CRISC IT Risk Assessment Practice Question
A hospital's risk team is assessing a new telehealth platform. The vendor reports that its encryption module was certified two years ago. The team wants to determine whether the residual risk of relying on that module is acceptable. Which action should the team take FIRST?
⚠ Common exam trap
The trap here is treating a past certification as ongoing proof of control effectiveness, when residual risk requires current, verifiable evidence.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request the vendor's current vulnerability scan results and patch history for the module.
Residual risk must be judged from current evidence about control effectiveness. An older certification says little about whether the encryption module still blocks today's exploits. Obtaining up-to-date scan results and patch records gives the team the factual basis to determine whether the remaining exposure is tolerable, which is the necessary first step before any treatment decision.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Immediately terminate the vendor contract because the certification is expired.
Why it's wrong here
Terminating the contract is a drastic treatment decision that should follow, not precede, an assessment of actual residual risk. Certifications often have multi-year validity, so an older date alone is not evidence of unacceptable exposure. Acting without current vulnerability data would be premature and could disrupt patient services, so this cannot be the first action.
- ✗
Accept the vendor's certification as sufficient evidence and close the risk.
Why it's wrong here
A certification from two years ago does not prove the module still resists current threats, because new vulnerabilities and attack techniques emerge continuously. Closing the risk based on outdated evidence ignores the possibility that the module has unpatched flaws. The team would be accepting risk without current data, which violates the principle that residual risk must be evaluated against the present threat landscape.
- ✓
Request the vendor's current vulnerability scan results and patch history for the module.
Why this is correct
Residual risk depends on the control's current effectiveness, not its historical certification. Requesting recent scan results and patch history gives the team evidence about whether known vulnerabilities remain unaddressed in the module. That data lets the team judge whether the encryption still provides the protection assumed in the risk calculation, making it the essential first step before deciding on acceptance.
- ✗
Re-rate the inherent risk to zero because encryption is in place.
Why it's wrong here
Inherent risk reflects exposure before controls and cannot be reduced to zero simply because a control exists. The presence of encryption affects residual risk, and only if the control is proven effective. Setting inherent risk to zero misrepresents the underlying threat and impact, and it would corrupt every downstream calculation, so it is clearly incorrect here.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.