712-50 · Question #59
Risk that remains after risk mitigation is known as
The correct answer is B. Residual risk. Residual risk is the standard term in risk management for the risk that persists after controls, countermeasures, or mitigation strategies have been applied - making B correct. "Persistent risk" (A) is not a recognized risk management term; it sounds plausible but doesn't exist…
Question
Risk that remains after risk mitigation is known as
Options
- APersistent risk
- BResidual risk
- CAccepted risk
- DNon-tolerated risk
How the community answered
(60 responses)- A5% (3)
- B72% (43)
- C7% (4)
- D17% (10)
Explanation
Residual risk is the standard term in risk management for the risk that persists after controls, countermeasures, or mitigation strategies have been applied - making B correct. "Persistent risk" (A) is not a recognized risk management term; it sounds plausible but doesn't exist in standard frameworks like NIST, ISO 27001, or CISSP. "Accepted risk" (C) is a response to residual risk - once you identify what remains, you may choose to accept it, but acceptance is the decision, not the leftover risk itself. "Non-tolerated risk" (D) is also fabricated terminology with no standing in any standard risk framework.
Memory tip: Think "residue" - like the residue left in a pan after cleaning. No matter how well you scrub (mitigate), something usually remains. That leftover = residual risk.
Topics
Community Discussion
No community discussion yet for this question.