The correct answer is A — Establish and keep an active risk register that includes mitigation strategies and a cost-benefit analysis.
Risk management is essential to identifying and mitigating threats such as natural disasters. While Agile teams do not typically use traditional risk registers extensively, at the enterprise level (especially in regulated or high-risk environments), maintaining a risk register aligned with Agile values is appropriate. It should include mitigation options and their associated cost-benefit to guide decision-making.
PMI Agile Practice Guide states:
“Agile risk management practices include establishing lightweight mechanisms such as risk-adjusted backlog prioritization, risk registers (in high-risk or large programs), and risk mitigation strategies.”
(PMI Agile Practice Guide, Section 7.3 – Managing Risk in Agile Projects)
PMBOK® Guide (6th Edition) supports this:
“The risk register is a critical project artifact that includes identified risks, their analysis, mitigation or response plans, and cost-benefit considerations for managing risks.”
Incorrect options:
B lacks the inclusion of mitigation strategies and full cost analysis.
C refers to surface-level risk visibility, not comprehensive risk planning.
D assumes avoidance is the only mitigation strategy, which is not always feasible or optimal.
Answer: A
—