Courseiva

CRISC Risk Response and Mitigation Practice Question

A risk practitioner is reviewing the organization's risk register and notes that a critical web application has a high inherent risk of SQL injection. The development team proposes implementing a web application firewall (WAF) with virtual patching. The risk practitioner's primary responsibility in this scenario is to:

⚠ Common exam trap

Candidates often confuse the risk practitioner's advisory role with hands-on implementation or risk acceptance authority.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evaluate whether the proposed control reduces risk to an acceptable level within the organization's risk appetite.

The risk practitioner's core duty is to evaluate risk responses, not to implement them or accept risk. In this scenario, the proposed WAF with virtual patching is a mitigation control. The practitioner must assess whether it reduces the SQL injection risk to a level consistent with the organization's risk appetite. This involves considering control effectiveness, potential residual risk, and cost-benefit. Only after this evaluation can the risk owner make an informed decision.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Immediately implement the WAF and virtual patching to address the vulnerability before any exploitation occurs.

    Why it's wrong here

    Implementing technical controls is typically the responsibility of IT operations or security engineering, not the risk practitioner. The risk practitioner focuses on risk analysis, evaluation, and monitoring. While timely mitigation is important, the practitioner's role is to assess and recommend, not to execute technical implementation. Taking direct implementation action would bypass proper change management and separation of duties.

  • ✗

    Transfer the risk by purchasing cyber insurance that covers SQL injection attacks, since the WAF may not be fully effective.

    Why it's wrong here

    Risk transfer via insurance is a valid response, but it is not the practitioner's primary responsibility in this scenario. The question asks about the practitioner's role when a control is proposed. The practitioner should first evaluate the control's effectiveness and alignment with risk appetite. Insurance may be a complementary measure, but it does not replace the need to assess whether the proposed mitigation is adequate.

  • ✗

    Accept the risk because the WAF will eventually be deployed and the residual risk will be managed by the IT team.

    Why it's wrong here

    Risk acceptance is a business decision that should be made by the risk owner, not the risk practitioner. The practitioner cannot unilaterally accept risk on behalf of the organization. Moreover, acceptance should only occur after evaluating whether the proposed control reduces risk to an acceptable level. Simply deferring to the IT team without assessment abdicates the practitioner's responsibility to provide risk-informed guidance.

  • ✓

    Evaluate whether the proposed control reduces risk to an acceptable level within the organization's risk appetite.

    Why this is correct

    The risk practitioner's role is to assess whether the proposed risk response (WAF with virtual patching) effectively mitigates the identified risk to a level that aligns with the organization's risk appetite. This involves analyzing the control's expected effectiveness, cost, and impact on residual risk. The practitioner does not implement controls or accept risk unilaterally; rather, they provide guidance to ensure the response is appropriate and aligned with business objectives.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.