← All Software Testing Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real Software Testing practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. Which quantitative technique uses repeated random sampling to model the probability distribution of overall project risk?

    Answer: Monte Carlo simulation

    Monte Carlo simulation runs thousands of iterations with random variable inputs to produce a probability distribution of outcomes such as schedule or cost.

  2. Failure Mode and Effects Analysis (FMEA) produces a Risk Priority Number (RPN). Which three factors are multiplied to calculate RPN?

    Answer: Severity, Occurrence, Detection

    RPN = Severity × Occurrence × Detection; higher RPNs indicate failure modes that most urgently require corrective action.

  3. A software team applies risk-based testing and decides NOT to test a low-risk feature to save time. This decision must be recorded because it represents:

    Answer: An accepted risk that increases residual risk

    Skipping tests for low-risk features is an explicit risk acceptance decision that raises residual risk, and it must be logged in the risk register.

  4. In Agile testing, product backlog items are often risk-ordered. What criterion makes an item 'high risk' in this context?

    Answer: Items with unclear requirements and high customer value

    Unclear requirements combined with high business value create both high probability of defects and high impact if those defects reach users.

  5. A contingency reserve in a test project budget specifically covers:

    Answer: The cost of known risks that are expected to occur

    Contingency reserves are allocated for identified risks with a quantified probability, whereas management reserves cover truly unknown risks.

  6. Which activity marks the formal closure of a risk in the risk register?

    Answer: The risk's trigger date passes without incident or the risk is fully resolved

    A risk is closed when it can no longer occur (trigger window has passed) or when it has been fully resolved and no longer poses a threat.

  7. Which risk category specifically covers the danger that third-party components or APIs used by the software under test may introduce defects?

    Answer: Dependency risk

    Dependency risk arises from reliance on external parties (vendors, APIs, libraries) whose quality or availability is outside the team's direct control.