Courseiva

CRISC Risk Response and Mitigation Practice Question

A company has identified a critical vulnerability in a legacy application that cannot be patched immediately. The application is used by a small number of users and supports a non-critical business process. Which of the following is the MOST appropriate risk response strategy?

⚠ Common exam trap

Many candidates choose mitigation by default, failing to recognize that when a vulnerability cannot be patched and the asset is low-impact, formal acceptance is the correct risk response per the CRISC framework.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Acceptance

Acceptance is the most appropriate response because the vulnerability exists in a legacy application that supports a non-critical business process and is used by a small number of users. The cost and operational impact of patching or replacing the application outweigh the risk, making it acceptable to operate with the known vulnerability under formal risk acceptance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Avoidance

    Why it's wrong here

    Avoidance means discontinuing the activity entirely, yet the application still supports a business process, so ceasing use is not feasible. It is tempting because the vulnerability cannot be patched, but avoidance applies when the underlying activity itself can be eliminated.

  • ✗

    Transfer

    Why it's wrong here

    Transferring risk requires a third party, such as cyber-insurance or an outsourced provider, to accept the financial loss. Here the vulnerability sits in a legacy application the company still operates, and no contract or insurer is named to absorb it. Transfer suits scenarios where a counterparty can genuinely assume the risk.

  • ✓

    Acceptance

    Why this is correct

    Acceptance suits this scenario because the residual risk falls within tolerance: the vulnerability affects a legacy application serving few users on a non-critical process, and patching is not immediately feasible. Formally documenting and monitoring that accepted exposure satisfies the stem's constraints, whereas mitigation, transfer or avoidance would demand disproportionate cost or effort.

  • ✗

    Mitigation

    Why it's wrong here

    Mitigation reduces likelihood or impact through controls, but the vulnerability cannot be patched immediately, so the residual exposure persists. It is tempting because it is the default response to vulnerabilities, yet with a small user base and non-critical process, accepting the risk is the appropriate strategy.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.