Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

After implementing security controls, a risk assessment shows that a residual risk of data exfiltration remains. Which document should formally record this residual risk and the decision to accept it?

⚠ Common exam trap

It's easy for candidates to confuse the risk register with the incident response plan, thinking that any risk-related documentation belongs in the incident response plan, but the risk register is specifically designed for tracking and formally accepting residual risks before any incident occurs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk register

The risk register is the formal document used to track identified risks, their assessed likelihood and impact, and the chosen risk response. When a residual risk remains after controls are implemented, the risk register records that residual risk level and formally documents management's decision to accept it, including the rationale and approval. This ensures auditability and accountability for the accepted risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Incident response plan

    Why it's wrong here

    An incident response plan defines detection, containment and recovery procedures during an active breach; it holds no risk-register entry or acceptance sign-off. It tempts because exfiltration is an incident, yet the stem asks where residual risk and the formal acceptance decision are documented, which is the risk register.

  • ✓

    Risk register

    Why this is correct

    The risk register formally documents identified risks, their assessed residual level and the management decision to accept them, providing an auditable record. It satisfies the stem's requirement to record residual risk and the acceptance decision.

  • ✗

    Business continuity plan

    Why it's wrong here

    A business continuity plan documents how critical operations resume after disruption; it does not record individual residual risks or acceptance decisions. Its disaster-recovery focus tempts candidates linking data loss to outages, but the stem requires a formal risk-acceptance record, which belongs in the risk register.

  • ✗

    Security baseline

    Why it's wrong here

    A security baseline specifies mandatory configuration settings for systems; it contains no risk entries or acceptance rationale. Baselines tempt because they are control documents produced alongside risk treatment, yet recording residual risk and the decision to accept it is the risk register's function, not a configuration standard's.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.