Courseiva

CRISC Information Technology and Security Practice Question

A retail company is implementing a new point-of-sale (POS) system that will process credit card transactions. The risk manager is reviewing the network architecture and notes that the POS devices will be on the same flat network as employee workstations and guest Wi-Fi. Which of the following is the MOST effective risk mitigation to protect cardholder data?

⚠ Common exam trap

The trap here is choosing encryption or monitoring as the primary control, while overlooking that network segmentation directly prevents unauthorized access to cardholder data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Segment the POS network from other networks and apply strict firewall rules.

Network segmentation with strict firewall rules is the most effective mitigation because it isolates the POS environment from other networks, preventing attackers from pivoting from compromised workstations or guest Wi-Fi. This aligns with PCI DSS requirements and reduces the scope of compliance. Other controls like encryption, IDS, or MFA are valuable but do not address the fundamental risk of a flat network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Require multi-factor authentication (MFA) for all POS transactions.

    Why it's wrong here

    MFA is typically used for user access, not for transaction processing. Applying MFA to each transaction would disrupt the customer experience and is not a standard control for POS environments. MFA protects against credential theft but does not address network-level threats. Segmentation is more directly effective for protecting cardholder data in this scenario.

  • ✗

    Implement full-disk encryption on all POS devices to protect data at rest.

    Why it's wrong here

    Full-disk encryption protects data if a device is physically stolen, but it does not prevent network-based attacks or malware from capturing data in transit or from memory. In a flat network, attackers can still move laterally and intercept transactions. Encryption is a valuable control, but it does not address the primary risk of network exposure.

  • ✗

    Deploy an intrusion detection system (IDS) to monitor for malicious traffic.

    Why it's wrong here

    An IDS can detect attacks but does not prevent them. It is a detective control, not a preventive one. In a flat network, an IDS may generate alerts, but the attacker could still access POS devices. While monitoring is important, it is not the most effective mitigation compared to segmentation, which proactively blocks unauthorized access.

  • ✓

    Segment the POS network from other networks and apply strict firewall rules.

    Why this is correct

    Network segmentation isolates the POS system from less secure environments, reducing the attack surface and limiting lateral movement in case of a breach. Strict firewall rules enforce least privilege, allowing only necessary traffic. This is a fundamental PCI DSS requirement and the most effective way to protect cardholder data from threats originating from employee workstations or guest Wi-Fi.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.