mediumMultiple Choice
CRISC Practice Question: A risk assessment reveals that a legacy system…
A risk assessment reveals that a legacy system has a high vulnerability score but low business criticality. The cost to remediate is high. What is the MOST appropriate risk response?
⚠ Common exam trap
CRISC often tests the confusion between technical severity (CVSS score) and business risk — candidates pick 'mitigate' because the vulnerability score is high, ignoring that low business criticality makes acceptance the appropriate response.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept the risk and monitor it
When a vulnerability is high-scoring but the affected system has low business criticality and remediation cost is high, the risk to the organization is low in business-impact terms. The most appropriate response is to accept the risk and monitor it, since the cost of remediation outweighs the potential business impact. Risk acceptance with ongoing monitoring is a legitimate CRISC-aligned response when residual risk is within tolerance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Avoid the risk by decommissioning the system
Why it's wrong here
Decommissioning removes the system entirely, which is disproportionate when the asset still delivers business value despite low criticality; avoidance suits systems with no remaining function. The stem's high remediation cost against low criticality points to accepting the residual risk instead.
- ✓
Accept the risk and monitor it
Why this is correct
Low business criticality means the potential impact does not justify the high remediation cost, so accepting the risk and monitoring it is proportionate. Continued monitoring ensures the exposure is revisited if criticality or threat conditions change.
- ✗
Mitigate the vulnerability with a patch
Why it's wrong here
Patching is mitigation, which the stem rules out by stating remediation cost is high relative to the system's low business criticality. Spending heavily to fix a low-value asset is unjustified. Mitigation suits high-criticality systems where the cost is proportionate to the potential business impact.
- ✗
Transfer the risk via a managed security service
Why it's wrong here
A managed security service operates controls on the organisation's behalf; it does not shift financial or legal liability for the legacy system's vulnerability. Transfer requires a contract, such as cyber insurance, that indemnifies losses. Outsourcing monitoring leaves the underlying risk owned by the organisation.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.