Courseiva

CRISC Information Technology and Security Practice Question

A manufacturing company is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. What is the most significant risk arising from this IT/OT convergence?

⚠ Common exam trap

CRISC often tests the distinction between operational risks (e.g., bandwidth, storage) and strategic risks (e.g., expanded attack surface), and candidates may choose a technical impact over the broader security risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Expanded attack surface from IT to OT systems

Expanded attack surface from IT to OT systems. Connecting ICS/OT networks to corporate IT networks creates a bridge that allows threats to move laterally from IT into OT environments. Historically, OT networks were air-gapped or highly segmented, but IT/OT convergence introduces new entry points and attack vectors, significantly increasing the risk of cyberattacks that can disrupt physical industrial processes. This is the most significant risk because it can lead to safety incidents, production outages, and physical damage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduced network bandwidth for OT operations

    Why it's wrong here

    Bandwidth contention is a performance concern, not the dominant risk. The real exposure is that flat connectivity lets IT-side threats pivot into OT, where unpatched controllers and safety systems cannot tolerate compromise. Bandwidth monitoring would be the focus when sizing links between segregated OT zones, not when justifying convergence risk.

  • ✓

    Expanded attack surface from IT to OT systems

    Why this is correct

    Linking ICS to the corporate network exposes operational technology to threats previously confined to IT, expanding the attack surface across both domains. This satisfies the stem's convergence scenario, where compromised corporate endpoints or lateral movement can now reach industrial control systems directly.

  • ✗

    Increased data storage costs

    Why it's wrong here

    Storage cost is a financial by-product, not the significant risk. Convergence exposes ICS to lateral movement from the corporate estate, threatening physical processes and safety. Storage sizing would be the correct consideration when planning retention for historian telemetry volumes, not when assessing IT/OT convergence exposure.

  • ✗

    Loss of proprietary control protocols

    Why it's wrong here

    Proprietary protocols remain in use on the OT segment regardless of corporate connectivity, so their loss is not the convergence risk; the real exposure is IT-borne malware and unauthorised access reaching ICS. It is tempting because protocol interoperability genuinely matters, and would be correct when integrating heterogeneous ICS equipment.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.