Courseiva

CISM Information Security Risk Management Practice Question

A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?

⚠ Common exam trap

The trap here is treating the choice as binary between shutting down and accepting, when interim compensating controls are the standard way to manage risk during a long remediation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement compensating controls such as network segmentation and enhanced monitoring while the replacement proceeds.

When permanent remediation will take time, compensating controls allow the organization to reduce risk to a tolerable level while maintaining business operations. Network segmentation and enhanced monitoring address the unsupported platform's exposure without interrupting sales, and they give the CISO a defensible interim posture that can be revisited as the replacement program progresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Transfer the risk to the terminal vendor through the existing support contract.

    Why it's wrong here

    The vendor no longer supports the operating system, so the support contract cannot transfer the operational and reputational consequences of a breach. Transfer mechanisms shift financial liability, not the underlying exposure, and a breach of customer payment data would still damage the retailer. This option also fails to address the interim period the CEO asked about.

  • ✓

    Implement compensating controls such as network segmentation and enhanced monitoring while the replacement proceeds.

    Why this is correct

    Compensating controls reduce the likelihood and impact of exploitation during the transition period without halting store operations. Segmentation limits lateral movement from compromised terminals, and enhanced monitoring improves detection. This balances continuity with risk reduction and provides the board with a defensible interim position while the permanent remediation is completed.

  • ✗

    Accept the risk because the CIO has committed to an 18-month replacement schedule.

    Why it's wrong here

    A remediation timeline is not the same as risk acceptance. Acceptance requires that residual exposure fall within the organization's tolerance and be formally approved. If the CISO believes the exposure is unacceptable, documenting a schedule without interim controls leaves an unapproved risk open and could expose the organization to regulatory and contractual consequences.

  • ✗

    Immediately disconnect all point-of-sale terminals until they are replaced.

    Why it's wrong here

    Disconnecting terminals would halt revenue-generating operations, an impact likely far exceeding the risk being addressed. Risk management seeks to bring exposure within tolerance, not to eliminate business function. An abrupt shutdown also ignores the possibility of interim controls that could reduce risk while maintaining service, making it a disproportionate response.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.