nerdexam
(ISC)2

CSSLP · Question #61

You work as a project manager for BlueWell Inc. You with your team are using a method or a (technical) process that conceives the risks even if all theoretically possible safety measures would be…

The correct answer is D. It is a risk that remains after planned risk responses are taken. Residual risk is defined as the risk that remains after all planned risk responses and mitigation actions have been implemented.

Secure Software Lifecycle Management

Question

You work as a project manager for BlueWell Inc. You with your team are using a method or a (technical) process that conceives the risks even if all theoretically possible safety measures would be applied. One of your team member wants to know that what is a residual risk. What will you reply to your team member?

Options

  • AIt is a risk that remains because no risk response is taken.
  • BIt is a risk that can not be addressed by a risk response.
  • CIt is a risk that will remain no matter what type of risk response is offered.
  • DIt is a risk that remains after planned risk responses are taken.

How the community answered

(36 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    86% (31)

Why each option

Residual risk is defined as the risk that remains after all planned risk responses and mitigation actions have been implemented.

AIt is a risk that remains because no risk response is taken.

This describes a risk that might be accepted without further action, not specifically the remainder after taking responses.

BIt is a risk that can not be addressed by a risk response.

This implies an unaddressable risk, which is different from residual risk that remains after attempting to address it.

CIt is a risk that will remain no matter what type of risk response is offered.

This definition is close but less precise than option D, as residual risk specifically implies actions were taken to reduce it.

DIt is a risk that remains after planned risk responses are taken.Correct

Residual risk refers to the risk that persists in a project or system even after risk responses have been executed and controls have been applied to mitigate identified threats.

Concept tested: Residual risk definition

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Risk Management#Residual Risk#Risk Response

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice