nerdexam
(ISC)2

CSSLP · Question #290

Which of the following describes a residual risk as the risk remaining after a risk mitigation has occurred?

The correct answer is A. DIACAP. DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) is a framework that specifically describes residual risk as the risk remaining after mitigation efforts have been applied.

Secure Software Deployment, Operations, Maintenance

Question

Which of the following describes a residual risk as the risk remaining after a risk mitigation has occurred?

Options

  • ADIACAP
  • BSSAA
  • CDAA
  • DISSO

How the community answered

(40 responses)
  • A
    93% (37)
  • C
    3% (1)
  • D
    5% (2)

Why each option

DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) is a framework that specifically describes residual risk as the risk remaining after mitigation efforts have been applied.

ADIACAPCorrect

DIACAP (Department of Defense Information Assurance Certification and Accreditation Process) explicitly includes the concept of residual risk, which is the level of risk remaining after security controls and mitigation strategies have been applied. It's a key part of its risk management framework to evaluate the remaining risk post-mitigation.

BSSAA

SSAA (System Security Accreditation Agreement) is a document outlining an agreement, not a process that describes residual risk in general terms.

CDAA

DAA (Designated Approving Authority) is an individual responsible for making accreditation decisions, not a framework or description of residual risk.

DISSO

ISSO (Information System Security Officer) is a role responsible for security, not a process or definition of residual risk.

Concept tested: Definition of residual risk in security frameworks

Topics

#Residual Risk#Risk Management#DIACAP#Certification and Accreditation

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice