SSCP Risk Identification, Monitoring, and Analysis Practice Question
An organization is developing a risk register. Which TWO elements are essential for each risk entry?
⚠ Common exam trap
The SSCP exam often tests the distinction between essential initial elements (description and rating) versus downstream elements (owner, residual risk, cost) to see if candidates confuse the risk register's foundational data with later risk treatment outputs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk description
Option B (Risk description) is essential because every risk register entry must clearly document the nature of the risk — what could happen, the threat/vulnerability involved, and the potential consequence — so it can be understood, communicated, and managed consistently. Option D (Likelihood and impact rating) is essential because risk registers require each risk to be assessed and prioritized by combining the probability of occurrence (likelihood) with the severity of the outcome (impact), which drives risk ranking and treatment decisions. Option A (Risk owner) is a valuable governance field but is not one of the two essential elements tested here, as ownership can be assigned after the risk is identified and described. Option C (Residual risk level) is not essential at the point of entry because residual risk is determined only after mitigation or treatment has been applied. Option E (Mitigation cost) is not essential because cost is a treatment consideration, not a defining attribute required for every risk entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk owner
Why it's wrong here
While helpful, risk owner is not always considered essential for every entry.
- ✓
Risk description
Why this is correct
Correct: A clear description of the risk is fundamental.
- ✗
Residual risk level
Why it's wrong here
Residual risk is determined after controls are applied.
- ✓
Likelihood and impact rating
Why this is correct
Correct: Likelihood and impact are key to risk assessment.
- ✗
Mitigation cost
Why it's wrong here
Mitigation cost is not always included in the initial risk register.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.