After a cloud infrastructure risk assessment, an organisation deploys additional network segmentation and tighter identity controls to reduce an identified threat. Which term describes the risk that remains after these controls are applied?
- AInherent risk, the level of risk present before any controls are considered
- BResidual risk, the level of risk that persists after controls have been applied Correct
- CTotal risk, the sum of every threat facing the environment before treatment
- DSecondary risk, a new risk introduced by the act of treating another risk
Why A is wrong: Inherent risk is the exposure that exists before controls are applied, so it describes the starting point rather than what remains after the segmentation and identity controls are in place.
Why B is correct: Residual risk is precisely the exposure that remains once selected controls have been implemented, which is what the organisation must accept, transfer, or treat further.
Why C is wrong: This describes an aggregate pre-treatment view of exposure and does not capture the specific concept of what is left over after controls are applied.
Why D is wrong: Secondary risk is a fresh exposure created by a response action, not the remaining portion of the original risk after controls are applied.