nerdexam
EC-Council

312-50V11 · Question #588

If the final set of security controls does not eliminate all risk in a system, what could be done next?

The correct answer is C. If the residual risk is low enough, it can be accepted.. When security controls cannot eliminate all risk, the remaining residual risk may be formally accepted if it falls within an organization's acceptable risk tolerance.

Information Security and Ethical Hacking Fundamentals

Question

If the final set of security controls does not eliminate all risk in a system, what could be done next?

Options

  • AContinue to apply controls until there is zero risk.
  • BIgnore any remaining risk.
  • CIf the residual risk is low enough, it can be accepted.
  • DRemove current controls since they are not completely effective.

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    5% (1)
  • C
    82% (18)
  • D
    5% (1)

Why each option

When security controls cannot eliminate all risk, the remaining residual risk may be formally accepted if it falls within an organization's acceptable risk tolerance.

AContinue to apply controls until there is zero risk.

Absolute zero risk is not a realistic or achievable goal in any real-world system, and indefinitely applying controls is not a practical risk management strategy.

BIgnore any remaining risk.

Ignoring remaining risk is irresponsible and violates sound risk management practice, as unacknowledged risk cannot be monitored or managed.

CIf the residual risk is low enough, it can be accepted.Correct

Residual risk is the risk that remains after security controls have been applied. Risk management frameworks such as NIST RMF recognize that zero risk is generally unattainable, so organizations formally evaluate residual risk against their risk tolerance. If the remaining risk is low enough to fall within acceptable thresholds, it can be documented and accepted by the authorizing official.

DRemove current controls since they are not completely effective.

Removing controls that partially reduce risk would increase overall exposure and is contrary to the goal of minimizing risk to the greatest feasible extent.

Concept tested: Residual risk acceptance in risk management

Source: https://csrc.nist.gov/glossary/term/residual_risk

Topics

#residual risk#risk management#risk acceptance#security controls

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice