A vulnerability scanner reports a critical remote code execution flaw in an internet-facing web server. During the next maintenance window, the operations team applies the vendor patch and restarts the service. Which risk response has been applied?
Select an answer to reveal the explanation.
Short Explanation
Think of patching like putting a lock on a door you can’t avoid using: it doesn’t remove the risk, it just lowers the chance someone walks in. When you patch, you’re actively reducing the vulnerability’s likelihood, not ignoring it, shifting it to insurance, or walking away from the asset. That makes it risk mitigation, not acceptance, transfer, or avoidance.
Full Explanation
Applying a vendor patch directly changes the risk equation by removing or reducing the vulnerable code path, which lowers the likelihood that an attacker can successfully exploit the finding. In vulnerability response, that is mitigation: the organization keeps the asset and the remaining risk but takes an action that makes exploitation less probable or less severe. Acceptance would mean knowingly retaining the risk after evaluation, typically because remediation is impractical, the risk is within tolerance, or compensating controls are sufficient. Transfer would shift residual risk to another party, such as through insurance, outsourcing, or contractual liability, without actually fixing the underlying weakness. Avoidance would eliminate exposure by removing the asset, disabling the service, or decommissioning the vulnerable component entirely, rather than correcting it. Exam caveat: distinguish between reducing likelihood through technical controls and changing who owns the residual risk. Operational check: confirm the patch was deployed, verified through authenticated scanning or configuration evidence, and that any residual risk is documented in the vulnerability register with owner, due date, and exception status if applicable.