SSCP · Question #1181
What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?
The correct answer is D. Residual risk. Residual risk is the level of risk that persists even after security controls and countermeasures have been implemented to mitigate identified threats and vulnerabilities.
Question
What term describes the amount of risk that remains after the countermeasures have been deployed and the vulnerabilities classified?
Options
- ATerminal risk
- BInfinite risk
- CImminent risk
- DResidual risk
How the community answered
(53 responses)- A2% (1)
- B2% (1)
- C6% (3)
- D91% (48)
Why each option
Residual risk is the level of risk that persists even after security controls and countermeasures have been implemented to mitigate identified threats and vulnerabilities.
Terminal risk is not a standard term in information security risk management; it does not accurately describe remaining risk after mitigation.
Infinite risk is not a recognized concept in risk management; risk is quantifiable and finite, even if high.
Imminent risk suggests a risk that is about to happen or is very close to occurring, not the amount of risk left after mitigation efforts.
Residual risk refers to the inherent risk that remains within a system or organization after all implemented security controls, mitigations, and countermeasures have been applied, as it is generally impossible to eliminate all risk completely.
Concept tested: Residual risk definition
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/shared-responsibility#residual-risk
Topics
Community Discussion
No community discussion yet for this question.