CISSP Security and Risk Management Practice Question
An organization has identified a risk with a high likelihood and high impact. Management decides to implement controls to reduce the likelihood. After controls, the risk is reassessed as medium likelihood and medium impact. What is the residual risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Medium likelihood, medium impact
Residual risk is the remaining risk after controls are applied. In this case, it is the medium likelihood and medium impact risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Low likelihood, low impact
Why it's wrong here
Reducing a risk initially identified with a "high likelihood" to *both* "low likelihood" and "low impact" suggests an exceptionally effective and comprehensive set of controls, potentially beyond what is typically achievable or cost-effective for a single risk. While controls aim to reduce risk, achieving such a drastic reduction in both dimensions simultaneously, especially from a high initial likelihood, is often unrealistic and implies near-elimination, which is rarely possible in practice. This level of reduction would likely exceed the typical outcome of risk mitigation efforts.
- ✓
Medium likelihood, medium impact
Why this is correct
After implementing security controls, the inherent risk (high likelihood, potentially high impact) is expected to be reduced to a more acceptable level. "Medium likelihood, medium impact" represents a plausible and common outcome of effective risk mitigation strategies, where controls successfully diminish the probability of the event occurring and/or lessen its potential consequences. This remaining risk, after controls are applied, is precisely what is defined as residual risk, indicating a successful but not absolute reduction from the initial state.
- ✗
High likelihood, high impact
Why it's wrong here
If the risk remains at "high likelihood, high impact" after controls have been implemented, it indicates that the applied controls were either entirely ineffective, insufficient, or perhaps not properly deployed to mitigate the identified threat. This scenario implies that the residual risk is essentially the same as the inherent risk, meaning no significant reduction was achieved, which contradicts the purpose of implementing risk controls in the first place. Therefore, this state would represent the inherent risk, not a successfully managed residual risk.
- ✗
Control risk is not a defined term
Why it's wrong here
While the term "control risk" is sometimes encountered in specific audit contexts, referring to the risk that internal controls fail to prevent or detect material misstatements, it is not the standard or most appropriate term in general information security risk management for the risk remaining after security measures are applied. The universally accepted and precise term for the risk that persists after all implemented controls have been considered and applied is "residual risk," making "control risk" an inaccurate descriptor in this context.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Residual risk
Residual risk is the level of risk that remains after all security controls and countermeasures have been applied.
About these practice questions
One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.