easyMultiple ChoiceObjective-mapped
CISSP Practice Question: A financial institution is conducting a…
A financial institution is conducting a vulnerability assessment of its internal network. The assessor runs a comprehensive scan and discovers that several Windows servers have missing security patches. The organization has a patch management policy that requires all critical patches to be applied within 30 days. The scan results show that some patches have been pending for 45 days. The assessor also finds that the servers are isolated in a separate VLAN with strict firewall rules limiting inbound traffic to only necessary ports. The business owner argues that because the servers are isolated, the risk is low and the patches can be delayed. As the security assessor, what should be the BEST course of action?
⚠ Common exam trap
Candidates often confuse compensating controls (Option A) with a complete solution, forgetting that policy violations require formal risk acceptance rather than just technical workarounds.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Escalate the finding to the risk management team for formal risk acceptance.
The organization's patch management policy has been violated (patches overdue by 45 days vs. 30-day requirement), and the business owner's informal risk acceptance is insufficient. Formal risk acceptance requires documented approval from the risk management team, ensuring accountability and alignment with the organization's risk appetite. The VLAN isolation and firewall rules are compensating controls, but they do not negate the need for proper risk treatment per policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Recommend additional compensating controls such as intrusion prevention.
Why it's wrong here
Recommending compensating controls, like an Intrusion Prevention System (IPS), is a valid risk mitigation strategy; however, it is not the initial best action after identifying a significant vulnerability. Before implementing or recommending specific controls, the identified risk must first be formally acknowledged and assessed by the appropriate risk management stakeholders. Bypassing this formal process can lead to unapproved expenditures or misaligned risk treatment strategies, failing to ensure organizational alignment on residual risk.
- ✗
Accept the risk and close the finding.
Why it's wrong here
Simply accepting the risk and closing the finding without formal documentation or stakeholder approval constitutes an informal risk acceptance, which is a critical lapse in governance. This action bypasses established risk management frameworks, preventing proper assessment of the risk's impact, likelihood, and potential treatment options. Such an approach lacks accountability, fails to inform management of the organization's true risk posture, and can lead to unmanaged liabilities.
- ✓
Escalate the finding to the risk management team for formal risk acceptance.
Why this is correct
Escalating the finding to the risk management team for formal risk acceptance is the correct procedure when a significant vulnerability is identified and immediate remediation is not feasible or desired. This process ensures that the decision to operate with a known risk is thoroughly documented, reviewed by appropriate organizational stakeholders, and approved by management with the authority to accept that level of risk. Formal acceptance establishes clear accountability and ensures the organization's risk posture is transparently understood and managed.
- ✗
Immediately apply the patches without further approval.
Why it's wrong here
Immediately applying patches without further approval is a deviation from established change management protocols and can introduce significant operational risks. Uncontrolled patching may lead to system instability, service outages, or unintended compatibility issues that disrupt critical business functions. Proper change management requires testing, scheduling, and approval to ensure that remediation efforts do not inadvertently create new problems or bypass necessary validation steps, especially in a financial institution.
Visual reference
Go deeper
Related to this question
Learn chapter
Security Governance and Principles
Key term
Quality update policy
A quality update policy is a set of rules and schedules that IT administrators use to control which Windows updates are deployed to devices to ensure stability, security, and compatibility.
Key term
Risk management
Risk management is the process of identifying, assessing, and controlling threats to an organization's capital, earnings, and operations, including IT systems and data.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.