CRISC Information Technology and Security Practice Question
A risk practitioner is reviewing the organization's vulnerability management programme. The vulnerability scan report shows thousands of findings, and remediation teams are overwhelmed. Which of the following is the MOST effective approach to prioritize remediation?
⚠ Common exam trap
The trap here is equating a high CVSS base score with high organizational risk and prioritizing solely on that number.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize using threat intelligence and exploitability data combined with the business criticality of the affected assets.
Vulnerability management fails when severity is confused with risk. The most effective approach combines exploitability signals, such as active exploitation and threat intelligence, with the business criticality of the asset, so remediation effort targets findings that could actually harm the organization. A pure CVSS threshold, blanket assignment, or extra scanning does not answer the prioritization question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remediate all findings with a Common Vulnerability Scoring System (CVSS) base score of 7.0 or higher within 30 days.
Why it's wrong here
CVSS base scores describe intrinsic severity but ignore whether the vulnerable asset is internet-facing, whether the vulnerability is being exploited in the wild, and what business process depends on the asset. A blanket severity threshold will over-prioritize unreachable systems and under-prioritize critical assets, leaving remediation teams still overwhelmed.
- ✗
Assign every finding to the system owner and require monthly status reporting until all findings are closed.
Why it's wrong here
Assigning all findings equally with monthly reporting creates administrative burden without discriminating between material and trivial risk. Teams will triage informally anyway, and the reporting will not reflect true residual risk. This approach treats every finding as equally important, which is precisely the condition that caused the overload.
- ✓
Prioritize using threat intelligence and exploitability data combined with the business criticality of the affected assets.
Why this is correct
Risk-based prioritization weighs the likelihood of exploitation, drawn from threat intelligence and known exploited vulnerability catalogs, against the business impact of the affected asset. This focuses limited remediation capacity on findings that present real, material risk to the organization, which is the core purpose of vulnerability risk management rather than severity sorting alone.
- ✗
Purchase an additional scanning tool and run scans more frequently to build a complete inventory of findings.
Why it's wrong here
More frequent scanning improves visibility but does not help decide what to fix first; it may increase the backlog. The scenario problem is prioritization of an already large finding set, not detection coverage. Adding tooling without a risk-based decision model leaves the remediation team with the same unmanageable queue.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.