Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A cybersecurity incident response team is reviewing a recent breach where sensitive customer data was exfiltrated. The team identifies that the breach occurred due to an unpatched vulnerability in a legacy web server, despite a patch being available for over six months. What type of risk was realized in this scenario?

  1. AAcceptable Risk
  2. BMitigated Risk
  3. CResidual Risk
  4. DInherent Risk
Show answer & explanation

Correct answer: C. Residual Risk

Residual risk is the risk that remains after controls and countermeasures have been implemented. In this case, the unpatched vulnerability represented a residual risk that was not adequately addressed, leading to the breach.

Why the other options are wrong

  • A. Acceptable risk is a level of risk an organization is willing to tolerate, which was clearly exceeded here.
  • B. Mitigated risk is a risk that has been reduced through the implementation of controls, but this risk was not fully mitigated.
  • D. Inherent risk is the risk level before any controls are applied.

Residual Risk

The risk that remains after all risk mitigation efforts have been implemented. It is the leftover risk an organization faces after controls are in place.

  • It's the risk remaining after controls.
  • It cannot be entirely eliminated.
  • Must be monitored and managed.

Memory trick: Remember 'RIM' for Risk: Inherent, Mitigated, Residual.

More Risk Management questions