CTFL 5.2.4: Explain what measures can be taken in response to analyzed product risks
K2Syllabus section 5.2.4
3 original PrepBench practice questions for learning objective 5.2.4 of the CTFL 4.0 syllabus. Try the examples below and check each answer against its syllabus reference.
Practice questions
Question 1
A product risk analysis has rated the payment module as high risk. Which of the following is an action for mitigating a product risk by testing?
- Transferring the risk to the supplier who provides the payment component
- Recording the risk in the risk register and monitoring whether it changes
- Selecting testers whose experience and skills suit this type of risk
- Preparing a contingency plan for payment failures that emerge after release
Show answer
- Transferring the risk to the supplier who provides the payment componentRisk transfer is a separate response option, not an action that mitigates by testing.
- Recording the risk in the risk register and monitoring whether it changesMonitoring is the other half of risk control, alongside mitigation.
- Correct answer: Selecting testers whose experience and skills suit this type of riskChoosing testers whose experience suits the risk type is a named action.
- Preparing a contingency plan for payment failures that emerge after releaseA contingency plan is a separate risk response, not mitigation by testing.
The actions the syllabus names for mitigating product risks by testing are: selecting testers with the right level of experience and skills for the given risk type, applying an appropriate level of independence of testing, performing reviews and static analysis, applying appropriate test techniques and coverage levels, applying test types addressing the affected quality characteristics, and performing dynamic testing including regression testing.
Syllabus section 5.2.4
Question 2
Product risk control consists of which two activities?
- Risk identification and risk assessment
- Risk categorization and risk prioritization
- Risk mitigation and risk monitoring
- Risk transfer and risk acceptance
Show answer
- Risk identification and risk assessmentIdentification and assessment make up risk analysis, not risk control.
- Risk categorization and risk prioritizationCategorization and prioritization are part of risk assessment, not risk control.
- Correct answer: Risk mitigation and risk monitoringRisk control consists of risk mitigation and risk monitoring.
- Risk transfer and risk acceptanceTransfer and acceptance are response options, not the two parts of risk control.
Product risk control comprises all measures taken in response to identified and assessed product risks, and consists of risk mitigation (implementing the proposed actions to reduce the risk level) and risk monitoring (ensuring the mitigations are effective and identifying emerging risks).
Syllabus section 5.2.4
Question 3
Besides mitigation by testing, which of the following is a response option to an analyzed product risk?
- Risk categorization, so that similar risks receive similar mitigation actions
- Risk transfer, in which the risk is passed to another party
- Risk identification, so that a comprehensive list of risks is generated
- Risk assessment, in which likelihood, impact and risk level are determined
Show answer
- Risk categorization, so that similar risks receive similar mitigation actionsCategorization is part of risk assessment, not a response to an analyzed risk.
- Correct answer: Risk transfer, in which the risk is passed to another partyRisk transfer is named among the response options.
- Risk identification, so that a comprehensive list of risks is generatedRisk identification is the first part of product risk analysis.
- Risk assessment, in which likelihood, impact and risk level are determinedRisk assessment is the second part of product risk analysis.
Once a risk has been analyzed, several response options are possible, for example risk mitigation by testing, risk acceptance, risk transfer, or a contingency plan. The other three options are all steps within product risk analysis rather than responses to an analyzed risk: identification generates the list, assessment determines likelihood, impact and level, and categorization helps assign mitigation actions.
Syllabus section 5.2.4
Original PrepBench practice material, not official exam questions or exam dumps. PrepBench is independent and is not affiliated with or endorsed by ISTQB®.