nerdexam
(ISC)2

CSSLP · Question #63

Which of the following statements is true about residual risks?

The correct answer is A. It is the probabilistic risk after implementing all security measures. Residual risk is the probabilistic risk that remains within a system or organization even after all security measures have been implemented.

Secure Software Concepts

Question

Which of the following statements is true about residual risks?

Options

  • AIt is the probabilistic risk after implementing all security measures.
  • BIt can be considered as an indicator of threats coupled with vulnerability.
  • CIt is a weakness or lack of safeguard that can be exploited by a threat.
  • DIt is the probabilistic risk before implementing all security measures.

How the community answered

(25 responses)
  • A
    88% (22)
  • B
    8% (2)
  • C
    4% (1)

Why each option

Residual risk is the probabilistic risk that remains within a system or organization even after all security measures have been implemented.

AIt is the probabilistic risk after implementing all security measures.Correct

Residual risk is the level of probabilistic risk that remains after security measures and controls have been put in place and implemented to mitigate identified risks.

BIt can be considered as an indicator of threats coupled with vulnerability.

Residual risk is the outcome of addressing threats and vulnerabilities, not an indicator of them.

CIt is a weakness or lack of safeguard that can be exploited by a threat.

This statement describes a vulnerability, which is a weakness, not a residual risk.

DIt is the probabilistic risk before implementing all security measures.

This describes inherent risk or raw risk, which is the risk level before any security measures are applied, not residual risk.

Concept tested: Residual risk definition

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Residual risk#Risk management#Security controls#Risk assessment

Community Discussion

No community discussion yet for this question.

Full CSSLP Practice