nerdexam
IsacaIsaca

CRISC · Question #237

CRISC Question #237: Real Exam Question with Answer & Explanation

Sign in or unlock CRISC to reveal the answer and full explanation for question #237. The question stem and answer options stay visible for context.

Submitted by takeshi77· Apr 18, 2026IT Risk Assessment

Question

A penetration test reveals several vulnerabilities in a web-facing application. Which of the following should be the FIRST step in selecting a risk response?

Options

  • ACorrect the vulnerabilities to mitigate potential risk exposure.
  • BDevelop a risk response action plan with key stakeholders.
  • CAssess the level of risk associated with the vulnerabilities.
  • DCommunicate the vulnerabilities to the risk owner.

Unlock CRISC to see the answer

You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Risk assessment#Vulnerability management#Risk response planning
Full CRISC PracticeBrowse All CRISC Questions