PMI-RMP (Risk Management Professional) Practice Exam
Cover all five PMI-RMP domains — risk strategy and planning, identification, analysis, response, and monitoring and closing — with scenario-based questions, instant feedback in Learn mode, and a full timed simulation in Exam mode. Start with a 24-hour free trial.
Start 24-hour free trial →PMI-RMP exam at a glance
- Vendor
- Project Management Institute (PMI)
- Exam name
- PMI Risk Management Professional (PMI-RMP)®
- Blueprint
- PMI-RMP Examination Content Outline (updated January 2023), supported by The Standard for Risk Management in Portfolios, Programs, and Projects (2019) and the PMBOK® Guide; verify edition before publish
- Format
- 115 questions (100 scored, 15 unscored pretest), multiple-choice and multiple-answer-select
- Duration
- 150 minutes (2.5 hours), with one optional 10-minute break
- Delivery
- Pearson VUE test center or online proctored
- Passing standard
- PMI does not publish a fixed passing score; performance is reported by domain (Above Target to Needs Improvement) and the overall result as pass or fail
- Prerequisites
- One of: secondary diploma + 36 months of risk-management experience + 40 contact hours of risk education; OR a four-year degree + 24 months of risk-management experience + 30 contact hours. Experience must be recent (within the last five years).
- Validity
- 3 years; renew with 30 PDUs
Source: PMI — PMI-RMP Certification Handbook & Exam Content Outline. Verify current details with PMI before applying.
About the PMI-RMP (Risk Management Professional) certification
The PMI-RMP is PMI’s specialist credential for project risk practitioners — the people who identify threats and opportunities early, quantify them, and shape responses before they hit the project. Where the PMP treats risk as one knowledge area, the PMI-RMP goes deep into the full risk lifecycle: setting risk strategy and thresholds, building the risk register, qualitative and quantitative analysis (including Monte Carlo simulation), response planning, and ongoing monitoring. Importantly, the exam treats risk as two-sided — capitalizing on opportunities, not just mitigating threats. For foundational reading on the delivery discipline risk management supports, see the Program & Project Management Fundamentals guide.
PowerKram’s PMI-RMP practice exam mirrors the scenario style of the real test and maps every question to one of the five domains, so your score report tells you exactly which area — strategy, identification, analysis, response, or monitoring — to strengthen.
PMI-RMP exam domains and weights
The PMI-RMP exam splits questions across five domains. The weighting is fairly even across the front of the risk lifecycle — Identification and Analysis each carry 23%, and Strategy & Planning 22% — reflecting that most of a risk professional’s value is created before a risk ever materializes.
Preliminary document analysis, assessing the project environment (PESTLE, SWOT), confirming risk thresholds against organizational risk appetite, and documenting the risk management plan.
Running identification exercises, examining assumptions and constraints, documenting risk triggers and thresholds, and building the risk register — classifying each risk as a threat or an opportunity.
Qualitative analysis (probability-and-impact, prioritization) and quantitative analysis (Monte Carlo simulation, sensitivity, expected monetary value) to understand exposure and rank risks.
Planning and implementing responses — avoid, transfer, mitigate, accept for threats; exploit, share, enhance, accept for opportunities — and managing the secondary and residual risks they create.
Tracking risk triggers and changing exposure, evaluating response effectiveness, reporting risk to stakeholders, and closing risks that are no longer relevant.
Weights are domain-level item percentages from the official outline. Source: PMI-RMP Examination Content Outline (updated Jan 2023).
Who the PMI-RMP is for
The PMI-RMP is a specialist credential, and its eligibility reflects dedicated risk experience rather than general project management. Every path requires risk-specific experience and risk-specific education — this is for people who actually practice risk management, not just manage projects that happen to have risks.
- Project risk managers and risk analysts formalizing deep expertise in the full risk lifecycle.
- Project and program managers on large, complex, or high-uncertainty projects where risk is a dedicated discipline.
