CompTIA Security+ (SY0-701)Security Program Management and OversightMedium

Before an organization implements full-disk encryption on laptops, the risk of data exposure from a lost device is rated as High. After encryption is deployed, the remaining risk is rated as Low. What term describes the risk level that remains after the control is applied?

  1. AControl risk
  2. BRisk appetite
  3. CInherent risk
  4. DResidual risk
Show answer & explanation

Correct answer: D. Residual risk

Residual risk is the risk that remains after security controls have been applied to reduce the original, or inherent, risk level.

Why the other options are wrong

  • A. Control risk generally refers to the possibility that a control fails or is ineffective, a different concept.
  • B. Risk appetite is the amount of risk an organization is willing to accept, not a measured post-control result.
  • C. Inherent risk is the risk level before any controls are applied.

Residual Risk

The risk that remains after security controls have been implemented to reduce the inherent risk level.

  • Inherent risk = risk before controls; residual risk = risk after controls
  • Organizations compare residual risk to risk appetite to decide if further action is needed
  • Cannot be reduced to zero — some risk always remains

Memory trick: Inherent is 'in the beginning'; residual is what's 'left over.'

More Security Program Management and Oversight questions