nerdexam
Isaca

CRISC · Question #426

Which of the following changes would be reflected in an organization's risk profile after the failure of a critical patch implementation?

The correct answer is D. Residual risk is increased. The failure of a critical patch implementation directly increases the organization's residual risk, as the intended control did not effectively mitigate the vulnerability.

Submitted by asante_acc· Apr 18, 2026Risk Response and Reporting

Question

Which of the following changes would be reflected in an organization's risk profile after the failure of a critical patch implementation?

Options

  • ARisk appetite is decreased.
  • BInherent risk is increased.
  • CRisk tolerance is decreased.
  • DResidual risk is increased.

How the community answered

(38 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    8% (3)
  • D
    84% (32)

Why each option

The failure of a critical patch implementation directly increases the organization's residual risk, as the intended control did not effectively mitigate the vulnerability.

ARisk appetite is decreased.

Risk appetite is a strategic decision about the amount of risk an organization is willing to take, which is not directly altered by a single operational control failure.

BInherent risk is increased.

Inherent risk is the risk level before any controls are applied; the patch failure affects the effectiveness of an implemented control, not the baseline inherent risk.

CRisk tolerance is decreased.

Risk tolerance defines acceptable variation around the risk appetite and is a strategic setting, not directly changed by the operational failure of a patch.

DResidual risk is increased.Correct

Residual risk is the risk that remains after controls have been implemented and are operating. When a critical patch implementation fails, the intended control against a vulnerability is ineffective, leaving the system exposed and directly increasing the amount of remaining, unmitigated risk, thereby raising the residual risk.

Concept tested: Residual risk definition and impact of control failure

Source: https://learn.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-governance-strategy-risk-management#gv-6-perform-risk-assessments-and-reviews

Topics

#Residual Risk#Risk Control Failure#Risk Profile#Risk Response

Community Discussion

No community discussion yet for this question.

Full CRISC Practice