Risk Mitigation for Unpatched Legacy Systems
During a risk assessment, a company identifies that a legacy system has a known CVE with a CVSS score of 9.8. The system is critical but cannot be patched immediately. The management decides to implement strict network segmentation and monitor the system continuously. This risk response is best described as:
Quick Answer
Risk mitigation is the correct classification here because the organization isn't eliminating the risk, transferring it to someone else, or simply accepting it; it's actively reducing the likelihood and impact of exploitation through added controls, which is the textbook definition of mitigation. Strict network segmentation limits what an attacker could reach even if they successfully exploited the vulnerability, shrinking the potential blast radius, while continuous monitoring increases the odds that an exploitation attempt is detected quickly, shortening the window of undetected compromise. Neither control removes the underlying flaw itself, the CVE with a CVSS score of 9.8 is still present and unpatched, which is exactly why this isn't risk avoidance, which would mean removing the system or the function entirely, or risk acceptance, which would mean doing nothing extra and living with the exposure as-is. It's also not risk transfer, since no third party like an insurer or vendor is absorbing the consequence. This distinction matters because these four standard risk response categories, avoid, mitigate, transfer, and accept, are commonly tested by describing a specific action and asking which category it falls into. Whenever a scenario describes adding compensating controls, such as segmentation, monitoring, or hardening, around a risk that still technically exists, that's mitigation.
⚠ Common exam trap
It's easy for candidates to confuse 'risk mitigation' with 'risk acceptance' because the system remains vulnerable, but the key distinction is that active controls are applied to reduce risk, not merely acknowledged.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Risk mitigation
Risk mitigation, because the company is implementing strict network segmentation and continuous monitoring to reduce the likelihood and impact of the vulnerability being exploited. This reduces the risk without eliminating it entirely, which is the essence of mitigation. The CVSS score of 9.8 indicates critical severity, and the controls (e.g., ACLs, VLANs, IDS/IPS) directly address the attack surface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk acceptance
Why it's wrong here
Incorrect: Acceptance would mean acknowledging the risk without implementing additional controls.
- ✗
Risk avoidance
Why it's wrong here
Incorrect: Avoidance would mean discontinuing the system or process.
- ✗
Risk transfer
Why it's wrong here
Incorrect: Transfer would involve insurance or outsourcing.
- ✓
Risk mitigation
Why this is correct
Correct: Mitigation reduces risk through controls like segmentation and monitoring.
Visual reference
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 920-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. During a risk assessment, a team identifies that a legacy application cannot be patched due to vendor end-of-life. The business decides to continue using the application but implement compensating controls such as network segmentation and strict access controls. This risk response strategy is best classified as:
medium- A.Risk mitigation
- B.Risk transfer
- ✓ C.Risk acceptance
- D.Risk avoidance
Why C: Risk acceptance means acknowledging the risk and taking no further action beyond existing controls. Compensating controls do not eliminate the risk; they reduce it to an acceptable level, which is still acceptance.
Variation 2. During a risk assessment, a company identifies that a legacy system cannot be patched due to vendor end-of-life. The system is critical to operations. Which risk response strategy is most appropriate initially?
medium- A.Avoid the risk by decommissioning the system immediately
- B.Transfer the risk by purchasing cyber insurance
- C.Accept the risk without any further action
- ✓ D.Mitigate the risk by implementing compensating controls
Why D: When a legacy system cannot be patched due to vendor end-of-life, the most appropriate initial risk response is to implement compensating controls. Compensating controls, such as network segmentation, strict access controls, or an intrusion detection system, reduce the likelihood or impact of exploitation without requiring a patch. This approach balances operational necessity with security, as immediate decommissioning (avoidance) may be infeasible for a critical system.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.