Determining Risk Response from Vulnerability Scan Policy
Exhibit
Vulnerability ID: VULN-001 Severity: Critical CVSS: 9.8 Port: 443 Service: HTTPS Status: Open Policy: All vulnerabilities with CVSS >= 9.0 must be remediated within 7 days.
Refer to the exhibit. A risk manager reviews the vulnerability scan output. According to the policy, what is the required risk response?
Quick Answer
The answer is to mitigate by patching or implementing compensating controls. This is correct because the policy mandates a specific risk response for vulnerabilities with a CVSS score of 9.0 or higher, which falls into the "Critical" severity band. Prioritizing risk response based on CVSS severity policy means that any scan output showing a score in this range triggers mandatory remediation, not acceptance, transfer, or deferral. On the CRISC exam, this scenario tests your ability to map a technical vulnerability assessment output to a governance-driven risk treatment decision, a common trap being the temptation to choose "accept" for high-severity items when a policy explicitly requires mitigation. Remember that policy always overrides subjective judgment in risk response. A useful memory tip: "Nine or higher? Mitigate or hire" — meaning any CVSS 9.0+ demands immediate patching or compensating controls, not a waiver.
⚠ Common exam trap
Watch out — candidates often choose 'Avoid by disabling the service' thinking it is the safest option, but CRISC emphasizes that risk avoidance should only be used when the risk cannot be mitigated to an acceptable level and the business can operate without the asset; patching is the primary response for known vulnerabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate by patching or compensating controls
The vulnerability scan output indicates a critical remote code execution vulnerability in the Apache Struts2 framework (CVE-2017-5638). According to policy, the required risk response is to mitigate by patching or implementing compensating controls because the vulnerability has a known exploit and high severity, making acceptance or transfer inappropriate without remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk
Why it's wrong here
Policy does not allow acceptance.
- ✗
Transfer the risk
Why it's wrong here
Insurance does not remediate the vulnerability.
- ✗
Avoid by disabling the service
Why it's wrong here
Avoidance is not required; mitigation is sufficient.
- ✓
Mitigate by patching or compensating controls
Why this is correct
Remediation is required.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. Which of the following is the MOST critical risk that should be addressed first?
easy- ✓ A.SSH protocol version 1.0 on 192.168.1.10
- B.RDP with weak encryption on 192.168.1.20
- C.SMB signing not required on 192.168.1.20
- D.Apache HTTP Server 2.2.3 on 192.168.1.10
Why A: SSH protocol version 1.0 is critically vulnerable to multiple security flaws, including session key recovery and man-in-the-middle attacks, due to weak integrity checks and lack of strong cryptographic algorithms. Unlike the other options, which represent misconfigurations or outdated software that can be mitigated with patches or configuration changes, SSHv1.0 is a deprecated protocol with known, easily exploitable vulnerabilities that directly compromise confidentiality and integrity of administrative access. This makes it the most critical risk to address first, as it exposes the core management interface of the asset.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.