Courseiva
mediumMultiple Choice

CRISC Practice Question: A risk assessment reveals that a legacy system…

A risk assessment reveals that a legacy system has a high vulnerability score but low business criticality. The cost to remediate is high. What is the MOST appropriate risk response?

⚠ Common exam trap

CRISC often tests the confusion between technical severity (CVSS score) and business risk — candidates pick 'mitigate' because the vulnerability score is high, ignoring that low business criticality makes acceptance the appropriate response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accept the risk and monitor it

When a vulnerability is high-scoring but the affected system has low business criticality and remediation cost is high, the risk to the organization is low in business-impact terms. The most appropriate response is to accept the risk and monitor it, since the cost of remediation outweighs the potential business impact. Risk acceptance with ongoing monitoring is a legitimate CRISC-aligned response when residual risk is within tolerance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Avoid the risk by decommissioning the system

    Why it's wrong here

    Decommissioning removes the system entirely, which is disproportionate when the asset still delivers business value despite low criticality; avoidance suits systems with no remaining function. The stem's high remediation cost against low criticality points to accepting the residual risk instead.

  • ✓

    Accept the risk and monitor it

    Why this is correct

    Low business criticality means the potential impact does not justify the high remediation cost, so accepting the risk and monitoring it is proportionate. Continued monitoring ensures the exposure is revisited if criticality or threat conditions change.

  • ✗

    Mitigate the vulnerability with a patch

    Why it's wrong here

    Patching is mitigation, which the stem rules out by stating remediation cost is high relative to the system's low business criticality. Spending heavily to fix a low-value asset is unjustified. Mitigation suits high-criticality systems where the cost is proportionate to the potential business impact.

  • ✗

    Transfer the risk via a managed security service

    Why it's wrong here

    A managed security service operates controls on the organisation's behalf; it does not shift financial or legal liability for the legacy system's vulnerability. Transfer requires a contract, such as cyber insurance, that indemnifies losses. Outsourcing monitoring leaves the underlying risk owned by the organisation.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.