ISC2-CC - Security Principles (26% of the exam) - Section 1.2

Understand the risk management process, including risk identification, assessment, and the treatment options of avoidance, mitigation, transfer, and acceptance.

Walk through the risk management lifecycle: identify assets and threats, assess the likelihood and impact of each risk, and select a treatment. Distinguish the four risk treatment options - avoid, mitigate (reduce), transfer (e.g. insurance), and accept - and recognise that residual risk remains after controls are applied and must be formally accepted by management.

Risk managementRisk assessmentRisk treatmentResidual riskThreat and vulnerability

Practice question for this objective

Free sampleSecurity Principlesmedium

After a company deploys encryption, access controls and monitoring, some risk to its customer database still remains. In risk management terminology, what is the name for the risk that persists after controls have been applied?

  • AInherent risk, the level of risk present before any controls or treatment are considered.
  • BResidual risk, the risk remaining after risk treatment and controls have been put in place. Correct
  • CTotal risk, the full exposure calculated from every threat facing the asset combined.
  • DTransferred risk, the portion of exposure that has been shifted to a third party by contract.
Residual risk is the exposure that remains after controls and risk treatment have been applied. Controls rarely eliminate risk completely, so the exposure left after treatment is termed residual risk, and the organisation must decide whether that remaining level is acceptable or needs further action.

Why A is wrong: Inherent risk is the starting exposure before controls; the question asks about what is left afterwards, which is a different measure.

Why B is correct: Residual risk is precisely the exposure that remains once mitigations are applied, which management then accepts or treats further.

Why C is wrong: Total risk describes overall exposure without regard to controls, so it does not name the portion that specifically remains after treatment.

Why D is wrong: Transfer is a treatment option, not the general term for leftover risk; controls here reduce risk in place rather than shifting it to another party.

See more ISC2-CC practice questions, answers explained.

Exam traps in Security Principles

Answers that look right on this material and are not. Each one is a distractor from a different question in the ISC2-CC bank for this domain.

  • Inherent risk, which is the level of risk present before any controls have been selected or applied.

    Why it is wrong: Tempting because it is a real term paired with residual risk, but inherent risk is measured before controls, whereas the question asks about what remains after them.

  • Selecting whether to avoid, mitigate, transfer or accept each risk that the portal is judged to present

    Why it is wrong: Choosing a treatment is a later step; you cannot decide how to treat risks that have not yet been identified or assessed.

  • Inherent risk, the level of risk present before any controls are considered

    Why it is wrong: Inherent risk is measured before controls are applied; the question describes the exposure that is left after controls are already in place, so this term names the wrong point in the process.

Examworthy is not affiliated with or endorsed by ISC2. Original, blueprint-aligned practice material only.