Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: Refer to the exhibit

Exhibit

Vulnerability Scan Report:

Vulnerability: CVE-2023-1234 (Critical) - Remote code execution in Apache Struts 2
Affected Hosts: 10.1.1.10, 10.1.1.20, 10.1.1.30
Port: 8080
Impact: CVSS 9.8
Patch available: Yes

Refer to the exhibit. What is the MOST immediate risk identification action?

⚠ Common exam trap

The trap here is that candidates often jump to documenting or validating the vulnerability without first checking the most obvious and efficient control—patch status—which is the immediate action to determine actual exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Check if the patch has been deployed

The exhibit (not shown) likely presents a vulnerability scan result or a security advisory. The most immediate risk identification action is to verify whether the identified vulnerability has already been mitigated by deploying the vendor-supplied patch. This confirms the current exposure status before any further risk assessment or documentation steps are taken.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Document the vulnerability in the risk register

    Why it's wrong here

    Documentation should follow confirmation of the issue.

  • Update asset inventory

    Why it's wrong here

    Inventory update is not immediate; the focus is on the vulnerability.

  • Check if the patch has been deployed

    Why this is correct

    Determining patch status is critical to understand the actual risk.

  • Validate the vulnerability manually

    Why it's wrong here

    The vulnerability scan already provides sufficient evidence.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.