712-50 · Question #121
The risk found after a control has been fully implemented is called:
The correct answer is A. Residual Risk. Residual risk is the risk that remains after controls have been applied - it's what's "left over" after your safeguards do their work. Controls reduce risk but rarely eliminate it entirely, so residual risk represents the accepted remainder that an organization lives with. B…
Question
The risk found after a control has been fully implemented is called:
Options
- AResidual Risk
- BTotal Risk
- CPost implementation risk
- DTransferred risk
How the community answered
(24 responses)- A79% (19)
- B4% (1)
- C13% (3)
- D4% (1)
Explanation
Residual risk is the risk that remains after controls have been applied - it's what's "left over" after your safeguards do their work. Controls reduce risk but rarely eliminate it entirely, so residual risk represents the accepted remainder that an organization lives with.
- B (Total Risk) is wrong because total risk is the full exposure before any controls are applied (the raw, unmitigated risk).
- C (Post implementation risk) is not a standard risk management term and describes no recognized concept in frameworks like CISSP, CISM, or ISO 27001.
- D (Transferred risk) is wrong because transferred risk refers to shifting risk to a third party (e.g., via insurance or outsourcing), not what remains after a control is in place.
Memory tip: Think of "residual" like a residue - the stuff left behind after you've scrubbed (controlled) the surface. Total Risk → Controls applied → Residual Risk is the leftover.
Topics
Community Discussion
No community discussion yet for this question.