nerdexam
EC-Council

312-50V9 · Question #479

If the final set of security controls does not eliminate all risk in a system, what could be done next?

The correct answer is C. If the residual risk is low enough, it can be accepted. After applying security controls, any remaining exposure is called residual risk, which can be formally accepted by management if it falls below an acceptable threshold.

Introduction to Ethical Hacking

Question

If the final set of security controls does not eliminate all risk in a system, what could be done next?

Options

  • AContinue to apply controls until there is zero risk.
  • BIgnore any remaining risk.
  • CIf the residual risk is low enough, it can be accepted.
  • DRemove current controls since they are not completely effective.

How the community answered

(51 responses)
  • A
    8% (4)
  • B
    18% (9)
  • C
    71% (36)
  • D
    4% (2)

Why each option

After applying security controls, any remaining exposure is called residual risk, which can be formally accepted by management if it falls below an acceptable threshold.

AContinue to apply controls until there is zero risk.

Zero risk is unattainable in any real-world system; attempting to eliminate all risk entirely is neither practical nor cost-effective.

BIgnore any remaining risk.

Ignoring risk is not a formal risk treatment strategy and leaves the organization without a documented decision or accountability.

CIf the residual risk is low enough, it can be accepted.Correct

Residual risk is the risk that remains after security controls have been implemented. Risk management frameworks such as NIST SP 800-30 explicitly allow organizations to accept residual risk when its level is deemed tolerable relative to the cost of further mitigation. Formal risk acceptance is a legitimate and documented risk treatment option, distinct from ignoring risk.

DRemove current controls since they are not completely effective.

Removing existing controls because they are not perfect would increase overall risk rather than reduce it, which is counterproductive.

Concept tested: Residual risk acceptance in risk management

Source: https://csrc.nist.gov/pubs/sp/800/30/r1/final

Topics

#residual risk#risk acceptance#risk management#security controls

Community Discussion

No community discussion yet for this question.

Full 312-50V9 Practice