Courseiva
easyMultiple ChoiceObjective-mapped

CISSP Practice Question: A large financial institution is finalizing its…

A large financial institution is finalizing its annual risk treatment plan based on a recent enterprise risk assessment. The risk appetite statement approved by the board specifies that the organization will accept only low residual risks for financial loss, but is willing to accept moderate risks for reputational damage if cost-benefit justifies. The risk register includes the following findings: 1) A critical SQL injection vulnerability in the online banking portal with high likelihood and critical impact; current controls include a web application firewall (WAF) that is not fully tuned. 2) Use of outdated TLS 1.0 encryption on internal communications between data centers; likelihood is medium, impact is low. 3) Lack of background checks for third-party vendors with access to sensitive data; likelihood is low, impact is moderate. 4) A single point of failure in the primary data center's power supply; likelihood is low, impact is critical. 5) An incident response plan that has not been tested in two years; likelihood is medium, impact is moderate. The CISO must prioritize actions for the upcoming quarter. What is the most appropriate first step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Immediately remediate the SQL injection vulnerability by tuning the WAF and applying vendor patches.

The SQL injection vulnerability has high likelihood and critical impact, resulting in a high risk level that exceeds the risk appetite for financial loss. Immediate remediation (tuning the WAF and applying vendor patches) is necessary to reduce the risk to an acceptable level and is the highest priority. Option A (transferring power supply risk via insurance) addresses a low-likelihood risk and is less urgent. Option C (outsourcing incident response) does not directly address the untested plan and is not as critical. Option D (accepting outdated TLS) may be acceptable given low impact, but it is not the first step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Transfer the single point of failure risk by purchasing business interruption insurance.

    Why it's wrong here

    Transferring the single point of failure risk through business interruption insurance is a valid risk treatment strategy, but it primarily addresses the financial consequences of an incident rather than preventing the incident itself or reducing its likelihood. While insurance can mitigate financial impact, it does not directly remediate the underlying high-risk vulnerability. In a scenario with an identified critical vulnerability like SQL injection, direct technical remediation takes precedence over purely financial risk transfer.

  • Immediately remediate the SQL injection vulnerability by tuning the WAF and applying vendor patches.

    Why this is correct

    Immediately remediating the SQL injection vulnerability by tuning the Web Application Firewall (WAF) and applying vendor patches is the most appropriate action because SQL injection represents a critical threat with potentially severe impact and high likelihood. This direct technical mitigation strategy actively reduces the attack surface and closes known security gaps, preventing unauthorized data access or manipulation. This proactive approach aligns with best practices for addressing the highest-priority risks first, directly improving the organization's security posture.

  • Outsource incident response to a managed security service provider (MSSP) to compensate for the untested plan.

    Why it's wrong here

    Outsourcing incident response to a Managed Security Service Provider (MSSP) to compensate for an untested plan, while beneficial for improving reactive capabilities, does not address the immediate, proactive need to mitigate a known high-risk vulnerability. Enhancing incident response is crucial for resilience, but it is a secondary concern compared to preventing a critical security incident from occurring in the first place. Prioritizing prevention of a high-impact event over improving response to a potential future event is fundamental risk management.

  • Accept the risk of outdated TLS 1.0 encryption because impact is low.

    Why it's wrong here

    Accepting the risk of outdated TLS 1.0 encryption, even if its immediate impact is assessed as low, is not the most critical action when a severe vulnerability like SQL injection is present. While TLS 1.0 is deprecated and susceptible to known attacks (e.g., BEAST, POODLE), its remediation typically involves upgrading protocols, which is important but often less immediately critical than closing a direct application-layer injection vulnerability that could lead to immediate data compromise. Risk prioritization dictates addressing the most impactful and likely threats first.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

3 more ways this is tested on CISSP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. During a risk assessment, a critical asset has a vulnerability with a CVSS score of 9.0. Which risk treatment strategy is most appropriate if the cost to mitigate exceeds the asset's value?

hard
  • A.Transfer
  • B.Acceptance
  • C.Avoidance
  • D.Mitigation

Why B: In risk management, a fundamental rule is that the cost of a safeguard (mitigation) should never exceed the value of the asset being protected. If mitigating a vulnerability costs more than the asset is worth, the organization should choose to accept the risk (Risk Acceptance). Spending more to protect an asset than the asset itself is worth is financially illogical.

Variation 2. An organization's risk assessment identified a vulnerability in a legacy system that cannot be patched because the vendor no longer supports it. The system processes sensitive customer data and is critical for daily operations. The risk is rated as high likelihood and high impact. The organization has a moderate risk appetite. Which risk treatment is most appropriate?

medium
  • A.Transfer the risk through cyber insurance
  • B.Avoid the risk by decommissioning the system
  • C.Accept the risk
  • D.Mitigate by implementing compensating controls

Why D: Since the system cannot be replaced immediately, implementing compensating controls (e.g., network segmentation, strict access controls, monitoring) reduces the risk to an acceptable level. Accepting a high risk is not advisable when it exceeds appetite. Cyber insurance does not protect against data breach consequences adequately. Decommissioning would disrupt critical operations.

Variation 3. A company's risk assessment identifies a high likelihood of a data breach due to outdated encryption standards. The cost to upgrade encryption is $50,000, and the estimated loss from a breach is $2,000,000. The risk manager decides to implement the upgrade. Which risk treatment option is being applied?

hard
  • A.Risk acceptance
  • B.Risk avoidance
  • C.Risk enhancement
  • D.Risk transfer
  • E.Risk mitigation

Why E: The risk manager is applying risk mitigation by implementing the encryption upgrade to reduce the likelihood or impact of a data breach. This directly addresses the identified risk by deploying a stronger cryptographic control, such as moving from AES-128 to AES-256 or replacing deprecated TLS 1.0/1.1 with TLS 1.3, thereby lowering the residual risk to an acceptable level.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.