Courseiva
PRINCE2 Practices →mediumMultiple Choice

PRINCE2 Threat Response Types: Avoid, Reduce, Transfer, Accept, Share

Which of the following is a valid threat response in PRINCE2?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Transfer

PRINCE2 defines five threat responses: Avoid, Reduce, Fallback, Transfer, and Accept. 'Transfer' is one of these, representing the action of shifting the risk to a third party (e.g., insurance or contract). The other options — Enhance, Reject, and Exploit — are not valid threat responses; Enhance and Exploit are opportunity responses, and Reject is not defined in PRINCE2.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enhance

    Why it's wrong here

    Enhance is an opportunity response, not a threat response, so it cannot address negative risk in PRINCE2. It is tempting because both risk types share the same response vocabulary, but the threat/opportunity axis determines which responses apply; enhance would be correct when exploiting a positive opportunity.

  • ✓

    Transfer

    Why this is correct

    Transfer shifts the threat's financial impact to a third party, such as an insurer or supplier, without altering the probability of the risk occurring. PRINCE2 recognises transfer as a valid response within its risk management approach, satisfying the scenario's requirement for a legitimate threat response.

  • ✗

    Reject

    Why it's wrong here

    Reject is an opportunity response in PRINCE2, applied when declining to pursue a positive opportunity, so it cannot answer a threat. It is tempting because the word suggests dismissing risk generally, but the threat/opportunity axis governs validity; reject would be correct for an opportunity the project chooses not to exploit.

  • ✗

    Exploit

    Why it's wrong here

    Exploit is a valid PRINCE2 threat response for opportunities, not threats, as it seeks to ensure a positive risk is realised by allocating resources to maximise its benefits. The question specifically asks for a threat response, and PRINCE2’s five threat responses are Avoid, Reduce, Fallback, Transfer, and Accept. Exploit is tempting because it mirrors the proactive logic of threat responses, but it belongs to the separate opportunity response category, where it would be correct for a scenario requiring capitalisation on an uncertain upside.

About these practice questions

This PRINCE2F question is part of Courseiva's 1,189-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PRINCE2F

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which THREE of the following are risk responses for a threat?

medium
  • ✓ A.Reduce
  • ✓ B.Avoid
  • C.Exploit
  • ✓ D.Transfer
  • E.Enhance

Why A: The five threat responses are: avoid, reduce, transfer, accept, share. Fallback is not a separate response; it is part of a plan.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PRINCE2F practice question is part of Courseiva's free PeopleCert certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PRINCE2F exam.