PMI-RMP PMI Risk Management Professional Exam Topics and Questions
These PMI Risk Management Professional (PMI-RMP) exam topics are organized according to official exam domains to help candidates quickly verify coverage and focus on assessment rather than theory. Each domain is paired with topic-wise PMI-RMP sample questions that reflect how objectives are tested in the actual exam. This structure enables efficient review, targeted self-assessment, and rapid identification of weak areas when preparing for the PMI Risk Management Professional certification exam.
Let's Practice Free PMI-RMP Questions Aligned with Official Exam Topics
This topic anchors everything else. You'll spend the largest share of marks establishing how risk work will run, who owns what, and where the organisation's boundaries sit. The cost comes in two forms: missed document analysis that leaves you working blind, and misaligned thresholds that send responses in the wrong direction. β Document review and environmental assessment The preliminary document analysis pulls together industry benchmarks, lessons learned, historical data, and any other material that tells you what has already gone...
This topic anchors everything else. You'll spend the largest share of marks establishing how risk work will run, who owns what, and where the organisation's boundaries sit. The cost comes in two forms: missed document analysis that leaves you working blind, and misaligned thresholds that send responses in the wrong direction.
β Document review and environmental assessment
The preliminary document analysis pulls together industry benchmarks, lessons learned, historical data, and any other material that tells you what has already gone wrong or right. You assign responsibility for that work early, typically to the project manager, risk manager, or financial controller, and you establish which documents matter for the risk process ahead. Environmental assessment follows: you determine which organisational process assets, enterprise environmental factors, and project methodology apply, then analyse the context using PESTLE, SWOT, or similar tools. Stakeholder analysis runs in parallel, and you evaluate the project management information system to understand what data you have and what you lack. Constraints come next: government rules, market regulations, organisational limits, environmental factors, and technical boundaries all shape what responses are possible. The business driver, key assumptions, and expected benefits close the loop.
β Risk appetite, thresholds and strategy
Risk appetite sits at organisational level; thresholds translate it into project terms. You align project risk thresholds to the wider appetite, calculate what the organisation can absorb across financial, scope, environmental, technical, legal, schedule, quality, and contract dimensions, then discuss those thresholds with stakeholders. Conflict resolution becomes part of the process when stakeholders disagree on how much risk to accept. Once thresholds are confirmed, you establish the risk management strategy: processes, tools, templates, metrics, and categories. Coaching the team on best practices follows, and you lead stakeholders to adopt the strategy rather than simply presenting it. The goal is a culture of risk awareness, not compliance theatre.
β The risk management plan
The plan documents roles and responsibilities, often aligned with a RACI chart, and lists the key artifacts and resources you will use. You outline who does what, when, where, and how for each risk management activity. The Risk Breakdown Structure supports the plan by organising risk categories into a hierarchy. Risk prioritisation criteria go into the plan, as does the communication plan that tailors messages for different stakeholders. You also define the stakeholder empowerment and education strategy, setting expectations on rules of engagement and ensuring shared understanding of principles and processes.
β Leading risk activities with stakeholders
Planning is one thing; leading the work is another. You collaborate with the team conducting risk planning, leverage the stakeholder analysis the project manager has done, and manage stakeholder risk appetite and attitudes as the work unfolds. Engagement in the prioritisation process is critical, so you tailor communication for each audience and empower stakeholders to own risk strategies in the plan. Training, coaching, and education create shared understanding and foster engagement. The emphasis is on servant leadership: you enable others to do the work rather than centralising it.
How Risk Strategy and Planning is tested
At 22 percent, this topic delivers the heaviest question load. Items test whether you can sequence the work correctly: document analysis before threshold setting, environmental assessment before strategy definition. They also test alignment, asking whether a proposed threshold matches a stated appetite or whether a response breaches an established constraint. Scenario items describe a project environment and ask which document, tool, or stakeholder action comes next. The trap is choosing the textbook answer over the contextually correct one. A second trap is confusing risk appetite with risk threshold, or assuming that a risk management plan is complete when it lists activities but omits communication or empowerment strategy. Candidates lose marks by selecting responses that sound professional but ignore the sequence, the alignment requirement, or the stakeholder dimension. The weighting means that a weak grasp of strategy and planning will cost you more marks than any other single gap.
The practice test gives you volume across all six tasks, so you can spot whether you consistently miss threshold-setting items or misread environmental-assessment scenarios. The PDF version lets you review the same bank offline, and the free demo shows you item style before you commit.
