PMI-RMP® Prep Hub — Free Risk Management Practice Questions, Case Studies & Mock Exams (Jan 2023 ECO)
PMI-RMP® Prep Hub is a free, all-in-one preparation tool for the PMI Risk Management Professional (PMI-RMP)® exam, with 1,500 ECO-aligned practice questions, active-recall flashcards, 50 applied case studies, and 5 full-length mock exams across Risk Strategy & Planning (22%), Risk Identification (23%), Risk Analysis (23%), Risk Response (13%), and Monitor & Close Risks (19%). Every question maps to a task and enabler in the PMI-RMP® Examination Content Outline (January 2023). This content is loaded interactively; the summary below is provided for search engines and readers without JavaScript. Last reviewed: 2026-09-13.
Exam at a glance
- Questions: 115 (including some unscored pretest items)
- Time: 150 minutes (2 hours 30 minutes)
- Domains & weight: Risk Strategy & Planning 22% · Risk Identification 23% · Risk Analysis 23% · Risk Response 13% · Monitor & Close Risks 19%
- Eligibility: Four-year degree + 36 months risk-management experience + 30 hours education, or secondary diploma + 48 months experience + 40 hours education
The 19 PMI-RMP® ECO tasks (January 2023)
Risk Strategy & Planning (22%, 6 tasks)
- D1T1 — Perform a preliminary document analysis: Gather and review documents (including industry benchmarks, previous lessons learned, historical data, and their sources); Determine and assign who is responsible for the preliminary document analysis; Establish documents relevant to the risk process.
- D1T2 — Assess project environment for threats and opportunities: Determine which OPA/EEF/project methodology is needed (e.g., agile, waterfall, hybrid); Analyze environmental factors in the planning phase (e.g., PESTLE, SWOT analysis); Determine organizational and cultural risk appetite; analyze environment for risk culture maturity (and more).
- D1T3 — Confirm risk thresholds based on risk appetites: Align project risk thresholds to organizational risk appetite; Calculate the risk the organization can absorb (financial, scope, environmental, technical, legal, schedule, quality, contract, etc.); Discuss risk thresholds (and more).
- D1T4 — Establish risk management strategy: Establish risk processes and tools; Provide risk management templates/forms; Determine risk metrics (and more).
- D1T5 — Document the risk management plan: Define organizational risk roles and responsibilities (align with a project RAM/RACI chart); Prepare a list of key artifacts/resources for the risk management plan; Outline key risk management activities (who, what, when, where, how) (and more).
- D1T6 — Plan and lead risk management activities with stakeholders: Collaborate with the team and stakeholders to plan risk management activities; Facilitate risk management workshops and meetings with stakeholders; Build and sustain genuine stakeholder engagement and buy-in in ongoing risk activities (and more).
Risk Identification (23%, 4 tasks)
- D2T1 — Conduct risk identification exercises: Select and apply appropriate risk identification techniques (brainstorming, Delphi technique, interviews, focus groups, checklist analysis, SME consultation); Engage the team and stakeholders in risk identification exercises; Distinguish threats from opportunities during identification (and more).
- D2T2 — Examine assumption and constraint analyses: Identify and document project assumptions and assess their genuine validity; Identify and document project constraints and assess their genuine risk implications; Challenge and test assumptions and constraints with stakeholders rather than accepting them at face value (and more).
- D2T3 — Document risk triggers and thresholds based on context/environment: Identify genuine, observable triggers indicating a risk may be materializing; Define thresholds specifying when a trigger becomes significant enough to warrant escalation or action; Consider the project's specific context and environment when defining relevant triggers and thresholds (and more).
- D2T4 — Develop risk register: Determine an appropriate risk register structure and fields for the project's specific context; Populate the risk register with genuinely well-structured, complete risk entries; Maintain the risk register as a genuinely living document throughout the project (and more).
