easyMultiple ChoiceObjective-mapped
CRISC Practice Question: A multinational corporation is conducting a risk…
A multinational corporation is conducting a risk assessment for its new online payment platform. The platform processes transactions in multiple currencies and stores sensitive customer financial data. The risk team has identified that the encryption algorithm used for data at rest is outdated and could be vulnerable to advanced attacks. The company's risk appetite is low for data breaches. The security team recommends upgrading the encryption to a modern standard, but the upgrade will require a 48-hour downtime impacting all global transactions. The business unit is concerned about revenue loss during the downtime. As the risk practitioner, what is the BEST course of action to balance security and business continuity?
⚠ Common exam trap
Test-takers frequently choose immediate remediation (Option D) without considering business impact, failing to recognize that risk management requires balancing security with operational continuity through compensating controls and scheduling.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Plan the upgrade during a low-traffic period and implement compensating controls such as additional monitoring during the downtime.
The best course of action because it balances the need to mitigate a high-risk encryption vulnerability with business continuity. By scheduling the upgrade during a low-traffic period and implementing compensating controls (e.g., enhanced monitoring and intrusion detection), the organization reduces the likelihood of exploitation during the 48-hour downtime while minimizing revenue loss. This aligns with the low risk appetite for data breaches and demonstrates a risk-based decision that treats the vulnerability without accepting unacceptable exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk and delay the upgrade until the next scheduled maintenance window in three months.
Why it's wrong here
Delaying the upgrade increases risk of data breach.
- ✓
Plan the upgrade during a low-traffic period and implement compensating controls such as additional monitoring during the downtime.
Why this is correct
This reduces risk while minimizing business disruption.
- ✗
Outsource the payment processing to a third-party vendor that already uses modern encryption.
Why it's wrong here
Outsourcing introduces new risks and may not be timely.
- ✗
Implement the upgrade immediately to mitigate the vulnerability, accepting the revenue loss.
Why it's wrong here
Unnecessary revenue loss when a less disruptive option exists.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.