mediumMultiple Choice
CISSP Practice Question: An organization's risk assessment identified a…
An organization's risk assessment identified a vulnerability in a legacy system that cannot be patched because the vendor no longer supports it. The system processes sensitive customer data and is critical for daily operations. The risk is rated as high likelihood and high impact. The organization has a moderate risk appetite. Which risk treatment is most appropriate?
⚠ Common exam trap
CISSP often tests the misconception that 'transfer' (insurance) eliminates risk, when in fact it only shifts financial impact and does not address the vulnerability itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Mitigate by implementing compensating controls
Since the system is critical for daily operations and cannot be decommissioned, and the organization has only a moderate risk appetite (meaning it is not willing to simply accept a high/high risk), the appropriate treatment is to reduce the risk by implementing compensating controls such as network segmentation, strict access controls, monitoring, and virtual patching. Compensating controls address the residual risk from the unpatched vulnerability without eliminating the business function. This aligns with the CISSP principle of selecting controls proportionate to risk tolerance and business need.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Transfer the risk through cyber insurance
Why it's wrong here
Transferring risk through cyber insurance primarily shifts the financial burden of a security incident to a third party. While it can mitigate the financial impact post-event, it does not directly reduce the likelihood of the vulnerability being exploited or the technical impact of the exploit itself. Furthermore, policies often have exclusions, deductibles, and coverage limits that may not fully cover all potential losses, making it an incomplete solution for an identified vulnerability that needs direct action.
- ✗
Avoid the risk by decommissioning the system
Why it's wrong here
Risk avoidance, such as decommissioning a system, eliminates the risk entirely by removing the asset or activity that generates it. However, this approach is often impractical or detrimental to business operations if the system provides essential services. Decommissioning should only be considered if the system's operational value is outweighed by the unmitigable risk it poses, and if alternative solutions for its functions are readily available without significant business disruption.
- ✗
Accept the risk
Why it's wrong here
Risk acceptance involves consciously deciding to take no action to reduce the likelihood or impact of a risk, typically because the cost of mitigation outweighs the potential loss, or the risk is within the organization's defined risk appetite. In this scenario, the prompt implies a significant vulnerability has been identified, suggesting the risk is likely above the acceptable threshold. Accepting a risk above appetite can lead to severe, potentially catastrophic, financial, reputational, or operational consequences.
- ✓
Mitigate by implementing compensating controls
Why this is correct
Risk mitigation involves implementing controls to reduce the likelihood or impact of a risk to an acceptable level. Compensating controls are alternative security measures deployed when primary controls are not feasible or effective, providing an equivalent level of protection. This approach allows the organization to continue critical business operations while addressing the identified vulnerability, making it a practical and responsible strategy when direct remediation is not immediately possible or too disruptive.
Go deeper
Related to this question
Learn chapter
Security Assessment and Testing
Key term
Risk tolerance
Risk tolerance is the amount of risk an organization or individual is willing to accept in pursuit of its objectives, defining the boundary between acceptable and unacceptable losses.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.