nerdexam
EC-Council

712-50 · Question #121

The risk found after a control has been fully implemented is called:

The correct answer is A. Residual Risk. Residual risk is the risk that remains after controls have been applied - it's what's "left over" after your safeguards do their work. Controls reduce risk but rarely eliminate it entirely, so residual risk represents the accepted remainder that an organization lives with. B…

IS Management Controls and Auditing Management

Question

The risk found after a control has been fully implemented is called:

Options

  • AResidual Risk
  • BTotal Risk
  • CPost implementation risk
  • DTransferred risk

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    4% (1)
  • C
    13% (3)
  • D
    4% (1)

Explanation

Residual risk is the risk that remains after controls have been applied - it's what's "left over" after your safeguards do their work. Controls reduce risk but rarely eliminate it entirely, so residual risk represents the accepted remainder that an organization lives with.

  • B (Total Risk) is wrong because total risk is the full exposure before any controls are applied (the raw, unmitigated risk).
  • C (Post implementation risk) is not a standard risk management term and describes no recognized concept in frameworks like CISSP, CISM, or ISO 27001.
  • D (Transferred risk) is wrong because transferred risk refers to shifting risk to a third party (e.g., via insurance or outsourcing), not what remains after a control is in place.

Memory tip: Think of "residual" like a residue - the stuff left behind after you've scrubbed (controlled) the surface. Total Risk → Controls applied → Residual Risk is the leftover.

Topics

#Residual Risk#Risk Management#Control Implementation#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice