HomeSubjectsUniversityBlogAbout

Risk Management

Topic in Software Engineering

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Risk management in software projects is identifying, analysing and controlling uncertain events that could harm schedule, cost or product quality. Questions separate project, technical and business risks and define risk probability, impact and exposure, calculated as probability multiplied by loss. Response strategies (avoid, transfer, mitigate, accept) and the RMMM plan, covering mitigation, monitoring and management, are common. Expect risk registers, triggers, secondary and residual risks, and qualitative versus quantitative analysis using Monte Carlo simulation. Boehm's top-ten risk list and Spiral model link risk to process, while agile teams track risk burndown and consider rare black-swan events.

Below are 30 practice questions from a pool of 210 Risk Management MCQs, one of 16 topics in Software Engineering. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Risk ManagementEasy

Q1. What is risk in software project management?

  1. A.An uncertain event that could positively or negatively affect the project✓ Correct
  2. B.A task that has already been fully completed and done in a systematic way
  3. C.A documented project functional requirement and spec for the project goals
  4. D.An absolute certainty in the project plan document across all phases

Explanation

A risk is an uncertain event that could affect project objectives.

Report an error in this question

Risk ManagementEasy

Q2. What is risk analysis?

  1. A.A source code implementation coding technique only
  2. B.Analyzing application source code logic and syntax
  3. C.A comprehensive software testing method approach
  4. D.Evaluating identified risks to determine their probability and impact✓ Correct

Explanation

Risk analysis assesses probability and impact of identified risks.

Report an error in this question

Risk ManagementEasy

Q3. What are the two components used to assess risk?

  1. A.Code and tests over the
  2. B.Scope and quality
  3. C.Probability and impact✓ Correct
  4. D.Time and money and its

Explanation

Risks are assessed by probability and impact.

Report an error in this question

Risk ManagementEasy

Q4. What is risk avoidance?

  1. A.Accepting the risk without any planned action taken
  2. B.Changing the project plan to eliminate a risk or its impact✓ Correct
  3. C.Deliberately ignoring the identified risk in full
  4. D.Avoiding the project entirely from the very start

Explanation

Risk avoidance eliminates the risk or protects from its impact.

Report an error in this question

Risk ManagementEasy

Q5. What is risk acceptance?

  1. A.Accepting all reported bugs as intended features only
  2. B.Accepting all proposed requirement changes submitted
  3. C.Accepting that the project will certainly fail overall
  4. D.Acknowledging a risk and deciding to take no preemptive action✓ Correct

Explanation

Risk acceptance means acknowledging the risk without proactive action.

Report an error in this question

Risk ManagementEasy

Q6. What is risk mitigation?

  1. A.Accepting all identified risks without any action
  2. B.Taking actions to reduce the probability or impact of a risk✓ Correct
  3. C.Deliberately ignoring all identified project risks
  4. D.Avoiding all projects and work activities entirely

Explanation

Risk mitigation reduces the likelihood or impact of a risk.

Report an error in this question

Risk ManagementEasy

Q7. What is risk identification?

  1. A.The process of determining which risks might affect the project✓ Correct
  2. B.Intentionally creating new project risks and issues
  3. C.Completely eliminating all identified project risks
  4. D.Deliberately ignoring all project risks completely

Explanation

Risk identification finds and documents risks that could affect the project.

Report an error in this question

Risk ManagementEasy

Q8. What is a risk response strategy?

  1. A.Deleting the risk register and all documents too
  2. B.Running away from all identified project risks now
  3. C.A planned approach to address an identified risk✓ Correct
  4. D.Deliberately ignoring the identified risk entirely

Explanation

A risk response strategy is a planned approach for addressing risks.

Report an error in this question

Risk ManagementEasy

Q9. What is a risk register?

  1. A.A physical cash register in a retail store space according to best practices
  2. B.A hardware register for storing CPU data and values by the development process
  3. C.A document listing identified risks, their analysis, and planned responses✓ Correct
  4. D.A specific type of application source code file only within the system boundary

Explanation

A risk register records risks with their analysis and planned responses.

Report an error in this question

Risk ManagementEasy

Q10. What is risk transfer?

  1. A.Transferring application source code ownership
  2. B.Moving data to a different storage location setup
  3. C.Shifting the impact of a risk to a third party✓ Correct
  4. D.Moving to a new office building location downtown

Explanation

Risk transfer shifts negative impact to a third party.

Report an error in this question

Risk ManagementMedium

Q11. What is Boehm's risk management approach?

