(ISC)2
CCSP · Question #886
After applying security controls, the remaining risk that an organization still faces is known as:
The correct answer is B. Residual risk. Inherent risk is the original risk before controls. After controls are in place, the leftover risk (what's not fully eliminated) is a residual risk.
Submitted by ngozi_ng· Apr 18, 2026Legal, Risk and Compliance
Question
After applying security controls, the remaining risk that an organization still faces is known as:
Options
- AInherent risk
- BResidual risk
- CUnexpected risk
- DTransferred risk
How the community answered
(19 responses)- B89% (17)
- C5% (1)
- D5% (1)
Explanation
Inherent risk is the original risk before controls. After controls are in place, the leftover risk (what's not fully eliminated) is a residual risk.
Topics
#Risk management#Residual risk#Security controls
Community Discussion
No community discussion yet for this question.