The question below asks you to match a planning activity to a project stage, testing whether you can sequence risk work in context.
A budget change request was initiated by a functional manager in an organization due to a shortage in the functional manager's department budget. The functional manager asks the CEO to approve utilization of a contingency budget reserved for one of the projects in its closing phase.
What should the risk manager of the related project have done to prevent this situation from happening?
Once strategy is set, you move into identification. This topic carries the highest weighting alongside Risk Analysis, and the cost is straightforward: risks you fail to identify cannot be managed. The work splits between running structured exercises and turning what you hear into a usable register. β Running identification exercises and analysing results You conduct meetings, interviews, focus groups, and other sessions with subject-matter experts, then perform detailed analysis of what comes back. That analysis covers documents, audio transcripts, telemetry...
Once strategy is set, you move into identification. This topic carries the highest weighting alongside Risk Analysis, and the cost is straightforward: risks you fail to identify cannot be managed. The work splits between running structured exercises and turning what you hear into a usable register.
β Running identification exercises and analysing results
You conduct meetings, interviews, focus groups, and other sessions with subject-matter experts, then perform detailed analysis of what comes back. That analysis covers documents, audio transcripts, telemetry data, and any other source that holds business context. Each risk is marked as a threat or an opportunity from the start. The exercise design matters: a poorly framed interview question will return generic answers, and a focus group without clear scope will drift. Detailed analysis means going beyond transcription to understand what the information means for project objectives. You are looking for specificity, not volume.
β Assumptions, constraints and their risks
Assumption and constraint analysis feeds identification. You leverage the results, categorise each assumption and constraint, then assess the risk associated with it. The relationship between assumptions or constraints and project objectives is often a cascade: one stakeholder's holiday schedule shifts a milestone, which delays a dependency, which threatens a contractual commitment. You encourage stakeholders to challenge assumptions and constraints rather than accepting them as fixed. The goal is to surface hidden risks early, when response options are still wide.
β Triggers, thresholds and the risk register
Triggers are the observable events that signal a risk is materialising; thresholds are the points at which you act. You assess, confirm, and document both against updated risk data, along with risk causes, timing, consequences, and impact. Stakeholders are empowered to challenge existing thresholds if the context has shifted. The risk register pulls everything together: you analyse the validity of identified risks and triggers, examine attributes such as probability, impact, and urgency, establish risk origin and ownership, and classify each risk as a threat or an opportunity. The register is not a static list; it is the working document for everything that follows.
How Risk Identification is tested
At 23 percent, this topic matches Risk Analysis for the highest weighting. Items test your ability to distinguish a valid risk from a vague concern, and a trigger from a consequence. Scenario-based items describe an identification exercise and ask what to do with ambiguous or conflicting information. They also test whether you can correctly classify a risk as internal or external, threat or opportunity, and whether you understand the relationship between assumptions and risks. The trap is treating identification as a checklist exercise: candidates who select the answer that lists the most activities, rather than the one that addresses the specific gap in the scenario, lose marks. Another trap is confusing a risk cause with a risk trigger, or documenting a risk without establishing ownership. The weighting means that weak identification skills will cost you as many marks as weak strategy, and because every subsequent topic depends on a complete register, the penalty compounds.
Identification questions often hinge on subtle distinctions between cause, trigger, and consequence. The practice test lets you work through enough scenarios to recognise those distinctions under timed conditions, and the PDF gives you a reference set to review when a pattern of misses appears.
The question that follows tests whether you can distinguish a risk trigger from a risk cause in a project scenario.
The project's customer has stated the project must be completed by a date indicated as the P90 date established on the Monte Carlo analysis. What should the project manager do to ensure the P90 date is met?
Identification tells you what the risks are; analysis tells you what they mean. You carry the same 23 per cent weighting here, and the cost is misallocated effort: respond to the wrong risks and you burn budget without reducing exposure. β Qualitative analysis and prioritisation Qualitative analysis starts with nominal classification of risks in the Risk Breakdown Structure, using the categories from the risk management plan. You estimate the impact of each risk on schedule, budget, resources, and scope, then...
Identification tells you what the risks are; analysis tells you what they mean. You carry the same 23 percent weighting here, and the cost is misallocated effort: respond to the wrong risks and you burn budget without reducing exposure.