  1. A.A production deployment automation approach and plan
  2. B.A framework with two main components: risk assessment and risk control✓ Correct
  3. C.A source code implementation coding approach and plan
  4. D.A comprehensive software testing approach and process

Explanation

Boehm's approach has risk assessment and risk control components.

Report an error in this question

Risk ManagementMedium

Q12. What is the RMMM plan?

  1. A.A comprehensive software testing plan and document only and related components
  2. B.Risk Mitigation, Monitoring, and Management Plan — a document for managing project risks✓ Correct
  3. C.A source code implementation coding plan and document by the project team members
  4. D.A plan based on Roman numeral notation and numbering in all development efforts

Explanation

RMMM documents strategies for risk mitigation, monitoring, and management.

Report an error in this question

Risk ManagementMedium

Q13. What are the top 10 software risks according to Boehm?

  1. A.Ten common source code coding errors and mistakes to achieve project objectives
  2. B.Ten common software testing risk types and categories in the engineering discipline
  3. C.Ten common deployment issues and concerns and problems for effective project outcomes
  4. D.Risks including personnel shortfalls, unrealistic schedules, wrong requirements, and gold plating✓ Correct

Explanation

Boehm's top risks include personnel shortfalls, unrealistic schedules, and wrong requirements.

Report an error in this question

Risk ManagementHard

Q14. What is Monte Carlo simulation in risk management?

  1. A.A technique using random sampling to simulate project outcomes and assess risk probability✓ Correct
  2. B.A comprehensive software testing simulation and approach in the development process
  3. C.A source code implementation coding simulation and test as part of the methodology
  4. D.A recreational casino gambling game activity and event for effective project outcomes

Explanation

Monte Carlo uses random sampling to model project scenarios.

Report an error in this question

Risk ManagementMedium

Q15. What is a risk trigger?

  1. A.A physical gun trigger mechanism device component only
  2. B.A software testing trigger or activation event and signal
  3. C.An indicator or symptom that a risk event is about to occur or has occurred✓ Correct
  4. D.A production deployment trigger or activation signal only

Explanation

A risk trigger indicates a risk is about to materialize.

Report an error in this question

Risk ManagementMedium

Q16. What is the difference between qualitative and quantitative risk analysis?

  1. A.Quantitative analysis is always purely subjective in nature for the development team
  2. B.The two approaches are completely identical in all ways within the project scope
  3. C.Qualitative analysis always uses only numeric data values throughout the project
  4. D.Qualitative uses subjective assessment (high/medium/low); quantitative uses numerical probabilities✓ Correct

Explanation

Qualitative uses subjective scales; quantitative uses numerical probabilities.

Report an error in this question

Risk ManagementMedium

Q17. What is a risk breakdown structure?

  1. A.A comprehensive software testing structure and model for quality purposes
  2. B.A source code structure and organization model layout during implementation
  3. C.A broken system that needs repair work and fixing in the system context
  4. D.A hierarchical organization of identified risks categorized by risk source✓ Correct

Explanation

A risk breakdown structure organizes risks into categories by source.

Report an error in this question

Risk ManagementHard

Q18. What is the concept of 'risk-driven development'?

  1. A.Deliberately ignoring risks in the development process in a systematic way for the project goals
  2. B.A comprehensive software testing approach and method only according to best practices
  3. C.Developing intentionally risky software applications at every stage across all phases
  4. D.A development approach that uses risk analysis to prioritize and guide architecture and design decisions✓ Correct

Explanation

Risk-driven development uses risk analysis to guide architecture and design.

Report an error in this question

Risk ManagementHard

Q19. What is sensitivity analysis in risk management?

  1. A.An emotional sensitivity analysis technique approach over the entire lifecycle
  2. B.A source code analysis technique and tool and method for all project stakeholders
  3. C.A security vulnerability analysis technique and method as defined by standards
  4. D.A technique that determines which risks have the greatest potential impact on project outcomes✓ Correct

Explanation

Sensitivity analysis identifies the most influential risk factors.

Report an error in this question

Risk ManagementMedium

Q20. What is the difference between known risks and unknown risks?

  1. A.Known risks cannot be managed effectively at all within the given constraints
  2. B.Unknown risks are far more common than known risks for all project stakeholders
  3. C.Known risks can be identified and planned for; unknown risks cannot be anticipated✓ Correct
  4. D.The two categories are fundamentally the same thing as defined by standards

Explanation

Known risks can be planned for; unknown risks cannot be anticipated.

