CISM Information Security Risk Management Practice Question
An information security manager is reviewing a risk register entry for a customer-facing web application. The entry lists a vulnerability that could allow unauthorized access to customer records. The application owner has proposed applying a vendor patch that has been available for 30 days. Which of the following risk treatment categories does applying the patch represent?
⚠ Common exam trap
The trap here is conflating any security action with avoidance or acceptance, when the decisive question is whether the action reduces exposure while the activity continues.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Risk mitigation involves applying controls that reduce the likelihood or impact of a risk while allowing the underlying business activity to continue. Patching a known vulnerability lowers the probability of exploitation, so it falls squarely into the mitigation category rather than avoidance, transfer, or acceptance, each of which describes a fundamentally different treatment approach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Risk mitigation
Why this is correct
Applying the vendor patch reduces the likelihood that the vulnerability can be exploited, which lowers the overall risk exposure while the business activity continues. This is the defining characteristic of risk mitigation: implementing controls to reduce likelihood or impact. Patching is a classic preventive control within a vulnerability management program.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means acknowledging the risk and taking no action to reduce it, usually because exposure already falls within tolerance or because treatment costs exceed the benefit. Applying a patch is an active control, the opposite of acceptance. Acceptance would be documented with a formal sign-off, not accompanied by remediation activity.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance means eliminating the activity or asset that generates the risk entirely, such as shutting down the application. Applying a patch preserves the business activity while reducing the vulnerability, so it does not avoid the risk. Avoidance is typically reserved for risks that cannot be brought within tolerance through any control.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts the financial consequence of a risk to a third party, most commonly through insurance or contractual indemnification. Patching does not shift any consequence to another party; it changes the underlying technical condition. Confusing a preventive control with transfer misstates where the risk ultimately resides, which remains with the organization.
Go deeper
Related to this question
About these practice questions
This CISM question is part of Courseiva's 924-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.