easyMultiple ChoiceObjective-mapped
CRISC Practice Question: A small manufacturing company is conducting its…
A small manufacturing company is conducting its first IT risk assessment. The company has a flat network with no segmentation, and all employees have administrative access to their workstations. The risk practitioner identifies that a malware infection on one workstation could easily spread to the entire network. The company has a limited budget for IT security improvements. Which of the following risk treatment options is MOST cost-effective and practical?
⚠ Common exam trap
Test-takers frequently choose network segmentation (Option C) as the ideal technical solution, but the question emphasizes cost-effectiveness and practicality for a small company with a limited budget, making the simpler, cheaper controls in Option B the better choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy endpoint protection software on all workstations and restrict administrative rights for users.
The most cost-effective and practical because deploying endpoint protection software provides immediate defense against known malware, while restricting administrative rights prevents users from installing unauthorized software or making system changes that could introduce malware. This combination directly addresses the root cause of the risk—unrestricted user privileges and lack of basic malware defenses—without requiring expensive network redesign or ongoing insurance premiums.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the company's data is not highly sensitive.
Why it's wrong here
Even non-sensitive data can cause disruption.
- ✓
Deploy endpoint protection software on all workstations and restrict administrative rights for users.
Why this is correct
Low cost, high impact on limiting malware spread.
- ✗
Implement network segmentation and a next-generation firewall.
Why it's wrong here
More expensive and complex than needed.
- ✗
Purchase cyber insurance to cover potential losses.
Why it's wrong here
Insurance does not prevent malware spread.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.