nerdexam
Isaca

CRISC · Question #323

A risk assessment has been completed on an application and reported to the application owner. The report includes validated vulnerability findings that require mitigation. Which of the following shoul

Sign in or unlock CRISC to reveal the answer and full explanation for question #323. The question stem and answer options stay visible for context.

Submitted by paula_co· Apr 18, 2026Risk Response and Reporting

Question

A risk assessment has been completed on an application and reported to the application owner. The report includes validated vulnerability findings that require mitigation. Which of the following should be the NEXT step?

Options

  • AReport the findings to executive management to enable treatment decisions.
  • BReassess each vulnerability to evaluate the risk profile of the application.
  • CConduct a penetration test to determine how to mitigate the vulnerabilities.
  • DPrepare a risk response that is aligned to the organization's risk tolerance.

Unlock CRISC to see the answer

You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#risk response#risk mitigation#risk tolerance#risk management process
Full CRISC Practice