CISM Information Security Risk Management Practice Question
A retail company's risk register shows that its point-of-sale terminals run an unsupported operating system. The CIO proposes replacing the terminals over 18 months, but the CISO believes the exposure is unacceptable in the interim. The CEO asks the CISO to recommend a course of action that balances business continuity with risk reduction. Which of the following is the MOST appropriate recommendation?
⚠ Common exam trap
The trap here is treating the choice as binary between shutting down and accepting, when interim compensating controls are the standard way to manage risk during a long remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement compensating controls such as network segmentation and enhanced monitoring while the replacement proceeds.
When permanent remediation will take time, compensating controls allow the organization to reduce risk to a tolerable level while maintaining business operations. Network segmentation and enhanced monitoring address the unsupported platform's exposure without interrupting sales, and they give the CISO a defensible interim posture that can be revisited as the replacement program progresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk to the terminal vendor through the existing support contract.
Why it's wrong here
The vendor no longer supports the operating system, so the support contract cannot transfer the operational and reputational consequences of a breach. Transfer mechanisms shift financial liability, not the underlying exposure, and a breach of customer payment data would still damage the retailer. This option also fails to address the interim period the CEO asked about.
- ✓
Implement compensating controls such as network segmentation and enhanced monitoring while the replacement proceeds.
Why this is correct
Compensating controls reduce the likelihood and impact of exploitation during the transition period without halting store operations. Segmentation limits lateral movement from compromised terminals, and enhanced monitoring improves detection. This balances continuity with risk reduction and provides the board with a defensible interim position while the permanent remediation is completed.
- ✗
Accept the risk because the CIO has committed to an 18-month replacement schedule.
Why it's wrong here
A remediation timeline is not the same as risk acceptance. Acceptance requires that residual exposure fall within the organization's tolerance and be formally approved. If the CISO believes the exposure is unacceptable, documenting a schedule without interim controls leaves an unapproved risk open and could expose the organization to regulatory and contractual consequences.
- ✗
Immediately disconnect all point-of-sale terminals until they are replaced.
Why it's wrong here
Disconnecting terminals would halt revenue-generating operations, an impact likely far exceeding the risk being addressed. Risk management seeks to bring exposure within tolerance, not to eliminate business function. An abrupt shutdown also ignores the possibility of interim controls that could reduce risk while maintaining service, making it a disproportionate response.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.