- PMO and governance staff responsible for risk registers, risk reporting, and organizational risk appetite.
- Schedulers, cost engineers, and planners who run quantitative risk analysis such as Monte Carlo on schedule and cost.
If you want the broad project-management foundation first, the PMP pairs naturally with the PMI-RMP, and the PMP covers risk as one of its knowledge areas. For role-by-role salary ranges and the risk and controls career paths the PMI-RMP supports, see the Career Hub — Product Manager role guide.
What this PMI-RMP practice exam delivers
Learn mode
Get the correct answer, the explanation, and why the other choices were wrong — immediately after each question. Ideal for the subtle distinctions the PMI-RMP tests, like secondary vs residual risk.
Exam mode
115 questions on the real 150-minute clock, including the multiple-answer-select items — build the pacing and judgment the actual PMI-RMP exam requires.
Source-linked explanations
Every answer cites the PMI source it derives from (the Exam Content Outline or The Standard for Risk Management in Portfolios, Programs, and Projects) so you can verify and dig deeper.
Score by PMI-RMP domain
Your results break down across all five domains — weighted as on the real exam — so practice shows exactly which part of the risk lifecycle to focus on.
Sample PMI-RMP practice questions
Ten free questions across the five domains, with full explanations. The complete bank is available with the 24-hour trial.
A project manager identifies a newly surfaced threat of a supplier delay. Before committing resources to a response, what should be done first?
- Perform qualitative risk analysis to assess its probability and impact
- Immediately implement a contingency plan
- Terminate the supplier
- Wait until the delay actually occurs
Show answer & explanation
Correct: A — Qualitative risk analysis first. Once a risk is identified, the next step is to assess its probability and impact so it can be prioritized. Analysis precedes response — you cannot choose a proportionate response without first understanding the exposure.
Why not the others: jumping to a contingency plan (B) commits resources before the risk is sized; terminating the supplier (C) is a drastic response chosen with no analysis; waiting for the delay (D) abandons risk management entirely.
Source: PMI-RMP Exam Content Outline — Risk Analysis → Further reading: PowerKram — Qualitative Risk Analysis →A team needs to prioritize a long list of identified risks quickly. Which tool supports this prioritization?
- A probability-and-impact matrix
- A Gantt chart
- A work breakdown structure (WBS)
- A stakeholder register
Show answer & explanation
Correct: A — Probability-and-impact matrix. The P×I matrix ranks risks by combining how likely each is with how severe its effect would be, giving a fast, defensible prioritization to focus attention and response effort.
Why not the others: a Gantt chart (B) shows schedule timing; a WBS (C) decomposes scope; a stakeholder register (D) records people — none ranks risk severity.
Source: PMI-RMP Exam Content Outline — Risk Analysis →A stakeholder asks how a risk differs from an issue. What is the key distinction?
- A risk is a potential future event; an issue is a problem that has already occurred
- Risks are always resolved, while issues are always ignored
- Risks are documented, while issues never are
- Risks are financial, while issues are technical
Show answer & explanation
Correct: A — Risk = future uncertainty; issue = present problem. A risk is an uncertain event that may happen and is tracked in the risk register; an issue is something that has happened and is tracked in the issue log and managed now.
Why not the others: B, C, and D invent distinctions that don’t hold — both risks and issues are documented, and neither is defined by being financial vs technical or resolved vs ignored.
Source: PMI-RMP Exam Content Outline — Risk Identification → Further reading: PowerKram — Risks vs Issues →A manager wants to transfer the financial consequence of a specific threat to a third party. Which response strategy does this?
- Transfer the risk (e.g., purchase insurance or a performance bond)
- Accept the risk
- Avoid the activity entirely
- Increase the contingency reserve
Show answer & explanation
Correct: A — Transfer. Transfer shifts the financial impact (and often ownership) of a threat to a third party — insurance, warranties, or contractual terms. The risk still exists, but its financial consequence is borne by someone else.
