ISC2 Governance, Risk and Compliance (CGRC) Practice Question
During a risk assessment for a new payroll system, you classify the system's inherent risk as high because no security safeguards have been considered yet. After controls are implemented and tested, you must report the system's residual risk. Which statement best distinguishes residual risk from inherent risk?
Residual risk represents potential impact before any threat exposure, while inherent risk describes what is left after controls fail.
Residual risk is equal to the organization's risk tolerance threshold, while inherent risk is the system's actual exposure level.
Residual risk excludes consideration of vulnerabilities, whereas inherent risk fully accounts for them.
Residual risk is the level remaining after applying and validating security controls, whereas inherent risk is the level present if no controls are in place.
Residual risk is the level of risk that remains after security controls have been implemented and their effectiveness evaluated. It reflects the threats and vulnerabilities that are still present despite safeguards. Inherent risk, by contrast, is the level of risk that exists before any preventive, detective, or corrective controls are applied. The incorrect options either invert the definitions, confuse residual risk with risk tolerance, or omit critical factors such as threats and vulnerabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are security controls?
Open an interactive chat with Bash
How is residual risk measured?
Open an interactive chat with Bash
What is the difference between inherent and residual risk in risk management frameworks?
Open an interactive chat with Bash
What does 'inherent risk' mean?
Open an interactive chat with Bash
How is 'residual risk' calculated in a risk assessment?
Open an interactive chat with Bash
How does 'residual risk' relate to organizational risk tolerance?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
System Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .