mediumMultiple ChoiceObjective-mapped
SSCP Practice Question: During a quarterly risk review, a hospital's…
During a quarterly risk review, a hospital's security team identifies that legacy medical devices cannot be patched and run outdated operating systems. Which risk treatment strategy is most appropriate for these devices?
⚠ Common exam trap
ISC2 often tests the misconception that 'remediate' always means patching, but for legacy systems where patching is impossible, compensating controls are the correct risk treatment strategy, not immediate replacement or insurance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement compensating controls such as network segmentation and strict access control
Since the legacy medical devices cannot be patched due to vendor obsolescence, the most appropriate risk treatment strategy is to implement compensating controls. Network segmentation (e.g., VLANs or firewalls) isolates the devices from the main hospital network, while strict access control (e.g., 802.1X or MAC-based filtering) limits exposure to threats. This reduces the likelihood of exploitation without relying on patching the outdated operating systems.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remediate by applying vendor patches
Why it's wrong here
Legacy devices often have no patches available; this is not feasible.
- ✓
Implement compensating controls such as network segmentation and strict access control
Why this is correct
Compensating controls mitigate the risk without changing the device itself.
- ✗
Retire and replace all devices immediately
Why it's wrong here
Retiring and replacing all devices immediately fails because the scenario describes a quarterly risk review, not a crisis requiring urgent removal; legacy devices often support critical patient care functions that cannot be disrupted without a phased migration plan that maintains clinical operations. This option is tempting because full replacement is the definitive risk elimination strategy, and it would be correct if the devices posed an active, exploitable threat with no compensating controls and a viable replacement already approved for deployment.
- ✗
Transfer the risk by purchasing cyber insurance
Why it's wrong here
Insurance transfers financial impact but does not reduce the likelihood of a breach.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.