QuestionQ58

Vulnerability Management

Which of the following best describes a type of risk that exists after mitigations or controls are enacted and implemented?

  • A Residual
  • B Acceptable
  • C Inherent
  • D Appropriate
Explanation

Residual risk is the risk that remains after security controls or mitigations have been applied to reduce inherent risk. It reflects the leftover exposure an organization must accept, transfer, or further mitigate, as opposed to inherent risk (the risk level before any controls are applied).

Community Discussion

No comments yet. Be the first to start the discussion!