Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A financial institution is conducting a…

A financial institution is conducting a vulnerability assessment of its internal network. The assessor runs a comprehensive scan and discovers that several Windows servers have missing security patches. The organization has a patch management policy that requires all critical patches to be applied within 30 days. The scan results show that some patches have been pending for 45 days. The assessor also finds that the servers are isolated in a separate VLAN with strict firewall rules limiting inbound traffic to only necessary ports. The business owner argues that because the servers are isolated, the risk is low and the patches can be delayed. As the security assessor, what should be the BEST course of action?

⚠ Common exam trap

Candidates often confuse compensating controls (Option A) with a complete solution, forgetting that policy violations require formal risk acceptance rather than just technical workarounds.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Escalate the finding to the risk management team for formal risk acceptance.

The organization's patch management policy has been violated (patches overdue by 45 days vs. 30-day requirement), and the business owner's informal risk acceptance is insufficient. Formal risk acceptance requires documented approval from the risk management team, ensuring accountability and alignment with the organization's risk appetite. The VLAN isolation and firewall rules are compensating controls, but they do not negate the need for proper risk treatment per policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Recommend additional compensating controls such as intrusion prevention.

    Why it's wrong here

    Recommending compensating controls, like an Intrusion Prevention System (IPS), is a valid risk mitigation strategy; however, it is not the initial best action after identifying a significant vulnerability. Before implementing or recommending specific controls, the identified risk must first be formally acknowledged and assessed by the appropriate risk management stakeholders. Bypassing this formal process can lead to unapproved expenditures or misaligned risk treatment strategies, failing to ensure organizational alignment on residual risk.

  • Accept the risk and close the finding.

    Why it's wrong here

    Simply accepting the risk and closing the finding without formal documentation or stakeholder approval constitutes an informal risk acceptance, which is a critical lapse in governance. This action bypasses established risk management frameworks, preventing proper assessment of the risk's impact, likelihood, and potential treatment options. Such an approach lacks accountability, fails to inform management of the organization's true risk posture, and can lead to unmanaged liabilities.

  • Escalate the finding to the risk management team for formal risk acceptance.

    Why this is correct

    Escalating the finding to the risk management team for formal risk acceptance is the correct procedure when a significant vulnerability is identified and immediate remediation is not feasible or desired. This process ensures that the decision to operate with a known risk is thoroughly documented, reviewed by appropriate organizational stakeholders, and approved by management with the authority to accept that level of risk. Formal acceptance establishes clear accountability and ensures the organization's risk posture is transparently understood and managed.

  • Immediately apply the patches without further approval.

    Why it's wrong here

    Immediately applying patches without further approval is a deviation from established change management protocols and can introduce significant operational risks. Uncontrolled patching may lead to system instability, service outages, or unintended compatibility issues that disrupt critical business functions. Proper change management requires testing, scheduling, and approval to ensure that remediation efforts do not inadvertently create new problems or bypass necessary validation steps, especially in a financial institution.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.