β Qualitative analysis and prioritisation
Qualitative analysis starts with nominal classification of risks in the Risk Breakdown Structure, using the categories from the risk management plan. You estimate the impact of each risk on schedule, budget, resources, and scope, then prioritise based on impact and urgency. Risk matrices apply here, drawing on the agreed assessment approach, historical information, definitions of probability and impact, risk categories, and pre-established criteria. Ordinal classification follows: you rank risks relative to one another rather than scoring them in isolation. Coaching stakeholders on categorisation strategies is part of the work, because stakeholder buy-in depends on shared understanding of how prioritisation happens. The output is a ranked list that directs where response effort goes.
β Quantitative analysis and modelling
Quantitative analysis puts numbers to the qualitative picture. You analyse risk data and process performance information against established metrics, perform forecast and trend analysis on new and historical data, and run sensitivity analysis using Monte Carlo simulation, decision trees, critical path analysis, expected monetary value, or similar techniques. Risk weighting and priority calculation follow. The purpose is to answer questions that qualitative analysis cannot: what is the probability of finishing on schedule given the current risk profile, or what is the expected cost impact of the top five threats? The work is more time-intensive than qualitative analysis, so you apply it selectively to the risks that matter most.
β Threats, opportunities and complexity
Analysis also means stepping back to assess project risk complexity using SWOT analysis, Ishikawa diagrams, or tree diagrams. You perform an impact analysis on project objectives, covering scope, schedule, cost, resources, quality, and stakeholders, and you assess project compliance objectives against organisational strategic objectives, including procedures, project plans, corporate governance, project governance, and regulatory governance. The goal is to identify threats and opportunities that were not visible in the initial identification pass. Empowering stakeholders to independently identify threats and opportunities closes the loop, turning analysis from a one-time exercise into an ongoing capability.
How Risk Analysis is tested
This topic shares the 23 percent weighting with Risk Identification, and items test whether you can choose the right analysis technique for the situation. Scenario items describe a risk profile and ask whether qualitative or quantitative analysis is appropriate, or which quantitative technique to apply. They test your understanding of when to use a risk matrix versus expected monetary value, or when sensitivity analysis adds value over a simple ranking. The trap is choosing the most sophisticated technique rather than the fit-for-purpose one. Another trap is confusing probability with impact, or failing to account for urgency when prioritising. Candidates also lose marks by selecting analysis approaches that ignore the data available: running Monte Carlo when you lack the input distributions, or building a decision tree when the decision points are not yet defined. The weighting means that analysis errors cost as much as identification gaps, and because response planning depends on correct prioritisation, the downstream cost is high.
Analysis items often require you to evaluate a technique against a scenario rather than recall a definition. The practice test gives you enough scenarios to build pattern recognition around when each technique fits, and the free demo shows you the question style without purchase commitment.
The question below presents a risk profile and asks which analysis technique will yield the most useful result for the decision ahead.
Response is where analysis converts into action. The weighting drops to 13 per cent, but the cost of a wrong answer is immediate: an inappropriate response wastes budget, and a missed response lets the risk materialise. The work divides into planning the response and implementing it. β Planning and evaluating responses You determine the appropriate risk response strategy for each risk: avoid, accept, mitigate, enhance, or contingency planning. Response actions follow, time-bound and assigned to action owners. Effectiveness assessment comes...
Response is where analysis converts into action. The weighting drops to 13 percent, but the cost of a wrong answer is immediate: an inappropriate response wastes budget, and a missed response lets the risk materialise. The work divides into planning the response and implementing it.
β Planning and evaluating responses
You determine the appropriate risk response strategy for each risk: avoid, accept, mitigate, enhance, or contingency planning. Response actions follow, time-bound and assigned to action owners. Effectiveness assessment comes next: you assess whether the response actions align with the identified strategy and evaluate their effect on probability or impact relative to project objectives such as cost, schedule, and environment. Communicating effectiveness uses tools such as risk burndown charts or dot plots. You also determine workarounds for risks that materialise without a planned response, allocate responsibilities using an appropriate responsibility matrix, and re-evaluate organisational risks in light of the planned responses. The goal is a response plan that is both realistic and sufficient.
β Implementing responses and managing feedback
Implementation means executing the risk response plan and the contingency plan when triggers fire. You encourage stakeholders to provide feedback on the risk response as it unfolds, because implementation rarely goes exactly as planned. Secondary and residual risks emerge from the response itself: a mitigation action introduces a new dependency, or an accepted risk leaves residual exposure that was not quantified. You evaluate and react to those risks, improvising as needed. The emphasis is on adaptability rather than rigid adherence to the plan.
