CRISC Risk Response and Mitigation Practice Question
A hospital's risk register identifies that a critical medical imaging server runs an unsupported operating system, creating a high likelihood of exploitation. The vendor will not release a patch, and the server cannot be taken offline because it supports active patient care. The CISO asks the risk practitioner to reduce the likelihood of exploitation without disrupting imaging services. Which risk response is MOST appropriate?
⚠ Common exam trap
The trap here is assuming that because the system is critical and cannot be replaced, the only remaining choice is to accept the risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Isolate the imaging server on a dedicated network segment with strict firewall rules and deploy a host-based intrusion prevention system.
When a critical asset cannot be patched or replaced, compensating controls are the correct mitigation approach. Network segmentation limits lateral movement, and host-based IPS can detect and block exploitation attempts on the unsupported system. These measures reduce likelihood without requiring downtime, unlike acceptance, avoidance, or pure risk transfer, which do not address the technical vulnerability in this operational context.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the server is essential to patient care and cannot be taken offline for replacement.
Why it's wrong here
Acceptance is inappropriate when a high-likelihood risk can be reduced with compensating controls. The scenario does not state that the risk is within appetite, and patient safety plus regulatory obligations make silent acceptance dangerous. Risk acceptance is a deliberate decision reserved for risks that cannot be economically or technically mitigated, not for a situation where segmentation and monitoring are feasible.
- ✓
Isolate the imaging server on a dedicated network segment with strict firewall rules and deploy a host-based intrusion prevention system.
Why this is correct
Compensating controls such as network segmentation and host-based IPS reduce the likelihood of exploitation while preserving availability for patient care. Because the vendor will not patch the unsupported OS, the risk practitioner must apply layered detective and preventive controls around the asset. This directly addresses the high likelihood of exploitation without requiring downtime or system replacement.
- ✗
Avoid the risk by immediately decommissioning the imaging server and moving all imaging workloads to a cloud provider.
Why it's wrong here
Avoidance would stop the activity entirely, but the server supports active patient care and cannot be taken offline. Migrating medical imaging to the cloud is a major project that cannot be completed immediately and may introduce new compliance and latency risks. Avoidance is not feasible here because it would disrupt clinical operations, which the scenario explicitly forbids.
- ✗
Transfer the risk by purchasing cyber insurance that covers medical device downtime and regulatory fines.
Why it's wrong here
Cyber insurance transfers the financial consequence of a loss but does not reduce the likelihood that the unsupported server is exploited. The scenario explicitly asks the practitioner to reduce likelihood without disrupting imaging services. Insurance is a valid risk response for financial impact, but it leaves the technical vulnerability unaddressed and does not prevent an attacker from compromising patient data.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.