nerdexam
(ISC)2

CGRC · Question #139

You and your project team are just starting the risk identification activities for a project that is scheduled to last for 18 months. Your project team has already identified a long list of risks that

The correct answer is B. Identify risks is an iterative process.. Risk identification is an ongoing and iterative process throughout the entire project lifecycle, not a one-time event or something done only until a certain phase. New risks can emerge, and existing risks can change at any time.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

You and your project team are just starting the risk identification activities for a project that is scheduled to last for 18 months. Your project team has already identified a long list of risks that need to be analyzed. How often should you and the project team do risk identification? Response:

Options

  • AAt least once per month
  • BIdentify risks is an iterative process.
  • CIt depends on how many risks are initially identified.
  • DSeveral times until the project moves into execution

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    93% (50)
  • C
    2% (1)
  • D
    4% (2)

Why each option

Risk identification is an ongoing and iterative process throughout the entire project lifecycle, not a one-time event or something done only until a certain phase. New risks can emerge, and existing risks can change at any time.

AAt least once per month

While monthly reviews might be part of a risk management plan, stating 'at least once per month' doesn't capture the continuous, as-needed nature of identification.

BIdentify risks is an iterative process.Correct

Risk identification is an iterative process, meaning it should be performed continuously throughout the entire project lifecycle, not just at the beginning or at fixed intervals. As a project progresses, new risks may emerge, existing risks may change, or previously unidentified risks may become apparent, necessitating ongoing identification efforts.

CIt depends on how many risks are initially identified.

The number of initially identified risks does not determine the frequency of future identification; new risks can always arise regardless of the initial count.

DSeveral times until the project moves into execution

Risk identification is not limited to the planning phases before execution; it continues during execution and monitoring, as new risks appear.

Concept tested: Project Risk Management - Iterative Process

Source: https://www.pmi.org/pmbok-guide-standards/foundational/pmbok

Topics

#Risk Identification#Risk Management Process#Iterative Process

Community Discussion

No community discussion yet for this question.

Full CGRC Practice