CRISC Information Technology and Security Practice Question
A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?
⚠ Common exam trap
CRISC often tests the distinction between operational risks (e.g., bandwidth, storage) and strategic risks (e.g., expanded attack surface), and candidates may choose a technical impact over the broader security risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Expanded attack surface from IT to OT systems
Expanded attack surface from IT to OT systems. Connecting ICS/OT networks to corporate IT networks creates a bridge that allows threats to move laterally from IT into OT environments. Historically, OT networks were air-gapped or highly segmented, but IT/OT convergence introduces new entry points and attack vectors, significantly increasing the risk of cyberattacks that can disrupt physical industrial processes. This is the most significant risk because it can lead to safety incidents, production outages, and physical damage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduced network bandwidth for OT operations
Why it's wrong here
Bandwidth contention is a performance concern, not the dominant risk. The real exposure is that flat connectivity lets IT-side threats pivot into OT, where unpatched controllers and safety systems cannot tolerate compromise. Bandwidth monitoring would be the focus when sizing links between segregated OT zones, not when justifying convergence risk.
- ✓
Expanded attack surface from IT to OT systems
Why this is correct
Linking ICS to the corporate network exposes operational technology to threats previously confined to IT, expanding the attack surface across both domains. This satisfies the stem's convergence scenario, where compromised corporate endpoints or lateral movement can now reach industrial control systems directly.
- ✗
Increased data storage costs
Why it's wrong here
Storage cost is a financial by-product, not the significant risk. Convergence exposes ICS to lateral movement from the corporate estate, threatening physical processes and safety. Storage sizing would be the correct consideration when planning retention for historian telemetry volumes, not when assessing IT/OT convergence exposure.
- ✗
Loss of proprietary control protocols
Why it's wrong here
Proprietary protocols remain in use on the OT segment regardless of corporate connectivity, so their loss is not the convergence risk; the real exposure is IT-borne malware and unauthorised access reaching ICS. It is tempting because protocol interoperability genuinely matters, and would be correct when integrating heterogeneous ICS equipment.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.