CRISC Risk Response and Mitigation Practice Question
A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?
⚠ Common exam trap
Many candidates choose mitigation by default, failing to recognize that when a vulnerability cannot be patched and the asset is low-impact, formal acceptance is the correct risk response per the CRISC framework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Acceptance
Acceptance is the most appropriate response because the vulnerability exists in a legacy application that supports a non-critical business process and is used by a small number of users. The cost and operational impact of patching or replacing the application outweigh the risk, making it acceptable to operate with the known vulnerability under formal risk acceptance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoidance
Why it's wrong here
Avoidance means discontinuing the activity entirely, yet the application still supports a business process, so ceasing use is not feasible. It is tempting because the vulnerability cannot be patched, but avoidance applies when the underlying activity itself can be eliminated.
- ✗
Transfer
Why it's wrong here
Transferring risk requires a third party, such as cyber-insurance or an outsourced provider, to accept the financial loss. Here the vulnerability sits in a legacy application the company still operates, and no contract or insurer is named to absorb it. Transfer suits scenarios where a counterparty can genuinely assume the risk.
- ✓
Acceptance
Why this is correct
Acceptance suits this scenario because the residual risk falls within tolerance: the vulnerability affects a legacy application serving few users on a non-critical process, and patching is not immediately feasible. Formally documenting and monitoring that accepted exposure satisfies the stem's constraints, whereas mitigation, transfer or avoidance would demand disproportionate cost or effort.
- ✗
Mitigation
Why it's wrong here
Mitigation reduces likelihood or impact through controls, but the vulnerability cannot be patched immediately, so the residual exposure persists. It is tempting because it is the default response to vulnerabilities, yet with a small user base and non-critical process, accepting the risk is the appropriate strategy.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.