CRISC Risk Response and Mitigation Practice Question
A recent security assessment identified that a critical web application is vulnerable to SQL injection due to unpatched software. The vendor has released a security patch. Which risk response is most appropriate?
⚠ Common exam trap
CRISC often tests the distinction between mitigation and avoidance — candidates pick 'take offline' thinking it is the safest response, but avoidance is only appropriate when the risk cannot be mitigated cost-effectively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate by applying the patch
Applying the vendor-released patch directly reduces the likelihood and impact of the SQL injection vulnerability, which is the definition of risk mitigation. Since a patch exists and the application is critical, mitigation is both feasible and the most appropriate response — it addresses the root cause rather than avoiding, accepting, or transferring the consequence.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Mitigate by applying the patch
Why this is correct
Applying the vendor patch removes the unpatched-software condition enabling SQL injection, reducing likelihood and impact to acceptable levels. Mitigation is appropriate because a known, available fix exists, satisfying the assessment finding rather than transferring, avoiding or accepting the risk.
- ✗
Avoid by taking the application offline
Why it's wrong here
Taking the application offline removes the vulnerability but also removes the business capability the application delivers, which is disproportionate when a vendor patch exists. Avoidance suits scenarios where no effective control can reduce risk to acceptable levels; here patching preserves functionality while eliminating the injection vector.
- ✗
Accept the risk
Why it's wrong here
Acceptance leaves the SQL injection exploitable, which is unjustifiable when a vendor patch is already available and the application is critical. It is tempting when remediation cost exceeds potential impact or the risk is trivial, but those conditions are absent here; the patch makes mitigation feasible and expected.
- ✗
Transfer via insurance
Why it's wrong here
Insurance covers financial loss after an incident; it cannot stop SQL injection exploiting the unpatched application, so the vulnerability persists. It is tempting because transferring residual risk is valid when no remediation exists or impact is purely financial, but here a vendor patch is available, making mitigation the applicable response.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.