A risk assessment identifies a critical vulnerability in a web application. Which control type would be most effective in preventing exploitation of this vulnerability?
Patching removes the vulnerable code path entirely, stopping exploitation before it can occur, which is the defining mechanism of a preventive control. This directly satisfies the stem's requirement for the control type most effective at preventing exploitation of the identified web application vulnerability.
Why this answer
A preventive control stops an incident before it occurs, and patching the vulnerability removes the exploitable condition entirely, which is the most effective way to prevent exploitation. Since the vulnerability is identified as critical, remediation via patching directly addresses the root cause rather than merely detecting or recovering from an exploit.
Exam trap
CRISC often tests the distinction between control types; candidates must recognize that 'prevent' questions require a preventive control, not a detective or corrective one, even if those are also valuable.
How to eliminate wrong answers
Option A is wrong because a compensating control (e.g., additional monitoring) only mitigates risk when the primary control cannot be applied; it does not prevent exploitation and is a secondary measure. Option C is wrong because a corrective control (backup restoration) operates after an incident has occurred and does not prevent the vulnerability from being exploited. Option D is wrong because a detective control (log monitoring) identifies an attack in progress or after the fact but does not stop it from succeeding.