Most risk questions on the PMP exam do not ask you what a risk is. They hand you a situation that has already been analyzed — the risk is identified, the probability is roughly known, the impact is described — and ask what you do about it. The answer options are usually four legitimate-sounding responses, and only one of them fits the scenario as written.
That is a narrow skill, and it is learnable. There are only ten response strategies. What separates candidates who get these right from candidates who guess is not knowing the list; it is knowing which two details in the scenario decide which item on the list applies.
The ten strategies
Five apply to threats and five to opportunities, and they pair up neatly.
| Threats | Opportunities | What you are doing |
|---|---|---|
| Avoid | Exploit | Making the outcome certain — removing the threat, or guaranteeing the upside |
| Mitigate | Enhance | Changing the numbers — reducing probability or impact, or increasing them |
| Transfer | Share | Bringing in a third party who is better placed to carry it |
| Accept | Accept | Taking no action now, and deciding in advance what happens if it occurs |
| Escalate | Escalate | Handing it to someone with the authority you do not have |
PM Study Circle's summaries of the threat and opportunity strategies define them along these lines: avoid eliminates the threat or protects the project from its impact, mitigate reduces likelihood or impact, transfer shifts impact to a third party, and accept means taking no action unless the risk occurs. On the opportunity side, exploit takes definitive action to make sure the opportunity is realized rather than merely attempted, enhance increases the likelihood that it happens, and share partners with another organization to realize something you could not realize alone.
Read the middle column rather than memorizing the words. Almost every wrong answer on these items is a strategy from the correct row's neighbours — mitigate offered where the scenario demands avoid, share offered where the scenario demands exploit.
The two questions that decide the answer
Do you have the authority to act?
This is the question that decides whether escalate is correct, and escalate is the most misread option on the list. PM Study Circle describes it as seeking help from outside the project team when the team lacks the authority or resources to respond. Note what that does not say. It is not the strategy for risks that are large, frightening, or politically awkward. It is the strategy for risks that sit outside your control — a regulatory change, an enterprise-wide vendor decision, a risk whose owner is another department.
The trap runs in both directions. Some questions describe a risk the project manager can clearly handle and offer escalation as a tempting show of diligence; escalating there is wrong, because it moves work to someone who did not need to receive it. Other questions describe a risk that plainly exceeds the project's boundary and offer four ways to handle it in-house; all four are wrong.
A useful habit: before choosing, say out loud who owns the thing that has to change. If that person is not on your project, escalate.
Are you changing the risk, or planning for it?
Avoid, mitigate, exploit and enhance all change the risk itself — they alter the plan so the probability or the impact is different. Accept changes nothing about the risk and instead prepares the project for it.
Acceptance splits two ways, and the distinction is tested. Passive acceptance means documenting the risk and doing nothing further. Active acceptance means setting aside a contingency reserve so that if the risk occurs, the project can absorb it. When a scenario says the team decided to accept a risk and then asks what should happen next, the answer usually involves a reserve and a monitoring plan — not a shrug.
Reserves, which the exam treats as a precision question
Reserve questions are among the few in risk management with an unambiguous right answer, so they are worth getting exactly right. PM Study Circle's comparison lays out the distinction:
- Contingency reserve covers known unknowns — identified risks documented in the risk register. It is typically controlled by the project manager and it sits inside the cost baseline.
- Management reserve covers unknown unknowns — events nobody identified in advance. It requires sponsor or senior management approval, and it sits above the cost baseline rather than inside it.
The arithmetic that follows is what questions test: cost estimate plus contingency reserve gives the cost baseline, and cost baseline plus management reserve gives the project budget. If a question asks whether a particular drawdown needs sponsor approval, you are being asked which reserve it comes from, and the answer depends on whether the risk was in the register.
When the question gives you numbers
Some risk items are not judgment calls at all. If a scenario supplies probabilities and dollar impacts, it usually wants expected monetary value. The calculation is probability multiplied by impact — a 40 percent chance of a $10,000 loss is an EMV of −$4,000, as the worked example in Agile Seekers' write-up of EMV and decision trees puts it. Decision tree analysis extends the same arithmetic across a branching set of choices: map the outcomes for each path, assign a probability and a value to each, total the EMV per path, and choose the path with the highest or least negative result.
The framing matters more than the multiplication. PMP Road's discussion of how risk is tested on the updated exam makes the point that EMV functions as a comparison tool — you are weighing one response option against another, not producing a number in isolation. Two responses that both reduce exposure can differ in cost, and the question is which leaves the project better off overall.
Residual and secondary risk
Two follow-on concepts turn up as distractors often enough to be worth naming. Residual risk is what remains after a response has been applied; mitigation in particular usually leaves some exposure behind, ideally inside tolerance. Secondary risk is a new risk created by the response itself — transferring work to a subcontractor removes one exposure and introduces contract and quality exposures that were not there before.
When an answer option says the risk is now closed because a response was implemented, treat it with suspicion. Responses change risks. They rarely delete them.
What the updated exam adds to this
PMI launched the updated PMP exam on 9 July 2026, and describes the update as including case and scenario-based questions alongside graphic-based questions. For risk items, PMP Road notes that this can mean being shown an artifact — a probability-impact matrix, a risk register extract — and asked what it tells you, rather than being given the same information as prose.
That changes the reading task, not the decision task. The two questions above still decide the answer. It does mean practice should include looking at a populated register or matrix and forming a judgment from it, because doing that for the first time under exam timing is slower than it needs to be.
How to practice this
Take any risk question you get wrong and write one sentence: which of the ten strategies was correct, and which detail in the scenario made it correct. After twenty or thirty of those, the patterns become visible — most people find they have one specific failure mode, usually escalating too readily or reaching for mitigate as a default.
Then work the reserve and EMV mechanics separately, as arithmetic drills rather than as scenarios. They are reliable points, and unlike judgment items, you can verify your own answer.