Courseiva
mediumMultiple ChoiceObjective-mapped

CRISC Practice Question: A financial services company uses a legacy…

A financial services company uses a legacy mainframe system for core banking transactions. The risk assessment identifies that the system does not support modern encryption standards, and data is transmitted in clear text over internal networks. The IT department has proposed implementing network segmentation and encryption at the application layer using a middleware solution. However, the cost is high and the project would take 18 months. Meanwhile, the company is planning to migrate to a new core system in two years. The risk appetite for data confidentiality is low. As the risk practitioner, what is the MOST appropriate risk response?

⚠ Common exam trap

Test-takers frequently confuse 'accepting the risk' with a valid response when a migration is planned, but the low risk appetite for data confidentiality makes acceptance inappropriate, and they may overlook that compensating controls can be implemented quickly and cost-effectively to reduce exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement compensating controls such as strict network access controls and monitoring.

The correct response is to implement compensating controls such as strict network access controls and monitoring. Given the low risk appetite for data confidentiality, the 18-month delay for the middleware solution is unacceptable, and the two-year migration timeline leaves a significant exposure window. Compensating controls like VLAN segmentation, ACLs, and continuous traffic monitoring can reduce the likelihood of exploitation of the clear-text transmission without requiring changes to the legacy mainframe itself.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement compensating controls such as strict network access controls and monitoring.

    Why this is correct

    Compensating controls reduce risk immediately.

  • Transfer the risk by purchasing cyber insurance covering data breach incidents.

    Why it's wrong here

    Insurance does not prevent data exposure.

  • Accept the risk because the system will be replaced in two years.

    Why it's wrong here

    Acceptance conflicts with low risk appetite.

  • Avoid the risk by accelerating the migration to the new system within 18 months.

    Why it's wrong here

    Acceleration may not be feasible.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.