nerdexam
Isaca

CISM · Question #721

An organization is close to going live with the implementation of a cloud-based application. Independent penetration test results have been received that show a high-rated vulnerability. Which of…

The correct answer is D. Assess whether the vulnerability is within the organization's risk tolerance levels. Why D is correct: Risk management decisions are rarely binary - a "high-rated" vulnerability doesn't automatically mean "stop everything." The organization must first assess the actual business impact, likelihood of exploitation, and whether existing controls mitigate the risk…

Submitted by haru.x· Apr 18, 2026Information Security Risk Management

Question

An organization is close to going live with the implementation of a cloud-based application. Independent penetration test results have been received that show a high-rated vulnerability. Which of the following would be the BEST way to proceed?

Options

  • APostpone the implementation until the vulnerability has been fixed.
  • BImplement the application and request the cloud service provider to fix the vulnerability.
  • CCommission further penetration tests to validate initial test results.
  • DAssess whether the vulnerability is within the organization's risk tolerance levels.

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    10% (4)
  • C
    19% (8)
  • D
    67% (28)

Explanation

Why D is correct: Risk management decisions are rarely binary - a "high-rated" vulnerability doesn't automatically mean "stop everything." The organization must first assess the actual business impact, likelihood of exploitation, and whether existing controls mitigate the risk enough to fall within acceptable tolerance levels before deciding on a course of action.

Why the distractors fail:

  • A is too absolute - postponing may be the right outcome, but only after a risk assessment concludes the vulnerability exceeds tolerance; jumping straight to postponement skips the decision-making process.
  • B is irresponsible - implementing a known high-severity vulnerability and hoping a third party will fix it shifts risk without managing it, and the CSP may not even own the vulnerable component.
  • C wastes time and money - additional testing to "validate" results adds no value when the organization already has actionable findings; assessment and remediation are what's needed next.

Memory tip: Think of the risk management lifecycle: Identify → Assess → Respond. Penetration testing handles "Identify" - the next step is always Assess (tolerance check), never jumping straight to a response like postponing or patching. When an exam question mentions a vulnerability and a pending decision, the answer almost always involves risk assessment first.

Topics

#Risk assessment#Risk tolerance#Vulnerability management#Security decision making

Community Discussion

No community discussion yet for this question.

Full CISM Practice