Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: A security analyst notes that a recent…

A security analyst notes that a recent penetration test successfully exploited a vulnerability in a legacy application that cannot be patched. The analyst recommends implementing network segmentation to limit the application's exposure. This recommendation is an example of:

⚠ Common exam trap

It's easy for candidates to confuse risk mitigation with risk avoidance — candidates often think that any action taken to address a vulnerability is avoidance, but avoidance requires eliminating the risk entirely (e.g., removing the application), whereas mitigation reduces but does not eliminate the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Risk mitigation

Implementing network segmentation to limit exposure of an unpatched legacy application is a classic example of risk mitigation. By isolating the application on a separate network segment (e.g., using VLANs or firewall rules), the analyst reduces the likelihood or impact of a successful exploit, even though the underlying vulnerability remains unpatched. This directly aligns with the CISSP definition of risk mitigation: applying controls to reduce risk to an acceptable level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Risk mitigation

    Why this is correct

    Network segmentation is a classic example of risk mitigation, as it directly reduces the potential impact and likelihood of a successful attack spreading across an entire network. By isolating critical systems or sensitive data into separate segments, a breach in one area is contained, preventing lateral movement and significantly diminishing the overall damage. This proactive control implements safeguards to lower the risk exposure to an acceptable level.

  • Risk acceptance

    Why it's wrong here

    Risk acceptance involves a conscious decision by an organization to acknowledge a risk and take no further action to reduce its likelihood or impact, often due to the cost of controls outweighing the potential loss. Implementing network segmentation, however, is a definitive and active control measure designed to reduce risk, directly contradicting the passive nature of risk acceptance. Therefore, this option is incorrect because an action is being taken.

  • Risk avoidance

    Why it's wrong here

    Risk avoidance entails eliminating the risk entirely by ceasing the activity that gives rise to it, such as discontinuing a vulnerable service or removing a susceptible asset from the environment. Network segmentation does not remove the underlying vulnerability or the asset itself; instead, it manages the risk by limiting its potential scope. Since the application or service remains operational, the risk has not been avoided.

  • Risk transfer

    Why it's wrong here

    Risk transfer involves shifting the financial or operational responsibility for a risk to a third party, typically through mechanisms like purchasing cybersecurity insurance or outsourcing a risky function to a specialized vendor. Network segmentation is an internal technical control that reduces an organization's direct exposure to a threat, rather than transferring any aspect of that risk to an external entity. It keeps the risk within the organization but manages it internally.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.