Courseiva

CISM Information Security Risk Management Practice Question

A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?

⚠ Common exam trap

The trap here is labelling compensating controls as risk acceptance because the vulnerability cannot be patched, when any control that actively lowers likelihood or impact constitutes mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

The organization is reducing the likelihood of exploitation through compensating technical controls while a permanent remedy is unavailable, which is the essence of risk mitigation. Avoidance would require removing the vulnerable function, transfer would require an insurer or contractual party to absorb the loss, and acceptance would mean taking no action. Virtual patching and monitoring modify the risk itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk avoidance

    Why it's wrong here

    Avoidance means eliminating the activity or asset that generates the risk, for example decommissioning the feature or refusing to process the data. Here the application continues to operate with its core functionality intact, so the underlying activity and its exposure remain. The virtual patch and monitoring reduce the probability of successful exploitation rather than removing the source of risk, which places this squarely in the mitigation category.

  • ✗

    Risk transfer

    Why it's wrong here

    Transfer shifts the financial consequence of a risk to a third party, typically through insurance, indemnification clauses, or outsourcing. A web application firewall rule and enhanced logging are technical controls the company operates and funds itself; no third party has assumed the loss. Transferring would require a contractual or insurance arrangement, and even then the reputational and regulatory consequences of a breach would largely remain with the provider.

  • ✗

    Risk acceptance

    Why it's wrong here

    Acceptance means acknowledging the exposure and taking no action to change its likelihood or impact, with the decision documented and approved at the appropriate authority level. Because the company is actively intervening with a virtual patch and monitoring, it is not accepting the risk in its current form. Acceptance might follow if the compensating controls were deemed ineffective and management formally chose to bear the exposure, but that is not the scenario described.

  • ✓

    Risk mitigation

    Why this is correct

    Deploying a virtual patch and increasing monitoring reduces the likelihood that the vulnerability will be successfully exploited while the organization works toward a permanent fix. The risk source still exists, but compensating controls lower the exposure to an acceptable level. This is the defining characteristic of mitigation: reducing likelihood or impact through controls rather than eliminating, transferring, or simply accepting the exposure.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.