What Is the Risk Remaining After Controls and Mitigating Factors Are Applied?
Which of the following best describes the risk present after controls and mitigating factors have been applied?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests your ability to distinguish risk terminology—specifically that 'residual' refers to leftover risk after safeguards, while 'inherent' is the risk before controls are applied.
Residual risk is the risk that remains after security controls and mitigation strategies are implemented. This CompTIA Security+ (SY0-701) concept is widely confirmed by community consensus, with all voters selecting 'Residual.'
Choosing 'Inherent' is a common mistake because it is the risk before controls, not after; learners often confuse the order of risk assessment phases.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Residual risk is defined as the risk that persists after security controls, safeguards, and mitigating factors have been applied. It represents the remaining likelihood and impact that cannot be fully eliminated, only reduced to an acceptable level. This aligns directly with the question's phrasing, making 'Residual' the clear and correct choice.Why the Other Options Are Wrong
- Avoided (B) refers to a risk response strategy where the risk is eliminated by not engaging in the risky activity, not the leftover risk after controls.
- Inherent (C) is the level of risk before any controls are implemented, the opposite of what the question asks.
- Operational (D) is a broad category of day-to-day risks, not a specific risk state defined by post-control residual assessment.
Community Comment Notes
Community comments unanimously support 'Residual,' with one user humorously comparing it to 'the amount of money in my account after my bills are paid.' Another comment explicitly states that residual risk 'cannot be completely eliminated, only reduced to an acceptable level,' reinforcing the core definition. These comments confirm the consensus and provide practical mnemonic value.Official Reference
Exam Strategy
Remember the order: inherent risk comes first, then controls are applied, leaving residual risk. If the question mentions 'after controls' or 'remaining risk,' the answer is always 'Residual.'
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →