Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization is developing a risk register. Which TWO elements are essential for each risk entry?

⚠ Common exam trap

The SSCP exam often tests the distinction between essential initial elements (description and rating) versus downstream elements (owner, residual risk, cost) to see if candidates confuse the risk register's foundational data with later risk treatment outputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk description

Option B (Risk description) is essential because every risk register entry must clearly document the nature of the risk — what could happen, the threat/vulnerability involved, and the potential consequence — so it can be understood, communicated, and managed consistently. Option D (Likelihood and impact rating) is essential because risk registers require each risk to be assessed and prioritized by combining the probability of occurrence (likelihood) with the severity of the outcome (impact), which drives risk ranking and treatment decisions. Option A (Risk owner) is a valuable governance field but is not one of the two essential elements tested here, as ownership can be assigned after the risk is identified and described. Option C (Residual risk level) is not essential at the point of entry because residual risk is determined only after mitigation or treatment has been applied. Option E (Mitigation cost) is not essential because cost is a treatment consideration, not a defining attribute required for every risk entry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk owner

    Why it's wrong here

    While helpful, risk owner is not always considered essential for every entry.

  • ✓

    Risk description

    Why this is correct

    Correct: A clear description of the risk is fundamental.

  • ✗

    Residual risk level

    Why it's wrong here

    Residual risk is determined after controls are applied.

  • ✓

    Likelihood and impact rating

    Why this is correct

    Correct: Likelihood and impact are key to risk assessment.

  • ✗

    Mitigation cost

    Why it's wrong here

    Mitigation cost is not always included in the initial risk register.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.