Risk Analysis (23%, 3 tasks)
- D3T1 — Perform qualitative analysis: Assess risk probability and impact for each identified risk; Apply a probability and impact matrix to prioritize risks; Perform risk data quality assessment (and more).
- D3T2 — Perform quantitative analysis: Select and apply appropriate quantitative analysis techniques based on decision needs; Perform and interpret Monte Carlo simulation results; Calculate and apply Expected Monetary Value (EMV) and decision tree analysis (and more).
- D3T3 — Identify threats and opportunities: Distinguish threats from opportunities within analysis outputs; Assess how identified threats and opportunities affect overall project objectives; Evaluate risk interdependencies and correlations affecting threats and opportunities (and more).
Risk Response (13%, 2 tasks)
- D4T1 — Determine risk response strategies: Select appropriate threat response strategies (avoid, mitigate, transfer, escalate, accept); Select appropriate opportunity response strategies (exploit, enhance, share, accept); Determine overall project-level risk response strategies (and more).
- D4T2 — Implement risk responses: Assign clear ownership for risk response actions to relevant risk owners and action owners; Ensure risk responses are genuinely executed as planned, with appropriate resources and timing; Recognize risk triggers and appropriately activate contingent responses or fallback plans (and more).
Monitor & Close Risks (19%, 4 tasks)
- D5T1 — Gather and analyze performance data: Collect genuine, relevant risk-related performance data and metrics throughout the project; Analyze variance between planned and actual risk exposure or outcomes; Assess genuine risk response effectiveness using collected performance data (and more).
- D5T2 — Monitor residual and secondary risks: Identify and track genuine residual risk remaining after a response has been implemented; Identify and track genuine secondary risks arising from implemented risk responses; Determine whether further response action is genuinely warranted for residual or secondary risk (and more).
- D5T3 — Provide information required to update relevant project documents: Provide genuinely accurate, timely information to update the risk register based on monitoring findings; Provide information to update the lessons learned register with genuine risk-related insights; Provide information to update other relevant project documents (e.g., issue log, schedule, budget documentation) (and more).
- D5T4 — Monitor project risk levels: Track genuine overall aggregate project risk exposure trends over time; Compare current genuine risk exposure against organizational thresholds and risk appetite; Identify genuinely emerging risks and changes in the overall project risk landscape (and more).
Sample PMI-RMP® practice questions
Why should a risk manager review historical data and lessons learned from similar past projects before beginning risk identification on a new project? (Risk Strategy & Planning — Perform a preliminary document analysis)
Answer: Historical information helps surface risk categories and patterns that genuinely recurred in comparable past work, informing a more complete initial risk identification effort
Genuinely similar past projects often reveal recurring risk patterns worth considering — a substantive practice (not mere formality), and relevant to projects of varying scale, not only very large ones.
Why should a risk manager assess which organizational process assets (OPAs) and enterprise environmental factors (EEFs) are genuinely relevant before beginning risk planning? (Risk Strategy & Planning — Assess project environment for threats and opportunities)
Answer: OPAs and EEFs shape the actual context within which risk must be managed, and identifying them early ensures the risk approach is genuinely grounded in real organizational and environmental realities
Genuinely understanding OPAs/EEFs grounds risk planning in real context — a substantive practice (not mere formality), and this concern applies to projects of varying organizational sizes.
What is the key distinction between an organization's 'risk appetite' and a project's 'risk threshold'? (Risk Strategy & Planning — Confirm risk thresholds based on risk appetites)
Answer: Risk appetite is a general, broad disposition toward risk-taking, while a risk threshold is a specific, measurable limit that translates that appetite into actionable project boundaries
This is the foundational distinction — appetite is general disposition, threshold is specific and actionable — a real, meaningful difference, and this distinction matters regardless of whether a formal enterprise risk management framework exists.
