase cyber-liability insurance to cover the cost of a data-breach defect reaching production. This is an example of which risk response?
Answer: Transfer
Purchasing insurance shifts the financial consequence of a risk to a third party, which is risk transfer.
In IEEE 829, which document is primarily responsible for capturing identified risks and their planned responses before testing begins?
Answer: Test plan
The IEEE 829 test plan includes a risk section that lists identified risks, their likelihood, impact, and mitigation strategies.