easyMultiple ChoiceObjective-mapped
CRISC Practice Question: During a risk assessment of a web application,…
During a risk assessment of a web application, the risk owner identifies that the application uses outdated encryption algorithms. What is the most appropriate next step?
⚠ Common exam trap
Candidates often confuse the immediate need to patch (Option D) with the proper risk management process, which requires documentation and analysis before any remediation action is taken.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the finding in the risk register and assign a remediation timeline.
The risk owner has identified a specific vulnerability (outdated encryption algorithms) that must be formally recorded in the risk register. The next step is to document the finding and assign a remediation timeline, which aligns with the risk assessment process of treating identified risks. This ensures the issue is tracked, prioritized, and addressed within the organization's risk management framework, rather than being escalated, ignored, or patched without analysis.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Escalate the issue to senior management for approval to accept the risk.
Why it's wrong here
Escalation is appropriate only if the risk exceeds tolerance, but the first step is documentation.
- ✗
Accept the risk without action because encryption is not critical.
Why it's wrong here
Acceptance requires documented justification and management approval; not recommended without analysis.
- ✓
Document the finding in the risk register and assign a remediation timeline.
Why this is correct
Proper documentation ensures the risk is tracked and addressed.
- ✗
Immediately patch the application to use modern encryption without further analysis.
Why it's wrong here
Immediate patching may introduce conflicts or operational issues; risk assessment recommends documented remediation planning.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.