ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a risk assessment for a new e-commerce server, you estimate a 0.4 annual likelihood of compromise with a $1 000 000 impact. Planned controls are expected to drop likelihood to 0.1 while impact remains the same. How should you record this change when comparing inherent and residual risk in the risk register?
List inherent risk as $100 000 and residual risk as $400 000 because the added controls introduce operational cost that raises residual exposure.
Show both inherent and residual risk as $400 000 since the impact value did not change.
Record inherent risk as the full $1 000 000 impact and residual risk as $100 000, because only impact values influence residual risk calculations.
List inherent risk as $400 000 and residual risk as $100 000, noting that management must decide whether the $100 000 exposure is acceptable.
Inherent risk is calculated before any safeguards are applied, so it remains the original likelihood (0.4) multiplied by the impact ($1 000 000), or $400 000. Residual risk is the amount that persists after control effectiveness is considered: 0.1 × $1 000 000, or $100 000. Decision makers must decide whether the reduced $100 000 residual exposure is acceptable or if further treatment is needed. Controls do not change inherent risk, nor do they automatically increase residual risk unless they leave new vulnerabilities unaddressed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the difference between inherent risk and residual risk?
Open an interactive chat with Bash
How do controls impact inherent and residual risk?
Open an interactive chat with Bash
What is the significance of a risk register in risk management?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .