PMP Process — Managing Technical Aspects Practice Question
You are managing a project to develop a new mobile application. During a risk review meeting, the team identifies that a key third-party API may be deprecated before the project completes, which could cause significant rework. The probability is assessed as medium, and the impact is high. The team has identified alternative APIs. What is the BEST risk response strategy?
⚠ Common exam trap
Watch out — candidates often choose 'Avoid' (Option C) thinking it eliminates the risk entirely, but in project management, avoidance often introduces new risks (e.g., increased cost, scope creep) and is not the best response when a feasible mitigation exists.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate the risk by developing a fallback plan using alternative APIs and testing integration early.
It proactively reduces both the probability and impact of the API deprecation risk by developing a fallback plan with alternative APIs and testing integration early. This allows the team to switch seamlessly if the primary API is deprecated, minimizing rework and schedule delays.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to the API provider by purchasing insurance.
Why it's wrong here
Risk transfer shifts the financial or operational burden of a risk to a third party, often through contracts, warranties, or insurance. However, for the specific risk of an API provider deprecating their service, standard insurance policies are generally not available, nor would the API provider typically offer such coverage against their own future business decisions. This makes purchasing insurance an impractical and ineffective transfer strategy for this particular technical risk.
- ✗
Accept the risk and take no action, as it may not happen.
Why it's wrong here
Risk acceptance involves acknowledging a risk's existence without taking proactive steps to alter its probability or impact. Passive acceptance, as described here, is typically reserved for low-priority risks where the cost of developing a response outweighs the potential impact, or for risks with very low probability. For a critical project dependency like an API, especially when feasible mitigation strategies exist, choosing passive acceptance is irresponsible and leaves the project highly vulnerable to significant disruption if the risk materializes.
- ✗
Avoid the risk by not using the API and building all functionality in-house.
Why it's wrong here
Risk avoidance eliminates the threat entirely by changing the project plan, such as altering scope or methodology, to prevent the risk event from occurring. While effective in removing the risk, building all API functionality in-house would significantly increase the project's scope, development time, and budget. This drastic measure often introduces new risks and inefficiencies, making it an overly costly and potentially unnecessary response compared to more targeted mitigation efforts.
- ✓
Mitigate the risk by developing a fallback plan using alternative APIs and testing integration early.
Why this is correct
Risk mitigation aims to reduce the probability or impact of a negative risk event to an acceptable level. Developing a fallback plan using alternative APIs directly reduces the potential impact of the primary API's deprecation by providing a viable alternative. Furthermore, early integration testing of this fallback solution proactively reduces the probability of issues with the alternative, making this a highly effective and proactive strategy to manage the risk while retaining the benefits of using an external API.
Go deeper
Related to this question
About these practice questions
This PMP question is part of Courseiva's 800-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.