After a company deploys encryption, access controls and monitoring, some risk to its customer database still remains. In risk management terminology, what is the name for the risk that persists after controls have been applied?
- AInherent risk, the level of risk present before any controls or treatment are considered.
- BResidual risk, the risk remaining after risk treatment and controls have been put in place. Correct
- CTotal risk, the full exposure calculated from every threat facing the asset combined.
- DTransferred risk, the portion of exposure that has been shifted to a third party by contract.
Why A is wrong: Inherent risk is the starting exposure before controls; the question asks about what is left afterwards, which is a different measure.
Why B is correct: Residual risk is precisely the exposure that remains once mitigations are applied, which management then accepts or treats further.
Why C is wrong: Total risk describes overall exposure without regard to controls, so it does not name the portion that specifically remains after treatment.
Why D is wrong: Transfer is a treatment option, not the general term for leftover risk; controls here reduce risk in place rather than shifting it to another party.