nerdexam
(ISC)2

SSCP · Question #1181

What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?

The correct answer is D. Residual risk. Residual risk is the level of risk that persists even after security controls and countermeasures have been implemented to mitigate identified threats and vulnerabilities.

Submitted by parkjh· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?

Options

  • ATerminal risk
  • BInfinite risk
  • CImminent risk
  • DResidual risk

How the community answered

(53 responses)
  • A
    2% (1)
  • B
    2% (1)
  • C
    6% (3)
  • D
    91% (48)

Why each option

Residual risk is the level of risk that persists even after security controls and countermeasures have been implemented to mitigate identified threats and vulnerabilities.

ATerminal risk

Terminal risk is not a standard term in information security risk management; it does not accurately describe remaining risk after mitigation.

BInfinite risk

Infinite risk is not a recognized concept in risk management; risk is quantifiable and finite, even if high.

CImminent risk

Imminent risk suggests a risk that is about to happen or is very close to occurring, not the amount of risk left after mitigation efforts.

DResidual riskCorrect

Residual risk refers to the inherent risk that remains within a system or organization after all implemented security controls, mitigations, and countermeasures have been applied, as it is generally impossible to eliminate all risk completely.

Concept tested: Residual risk definition

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility#residual-risk

Topics

#Residual Risk#Risk Management#Countermeasures#Vulnerability Management

Community Discussion

No community discussion yet for this question.

Full SSCP Practice