SSCP Risk Identification, Monitoring, and Analysis Practice Question
A financial services firm classifies its customer database as its most critical asset. The risk register shows a single entry for "unauthorized database access" with an annualized loss expectancy of $2,000,000. Management approves a database activity monitoring (DAM) solution plus tokenization of account numbers, which reduces the annualized loss expectancy to $300,000. Which of the following BEST describes the $300,000 figure in risk terms?
⚠ Common exam trap
The trap here is treating any post-control dollar figure as control cost or as inherent risk, when a reduced expected loss is by definition residual risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The residual risk remaining after the controls are applied
Annualized loss expectancy quantifies expected yearly loss for a given risk. Applying controls that cut the figure from $2,000,000 to $300,000 leaves $300,000 of expected annual loss still present, which is the residual risk. Documenting that value allows comparison with the organization's risk tolerance and supports decisions about accepting or further treating the remaining exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The risk appetite threshold approved by the board for this asset
Why it's wrong here
Risk appetite is the amount of risk an organization is willing to pursue or retain, expressed as a threshold set by governance, not a computed loss estimate. The $300,000 arose from measuring the effect of specific controls on expected loss, so it is an outcome of treatment rather than a predetermined tolerance level that management declares in advance.
- ✗
The total cost of ownership of the implemented controls
Why it's wrong here
Total cost of ownership covers licensing, deployment, staffing, and maintenance of the DAM and tokenization controls. That figure is an investment amount, not a residual loss projection, and it would be compared against the reduction in expected loss to justify the spend. The $300,000 represents what the organization still expects to lose annually, so labeling it control cost misstates its meaning in the risk register.
- ✗
The inherent risk of the database before any controls existed
Why it's wrong here
Inherent risk describes exposure in the absence of controls, which in this scenario corresponds to the original $2,000,000 annualized loss expectancy. The $300,000 is the post-treatment figure, so treating it as inherent risk inverts the relationship and would mislead anyone reading the register about how much protection the DAM and tokenization actually provide.
- ✓
The residual risk remaining after the controls are applied
Why this is correct
Residual risk is the expected loss that persists after mitigation. The original annualized loss expectancy was $2,000,000, and the approved controls reduced it to $300,000; that remaining exposure is precisely the residual risk. Recording it lets management compare it against the organization's risk appetite and decide whether further treatment, transfer, or acceptance is warranted.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.