CAS-004 Governance, Risk, and Compliance Practice Question
A security manager at a defense contractor is reviewing the organization's risk register. A critical vulnerability in a widely used open-source library has been identified. The vendor has not released a patch, and the library is embedded in a custom application that cannot be easily replaced. The manager decides to implement a virtual patching solution at the network perimeter. Which risk treatment strategy does this represent?
⚠ Common exam trap
A common mix-up: candidates confuse virtual patching with risk transfer, because a third-party tool is used, but the risk remains with the organization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Virtual patching is a compensating control that reduces the likelihood of exploitation by filtering malicious traffic. Since the underlying vulnerability remains but its risk is lowered, this is risk mitigation. Transfer, acceptance, and avoidance do not involve actively reducing the risk through controls, making mitigation the correct classification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk transfer
Why it's wrong here
Risk transfer involves shifting the financial impact to a third party, typically through insurance or outsourcing. Virtual patching does not transfer risk; the organization retains the risk but controls it. The vendor is not assuming liability, and no insurance is involved, so this is not transfer.
- ✓
Risk mitigation
Why this is correct
Virtual patching reduces the likelihood or impact of exploitation by blocking attack vectors, even without a vendor patch. This is a form of risk mitigation because it lowers the risk to an acceptable level through compensating controls. It does not eliminate the vulnerability but manages it effectively.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance involves eliminating the risk by discontinuing the activity or system that introduces it. The organization continues to use the vulnerable library, so avoidance is not occurring. Virtual patching allows continued operation while managing the risk, which is mitigation, not avoidance.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means acknowledging the risk and choosing to do nothing, often because the cost of mitigation exceeds the potential loss. Here, the manager is actively implementing a control, so the risk is not being accepted. Acceptance would be appropriate only if no action were taken.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.