正解:D
Residual risk is the level of risk that remains after applying controls or other risk treatments. A critical patch is a type of control that aims to reduce the risk of a known vulnerability being exploited by attackers. If the patch implementation fails, the control is ineffective and the risk is not reduced. Therefore, the residual risk is increased, as the organization is still exposed to the potential negative consequences of the vulnerability.
References:
*ISACA, Risk and Information Systems Control Review Manual, 7th Edition, 2020, p. 2111
*ISACA, Practical Patch Management and Mitigation2