Courseiva
IT Risk Assessment →hardMultiple Select

CRISC IT Risk Assessment Practice Question

A retail company is assessing risk for a legacy point-of-sale system that cannot be patched. The risk team wants to identify controls that would reduce the likelihood of a successful exploitation of known vulnerabilities on these terminals. Which TWO of the following are preventive controls that would BEST reduce the likelihood of exploitation? (Choose two.)

⚠ Common exam trap

The trap here is treating monitoring, scanning, or backups as if they reduce the likelihood of exploitation, when they are detective or corrective rather than preventive.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Segment the point-of-sale terminals onto a dedicated network with strict firewall rules limiting outbound and inbound traffic

Preventive controls reduce the likelihood of a successful attack. Network segmentation with restrictive firewall rules and application allowlisting both stop exploitation attempts from succeeding on unpatched terminals by limiting reachability and blocking unauthorized code execution. Logging, backups, and vulnerability scanning are valuable but are detective or corrective in nature and do not lower the probability of exploitation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct quarterly vulnerability scans of the point-of-sale network

    Why it's wrong here

    Vulnerability scanning is a detective and assessment activity that identifies weaknesses but does not block exploitation. Quarterly scans also leave long windows between assessments. Scanning supports risk identification and prioritization, yet it does not reduce the likelihood of a successful exploit on terminals that cannot be patched.

  • ✓

    Segment the point-of-sale terminals onto a dedicated network with strict firewall rules limiting outbound and inbound traffic

    Why this is correct

    This is correct because network segmentation with restrictive firewall rules prevents exploitation attempts from reaching the unpatched terminals and limits lateral movement, directly lowering the likelihood that a known vulnerability is successfully exploited. It is a preventive control that reduces exposure even when patching is not feasible on the legacy point-of-sale devices.

  • ✗

    Enable detailed logging and forward terminal logs to a centralized SIEM for monitoring

    Why it's wrong here

    Centralized logging and SIEM monitoring are detective controls. They improve visibility and shorten detection and response time, but they do not stop an exploitation attempt from succeeding on the legacy terminals. The question asks specifically for controls that reduce the likelihood of exploitation, which detection alone does not accomplish.

  • ✓

    Deploy application allowlisting on the terminals so only approved executables can run

    Why this is correct

    This is correct because application allowlisting blocks unauthorized code, including many exploit payloads and malware, from executing on the terminals. By preventing malicious processes from running, it directly reduces the likelihood that a vulnerability exploitation attempt succeeds, making it a preventive control well suited to unpatched point-of-sale systems.

  • ✗

    Perform daily backups of terminal configuration and transaction data

    Why it's wrong here

    Backups are corrective and recovery controls that help restore operations after an incident. They do not prevent exploitation or reduce its likelihood on the unpatched point-of-sale terminals. While valuable for resilience, backups address impact recovery rather than the probability of a successful attack.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.