Governance & ComplianceQuestion 98 of 100

The residual risk that remains after all controls have been applied should be:

a.Ignored entirely
b.Transferred automatically
c.Eliminated completely
d.Accepted by management

Explanation

Residual risk is what remains after mitigations are in place, and it cannot usually be reduced to zero. Senior management should formally acknowledge and accept it. This ensures leadership is aware of and owns the remaining exposure.

Practice all 100 questions free — no signup required.

Related questions on this topic

Last reviewed: · editorial process

Sen Lin, PrepPass Founder · Verified against CompTIA Security+ (SY0-701) · How we review
Report