Courseiva

CRISC Risk Response and Mitigation Practice Question

A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?

⚠ Common exam trap

Watch out — candidates often confuse risk mitigation with risk avoidance because compensating controls are used instead of removing the vulnerable system.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk mitigation

The organization is actively reducing the likelihood and impact of a vulnerability by deploying a WAF and network segmentation. These compensating controls are classic risk mitigation actions. Risk mitigation is the appropriate strategy when an organization chooses to implement controls to bring residual risk within appetite rather than accepting, transferring, or avoiding the risk entirely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk acceptance

    Why it's wrong here

    Risk acceptance means acknowledging the risk and taking no action to reduce its likelihood or impact. Here, the organization is actively implementing a WAF and segmentation, which reduces the risk exposure rather than simply accepting it. Acceptance would be appropriate only if the cost of mitigation outweighed the benefit and the risk fell within appetite, but the scenario describes active controls being deployed.

  • ✗

    Risk transfer

    Why it's wrong here

    Risk transfer shifts the financial impact of a risk to a third party, typically through insurance or contractual agreements. In this scenario, no insurance or outsourcing is mentioned; the organization is investing in technical controls to reduce the risk directly. The WAF and segmentation do not transfer the risk but rather mitigate it internally.

  • ✓

    Risk mitigation

    Why this is correct

    Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Deploying a WAF with virtual patching and network segmentation directly reduces the exploitability of the unpatched application and limits lateral movement, thereby lowering the overall risk. This aligns with the organization's decision to take action rather than transfer, avoid, or accept the risk.

  • ✗

    Risk avoidance

    Why it's wrong here

    Risk avoidance eliminates the activity or asset that gives rise to the risk. Here, the trading application remains in use, and the organization is implementing compensating controls to manage the risk. Avoidance would involve decommissioning the application or discontinuing its use, which is not what the scenario describes.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.