Report an error in this question

Risk ManagementHard

Q21. What is the concept of 'risk appetite' vs 'risk tolerance'?

  1. A.The two concepts are completely identical in every way within the given constraints in all development efforts
  2. B.Risk appetite is the level of risk an organization is willing to pursue; risk tolerance is the acceptable variation in outcomes✓ Correct
  3. C.Risk appetite is always smaller than risk tolerance level by the project team members and related components
  4. D.Risk tolerance always means absolutely zero risk accepted to achieve project objectives in the engineering discipline

Explanation

Appetite is the broad level of acceptable risk; tolerance defines acceptable outcome variation.

Report an error in this question

Risk ManagementHard

Q22. What is the Failure Mode and Effects Analysis (FMEA) in software?

  1. A.A failure analysis report document summary and overview for quality purposes in practice typically
  2. B.A systematic technique for identifying potential failure modes, their causes, and effects on the system✓ Correct
  3. C.A production deployment analysis and report and summary by the organization at every stage
  4. D.A source code implementation coding technique and method as a standard approach

Explanation

FMEA identifies potential failure modes, their causes, and effects.

Report an error in this question

Risk ManagementMedium

Q23. What is a contingency plan?

  1. A.The main and primary project plan document overall
  2. B.A production deployment plan and schedule doc
  3. C.A comprehensive software testing plan document
  4. D.A backup plan activated when a risk materializes✓ Correct

Explanation

A contingency plan is activated when an identified risk materializes.

Report an error in this question

Risk ManagementHard

Q24. What is the concept of 'risk-based testing'?

  1. A.A testing approach that uses risk analysis to prioritize test cases and allocate testing effort✓ Correct
  2. B.Testing software without a formal plan or schedule during implementation
  3. C.Random and unstructured software testing approaches in the system context
  4. D.Testing software with risky input data and scenarios throughout the project

Explanation

Risk-based testing prioritizes test cases based on risk analysis.

Report an error in this question

Risk ManagementHard

Q25. What is secondary risk?

  1. A.A risk that is considered less important than others during the software lifecycle
  2. B.A specific type of reported software bug and defect for the development team
  3. C.A new risk that arises as a direct result of implementing a risk response✓ Correct
  4. D.A backup risk for contingency planning purposes only within the project scope

Explanation

Secondary risk is created as a consequence of implementing a risk response.

Report an error in this question

Risk ManagementMedium

Q26. What is a risk exposure (risk magnitude)?

  1. A.A production deployment issue and concern problem
  2. B.A type of security vulnerability and exposure found
  3. C.The product of risk probability and risk impact✓ Correct
  4. D.Physical exposure to sunlight and weather outdoors

Explanation

Risk exposure equals probability times impact.

Report an error in this question

Risk ManagementMedium

Q27. What is risk monitoring?

  1. A.Continuously tracking identified risks and identifying new risks throughout the project✓ Correct
  2. B.Monitoring application source code changes and edits as part of the methodology
  3. C.Monitoring production server health status and uptime in the development process
  4. D.Monitoring individual team member performance metrics during the software lifecycle

Explanation

Risk monitoring continuously tracks and identifies risks throughout the project.

Report an error in this question

Risk ManagementHard

Q28. What is the Expected Monetary Value (EMV) in risk analysis?

  1. A.An employee salary expectation and forecast amount in practice typically
  2. B.A project budget and financial metric and measurement as a standard approach
  3. C.A product pricing strategy and approach and methodology by the organization
  4. D.The product of probability and monetary impact of a risk, used in decision trees✓ Correct

Explanation

EMV multiplies probability by monetary impact for decision-making.

Report an error in this question

Risk ManagementHard

Q29. What is a decision tree in risk management?

  1. A.A test hierarchy and organization structure and setup and its related activities
  2. B.A diagram showing decision choices, chance events, probabilities, and outcomes for risk analysis✓ Correct
  3. C.A physical tree growing in a garden area outdoors within the system boundary
  4. D.A source code tree and directory structure and layout by the development process

Explanation

Decision trees map choices, probabilities, and outcomes for risk-based decisions.

Report an error in this question

Risk ManagementHard

Q30. What is residual risk?

  1. A.The risk that remains after risk responses have been implemented✓ Correct
  2. B.A production deployment issue and concern and problem
  3. C.No risk at all remaining after response is applied
  4. D.A specific type of source code error found in the code

Explanation

Residual risk remains after risk response measures are applied.

Report an error in this question

Ready to test yourself on Risk Management?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Risk Management Quiz