PMP · Question #312
A project manager is leading a project that is in an advanced stage. All high-level risks identified in the risk management plan have been resolved or are no longer a risk for the project. Only low- l
The correct answer is D. Reevaluate identified risks and update the risk register.. Even in advanced stages with only low-level risks remaining, the project manager must continuously reevaluate and update the risk register to maintain an accurate risk profile.
Question
Options
- AReclassify low-level risks as high-level risks.
- BNotify stakeholders that all high-level risks have been resolved.
- CReduce the priority of project risks as all remaining risks are low-level.
- DReevaluate identified risks and update the risk register.
How the community answered
(44 responses)- A9% (4)
- B5% (2)
- C7% (3)
- D80% (35)
Why each option
Even in advanced stages with only low-level risks remaining, the project manager must continuously reevaluate and update the risk register to maintain an accurate risk profile.
Reclassifying low-level risks as high-level risks without a new assessment of their probability and impact is arbitrary and incorrect.
While notifying stakeholders is part of communication, it's not the first or only action; the priority is to ensure the risk register is current and accurate through continuous management.
Reducing the priority of all project risks simply because only low-level risks remain is a passive approach; the active management of risks still requires regular reevaluation.
Risk management is an ongoing process throughout the entire project lifecycle, regardless of the stage. Even if high-level risks are resolved, the project manager must continuously reevaluate all identified risks, assess their current probability and impact, and update the risk register accordingly. This ensures the risk profile remains accurate, new risks are identified, and appropriate monitoring and response plans are in place for remaining risks, even low-level ones.
Concept tested: Continuous risk management and monitoring
Source: https://www.pmi.org/pmbok-guide-standards/foundational/pmbok/project-risk-management
Topics
Community Discussion
6D is correct because risk management is never really done, even late in the game. Low-level risks can compound or escalate as the project shifts, so the PM needs to keep reevaluating what is on the radar and keep the risk register honest. The other answers lean toward assuming things are fine or just relabeling risks, which misses the point. From an agile mindset, you inspect and adapt continuously rather than declaring victory just because the big threats are gone.
Nice call on D, the continuous reevaluation is key, but I would add that on my exam they also wanted to see new risks added as the project evolves, not just the existing ones re-scored.
Got D on my exam last week, risk register updates are always the move.
Agreed on D, but worth noting the register itself is just an artifact. The real value is that updating it forces the conversation about whether the response strategy is actually working.
D is the right call here because risk management is never really finished, even when the big risks are gone. I am curious though, does anyone know if reevaluation in this context is triggered by a specific process or if it is just part of ongoing monitor and control?
Agreed on D, and from an Agile lens the reevaluation is not a separate monitor-and-control process but a natural byproduct of inspecting the increment every sprint and updating the risk-adjusted backlog.