A software company has recently completed a project that delivered a new web application. Throughout the project, several issues were realized that resulted in cost and schedule overruns. The project's executive sponsor has requested a deep-dive into what went wrong since the company will be developing additional web applications in the future.
What should the risk manager do?
Answer : B
The correct answer is B. Conduct a retrospective meeting with stakeholders and inquire about what went well and what could be improved on future projects.
The question focuses on a completed project and asks what the risk manager should do after the executive sponsor requests a deep review of what went wrong for the benefit of future projects. This is a classic lessons learned and risk closure activity. A retrospective with stakeholders is the most complete and effective approach because it captures multiple perspectives on what happened, what worked, what failed, and what should be improved in future similar initiatives.
A retrospective goes beyond reviewing documents. It helps uncover root causes, process gaps, missed warning signs, ineffective responses, communication failures, and organizational learning opportunities. Because the company plans to develop more web applications, the objective is not only to analyze the past but also to improve future risk management and delivery performance.
Why the other options are incorrect:
A . Gather the project's status reports and meeting minutes to determine when issues occurred and how quickly the issues were addressed.
These documents may support the review, but they are not enough by themselves for a full deep-dive. They provide historical evidence but not the richer insight gained from stakeholder reflection.
C . Work with the project manager to determine if additional resources could have prevented or mitigated the issues that arose on the project.
This is too narrow. The project may have suffered from many causes beyond resource limitations, including planning weaknesses, requirements issues, inadequate risk responses, vendor problems, or governance gaps.
D . Review the project's risk register and determine how comprehensive and effective each risk and issue response was.
Reviewing the risk register is useful, but it is still narrower than a full retrospective. Some realized issues may never have been captured properly in the register, and the sponsor requested a broader deep-dive into what went wrong overall.
Best-practice reasoning:
At project closure, organizations should capture lessons learned through structured review with relevant stakeholders. This supports continuous improvement, improves future risk identification and response planning, and strengthens organizational process assets.
Reference-aligned basis:
This answer is consistent with standard risk management guidance that emphasizes:
lessons learned and retrospective reviews at project or phase closure,
stakeholder participation in evaluating what worked and what did not,
updating organizational knowledge for future projects.
PMI, A Guide to the Project Management Body of Knowledge (PMBOK Guide), Monitor Risks and Project/Phase Closure
PMI, Practice Standard for Project Risk Management
A project has consistently been lagging in cost performance index (CPI) and schedule performance index (SPI) over the past few months. The risk manager realizes that some activities are taking longer than expected and more resources are needed.
Which project artifact should the risk manager analyze to mitigate the risk of further project overrun?
Answer : A
When a project experiences consistent deviations in cost performance index (CPI) and schedule performance index (SPI), it indicates underlying issues with the project's assumptions regarding schedule and resources. Analyzing these assumptions helps identify discrepancies between planned and actual performance, such as underestimated task durations or insufficient resource allocation. By revisiting and adjusting these assumptions, the risk manager can develop strategies to mitigate further overruns and align the project with its objectives.
PMI Risk Management Study Guide Reference:
The PMI-RMP Exam Content Outline emphasizes the importance of examining assumption and constraint analyses to identify risks arising from inaccurate or incomplete project assumptions, which can lead to performance issues.
During project planning, a risk is identified for which the risk manager has defined a mitigation strategy. Later during project execution, this risk still leaves substantial residual risk.
What should the risk manager do to handle this situation?
Answer : C
If a risk still leaves substantial residual risk after implementing the mitigation strategy, the risk manager should revisit the risk register and redefine the mitigation strategy to reduce the residual risk to an acceptable level.
According to the PMBOK Guide, 6th edition, Chapter 11: Project Risk Management1, an effect of adding the correlation to the Monte Carlo schedule risk analysis model is that it increases the standard deviation of the model. This is because:
Correlation is the statistical relationship between two or more variables. In a schedule risk analysis, correlation can be used to model the dependency between the durations of different activities. For example, if two activities are positively correlated, it means that if one activity takes longer than expected, the other activity is also likely to take longer than expected. Conversely, if two activities are negatively correlated, it means that if one activity takes longer than expected, the other activity is likely to take shorter than expected.
A Monte Carlo schedule risk analysis is a simul-ation technique that uses random values for uncertain variables, such as activity durations, to generate possible outcomes for the project schedule. The simul-ation is repeated many times to produce a probability distribution of the project completion date and duration. The standard deviation is a measure of the variability or dispersion of the distribution. A higher standard deviation means that the distribution is more spread out and less predictable.
