Exam ISO-IEC-27001-Lead-Implementer Topic 4 Question 46 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 46
Topic #: 4
Which statement regarding residual risk is correct?

Suggested Answer: A Vote an answer

Residual risk is defined in ISO/IEC 27000:2018 as the risk remaining after risk treatment. According to ISO
/IEC 27005:2022, residual risk can include risks that were not identified during the risk assessment process - meaning unidentified risks form part of the residual risk. This is because no risk assessment is exhaustive; unknown or emerging threats may exist outside the assessed scope. Option B is incorrect because residual risk is not limited to retained risk alone; it includes any risk remaining after all treatment options, including modification, sharing, and avoidance. Option C is incorrect because transferred risks (via insurance or contracts) still contribute to residual risk, as the transfer may be partial or incomplete. Therefore, the only fully correct statement is that residual risk can consist of unidentified risk, consistent with ISO/IEC 27005:
2022 risk management guidance.

by Jeremy at Aug 15, 2026, 01:42 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10