Tools and Techniques for Identifying Project Risks
Your project is in the planning phase, and you are developing the risk management plan. Which THREE tools or techniques should you use to identify risks?
Quick Answer
The answer is the Delphi technique, SWOT analysis, and the prompt’s implied third tool (typically checklists or brainstorming) for identifying risks during the planning phase. The Delphi technique is correct because it gathers expert consensus anonymously, eliminating bias and groupthink, while SWOT analysis systematically examines Strengths, Weaknesses, Opportunities, and Threats to reveal both internal and external risks—both are explicitly listed in the PMBOK Guide as data analysis techniques for the Identify Risks process. On the PMP exam, this question tests your ability to distinguish planning-phase tools from those used later, such as risk audits in monitoring and controlling. A common trap is confusing the Delphi technique with simple brainstorming; remember that Delphi requires anonymity and multiple rounds. For a memory tip, think “SWOT your risks, then Delphi the consensus” to recall that SWOT uncovers threats and opportunities, while Delphi refines expert input without pressure.
⚠ Common exam trap
Candidates often confuse the outputs or subsequent analysis tools with the tools used for initial risk identification, leading candidates to select the risk register or probability and impact matrix instead of the correct identification techniques.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).
SWOT analysis (B) is a recognized risk identification technique that examines internal Strengths and Weaknesses and external Opportunities and Threats to surface potential project risks. Brainstorming sessions (C) gather stakeholders and team members to generate a broad list of possible risks through open, creative discussion. The Delphi technique (D) is an anonymous expert-consensus method used during risk identification to reduce bias and converge on risks that experts agree are significant. Option A is incorrect here because the risk register is an output (documentation) of the Identify Risks process, not a tool or technique. Option E is incorrect because the probability and impact matrix is a tool used in Perform Qualitative Risk Analysis to prioritize already-identified risks, not to identify them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Creating a risk register to document identified risks.
Why it's wrong here
A risk register is the output that records risks once identified, not a tool or technique used to identify them. It is tempting because it is central to risk management, but identification techniques include brainstorming, interviews, checklists and assumption analysis, which populate the register.
- ✓
SWOT analysis (Strengths, Weaknesses, Opportunities, Threats).
Why this is correct
SWOT analysis examines internal strengths and weaknesses alongside external opportunities and threats, surfacing risks arising from organisational and environmental factors that other identification techniques overlook. It satisfies the planning-phase requirement to identify risks before qualitative and quantitative analysis begin.
- ✓
Brainstorming sessions with stakeholders and team members.
Why this is correct
Brainstorming with stakeholders and team members draws on diverse perspectives to surface potential risks, satisfying the planning-phase requirement to identify risks before analysis. It generates a broad candidate list that later techniques, such as SWOT or the Delphi technique, can refine and prioritise.
- ✓
Delphi technique to achieve expert consensus anonymously.
Why this is correct
The Delphi technique gathers expert judgements through anonymous iterative rounds, reaching consensus on potential risks without bias from dominant personalities. This satisfies the planning-phase requirement to identify risks, particularly where subject-matter expertise is dispersed or open discussion would be distorted by seniority.
- ✗
Probability and impact matrix for ranking risks.
Why it's wrong here
The probability and impact matrix ranks and prioritises risks already identified; it does not generate them. It is tempting because it is a recognised risk tool, but it belongs to qualitative risk analysis. Identification uses brainstorming, interviews, checklists and assumption analysis instead.
Go deeper
Related to this question
About these practice questions
One of 820 original PMP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PMP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are the project manager for a software development project. During a risk review meeting, the team identifies several new risks. Which THREE actions should you take to update the risk register? (Choose three.)
medium- ✓ A.Identify root causes of each risk.
- ✓ B.Assign a risk owner for each risk.
- ✓ C.Document the identified risks and their descriptions.
- D.Perform a quantitative analysis using Monte Carlo simulation.
- E.Develop detailed response plans for high-priority risks.
Why A: The risk register should include identified risks, root causes, potential responses, and risk owners. Probability and impact assessment is part of qualitative analysis. Prioritization occurs after assessment. Options A, B, and C are standard entries. Option D is incorrect as it's part of quantitative analysis, which is performed after qualitative analysis if needed. Option E is incorrect because developing detailed response plans occurs after risk analysis, not during initial identification.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PMP practice question is part of Courseiva's free PMI certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PMP exam.