Why not the others: accept (B) keeps the consequence in-house; avoid (C) eliminates the risk by not doing the activity, not transferring it; increasing contingency (D) is a form of active acceptance, not transfer.
Source: PMI-RMP Exam Content Outline — Risk Response →A team needs to quantify the combined effect of many uncertain variables on the project completion date. Which technique is most appropriate?
- Monte Carlo simulation
- SWOT analysis
- MoSCoW prioritization
- A RACI matrix
Show answer & explanation
Correct: A — Monte Carlo simulation. Monte Carlo is a quantitative technique that runs thousands of iterations across the ranges of uncertain inputs to produce a probability distribution of outcomes — for example, the likelihood of finishing by a given date.
Why not the others: SWOT (B) is a qualitative context tool; MoSCoW (C) prioritizes requirements; a RACI matrix (D) assigns responsibilities — none produces a quantitative outcome distribution.
Source: PMI-RMP Exam Content Outline — Risk Analysis (quantitative) → Further reading: PowerKram — Quantitative Risk Analysis →During planning, a risk manager needs to set the level of risk exposure the organization is willing to accept on the project. What is this called?
- Confirming risk thresholds aligned to the organization’s risk appetite
- Ignoring risks until they occur
- Freezing the project scope
- Delegating all risk decisions to stakeholders
Show answer & explanation
Correct: A — Confirm risk thresholds against risk appetite. A core planning task is translating the organization’s risk appetite into measurable thresholds (cost, schedule, quality) that define how much exposure is acceptable and when to escalate.
Why not the others: ignoring risks (B) is the opposite of planning; freezing scope (C) is a scope action, not a risk threshold; delegating all decisions (D) abdicates the risk manager’s role.
Source: PMI-RMP Exam Content Outline — Risk Strategy and Planning → Further reading: PowerKram — Risk Appetite & Thresholds →A risk manager wants to track risk triggers and the agreed responses throughout the project. Which document holds this information?
- The risk register
- The issue log
- The project charter
- The stakeholder register
Show answer & explanation
Correct: A — The risk register. The risk register is the living record of identified risks along with their probability, impact, owners, triggers, and planned responses — the primary artifact for monitoring risk over the life of the project.
Why not the others: the issue log (B) tracks problems that have already occurred; the project charter (C) authorizes the project; the stakeholder register (D) records stakeholders — none tracks risk triggers and responses.
Source: PMI-RMP Exam Content Outline — Monitor and Close Risks →After implementing risk responses, a team reviews the exposure that remains. What are these called?
- Residual risks — the exposure that remains after responses are implemented
- Risks that were ignored during planning
- Risks that were fully transferred to vendors
- Risks that have no possible mitigation
Show answer & explanation
Correct: A — Residual risks. Residual risk is the exposure left over after a response has been applied — no response eliminates risk entirely, so the remaining portion is documented, accepted, or managed further. (Contrast with a secondary risk, which is a new risk created by a response.)
Why not the others: ignored risks (B) were never assessed; fully transferred risk (C) describes a transfer response, not what remains after responses generally; “no possible mitigation” (D) is not the definition of residual risk.
Source: PMI-RMP Exam Content Outline — Risk Response → Further reading: PowerKram — Residual vs Secondary Risk →A stakeholder asks what defines a secondary risk. Which description is correct?
- A new risk that arises directly from implementing a response to another risk
- Any risk with a low probability of occurring
- A risk that is unrelated to the project
- A risk that was identified late in the project
Show answer & explanation
Correct: A — A risk created by a response. A secondary risk is one that the response itself introduces — for example, outsourcing a task (a transfer response) creates a new vendor-dependency risk. They must be identified and managed like any other risk.
Why not the others: low probability (B), unrelated (C), and late-identified (D) describe attributes or timing of risks generally, not the cause-by-response relationship that defines a secondary risk.
