ISC2 Governance, Risk and Compliance (CGRC) Practice Question
Your security scan flags a critical remote code-execution flaw on a public-facing application server. The vendor has issued a patch, yet operations will not permit a reboot for the next 48 hours. Which action best satisfies ongoing compliance requirements to remediate the risk while minimizing business disruption?
Accept the risk for 48 hours because there is no current evidence of active exploitation.
Immediately disconnect the server from the network until it can be patched.
Implement a targeted web application firewall signature that blocks the exploit traffic, then apply the vendor patch at the next maintenance window.
Wait until the next scheduled patch night to install the update and record the vulnerability in the POA&M.
Applying a temporary compensating control is the most effective way to reduce exposure when an immediate patch is infeasible. Deploying a tailored web application firewall (WAF) rule or similar filter blocks known exploit patterns, lowering the likelihood of compromise. This technical configuration change is a valid corrective action under risk-mitigation guidance and allows the organization to stay compliant until the patch can be installed during the approved maintenance window. Simply delaying the fix or formally accepting the risk leaves the system vulnerable. Disconnecting the server would eliminate the risk but unnecessarily halts the service and is not proportionate to the business need.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a web application firewall (WAF) and how does it work?
Open an interactive chat with Bash
What is a POA&M and when is it used?
Open an interactive chat with Bash
Why is compensating control better than risk acceptance in this scenario?
Open an interactive chat with Bash
ISC2 Governance, Risk and Compliance (CGRC)
Compliance Maintenance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .