Courseiva
Information Technology and SecuritymediumMultiple ChoiceObjective-mapped

CRISC Information Technology and Security Practice Question

During a solution architecture review, the Architecture Review Board (ARB) identifies that a new application communicates with a legacy system using plain text over a public network. Which risk treatment option is MOST appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Require encryption (e.g., TLS) for the communication

The risk of data exposure can be mitigated by implementing encryption, such as TLS, to protect data in transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require encryption (e.g., TLS) for the communication

    Why this is correct

    Encryption mitigates the risk of data exposure effectively.

  • Transfer the risk to a third-party vendor

    Why it's wrong here

    Risk transfer is not applicable for a technical control like encryption.

  • Accept the risk because the legacy system cannot be changed

    Why it's wrong here

    Acceptance may be considered but is not the most appropriate as encryption can be implemented.

  • Decommission the legacy system immediately

    Why it's wrong here

    Immediate decommissioning of the legacy system would remove the plain-text transmission risk, but it fails the scenario because no alternative system or migration plan is specified; the ARB review identifies a communication vulnerability, not that the legacy system itself is obsolete. This option is tempting because decommissioning is a definitive risk-avoidance treatment for an end-of-life system, and it would be correct if the legacy system had a documented replacement already in production and the business had approved its retirement.

About these practice questions

Courseiva writes every CRISC question from scratch — 983 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.