CGRC · Question #658
Which of the following statements is true about residual risks? Response:
The correct answer is C. It is the probabilistic risk after implementing all security measures. Residual risk is the level of risk that remains after all implemented security measures have been applied and are operating effectively.
Question
Which of the following statements is true about residual risks? Response:
Options
- AIt is a weakness or lack of safeguard that can be exploited by a threat.
- BIt can be considered as an indicator of threats coupled with vulnerability.
- CIt is the probabilistic risk after implementing all security measures.
- DIt is the probabilistic risk before implementing all security measures.
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C89% (33)
- D3% (1)
Why each option
Residual risk is the level of risk that remains after all implemented security measures have been applied and are operating effectively.
This describes a vulnerability, which is a weakness that can be exploited, not the remaining risk after mitigation.
This is a general description of risk itself (the potential for harm from threats exploiting vulnerabilities), not specifically residual risk.
Residual risk refers to the amount of risk that persists even after all known and applicable security controls, safeguards, and countermeasures have been implemented and are functioning as intended.
This describes inherent or gross risk, which is the level of risk present before any security measures are put in place.
Concept tested: Residual risk definition
Source: https://csrc.nist.gov/glossary/term/residual-risk
Topics
Community Discussion
No community discussion yet for this question.