How Risk Response is tested
At 13 percent, this topic delivers fewer items than the strategy, identification, or analysis domains, but the items test decision-making under constraint. Scenario items describe a risk and ask which response strategy fits, or present a response action and ask whether it aligns with the stated strategy. They test whether you understand the difference between a mitigation that reduces probability and one that reduces impact, and whether you can identify a secondary risk introduced by a response. The trap is selecting the response that sounds most active rather than the one that fits the risk appetite and threshold. Candidates lose marks by choosing avoidance when acceptance is appropriate, or by failing to assign ownership for a response action. Another trap is treating the response plan as final: items may describe changed circumstances and ask whether the original response still applies. The lower weighting means response errors cost fewer marks in aggregate, but because response failures are visible to stakeholders and sponsors, the reputational cost on a real project is high.
Response strategy questions turn on context: the same risk may call for different responses depending on appetite, thresholds, and constraints. Working through the full question bank lets you see how context shifts the correct answer, and the PDF format lets you compare similar scenarios side by side.
The question below describes a risk and asks which response strategy aligns with the stated project constraints and organisational appetite.
Monitoring closes the loop. At 19 per cent, this topic tests whether you can track what is happening, update what has changed, and communicate the current state. The cost is stale information: a risk register that no longer reflects reality cannot guide decisions. β Performance data and variance analysis You reconcile performance data and reports from risk-relevant work packages, then analyse the data to determine completion status against the baseline. Variance analysis follows, comparing actual performance to planned performance and...
Monitoring closes the loop. At 19 percent, this topic tests whether you can track what is happening, update what has changed, and communicate the current state. The cost is stale information: a risk register that no longer reflects reality cannot guide decisions.
β Performance data and variance analysis
You reconcile performance data and reports from risk-relevant work packages, then analyse the data to determine completion status against the baseline. Variance analysis follows, comparing actual performance to planned performance and identifying where the gaps sit. You also monitor impact against overall project risk exposure to the enterprise, because individual risk performance may look acceptable while aggregate exposure drifts outside tolerance. The goal is a current, accurate picture of where the project stands relative to risk objectives.
β Residual and secondary risks
Monitoring risk response surfaces residual and secondary risks. Residual risks are the exposure that remains after a response is implemented; secondary risks are new risks introduced by the response itself. You monitor both, assess their impact on project objectives, and update and communicate that impact to stakeholders. The distinction matters: a residual risk may be acceptable, but a secondary risk that threatens a critical objective demands a new response. Monitoring ensures that neither category is overlooked.
β Document updates and risk closure
You aggregate and summarise risk data, then update project documents including the risk register, lessons learned, project management plan, and change logs. Risks that have expired are monitored and closed out, removing them from active tracking. The discipline here is keeping the register current without letting it bloat: closed risks should be archived, not left in the active list where they obscure the live picture.
β Risk levels and stakeholder reporting
You assess project risk level, prepare reports for different stakeholders, and communicate risk levels to key stakeholders. Reporting is tailored: executives need aggregate exposure and trend direction, while delivery teams need detail on specific risks affecting their work packages. The goal is to ensure that every stakeholder has the information they need to make decisions, without overwhelming them with information they do not.
How Monitor and Close Risks is tested
At 19 percent, this topic tests whether you can maintain accurate tracking and communicate effectively. Scenario items describe performance data and ask whether variance is within tolerance, or present a risk status update and ask which document should be updated. They test your understanding of the difference between residual and secondary risks, and whether you can identify when a risk should be closed versus when it should remain under active monitoring. The trap is continuing to monitor a risk that has expired, or closing a risk prematurely when residual exposure remains. Candidates also lose marks by selecting a reporting approach that is too detailed for the audience, or too aggregated to support decisions. Another trap is failing to update lessons learned or the project management plan when risk data changes. The weighting is lower than strategy or identification, but monitoring errors compound over time: a register that drifts out of date undermines every other risk process.
Monitoring questions often test whether you can interpret performance data and decide what action follows. The practice test gives you timed exposure to those interpretation tasks, and the PDF lets you revisit scenarios where the correct action was not immediately obvious.
The question below gives you performance data and asks which monitoring action is appropriate given the variance and the stated thresholds.
Ready to Start Practicing?
Access all questions and start your exam preparation journey
Upgrade to Full PMI-RMP Exam Questions π