Why should a risk manager establish clear, defined risk processes and select appropriate tools early when establishing a risk management strategy? (Risk Strategy & Planning — Establish risk management strategy)
Answer: Clear processes and tools provide the team with a consistent, repeatable way to identify, analyze, and respond to risk throughout the project
Clear, consistent processes/tools genuinely support repeatable risk management — a substantive practice (not mere formality), tailored to context (not identical across every project), and relevant to projects of varying sizes.
Why should a risk management plan explicitly define organizational risk roles and responsibilities, rather than leaving them ambiguous? (Risk Strategy & Planning — Document the risk management plan)
Answer: Clear roles and responsibilities reduce the risk of important risk management activities falling through the cracks due to diffused, unclear ownership
Clear roles genuinely reduce the risk of neglected activities due to diffused responsibility — a substantive practice (not mere formality), distributed responsibility (not concentration in one person) is often appropriate, and this concern applies to projects of varying sizes.
Why should a risk manager collaborate with the team and relevant stakeholders when planning risk management activities, rather than planning them alone? (Risk Strategy & Planning — Plan and lead risk management activities with stakeholders)
Answer: Genuine collaboration draws on the team's and stakeholders' direct knowledge, producing a more realistic and well-supported plan for risk management activities
Genuine collaboration draws on real, relevant knowledge producing a more realistic plan — a substantive practice (not mere formality), collaborative input matters (not solely the risk manager's own judgment), and this applies to teams of varying sizes.
Why should a risk manager select from a range of different risk identification techniques (e.g., brainstorming, interviews, checklist analysis) rather than always using a single default technique? (Risk Identification — Conduct risk identification exercises)
Answer: Different techniques genuinely surface different types of risk insight, so varying the technique based on context improves the overall comprehensiveness of identification
Different techniques genuinely surface different insight, so context-appropriate variation improves comprehensiveness — a substantive practice (not mere formality), and this concern applies to projects of varying sizes.
Why should a risk manager explicitly identify and document a project's underlying assumptions as part of risk identification, rather than leaving them implicit? (Risk Identification — Examine assumption and constraint analyses)
Answer: Explicit assumptions can be genuinely examined for fragility, whereas implicit, unexamined assumptions risk silently exposing the project to unrecognized risk
Making assumptions explicit allows genuine examination for fragility — implicit assumptions risk silent, unrecognized exposure, a substantive concern (not mere formality), and this applies to assumptions from any source, not solely the charter, and regardless of a formal ERM framework's existence.
What is a 'risk trigger,' as distinct from the risk itself? (Risk Identification — Document risk triggers and thresholds based on context/environment)
Answer: A trigger is an observable signal, condition, or event that indicates a risk may genuinely be starting to materialize, rather than the risk's own underlying cause or eventual consequence
A trigger is specifically the observable signal of emerging materialization — distinct from both the risk's cause and its consequence, not identical to the risk itself, and relevant before (not only after) full materialization into an issue.
Why should a risk manager determine an appropriate risk register structure tailored to the project's specific context, rather than always using an identical, generic template? (Risk Identification — Develop risk register)
Answer: Different projects have genuinely different risk profiles and complexity levels, so a tailored structure better captures the information that is actually genuinely relevant to this specific project
Genuinely different risk profiles and complexity levels call for a tailored structure — a substantive practice (not mere formality), a universal structure ignores real contextual differences, and this concern applies regardless of a formal ERM framework's existence.
What is the PRIMARY purpose of assessing a risk's probability and impact during qualitative analysis? (Risk Analysis — Perform qualitative analysis)
Answer: To evaluate the likelihood of a risk occurring and its potential effect on project objectives, supporting prioritization for further action
Probability and impact assessment specifically evaluates likelihood and consequence to support prioritization — not related to budgeting, individual task assignment, or eliminating stakeholder engagement.
