Courseiva
mediumMultiple Choice

CRISC Practice Question: Based on the exhibit, which aspect of risk…

Exhibit

Refer to the exhibit.

---
Vulnerability Scan Report Excerpt
Target: 192.168.1.100
Vulnerability: CVE-2023-XXXX
Severity: Critical
Status: Open (first detected: 2024-01-15)
Last scan: 2024-04-10
Patches available: Yes
Risk accepted: Yes (by system owner on 2024-02-01)
---

Based on the exhibit, which aspect of risk monitoring is MOST concerning?

⚠ Common exam trap

The trap here is that candidates often focus on the technical severity (critical) or the scan frequency, but CRISC emphasizes that the most concerning aspect of risk monitoring is the failure to act on known risks, not the initial risk level or the timing of scans.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vulnerability has been open for three months with no evidence of monitoring or remediation despite a patch being available.

The vulnerability has been open for three months with a patch available, yet there is no evidence of monitoring or remediation. This indicates a complete breakdown of the risk monitoring process, as the organization failed to track, escalate, or patch a known critical vulnerability, leaving the system exposed to exploitation. In risk monitoring, the absence of any monitoring activity or remediation action over such a long period is far more concerning than the severity alone, as it reflects a systemic failure in the control environment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The vulnerability has been open for three months with no evidence of monitoring or remediation despite a patch being available.

    Why this is correct

    A patchable vulnerability left open three months with no monitoring or remediation evidence indicates risk response and tracking have failed. The availability of a patch removes justification for inaction, making this the most concerning aspect of the risk monitoring process.

  • ✗

    The vulnerability severity is critical.

    Why it's wrong here

    Severity alone is a static rating, not evidence of monitoring weakness; a critical vulnerability with a documented, tracked remediation plan is managed risk. Monitoring concerns arise from gaps such as missed reassessment, absent ownership, or overdue treatment, not the score itself.

  • ✗

    The last scan was three months after the initial detection.

    Why it's wrong here

    A three-month gap between detection and the follow-up scan leaves the risk unmonitored for a quarter, so degradation or exploitation goes unseen. It is tempting because scan frequency is a genuine monitoring metric, and a delayed scan would be the correct concern if the stem showed a defined schedule that was missed.

  • ✗

    The risk was accepted by the system owner.

    Why it's wrong here

    Acceptance is a legitimate, documented risk response, so it does not itself indicate monitoring failure; the stem asks about monitoring. It tempts because accepted risks still require periodic review, and acceptance without monitoring would be the correct concern if the exhibit showed no review date or owner sign-off.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.