hardMultiple Choice
CAS-004 Practice Question: During a risk assessment, a residual risk is…
During a risk assessment, a residual risk is identified as high. What should be the NEXT step?
⚠ Common exam trap
In CASP+, a common misconception is that residual risk is automatically acceptable or can be ignored, when in fact it must be actively managed and reduced if it exceeds the defined risk appetite.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement additional controls to reduce the risk to an acceptable level
When residual risk remains high after applying controls, the correct next step is to implement additional controls to reduce it to an acceptable level. This aligns with the risk treatment process in NIST SP 800-37, where residual risk must be evaluated against the organization's risk appetite and, if unacceptable, further mitigation is required. Simply transferring, ignoring, or accepting a high residual risk without analysis violates governance principles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to a third party
Why it's wrong here
Transferring a high residual risk is a treatment option, but the stem's next step after identifying residual risk is to reassess or escalate it, since transfer applies to inherent risks shared via insurance or contracts, not residual exposure already remaining after controls.
- ✓
Implement additional controls to reduce the risk to an acceptable level
Why this is correct
A high residual risk exceeds the organisation's acceptable threshold, so the next step is implementing additional controls to reduce it to an acceptable level. Acceptance is only valid once residual risk falls within tolerance, making further mitigation the required action.
- ✗
Ignore the risk because it is residual
Why it's wrong here
Ignoring a high residual risk leaves the organisation exposed without documented approval, breaching risk management process. Ignoring suits only risks below tolerance thresholds; a high residual rating demands escalation, additional controls, or formal acceptance by an authorised owner.
- ✗
Accept the residual risk as is
Why it's wrong here
Accepting a high residual risk requires formal sign-off, but the stem asks for the next step after identification, which is further treatment or escalation, not acceptance. Acceptance suits low residual risks within tolerance, where documented approval closes the risk register entry.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.