Why should a risk manager select a quantitative analysis technique based on the specific decision need, rather than always defaulting to the most sophisticated available technique? (Risk Analysis — Perform quantitative analysis)
Answer: PMI guidance emphasizes that quantitative techniques should be chosen because they answer a genuine decision need, not because a more sophisticated technique simply sounds more advanced
Technique selection should genuinely match the decision need — sophistication for its own sake doesn't guarantee more valuable insight, this is a substantive practice (not mere formality), and applies regardless of a formal ERM framework's existence.
Why is it important to explicitly distinguish threats from opportunities within the outputs of qualitative and quantitative risk analysis, rather than treating all analyzed risks identically? (Risk Analysis — Identify threats and opportunities)
Answer: Threats and opportunities warrant genuinely different response strategies and stakeholder framing, so failing to distinguish them risks a less effective, less appropriately targeted overall approach
Genuinely different response strategies for threats versus opportunities make this distinction important — a substantive practice (not mere formality), opportunities are a legitimate part of analysis (not something to exclude), and this concern applies regardless of a formal ERM framework's existence.
A risk manager decides to eliminate a threat entirely by removing its underlying cause (e.g., canceling a risky scope element). Which threat response strategy does this represent? (Risk Response — Determine risk response strategies)
Answer: Avoid, since this strategy specifically involves eliminating the threat or protecting the project from its impact by removing the cause
Eliminating a threat by removing its cause is the defining characteristic of the Avoid strategy — Mitigate reduces (not eliminates), Transfer shifts ownership (not elimination), and Accept takes no proactive elimination action.
Why should a risk manager ensure a clear, specific individual (risk owner or action owner) is assigned responsibility for implementing a given risk response, rather than leaving this responsibility ambiguous? (Risk Response — Implement risk responses)
Answer: Clear ownership creates genuine accountability, reducing the risk that a planned response is never actually implemented due to diffused, unclear responsibility
Clear ownership genuinely reduces the risk of neglected implementation due to diffused responsibility — a substantive practice (not mere formality), specific individual accountability (not purely collective) is important, and this concern applies to responses of varying financial scale.
Key risk management terms
- Risk Appetite: The general, broad disposition an organization has toward risk-taking, forming the basis for more specific project risk thresholds.
- Risk Threshold: A specific, measurable limit that translates organizational risk appetite into actionable boundaries for a particular project.
- Risk Breakdown Structure (RBS): A hierarchical framework organizing potential sources of risk into categories, supporting comprehensive risk identification.
- Risk Register: The central document capturing each identified risk's cause, trigger, consequence, probability, impact, response, and owner.
- Cause-Trigger-Consequence Model: A structured way to document a risk's underlying cause, observable trigger, and potential effect on objectives.
- Risk Trigger: An observable signal, condition, or event indicating that a risk may be starting to materialize.
- Risk Threshold Escalation: The point at which a trigger becomes significant enough to warrant a defined escalation or action.
- Probability and Impact Matrix: A structured, visual tool combining a risk's probability and impact ratings into an overall priority level.
- Risk Data Quality Assessment: Evaluating the reliability, accuracy, and genuine understanding underlying data used for risk analysis.
- Expected Monetary Value (EMV): A risk's probability multiplied by its monetary impact, producing a probability-weighted expected value.
- Decision Tree Analysis: A visual technique mapping decision points, probabilities, and monetary outcomes to compare competing alternatives.
- Monte Carlo Simulation: A quantitative technique modeling a distribution of possible project outcomes through many randomly sampled iterations.
- Sensitivity Analysis: A technique identifying which uncertain input variables most significantly affect an overall project outcome.
- Tornado Diagram: A visual chart ranking variables by their relative effect on an outcome, from most to least influential.
- Threat Response: Avoid: A strategy eliminating a threat or protecting the project from its impact by removing the underlying cause.
- Threat Response: Mitigate: A strategy reducing (not eliminating) a threat's probability or impact to an acceptable level.
- Threat Response: Transfer: A strategy shifting a threat's impact and ownership to a third party, such as through insurance or a contract.
