nerdexam
(ISC)2

CCSP · Question #886

After applying security controls, the remaining risk that an organization still faces is known as:

The correct answer is B. Residual risk. Inherent risk is the original risk before controls. After controls are in place, the leftover risk (what's not fully eliminated) is a residual risk.

Submitted by ngozi_ng· Apr 18, 2026Legal, Risk and Compliance

Question

After applying security controls, the remaining risk that an organization still faces is known as:

Options

  • AInherent risk
  • BResidual risk
  • CUnexpected risk
  • DTransferred risk

How the community answered

(19 responses)
  • B
    89% (17)
  • C
    5% (1)
  • D
    5% (1)

Explanation

Inherent risk is the original risk before controls. After controls are in place, the leftover risk (what's not fully eliminated) is a residual risk.

Topics

#Risk management#Residual risk#Security controls

Community Discussion

No community discussion yet for this question.

Full CCSP Practice