Courseiva
Process — Managing Technical AspectsmediumMultiple SelectObjective-mapped

Tools and Techniques for Identifying Project Risks

Your project is in the planning phase, and you are developing the risk management plan. Which THREE tools or techniques should you use to identify risks?

Quick Answer

The answer is the Delphi technique, SWOT analysis, and the prompt’s implied third tool (typically checklists or brainstorming) for identifying risks during the planning phase. The Delphi technique is correct because it gathers expert consensus anonymously, eliminating bias and groupthink, while SWOT analysis systematically examines Strengths, Weaknesses, Opportunities, and Threats to reveal both internal and external risks—both are explicitly listed in the PMBOK Guide as data analysis techniques for the Identify Risks process. On the PMP exam, this question tests your ability to distinguish planning-phase tools from those used later, such as risk audits in monitoring and controlling. A common trap is confusing the Delphi technique with simple brainstorming; remember that Delphi requires anonymity and multiple rounds. For a memory tip, think “SWOT your risks, then Delphi the consensus” to recall that SWOT uncovers threats and opportunities, while Delphi refines expert input without pressure.

⚠ Common exam trap

Candidates often confuse the outputs or subsequent analysis tools with the tools used for initial risk identification, leading candidates to select the risk register or probability and impact matrix instead of the correct identification techniques.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).

SWOT analysis (B) is a key tool for identifying risks because it examines the project from four angles—Strengths, Weaknesses, Opportunities, and Threats—to uncover both internal and external risks. This technique is specifically listed in the PMBOK Guide as a data analysis technique for the Identify Risks process during planning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Creating a risk register to document identified risks.

    Why it's wrong here

    The risk register is an output of risk identification, not a technique.

  • SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).

    Why this is correct

    SWOT analysis helps identify risks by examining internal and external factors.

  • Brainstorming sessions with stakeholders and team members.

    Why this is correct

    Brainstorming is a key technique for generating a list of potential risks.

  • Delphi technique to achieve expert consensus anonymously.

    Why this is correct

    The Delphi technique is used to gather expert opinions and identify risks.

  • Probability and impact matrix for ranking risks.

    Why it's wrong here

    This is a tool for qualitative risk analysis, not for identification.

About these practice questions

One of 800 original PMP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PMP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. You are the project manager for a software development project. During a risk review meeting, the team identifies several new risks. Which THREE actions should you take to update the risk register? (Choose three.)

medium
  • A.Identify root causes of each risk.
  • B.Assign a risk owner for each risk.
  • C.Document the identified risks and their descriptions.
  • D.Perform a quantitative analysis using Monte Carlo simulation.
  • E.Develop detailed response plans for high-priority risks.

Why A: The risk register should include identified risks, root causes, potential responses, and risk owners. Probability and impact assessment is part of qualitative analysis. Prioritization occurs after assessment. Options A, B, and C are standard entries. Option D is incorrect as it's part of quantitative analysis, which is performed after qualitative analysis if needed. Option E is incorrect because developing detailed response plans occurs after risk analysis, not during initial identification.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.