The correct answer is A. Residual risk.
Residual risk is the risk that remains after safeguards, controls, or mitigation strategies have been applied. In some cases, a risk cannot be fully eliminated or mitigated. The organization must then decide whether to accept, transfer, avoid, or further manage the remaining risk.
This aligns with CompTIA Security+ SY0-701 risk management concepts, especially risk treatment, risk acceptance, risk tolerance, and residual risk.
Why the other options are incorrect:
B. Risk appetite
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its objectives. It does not specifically describe a risk that remains after mitigation attempts.
C. Reviewed risk
This is not the best formal risk management term for a risk that cannot be mitigated.
D. Risk register
A risk register is a document or system used to track identified risks, risk owners, likelihood, impact, treatment plans, and status. It does not describe the remaining risk itself.
Therefore, a risk that cannot be fully mitigated is best described as residual risk.
Submit