mediumMultiple Choice
SSCP Practice Question: During a quarterly risk review, a hospital's…
During a quarterly risk review, a hospital's security team identifies that legacy medical devices cannot be patched and run outdated operating systems. Which risk treatment strategy is most appropriate for these devices?
⚠ Common exam trap
ISC2 often tests the misconception that 'remediate' always means patching, but for legacy systems where patching is impossible, compensating controls are the correct risk treatment strategy, not immediate replacement or insurance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement compensating controls such as network segmentation and strict access control
Since the legacy medical devices cannot be patched due to vendor obsolescence, the most appropriate risk treatment strategy is to implement compensating controls. Network segmentation (e.g., VLANs or firewalls) isolates the devices from the main hospital network, while strict access control (e.g., 802.1X or MAC-based filtering) limits exposure to threats. This reduces the likelihood of exploitation without relying on patching the outdated operating systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remediate by applying vendor patches
Why it's wrong here
The scenario states the devices cannot be patched, so remediation is unavailable; the treatment must address the residual vulnerability instead. Patching is the correct response when vendor support exists and maintenance windows permit deployment. For unpatchable devices, network segmentation and compensating controls reduce exposure.
- ✓
Implement compensating controls such as network segmentation and strict access control
Why this is correct
Because the legacy devices cannot be patched, the residual risk must be reduced through compensating controls: network segmentation isolates them and strict access control limits exposure. This treats the risk without requiring the unavailable patching the stem rules out.
- ✗
Retire and replace all devices immediately
Why it's wrong here
Retiring and replacing all devices immediately fails because the scenario describes a quarterly risk review, not a crisis requiring urgent removal; legacy devices often support critical patient care functions that cannot be disrupted without a phased migration plan that maintains clinical operations. This option is tempting because full replacement is the definitive risk elimination strategy, and it would be correct if the devices posed an active, exploitable threat with no compensating controls and a viable replacement already approved for deployment.
- ✗
Transfer the risk by purchasing cyber insurance
Why it's wrong here
Insurance compensates financial loss after an incident; it does not reduce the likelihood or impact of compromise on the devices themselves. Transfer suits low-probability, high-cost exposures where residual loss is acceptable. Here the devices remain exploitable, so isolation and compensating controls are required.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.