CISM Information Security Risk Management Practice Question
A software-as-a-service provider must decide how to treat a newly identified risk: a critical vulnerability in an open-source library used by its customer-facing application. No patch is available from the maintainer, and exploitation in the wild has been observed at other firms. The vulnerability cannot be removed without breaking core functionality. Which risk treatment option is being applied if the company deploys a virtual patch at the web application firewall and tightens monitoring?
⚠ Common exam trap
The trap here is labelling compensating controls as risk acceptance because the vulnerability cannot be patched, when any control that actively lowers likelihood or impact constitutes mitigation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
The organization is reducing the likelihood of exploitation through compensating technical controls while a permanent remedy is unavailable, which is the essence of risk mitigation. Avoidance would require removing the vulnerable function, transfer would require an insurer or contractual party to absorb the loss, and acceptance would mean taking no action. Virtual patching and monitoring modify the risk itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk avoidance
Why it's wrong here
Avoidance means eliminating the activity or asset that generates the risk, for example decommissioning the feature or refusing to process the data. Here the application continues to operate with its core functionality intact, so the underlying activity and its exposure remain. The virtual patch and monitoring reduce the probability of successful exploitation rather than removing the source of risk, which places this squarely in the mitigation category.
- ✗
Risk transfer
Why it's wrong here
Transfer shifts the financial consequence of a risk to a third party, typically through insurance, indemnification clauses, or outsourcing. A web application firewall rule and enhanced logging are technical controls the company operates and funds itself; no third party has assumed the loss. Transferring would require a contractual or insurance arrangement, and even then the reputational and regulatory consequences of a breach would largely remain with the provider.
- ✗
Risk acceptance
Why it's wrong here
Acceptance means acknowledging the exposure and taking no action to change its likelihood or impact, with the decision documented and approved at the appropriate authority level. Because the company is actively intervening with a virtual patch and monitoring, it is not accepting the risk in its current form. Acceptance might follow if the compensating controls were deemed ineffective and management formally chose to bear the exposure, but that is not the scenario described.
- ✓
Risk mitigation
Why this is correct
Deploying a virtual patch and increasing monitoring reduces the likelihood that the vulnerability will be successfully exploited while the organization works toward a permanent fix. The risk source still exists, but compensating controls lower the exposure to an acceptable level. This is the defining characteristic of mitigation: reducing likelihood or impact through controls rather than eliminating, transferring, or simply accepting the exposure.
Go deeper
Related to this question
About these practice questions
One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.