CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
Before an organization implements full-disk encryption on laptops, the risk of data exposure from a lost device is rated as High. After encryption is deployed, the remaining risk is rated as Low. What term describes the risk level that remains after the control is applied?
- AControl risk
- BRisk appetite
- CInherent risk
- DResidual risk
Show answer & explanationAnswer & explanation
Correct answer: D. Residual risk
Residual risk is the risk that remains after security controls have been applied to reduce the original, or inherent, risk level.
Why the other options are wrong
- A. Control risk generally refers to the possibility that a control fails or is ineffective, a different concept.
- B. Risk appetite is the amount of risk an organization is willing to accept, not a measured post-control result.
- C. Inherent risk is the risk level before any controls are applied.
Residual Risk
The risk that remains after security controls have been implemented to reduce the inherent risk level.
- Inherent risk = risk before controls; residual risk = risk after controls
- Organizations compare residual risk to risk appetite to decide if further action is needed
- Cannot be reduced to zero — some risk always remains
Memory trick: Inherent is 'in the beginning'; residual is what's 'left over.'