Courseiva

CRISC Risk Response and Mitigation Practice Question

A retail company is implementing a new point-of-sale (POS) system that accepts contactless payments. The risk practitioner identifies that the existing network segmentation between the POS environment and the corporate network is inadequate. The risk committee asks for compensating controls that will reduce the risk of lateral movement from a compromised POS terminal. Which TWO of the following controls BEST address this risk? (Choose two.)

⚠ Common exam trap

The trap here is selecting data protection controls like encryption or detective controls like scanning when the risk is specifically about network lateral movement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement network access control (NAC) that requires POS terminals to authenticate and comply with a hardened configuration before joining the network.

Lateral movement from a compromised POS terminal is best mitigated by preventive controls that restrict network traffic and enforce device trust. A next-generation firewall with least-privilege rules limits what the POS network can reach, and network access control ensures only compliant, authenticated devices connect. Together they compensate for weak segmentation by reducing the pathways and trust an attacker can exploit. Encryption, scanning, and centralization do not directly block lateral movement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store payment card data in a centralized encrypted database on the corporate network to simplify management.

    Why it's wrong here

    Centralizing payment card data on the corporate network increases the potential impact of a compromise and may violate PCI DSS segmentation requirements. This option moves sensitive data closer to the corporate environment, which is the opposite of the desired risk reduction. It also does not prevent lateral movement; it expands the scope and attractiveness of the corporate network as a target.

  • ✓

    Implement network access control (NAC) that requires POS terminals to authenticate and comply with a hardened configuration before joining the network.

    Why this is correct

    Network access control ensures that only compliant, authenticated POS devices can connect to the network. This reduces the likelihood that a compromised or unauthorized device can establish a foothold and move laterally. By enforcing hardened configurations and device identity, NAC acts as a preventive control that complements segmentation and directly addresses the risk of lateral movement from a compromised terminal.

  • ✗

    Enable full disk encryption on all POS terminals to protect payment card data at rest.

    Why it's wrong here

    Full disk encryption protects data at rest if a terminal is physically stolen, but it does not prevent lateral movement from a compromised terminal across the network. The identified risk is inadequate segmentation, not physical theft. Encryption is a valuable data protection control, but it operates at a different layer and does not restrict network traffic between the POS and corporate environments.

  • ✓

    Deploy a next-generation firewall between the POS network and the corporate network with rules that deny all traffic except required payment processor endpoints.

    Why this is correct

    A next-generation firewall enforcing least-privilege rules between the POS and corporate networks directly reduces lateral movement. By allowing only required payment processor endpoints, the control limits an attacker's ability to pivot from a compromised terminal to corporate systems. This is a preventive network control that compensates for inadequate segmentation and is a recognized mitigation for POS environments.

  • ✗

    Conduct quarterly vulnerability scans of the POS environment to identify missing patches.

    Why it's wrong here

    Vulnerability scanning is a detective control that identifies weaknesses but does not prevent lateral movement. Quarterly scans may also be too infrequent to address active threats. While scanning is important for maintaining security hygiene, it does not compensate for inadequate network segmentation. The risk committee asked for controls that reduce the risk of lateral movement, which requires preventive network and access controls.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.