CRISC Information Technology and Security Practice Question
A risk manager is evaluating the organization's vulnerability management program. The organization scans its external-facing systems weekly but has no process for prioritizing vulnerabilities based on business impact. Which of the following should the risk manager recommend as the MOST effective improvement?
⚠ Common exam trap
The trap here is equating more frequent scanning or stricter deadlines with better risk management, when the real gap is the absence of risk-based prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a risk-based vulnerability prioritization process that considers asset criticality, threat intelligence, and exploitability.
The program lacks a risk-based approach to prioritization. The most effective improvement is to implement a process that ranks vulnerabilities by the risk they pose, considering asset criticality, threat intelligence, and exploitability. This ensures that limited resources are directed to the most significant risks, aligning vulnerability management with business objectives.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a risk-based vulnerability prioritization process that considers asset criticality, threat intelligence, and exploitability.
Why this is correct
A risk-based prioritization process ensures that remediation efforts focus on vulnerabilities that pose the greatest risk to the business. By factoring in asset criticality, threat intelligence, and exploitability, the organization can allocate resources efficiently and reduce the most significant exposures first. This directly addresses the missing prioritization component and aligns vulnerability management with business risk.
- ✗
Require all vulnerabilities to be remediated within 30 days regardless of severity to enforce a strict SLA.
Why it's wrong here
A uniform remediation deadline ignores risk differences and can lead to inefficient use of resources. Critical vulnerabilities on high-value assets might require faster action, while low-risk ones can be deferred. A strict 30-day SLA for all vulnerabilities may be unachievable and could cause teams to focus on easy fixes rather than the most impactful ones.
- ✗
Outsource vulnerability scanning to a third-party provider to gain access to more comprehensive threat data.
Why it's wrong here
Outsourcing may provide additional threat intelligence, but it does not inherently solve the prioritization problem. The organization still needs a process to interpret and act on the data. Without internal risk-based criteria, even comprehensive scanning results may not lead to effective remediation. The core issue is the lack of a prioritization framework, not the scanning capability.
- ✗
Increase the frequency of external scans to daily to catch vulnerabilities faster.
Why it's wrong here
Increasing scan frequency may reduce the window of exposure, but it does not address the lack of prioritization. Without a risk-based approach, the organization may still waste resources on low-impact vulnerabilities while critical ones remain unaddressed. Frequency alone does not ensure that the most significant risks are mitigated first.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.