Courseiva

CRISC Risk Response and Mitigation Practice Question

A small e-commerce company has identified a high-risk vulnerability in its payment processing system that could expose customer credit card data. The IT team recommends immediately patching the system, but the patch requires a 4-hour downtime during peak sales hours. The risk manager proposes accepting the risk until the next scheduled maintenance window in two weeks. The CEO is concerned about potential fines from PCI DSS non-compliance. What is the BEST course of action?

⚠ Common exam trap

CRISC often tests whether candidates default to 'accept the risk' or 'patch immediately' when the correct answer is a balanced compensating control that addresses both risk and business impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a compensating control (e.g., web application firewall) and schedule the patch during off-peak hours within 48 hours.

The best course of action balances risk mitigation, business continuity, and compliance. Implementing a compensating control such as a web application firewall reduces the immediate exposure of the vulnerability while allowing the patch to be scheduled during off-peak hours within a short timeframe (48 hours), avoiding both peak-hour downtime and prolonged exposure. This aligns with CRISC's emphasis on risk response options that are proportionate and timely, and it addresses the CEO's PCI DSS compliance concern by reducing the window of non-compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delay the patch until the next maintenance window but document the risk acceptance with CEO sign-off.

    Why it's wrong here

    Documenting risk acceptance does not remove the PCI DSS violation; the vulnerability still exposes cardholder data for two weeks, and sign-off cannot waive regulatory liability. Formal risk acceptance fits low-severity risks within appetite, not high-risk exposures to payment data that attract fines.

  • ✗

    Accept the risk and schedule the patch during the next maintenance window as originally planned.

    Why it's wrong here

    Accepting the risk leaves cardholder data exposed for two weeks, breaching PCI DSS requirements and inviting fines the CEO flagged. Risk acceptance suits low-impact risks within tolerance; here the exposure is high and regulatory, so the patch must be expedited rather than deferred to the routine maintenance window.

  • ✗

    Apply the patch immediately during peak hours, accepting the revenue loss from downtime.

    Why it's wrong here

    Taking four hours of peak-hour downtime to patch immediately sacrifices revenue unnecessarily when the patch can be deployed during a low-traffic period within the same day. Immediate patching suits vulnerabilities already being actively exploited; here the priority is closing the exposure without peak-hour outage.

  • ✓

    Implement a compensating control (e.g., web application firewall) and schedule the patch during off-peak hours within 48 hours.

    Why this is correct

    A web application firewall filters malicious traffic while the patch is deferred, reducing exposure during the two-week gap, and off-peak patching within 48 hours restores compliance faster than the maintenance window. This satisfies the PCI DSS and downtime constraints simultaneously.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.