nerdexam
(ISC)2

SSCP · Question #431

What does "residual risk" mean?

The correct answer is A. The security risk that remains after controls have been implemented. Residual risk is "The security risk that remains after controls have been implemented" ISO/IEC TR 13335-1 Guidelines for the Management of IT Security (GMITS), Part 1: Concepts and Models for IT Security, 1996. "Weakness of an assets which can be exploited by a threat" is vulnera

Submitted by amina.ke· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

What does "residual risk" mean?

Options

  • AThe security risk that remains after controls have been implemented
  • BWeakness of an assets which can be exploited by a threat
  • CRisk that remains after risk assessment has has been performed
  • DA security risk intrinsic to an asset being audited, where no mitigation has taken place.

How the community answered

(34 responses)
  • A
    88% (30)
  • B
    3% (1)
  • C
    6% (2)
  • D
    3% (1)

Explanation

Residual risk is "The security risk that remains after controls have been implemented" ISO/IEC TR 13335-1 Guidelines for the Management of IT Security (GMITS), Part 1: Concepts and Models for IT Security, 1996. "Weakness of an assets which can be exploited by a threat" is vulnerability. "The result of unwanted incident" is impact. Risk that remains after risk analysis has been performed is a distracter. Risk can never be eliminated nor avoided, but it can be mitigated, transferred or accpeted. Even after applying a countermeasure like for example putiing up an Antivirus. But still it is not 100% that systems will be protected by antivirus.

Topics

#Residual risk#Risk management#Security controls#Risk mitigation

Community Discussion

No community discussion yet for this question.

Full SSCP Practice