Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A cybersecurity team is conducting a risk assessment and has identified a critical vulnerability in a widely used web server application. This vulnerability allows for remote code execution. The team has determined that the likelihood of an exploit occurring is 'High' and the impact of a successful exploit would be 'Severe'. Which of the following best describes the inherent risk of this vulnerability?

  1. AHigh
  2. BModerate
  3. CResidual
  4. DLow
Show answer & explanation

Correct answer: A. High

Inherent risk is the level of risk before any controls or mitigation strategies are applied. With a 'High' likelihood and 'Severe' impact, the inherent risk is unequivocally high. The question describes the risk without mentioning any applied controls.

Why the other options are wrong

  • B. Moderate risk would imply a combination of medium likelihood and impact.
  • C. Residual risk is the risk remaining after controls have been implemented.
  • D. Low risk would imply low likelihood and low impact.

Inherent Risk

The level of risk before any risk mitigation controls or countermeasures have been applied. It is the raw risk an organization faces.

  • Calculated based on raw likelihood and impact.
  • Serves as a baseline for risk assessment.
  • Often contrasted with residual risk.

Memory trick: Inherent risk is the raw, untamed danger.

More Risk Management questions