CRISC Information Technology and Security Practice Question
A risk analyst is assessing the risk of a legacy application that stores customer data in plaintext. The application is scheduled for decommissioning in 18 months, but until then it must remain operational. Which of the following is the BEST risk response?
⚠ Common exam trap
The trap here is assuming that because the application will be decommissioned soon, it is acceptable to leave the data unprotected or to rely solely on insurance, rather than applying a feasible technical control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement database encryption at rest and in transit for the legacy application as a compensating control until decommissioning.
Implementing encryption at rest and in transit is the best risk response because it directly mitigates the risk of plaintext data exposure. It acts as a compensating control that can be applied without major changes to the legacy application, protecting sensitive data until decommissioning. This approach balances risk reduction with operational continuity, unlike acceptance, transfer, or avoidance which either leave the risk or disrupt business.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the application will be decommissioned soon and the cost of encryption is not justified.
Why it's wrong here
Accepting the risk without mitigating controls leaves sensitive data exposed for 18 months. The potential impact of a data breach could be severe, including regulatory fines and reputational damage. Risk acceptance should be a conscious decision after evaluating the cost-benefit, but here the risk is high and the duration is significant. It is not the best response when a feasible mitigation exists.
- ✓
Implement database encryption at rest and in transit for the legacy application as a compensating control until decommissioning.
Why this is correct
Implementing encryption at rest and in transit is a feasible compensating control that protects the data even if the application is compromised. It addresses the plaintext storage risk directly and reduces the potential impact. This is the best response because it mitigates the risk during the remaining operational period without requiring major application changes, and it aligns with data protection best practices.
- ✗
Transfer the risk by purchasing cyber insurance to cover potential data breach costs.
Why it's wrong here
Cyber insurance transfers financial impact but does not reduce the likelihood or prevent the data exposure. The risk of a breach still exists, and insurance may not cover all costs or may have exclusions. While insurance is a valid risk response, it is not the best here because a direct technical control (encryption) can significantly reduce the risk itself, which is preferable.
- ✗
Avoid the risk by immediately shutting down the legacy application, even if it disrupts business operations.
Why it's wrong here
Avoiding the risk by shutting down the application may cause significant business disruption and is not practical given the 18-month timeline. Risk avoidance should be considered when the risk is unacceptable and no other controls are feasible, but here a compensating control is available. This response is too drastic and may introduce new operational risks.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.