- Threat Response: Escalate: A strategy raising a risk to a level of management or authority better positioned to address it.
- Opportunity Response: Exploit: A strategy taking action to ensure an opportunity's positive outcome genuinely materializes with certainty.
- Opportunity Response: Enhance: A strategy proactively increasing an opportunity's probability or impact without guaranteeing its occurrence.
- Opportunity Response: Share: A strategy allocating ownership of an opportunity to a third party better positioned to help capture it.
- Contingent Response: A predefined action plan implemented only if a specific, defined trigger condition is reached.
- Fallback Plan: A secondary, alternative plan activated if a primary contingent response proves insufficient.
- Residual Risk: The risk exposure that remains after a response has been implemented, since most responses reduce rather than eliminate exposure.
- Secondary Risk: A new risk that arises specifically as a direct result of implementing a response to an existing risk.
- Risk Owner: The individual accountable overall for a specific identified risk, who may differ from the action owner executing a response.
- Contingency Reserve: Funds or time set aside to address the cost or schedule impact of known, identified risks.
- Management Reserve: Funds or time set aside for genuinely unknown, unidentified risks, distinct from contingency reserve for known risks.
- Variance Analysis: Comparing planned versus actual risk exposure or outcomes to assess whether performance is tracking as expected.
- Trend Analysis: Examining patterns across successive performance measurements over time to reveal direction of change.
- Root Cause Analysis: Investigating the genuine underlying reason behind an observed risk or performance pattern, such as through the '5 Whys' technique.
- Risk Urgency: How soon a risk's trigger might occur and how much lead time is needed to prepare an effective response, distinct from overall priority.
- Stakeholder Risk Tolerance: The degree of risk exposure a specific stakeholder or stakeholder group is willing to accept.
- Risk Communication Plan: A defined approach for how risk-related information will be shared with different stakeholder audiences.
- Assumption and Constraint Analysis: Examining project assumptions and constraints to assess their validity and translate fragile ones into identified risk exposure.
- Delphi Technique: An anonymous, iterative expert-judgment technique used to build consensus on a risk without direct confrontation.
- Risk Category: A grouping (e.g., technical, external, organizational) used to organize identified risks and reveal systemic patterns.
- Watch List: A status for lower-priority risks that don't currently warrant active management but merit continued observation.
- Risk Culture Maturity: The degree to which an organization proactively and openly discusses and manages risk versus reactively surfacing issues.
- Aggregate Risk Exposure: The combined, portfolio-level view of probability-weighted risk across an entire project's risk register.
Frequently asked questions
How many questions are on the PMI-RMP exam?
The exam has 115 questions (including some unscored pretest items) and you have 150 minutes (2 hours 30 minutes) to complete it.
What are the five domains and their weights?
Risk Strategy & Planning 22%, Risk Identification 23%, Risk Analysis 23%, Risk Response 13%, and Monitor & Close Risks 19%.
What are the eligibility requirements for the PMI-RMP?
With a four-year degree: 36 months of risk-management experience within the last five years plus 30 hours of risk-management education. With a secondary diploma: 48 months of experience plus 40 hours of education.
Which domain should I focus on most?
Risk Identification and Risk Analysis are tied at 23% each, the largest domains, so both deserve strong study time, alongside Risk Strategy & Planning at 22%.
Is the PMI-RMP Prep Hub free?
Yes. All 1,500 practice questions, flashcards, 50 case studies, and 5 mock exams are free to use in any modern browser, with progress saved locally on your device.
How should I study for the PMI-RMP exam?
Study by ECO domain, task, and enabler, drill the practice bank with detailed explanations, use flashcards for active recall, review case studies, and take full-length timed mock exams until you consistently score around 75% or higher.
PMI-RMP, PMP, CAPM, PMI-ACP and PMI are registered marks of the Project Management Institute, Inc. This is an independent study resource and is not affiliated with or endorsed by PMI.