Adding correlation to the Monte Carlo schedule risk analysis model increases the standard deviation of the model because it introduces more variability and uncertainty to the simul-ation. Correlated activities can have a cumulative effect on the project schedule, either positively or negatively, depending on the direction and strength of the correlation. This can result in more extreme outcomes for the project completion date and duration, which increase the spread of the distribution and the standard deviation.
:
PMBOK Guide, 6th edition, Chapter 11: Project Risk Management1
Risk Management Professional (PMI-RMP) Exam Cert Guide2
Upon reviewing the risk analysis results, the project manager notices several risks that occur more frequently than others. What should the project manager do?
Answer : D
The project manager should implement the risk handling strategies for the risks that occur more frequently, as this will help reduce their impact on the project and improve overall project performance.
Exploit is a positive risk response strategy that aims to ensure that the opportunity is realized1.It involves eliminating the uncertainty associated with a particular upside risk and making it happen2. For example, if there is an opportunity to reduce the project cost by using a cheaper supplier, the project manager can exploit it by signing a contract with the supplier and securing the savings.Exploit is the opposite of avoid, which is a negative risk response strategy that seeks to eliminate the threat or protect the project from its impact2.
The other options are not appropriate for taking full advantage of opportunities.Mitigate is a negative risk response strategy that reduces the probability and/or impact of a threat2.It is the opposite of enhance, which is a positive risk response strategy that increases the probability and/or impact of an opportunity1.Accept is a risk response strategy that involves acknowledging the risk and not taking any action unless the risk occurs2. It can be applied to both threats and opportunities, but it does not actively pursue them.Transfer is a negative risk response strategy that shifts the impact of a threat to a third party, along with ownership of the response2.It is the opposite of share, which is a positive risk response strategy that allocates ownership of an opportunity to a third party who is best able to capture it for the benefit of the project1.
eferences:1: How To Exploit and Enhance Project Opportunities - Project Risk Coach22: A Guide to the Project Management Body of Knowledge (PMBOK Guide) -- Sixth Edition, page 443-4451
Stakeholder deliverable reviews will start soon and additional work is expected to resolve any issues or required adjustments. Budget overruns during execution have put serious constraints on the remainder of the project's budget.
What should the project manager do next?
Answer : B
The project manager should reassess the risks and analyze the reserve to determine if any adjustments can be made to accommodate the expected additional work. This will help in identifying potential budget-saving measures and making informed decisions on how to proceed.
According to the PMI Risk Management Professional (PMI-RMP) Reference Materials, risk reassessment is the process of reanalyzing existing project risks and identifying new risks throughout the project life cycle1. Reserve analysis is the process of estimating the amount of contingency reserve and management reserve needed to account for the uncertainty and variability of the project2. In this case, the project manager should conduct a risk reassessment and reserve analysis as the next step, because the budget overruns during execution have changed the risk profile of the project and reduced the available funds to handle future risks. By conducting a risk reassessment, the project manager can update the risk register and the risk response plan with the current status of the project risks and the effectiveness of the risk responses. By conducting a reserve analysis, the project manager can determine if the remaining contingency reserve and management reserve are sufficient to cover the potential impact of the project risks, and request additional funds if needed.
A risk management team has completed a quantitative analysis, and the individual score in terms of schedule and cost has been identified. The team is consolidating inputs for contingency planning and notices that the available time and funds are not sufficient for all the risks.
What should the risk manager advise the project team?
Answer : D
In situations where available time and funds are insufficient to address all identified risks, it's imperative to prioritize risks based on their potential impact on the project. Focusing on high-impact risks ensures that the most critical threats to project success are managed effectively within the constraints. This approach involves conducting a thorough risk assessment to categorize risks by their severity and likelihood, allowing the project team to allocate resources strategically. By concentrating on high-impact risks, the team can develop contingency plans that safeguard the project's primary objectives, even if lower-impact risks cannot be fully mitigated due to resource limitations.
PMI Risk Management Study Guide Reference:
The PMI-RMP Exam Preparation Study Guide emphasizes the importance of prioritizing risks, stating that 'project teams often face constraints in resources, making it essential to focus on risks that pose the greatest threat to project objectives.'
A new project to develop a custom software solution for a high-profile client is being initiated. The project sponsor emphasizes the importance of delivering the solution on time and within budget, as this project could lead to significant future opportunities. The risk manager recognizes that the team lacks a standardized approach to managing risks and that some team members are unfamiliar with risk management practices.
What should the risk manager do?
Answer : B
Establishing a risk management framework and involving the team in developing the risk plan creates ownership and builds risk management capability. PMBOK Guide states:
'A risk management plan should be developed early in the project and should involve the project team to ensure buy-in and effective implementation.'
--- PMBOK Guide, 6th Edition, Section 11.1
PMBOK Guide, 6th Edition, Section 11.1