ISC Risk Management Practice Question
You are integrating an enterprise risk register with a GRC tool (e.g., Archer). Which method provides the most accurate view of 'Residual Risk' to the board?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inherent Risk multiplied by Control Gap
Residual risk is calculated as Inherent Risk minus the effectiveness of current controls (Control Effectiveness).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Asset Value multiplied by Threat Frequency
Why it's wrong here
This calculates Inherent Risk, not Residual.
- ✗
Compliance Score subtracted from 100
Why it's wrong here
Compliance is a proxy, not a direct measure of residual risk.
- ✗
Total Budget divided by Number of Findings
Why it's wrong here
This is a resource metric, not a risk quantification.
- ✓
Inherent Risk multiplied by Control Gap
Why this is correct
This represents the remaining risk exposure after accounting for control deficiencies.
About these practice questions
One of 219 original ISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official (ISC)² exam blueprint
This ISC practice question is part of Courseiva's free (ISC)² certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ISC exam.