CRISC Risk Response and Mitigation Practice Question
A financial services firm has determined that a critical trading application cannot be patched for a known remote code execution vulnerability because the vendor no longer supports the platform. The risk manager decides to deploy a web application firewall (WAF) with virtual patching and network segmentation to isolate the application from the internal network. Which risk response strategy does this represent?
⚠ Common exam trap
Watch out — candidates often confuse risk mitigation with risk avoidance because compensating controls are used instead of removing the vulnerable system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
The organization is actively reducing the likelihood and impact of a vulnerability by deploying a WAF and network segmentation. These compensating controls are classic risk mitigation actions. Risk mitigation is the appropriate strategy when an organization chooses to implement controls to bring residual risk within appetite rather than accepting, transferring, or avoiding the risk entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance means acknowledging the risk and taking no action to reduce its likelihood or impact. Here, the organization is actively implementing a WAF and segmentation, which reduces the risk exposure rather than simply accepting it. Acceptance would be appropriate only if the cost of mitigation outweighed the benefit and the risk fell within appetite, but the scenario describes active controls being deployed.
- ✗
Risk transfer
Why it's wrong here
Risk transfer shifts the financial impact of a risk to a third party, typically through insurance or contractual agreements. In this scenario, no insurance or outsourcing is mentioned; the organization is investing in technical controls to reduce the risk directly. The WAF and segmentation do not transfer the risk but rather mitigate it internally.
- ✓
Risk mitigation
Why this is correct
Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk. Deploying a WAF with virtual patching and network segmentation directly reduces the exploitability of the unpatched application and limits lateral movement, thereby lowering the overall risk. This aligns with the organization's decision to take action rather than transfer, avoid, or accept the risk.
- ✗
Risk avoidance
Why it's wrong here
Risk avoidance eliminates the activity or asset that gives rise to the risk. Here, the trading application remains in use, and the organization is implementing compensating controls to manage the risk. Avoidance would involve decommissioning the application or discontinuing its use, which is not what the scenario describes.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.