mediumMultiple Choice
SSCP Practice Question: A financial institution uses a risk management…
A financial institution uses a risk management framework based on ISO 31000. During a quarterly risk review, the risk manager identifies that the residual risk for a critical trading application remains high despite multiple controls. The application's risk score has not decreased after implementing two-factor authentication and encryption. The risk appetite statement says 'no high residual risk for systems processing transactions over $10M.' What should the risk manager do next?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate to senior management for a decision on additional controls or risk acceptance.
When residual risk exceeds the organization's risk appetite, standard risk management frameworks (like ISO 31000) require escalation to senior management to decide on additional controls or formal risk acceptance. Option A is incorrect because disabling non-essential features may not sufficiently reduce the risk to within appetite and could harm business operations. Option B is incorrect because cyber insurance transfers financial loss but does not reduce the residual risk itself; the risk appetite statement addresses residual risk, not just financial impact. Option D is incorrect because the risk appetite explicitly prohibits high residual risk for this system, so acceptance would violate policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduce the risk by disabling non-essential features of the application.
Why it's wrong here
Disabling non-essential features is another reduction control, yet the stem states controls already failed to lower the residual risk below the appetite threshold. Reduction is tempting because it is the default ISO 31000 treatment, and would be correct if further feasible controls could realistically bring the score within appetite.
- ✗
Transfer the risk by purchasing cyber insurance.
Why it's wrong here
Insurance transfers financial loss but leaves the residual risk high, breaching the risk appetite statement that forbids high residual risk on these systems. Transfer is tempting because ISO 31000 lists it as a valid treatment, and it would be correct for low-likelihood, high-impact risks outside appetite tolerance.
- ✓
Escalate to senior management for a decision on additional controls or risk acceptance.
Why this is correct
Residual risk still breaches the stated risk appetite, which the risk manager cannot accept unilaterally. ISO 31000 requires escalation so senior management decides whether to fund further treatment or formally accept the exposure, preserving accountability for the trading application.
- ✗
Accept the risk because controls are already in place.
Why it's wrong here
Acceptance is invalid because the risk appetite statement explicitly prohibits high residual risk for systems processing transactions over $10M. Acceptance is tempting because it is a legitimate ISO 31000 treatment once risk falls within appetite, and would be correct if the residual score were below the stated threshold.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.