IT Practice Exams

PK0-005 · Project Management Concepts · Updated July 26, 2026

Qualitative Risk Analysis: Probability-Impact Scoring and Choosing a Response

Qualitative risk analysis ranks a project’s risks by rating each one on simple scales for probability (how likely it is to occur) and impact (how bad it would be if it did), then combining the two ratings — usually by multiplying them — into a single score used to prioritize attention. It is fast, subjective by design, and typically the first analysis pass after risks are identified. For PK0-005 you need to be able to compute a score, read a probability-impact matrix, tell qualitative from quantitative analysis, and connect a high-priority risk to the right response strategy.

How probability-impact scoring works

Each identified risk gets two ratings on an agreed scale — commonly 1 to 5, where 1 is low and 5 is high:

  • Probability: the team’s judgment of how likely the risk event is.
  • Impact: the team’s judgment of the damage to scope, schedule, cost, or quality if it happens.

The risk score is the product of the two. A risk rated 4 for probability and 3 for impact scores 4 × 3 = 12. On a 1–5 scale the scores range from 1 (rare and trivial) to 25 (near-certain and severe), and sorting the register by score instantly shows which risks deserve response planning first. The exam does occasionally ask you to do this arithmetic, so remember: multiply, don’t add.

The visual companion is the probability-impact matrix (also called a risk matrix or heat map): a grid with probability on one axis and impact on the other, with cells color-coded — typically green for low scores, yellow for moderate, red for high. Plotting risks on the grid lets stakeholders see the danger zone at a glance without reading a table of numbers. When a scenario describes rating risks 1–5 on two dimensions and plotting them on a color-coded grid, that is qualitative risk analysis, full stop.

Scores and rankings live in the risk register alongside each risk’s owner and response plan, and they get re-rated as conditions change — a risk that was a 6 in planning can be a 16 by mid-project.

Qualitative vs. quantitative analysis

The exam expects you to distinguish the two analysis types cleanly:

Qualitative analysisQuantitative analysis
InputsTeam judgment, ordinal scales (1–5, low/med/high)Numeric data: dollar amounts, durations, probabilities as percentages
OutputRelative ranking / priority scoreExpected monetary value (EMV), schedule or cost estimates, simulation results
EffortLow — a workshop and a scoring scaleHigh — requires data, models, sometimes Monte Carlo simulation
When usedEvery project, on all identified risks, early and oftenSelectively, on top-ranked risks that justify the effort

A useful tell: if the scenario multiplies a percentage probability by a dollar impact (e.g., 20% × $50,000 = $10,000 EMV), it is quantitative. If it uses ordinal ratings and a colored grid, it is qualitative. Qualitative analysis usually comes first and feeds quantitative analysis, which is only applied where the stakes warrant real number-crunching.

From score to response strategy

Prioritization exists to drive decisions. For threats (negative risks), PK0-005 uses the four classic response strategies:

  • Avoid — change the plan so the risk cannot occur at all: drop the risky feature, choose a proven technology, resequence the work. Probability goes to zero.
  • Mitigate — take action to reduce the probability, the impact, or both, while accepting that the risk still exists. Adding a redundant server with automated failover is a textbook mitigation: the primary can still fail, but the impact on users shrinks dramatically. (Eliminating a single point of failure is one of the most common IT mitigation moves.)
  • Transfer — shift the financial consequence to a third party: insurance, fixed-price contracts, or outsourcing the risky component to a vendor. The risk still exists; someone else bears the cost.
  • Accept — do nothing proactive, either passively (just monitor) or actively (set aside a contingency reserve). Appropriate for low-score risks where any response would cost more than the exposure.

For opportunities (positive risks), the mirror strategies are exploit, enhance, share, and accept — worth recognizing, though threat strategies dominate the exam.

The score guides the choice: red-zone risks generally justify avoidance or serious mitigation spending; yellow-zone risks get proportionate mitigation or transfer; green-zone risks are usually accepted and watched. There is no rigid mapping — a low-probability, catastrophic-impact risk may still demand mitigation — but “response effort proportional to score” is the principle CompTIA tests.

How the PK0-005 exam tests this

  • A calculation item: given a probability rating and an impact rating on a 1–5 scale, compute the risk score — the correct answer is the product, with the sum offered as a distractor.
  • A technique-identification scenario: a team rates risks on two ordinal dimensions and plots them on a color-coded grid, and you must name the analysis type (qualitative) against distractors like quantitative analysis or SWOT.
  • A response-strategy scenario: the team takes an action that reduces impact or probability without eliminating the risk — redundancy, extra testing, cross-training — and you must recognize mitigation, distinguishing it from avoidance (risk eliminated) and transfer (risk shifted to a third party).
  • A sequencing or scoping question: which analysis comes first after identification, or which risks proceed to quantitative analysis (only the high-priority ones).

Risk analysis is a core Project Management Concepts topic — the full PK0-005 study guide shows how heavily that domain is weighted and what else it includes. A few passes through a practice exam bank turn the scoring arithmetic into a free point.

Quick reference

  • Qualitative analysis = ordinal ratings + judgment; fast, applied to all identified risks first.
  • Risk score = probability × impact (4 probability × 3 impact = 12).
  • The probability-impact matrix is the color-coded grid visualization of those scores.
  • Quantitative analysis uses real numbers (EMV, simulations) and is reserved for top-ranked risks.
  • Threat responses: avoid (eliminate), mitigate (reduce P or I), transfer (shift to third party), accept (live with it).
  • Redundancy and failover are mitigation — the risk remains, the impact shrinks.
  • Opportunity responses mirror them: exploit, enhance, share, accept.
  • Re-score risks throughout the project; ratings from planning go stale.
Choose your exam → Lifetime access
from $59, once