CRISC Information Technology and Security Practice Question
A risk practitioner is reviewing the organization's vulnerability management process. The team currently relies on the Common Vulnerability Scoring System (CVSS) base score alone to prioritize remediation. The CISO asks for a more risk-based prioritization approach. Which of the following should the practitioner recommend as the MOST effective enhancement?
⚠ Common exam trap
The trap here is assuming that a higher CVSS base score always means higher risk, when exploit likelihood and asset context often change the true priority.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incorporate the Exploit Prediction Scoring System (EPSS) score and asset criticality into the prioritization.
Risk-based vulnerability prioritization requires combining likelihood of exploitation with business impact. EPSS provides an empirical, forward-looking probability of exploitation, while asset criticality reflects the business consequence if the asset is compromised. Together they allow the team to focus remediation on the findings that present the greatest actual risk, rather than treating all high CVSS findings as equivalent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incorporate the Exploit Prediction Scoring System (EPSS) score and asset criticality into the prioritization.
Why this is correct
EPSS estimates the probability that a vulnerability will be exploited in the wild within 30 days, and combining it with asset criticality aligns remediation with actual business risk. CVSS base score alone reflects intrinsic severity, not likelihood of exploitation or business impact. This enhancement directly supports risk-based prioritization, which is a core CRISC objective.
- ✗
Replace CVSS base scores with the Common Weakness Enumeration (CWE) identifiers for all findings.
Why it's wrong here
CWE classifies the type of software weakness, not the severity or likelihood of exploitation of a specific instance. It is useful for root-cause analysis and developer education but does not provide a quantitative risk signal for remediation ordering. Substituting it for CVSS would reduce, not improve, prioritization fidelity.
- ✗
Apply a uniform 30-day remediation deadline to all high and critical CVSS findings.
Why it's wrong here
A uniform deadline ignores differences in exploit likelihood, exposure, and asset value. It may force unnecessary emergency work on low-risk systems while under-prioritizing critical assets with medium-severity findings. This is a policy simplification, not a risk-based prioritization enhancement.
- ✗
Increase the frequency of authenticated vulnerability scans from monthly to weekly.
Why it's wrong here
More frequent scanning improves discovery timeliness but does not change the prioritization logic. The team would still rank findings by CVSS base score, so the underlying risk-based decision-making gap remains. This option addresses detection cadence rather than the prioritization approach the CISO requested.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.