Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

An organization uses a risk register to track identified risks. A risk owner reports that a mitigation control was implemented six months ago, but the residual risk rating has not been updated and no post-implementation review was performed. Which activity is MOST important for maintaining the integrity of the risk management process?

⚠ Common exam trap

The trap here is treating implementation of a control as proof that the risk is resolved, skipping the reassessment that determines residual risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Reassess the risk with the control in place, document the updated likelihood and impact, and adjust the residual risk rating accordingly.

A risk register is only useful if it reflects current exposure. When a control is deployed, the risk must be reassessed to measure how much likelihood or impact it actually reduced, and the residual rating updated with evidence. This validation step closes the treatment loop and supports accurate reporting to management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk to a third party through cyber insurance and remove the original mitigation control.

    Why it's wrong here

    Insurance can complement treatment but does not replace a functioning control, and transferring risk does not remove the need to reassess and document the exposure. Removing an effective control to rely on insurance increases the likelihood of loss and undermines the risk register's accuracy.

  • ✗

    Escalate the risk to the board as an accepted risk without further analysis because the owner has already acted.

    Why it's wrong here

    Board escalation is appropriate for significant or unaddressed exposures, but escalating without reassessment provides no new information and mislabels the item as accepted. Acceptance is a formal decision made after understanding residual risk, not a default outcome of implementing a control.

  • ✗

    Close the risk entry because the mitigation control has been implemented and the risk is therefore eliminated.

    Why it's wrong here

    Implementing a control reduces risk but rarely eliminates it; residual risk always remains. Closing the entry without reassessment removes it from oversight and creates a false sense of security. The register should reflect the remaining exposure, not assume that a deployed control equals zero risk.

  • ✓

    Reassess the risk with the control in place, document the updated likelihood and impact, and adjust the residual risk rating accordingly.

    Why this is correct

    Risk registers become unreliable when controls are recorded but their effect is never measured. Reassessing likelihood and impact with the control operating provides an evidence-based residual rating, confirms whether the treatment achieved its objective, and keeps decisions aligned with actual exposure. This is the core feedback loop of risk monitoring and analysis.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.