nerdexam
EC-Council

712-50 · Question #59

Risk that remains after risk mitigation is known as

The correct answer is B. Residual risk. Residual risk is the standard term in risk management for the risk that persists after controls, countermeasures, or mitigation strategies have been applied - making B correct. "Persistent risk" (A) is not a recognized risk management term; it sounds plausible but doesn't exist…

IS Management Controls and Auditing Management

Question

Risk that remains after risk mitigation is known as

Options

  • APersistent risk
  • BResidual risk
  • CAccepted risk
  • DNon-tolerated risk

How the community answered

(60 responses)
  • A
    5% (3)
  • B
    72% (43)
  • C
    7% (4)
  • D
    17% (10)

Explanation

Residual risk is the standard term in risk management for the risk that persists after controls, countermeasures, or mitigation strategies have been applied - making B correct. "Persistent risk" (A) is not a recognized risk management term; it sounds plausible but doesn't exist in standard frameworks like NIST, ISO 27001, or CISSP. "Accepted risk" (C) is a response to residual risk - once you identify what remains, you may choose to accept it, but acceptance is the decision, not the leftover risk itself. "Non-tolerated risk" (D) is also fabricated terminology with no standing in any standard risk framework.

Memory tip: Think "residue" - like the residue left in a pan after cleaning. No matter how well you scrub (mitigate), something usually remains. That leftover = residual risk.

Topics

#Risk Management#Risk Mitigation#Residual Risk#Risk Assessment

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice