CRISC Information Technology and Security Practice Question
During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?
⚠ Common exam trap
CRISC often tests the misconception that risk transfer (e.g., to a vendor) or acceptance is acceptable when a simple technical control like encryption can mitigate the risk; candidates may overlook that encryption is a direct and feasible treatment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require encryption (e.g., TLS) for the communication
Requiring encryption (e.g., TLS) directly mitigates the confidentiality and integrity risk of plaintext transmission over a public network by protecting data in transit. This is the most appropriate risk treatment because it addresses the root cause—unprotected communication—without disrupting the legacy system's functionality. TLS provides encryption, authentication, and integrity checking, which are standard controls for this scenario. The ARB should mandate this as a condition of approval.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Require encryption (e.g., TLS) for the communication
Why this is correct
TLS encrypts data in transit, directly removing the plain-text exposure over the public network that the ARB flagged. Encryption is a preventive control that reduces likelihood, which suits an architectural review where the risk is interception of credentials or sensitive payloads.
- ✗
Transfer the risk to a third-party vendor
Why it's wrong here
Transferring to a vendor does not remove the plain-text exposure; the organisation still relies on the legacy link, and liability rarely shifts fully. Transfer suits insurable or contractual losses, such as outsourcing a service with indemnities, not an architectural flaw needing encryption.
- ✗
Accept the risk because the legacy system cannot be changed
Why it's wrong here
Acceptance leaves credentials and data exposed on a public network, which the ARB should not tolerate when encryption or a private path is feasible. Acceptance is valid only for low-impact risks where treatment cost exceeds the loss, not for fixable plain-text transmission.
- ✗
Decommission the legacy system immediately
Why it's wrong here
Immediate decommissioning of the legacy system would remove the plain-text transmission risk, but it fails the scenario because no alternative system or migration plan is specified; the ARB review identifies a communication vulnerability, not that the legacy system itself is obsolete. This option is tempting because decommissioning is a definitive risk-avoidance treatment for an end-of-life system, and it would be correct if the legacy system had a documented replacement already in production and the business had approved its retirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.