Courseiva
easyMultiple Choice

CISSP Practice Question: A large financial institution is finalizing its…

A large financial institution is finalizing its annual risk treatment plan based on a recent enterprise risk assessment. The risk appetite statement approved by the board specifies that the organization will accept only low residual risks for financial loss, but is willing to accept moderate risks for reputational damage if cost-benefit justifies. The risk register includes the following findings: 1) A critical SQL injection vulnerability in the online banking portal with high likelihood and critical impact; current controls include a web application firewall (WAF) that is not fully tuned. 2) Use of outdated TLS 1.0 encryption on internal communications between data centers; likelihood is medium, impact is low. 3) Lack of background checks for third-party vendors with access to sensitive data; likelihood is low, impact is moderate. 4) A single point of failure in the primary data center's power supply; likelihood is low, impact is critical. 5) An incident response plan that has not been tested in two years; likelihood is medium, impact is moderate. The CISO must prioritize actions for the upcoming quarter. What is the most appropriate first step?

⚠ Common exam trap

CISSP often tests the misconception that any low-impact risk can be accepted outright, or that insurance is a universal fix — candidates must instead rank by likelihood × impact against the stated risk appetite and pick the highest-exposure item for immediate remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately remediate the SQL injection vulnerability by tuning the WAF and applying vendor patches.

The SQL injection vulnerability in the online banking portal represents the highest-priority risk because it combines high likelihood with critical impact on a customer-facing financial system, directly violating the board's stated risk appetite of accepting only low residual risk for financial loss. Tuning the WAF and applying vendor patches directly reduces the likelihood and impact of exploitation, addressing the risk at its source. Under CISSP risk management principles, treatment priority is driven by risk exposure (likelihood × impact) relative to the organization's risk appetite, and this finding clearly exceeds the acceptable threshold.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the single point of failure risk by purchasing business interruption insurance.

    Why it's wrong here

    Transferring the single point of failure risk through business interruption insurance is a valid risk treatment strategy, but it primarily addresses the financial consequences of an incident rather than preventing the incident itself or reducing its likelihood. While insurance can mitigate financial impact, it does not directly remediate the underlying high-risk vulnerability. In a scenario with an identified critical vulnerability like SQL injection, direct technical remediation takes precedence over purely financial risk transfer.

  • ✓

    Immediately remediate the SQL injection vulnerability by tuning the WAF and applying vendor patches.

    Why this is correct

    Immediately remediating the SQL injection vulnerability by tuning the Web Application Firewall (WAF) and applying vendor patches is the most appropriate action because SQL injection represents a critical threat with potentially severe impact and high likelihood. This direct technical mitigation strategy actively reduces the attack surface and closes known security gaps, preventing unauthorized data access or manipulation. This proactive approach aligns with best practices for addressing the highest-priority risks first, directly improving the organization's security posture.

  • ✗

    Outsource incident response to a managed security service provider (MSSP) to compensate for the untested plan.

    Why it's wrong here

    Outsourcing incident response to a Managed Security Service Provider (MSSP) to compensate for an untested plan, while beneficial for improving reactive capabilities, does not address the immediate, proactive need to mitigate a known high-risk vulnerability. Enhancing incident response is crucial for resilience, but it is a secondary concern compared to preventing a critical security incident from occurring in the first place. Prioritizing prevention of a high-impact event over improving response to a potential future event is fundamental risk management.

  • ✗

    Accept the risk of outdated TLS 1.0 encryption because impact is low.

    Why it's wrong here

    Accepting the risk of outdated TLS 1.0 encryption, even if its immediate impact is assessed as low, is not the most critical action when a severe vulnerability like SQL injection is present. While TLS 1.0 is deprecated and susceptible to known attacks (e.g., BEAST, POODLE), its remediation typically involves upgrading protocols, which is important but often less immediately critical than closing a direct application-layer injection vulnerability that could lead to immediate data compromise. Risk prioritization dictates addressing the most impactful and likely threats first.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a risk assessment, a critical asset has a vulnerability with a CVSS score of 9.0. Which risk treatment strategy is most appropriate if the cost to mitigate exceeds the asset's value?

hard
  • A.Transfer
  • ✓ B.Acceptance
  • C.Avoidance
  • D.Mitigation

Why B: In risk management, a fundamental rule is that the cost of a safeguard (mitigation) should never exceed the value of the asset being protected. If mitigating a vulnerability costs more than the asset is worth, the organization should choose to accept the risk (Risk Acceptance). Spending more to protect an asset than the asset itself is worth is financially illogical.

Variation 2. An organization's risk assessment identified a vulnerability in a legacy system that cannot be patched because the vendor no longer supports it. The system processes sensitive customer data and is critical for daily operations. The risk is rated as high likelihood and high impact. The organization has a moderate risk appetite. Which risk treatment is most appropriate?

medium
  • A.Transfer the risk through cyber insurance
  • B.Avoid the risk by decommissioning the system
  • C.Accept the risk
  • ✓ D.Mitigate by implementing compensating controls

Why D: Since the system is critical for daily operations and cannot be decommissioned, and the organization has only a moderate risk appetite (meaning it is not willing to simply accept a high/high risk), the appropriate treatment is to reduce the risk by implementing compensating controls such as network segmentation, strict access controls, monitoring, and virtual patching. Compensating controls address the residual risk from the unpatched vulnerability without eliminating the business function. This aligns with the CISSP principle of selecting controls proportionate to risk tolerance and business need.

Variation 3. A company's risk assessment identifies a high likelihood of a data breach due to outdated encryption standards. The cost to upgrade encryption is $50,000, and the estimated loss from a breach is $2,000,000. The risk manager decides to implement the upgrade. Which risk treatment option is being applied?

hard
  • A.Risk acceptance
  • B.Risk avoidance
  • C.Risk enhancement
  • D.Risk transfer
  • ✓ E.Risk mitigation

Why E: The risk manager is applying risk mitigation by implementing the encryption upgrade to reduce the likelihood or impact of a data breach. This directly addresses the identified risk by deploying a stronger cryptographic control, such as moving from AES-128 to AES-256 or replacing deprecated TLS 1.0/1.1 with TLS 1.3, thereby lowering the residual risk to an acceptable level.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.