Courseiva

CISM Information Security Risk Management Practice Question

An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?

⚠ Common exam trap

The trap here is conflating any security action with avoidance or acceptance, when the decisive question is whether the action reduces exposure while the activity continues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

Risk mitigation involves applying controls that reduce the likelihood or impact of a risk while allowing the underlying business activity to continue. Patching a known vulnerability lowers the probability of exploitation, so it falls squarely into the mitigation category rather than avoidance, transfer, or acceptance, each of which describes a fundamentally different treatment approach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk mitigation

    Why this is correct

    Applying the vendor patch reduces the likelihood that the vulnerability can be exploited, which lowers the overall risk exposure while the business activity continues. This is the defining characteristic of risk mitigation: implementing controls to reduce likelihood or impact. Patching is a classic preventive control within a vulnerability management program.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance means acknowledging the risk and taking no action to reduce it, usually because exposure already falls within tolerance or because treatment costs exceed the benefit. Applying a patch is an active control, the opposite of acceptance. Acceptance would be documented with a formal sign-off, not accompanied by remediation activity.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance means eliminating the activity or asset that generates the risk entirely, such as shutting down the application. Applying a patch preserves the business activity while reducing the vulnerability, so it does not avoid the risk. Avoidance is typically reserved for risks that cannot be brought within tolerance through any control.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts the financial consequence of a risk to a third party, most commonly through insurance or contractual indemnification. Patching does not shift any consequence to another party; it changes the underlying technical condition. Confusing a preventive control with transfer misstates where the risk ultimately resides, which remains with the organization.

About these practice questions

This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.