Certified Ethical Hacker – CEH – 312-50 – Question338

What term describes the amount of risk that remains after the vulnerabilities are classified and the countermeasures have been deployed?


A.
Residual risk
B. Inherent risk
C. Deferred risk
D. Impact risk

Correct Answer: A

Explanation:

The residual risk is the risk or danger of an action or an event, a method or a (technical) process that, although being abreast with science, still conceives these dangers, even if all theoretically possible safety measures would be applied (scientifically conceivable measures); in other words, the amount of risk left over after natural or inherent risks have been reduced by risk controls.

References: https://en.wikipedia.org/wiki/Residual_risk