Courseiva
mediumMultiple ChoiceObjective-mapped

SSCP Practice Question: During a quarterly risk review, a hospital's…

During a quarterly risk review, a hospital's security team identifies that legacy medical devices cannot be patched and run outdated operating systems. Which risk treatment strategy is most appropriate for these devices?

⚠ Common exam trap

ISC2 often tests the misconception that 'remediate' always means patching, but for legacy systems where patching is impossible, compensating controls are the correct risk treatment strategy, not immediate replacement or insurance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement compensating controls such as network segmentation and strict access control

Since the legacy medical devices cannot be patched due to vendor obsolescence, the most appropriate risk treatment strategy is to implement compensating controls. Network segmentation (e.g., VLANs or firewalls) isolates the devices from the main hospital network, while strict access control (e.g., 802.1X or MAC-based filtering) limits exposure to threats. This reduces the likelihood of exploitation without relying on patching the outdated operating systems.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Remediate by applying vendor patches

    Why it's wrong here

    Legacy devices often have no patches available; this is not feasible.

  • Implement compensating controls such as network segmentation and strict access control

    Why this is correct

    Compensating controls mitigate the risk without changing the device itself.

  • Retire and replace all devices immediately

    Why it's wrong here

    Retiring and replacing all devices immediately fails because the scenario describes a quarterly risk review, not a crisis requiring urgent removal; legacy devices often support critical patient care functions that cannot be disrupted without a phased migration plan that maintains clinical operations. This option is tempting because full replacement is the definitive risk elimination strategy, and it would be correct if the devices posed an active, exploitable threat with no compensating controls and a viable replacement already approved for deployment.

  • Transfer the risk by purchasing cyber insurance

    Why it's wrong here

    Insurance transfers financial impact but does not reduce the likelihood of a breach.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.