mediumMultiple Choice
CRISC Practice Question: A company has identified that its legacy…
A company has identified that its legacy financial system has a high inherent risk due to outdated architecture. The system cannot be replaced for three years. What is the best risk treatment strategy?
⚠ Common exam trap
Many candidates choose risk acceptance (Option A) or transfer (Option B) without recognizing that high inherent risk demands active reduction measures, especially when the system cannot be decommissioned.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement compensating controls such as network segmentation and enhanced monitoring.
When a legacy system cannot be replaced for three years, the most effective risk treatment is to reduce the likelihood and impact of exploitation through compensating controls. Network segmentation limits lateral movement from the legacy system, and enhanced monitoring (e.g., SIEM with custom rules for anomalous traffic) provides early detection of compromise. This aligns with the ISACA risk treatment principle of risk reduction when avoidance or transfer is not feasible.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk and allocate contingency funds for potential incidents.
Why it's wrong here
Acceptance leaves the high inherent risk untreated for three years, exceeding tolerance for a financial system. It is tempting because acceptance with contingency funds suits low-impact risks where treatment costs exceed exposure, but this system's high rating demands controls that reduce likelihood or impact.
- ✗
Transfer the risk by purchasing cyber insurance.
Why it's wrong here
Insurance compensates financial loss after an incident but leaves the outdated architecture's likelihood and impact unchanged, and cannot cover regulatory or availability consequences. It is tempting because transfer suits low-frequency, high-severity risks, yet here the residual risk remains and must still be mitigated.
- ✗
Avoid the risk by discontinuing the system immediately.
Why it's wrong here
Discontinuing the system immediately removes the risk but destroys the business capability it supports, which the three-year timeline implies is unacceptable. It is tempting because avoidance eliminates risk entirely, and is correct only when the activity can genuinely cease without critical operational loss.
- ✓
Implement compensating controls such as network segmentation and enhanced monitoring.
Why this is correct
Because replacement is impossible for three years, risk must be mitigated rather than avoided or transferred. Network segmentation limits lateral movement and enhanced monitoring detects compromise attempts, directly reducing the high inherent risk posed by the outdated architecture while the legacy system remains in production.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.