Source: PMI-RMP Exam Content Outline — Risk Response →A risk manager wants to communicate current risk exposure and response status to project stakeholders. Which artifact is designed for this?
- A risk report
- A change log
- A work breakdown structure (WBS)
- A test case
Show answer & explanation
Correct: A — A risk report. The risk report summarizes overall project risk exposure and the status of significant individual risks and responses, making it the primary vehicle for communicating risk to stakeholders and leadership.
Why not the others: a change log (B) tracks change requests; a WBS (C) decomposes scope; a test case (D) is a quality artifact — none communicates risk exposure.
Source: PMI-RMP Exam Content Outline — Monitor and Close Risks →Keep going: Learning & Career resources
A risk credential earns its return when paired with the broader delivery fundamentals and a clear sense of the risk and controls roles it opens up. Two PowerKram hubs back this exam up.
Deep dive: PMI-RMP exam structure, eligibility, study path & recertification
Exam structure and how it’s scored
The PMI-RMP exam delivers 115 questions in 150 minutes (2.5 hours), with one optional 10-minute break roughly halfway. Of the 115, 100 are scored and 15 are unscored pretest items mixed in randomly, so treat every question with equal effort. Questions are multiple-choice and multiple-answer-select (pick-the-correct-several), and span predictive, agile, and hybrid contexts. PMI does not publish a fixed passing percentage; results are reported by domain on an Above-Target-to-Needs-Improvement scale, with an overall pass or fail. Read the risk fundamentals guide →
Eligibility paths
The PMI-RMP has two main eligibility paths, both requiring risk-specific (not general project-management) experience plus risk-specific education. With a secondary diploma you need 36 months of risk-management experience and 40 contact hours of risk education; with a four-year degree, 24 months and 30 contact hours. Experience must be reasonably recent. Because the experience must be specialized risk work, candidates sometimes need to document their risk responsibilities carefully — PMI audits a share of applications. Read the risk-career guide →
Realistic study path
The core references are PMI’s The Standard for Risk Management in Portfolios, Programs, and Projects (2019) and the PMBOK® Guide — but the Exam Content Outline should drive your plan, because the PMI-RMP goes deeper than the PMBOK® risk chapters. Be fluent in the distinctions the exam loves to test (risk vs issue, secondary vs residual risk, qualitative vs quantitative analysis, threat vs opportunity responses) and comfortable with the concepts behind Monte Carlo and expected monetary value. PowerKram’s domain-level scoring surfaces your weakest domain early. Read the risk study guide →
Cost, scheduling, and retake policy
The PMI-RMP exam fee is reduced for PMI members, and membership includes access to The Standard for Risk Management and the PMBOK® Guide. The exam is delivered at Pearson VUE centers or online with a proctor. You may attempt the exam up to three times within your one-year eligibility period. Verify current fees and policies on PMI’s site before applying. PMI’s official PMI-RMP page →
Recertification (PDUs)
The PMI-RMP is valid for three years. To renew, you earn 30 Professional Development Units (PDUs) within the Continuing Certification Requirements (CCR) cycle — the same lighter requirement as PMI’s other specialist credentials, and half the PMP’s 60. Risk work, courses, webinars, and risk communities all count. PMI’s CCR Handbook is the authoritative reference. Read the PDU and recertification guide →
Career outlook for PMI-RMP holders
Poorly managed risk is one of the most common reasons projects overrun on cost and schedule, which makes credible risk expertise valuable — especially on large, complex programs in construction, engineering, energy, finance, and defense. The PMI-RMP signals depth that a generalist credential does not, helping practitioners stand out for project risk manager, risk analyst, and project controls roles. For salary ranges and role-specific paths, see the Career Hub. Career Hub — Product Manager role →
Start your free 24-hour PMI-RMP practice trial
Full access to the question bank, both study modes, and domain-level scoring across all five PMI-RMP domains. No credit card required.
Start free trial →