Courseiva

CRISC Information Technology and Security Practice Question

A manufacturing company is evaluating the risks of connecting its OT network to the IT network. Which THREE risks are MOST significant due to IT/OT convergence?

⚠ Common exam trap

CRISC often tests the misconception that IT/OT convergence is primarily a compliance or cost issue — the exam expects you to recognize that safety, physical damage, and expanded attack paths are the dominant risks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Expansion of attack paths from IT to OT systems

Option A is correct because IT/OT convergence creates bridges between previously isolated environments, allowing attackers who compromise IT systems (e.g., via phishing or unpatched enterprise apps) to pivot laterally into OT networks and reach industrial control systems. Option B is correct because many OT devices such as PLCs, RTUs, and HMIs run legacy operating systems and proprietary protocols (e.g., Modbus, DNP3) with no authentication, encryption, or patch support, making them inherently vulnerable once exposed to IT-side threats. Option D is correct because compromised OT systems can directly manipulate physical processes—causing equipment damage, production outages, or safety incidents that endanger personnel, which is a uniquely severe consequence not present in pure IT breaches. Option C is not a convergence-specific risk; GDPR governs personal data protection and is largely irrelevant to OT process control data. Option E is incorrect because data storage costs are a general IT operational concern, not a significant security or safety risk arising from IT/OT convergence.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Expansion of attack paths from IT to OT systems

    Why this is correct

    Interconnecting IT and OT exposes previously isolated industrial control systems to IT-borne threats, letting attackers pivot from compromised business hosts into operational technology. This expanded attack surface is the direct consequence of convergence described in the stem.

  • ✓

    Legacy OT devices lacking modern security controls

    Why this is correct

    Many OT devices run unpatched firmware and lack authentication or encryption, so they cannot be hardened like IT endpoints. Connecting them to IT removes the air gap that previously compensated for these missing controls, directly satisfying the stem's convergence risk.

  • ✗

    Compliance with GDPR

    Why it's wrong here

    GDPR governs personal data of EU individuals; OT telemetry from sensors and PLCs is machine data, so the regulation does not drive the convergence risk profile. GDPR compliance is the correct consideration when IT systems process EU personal data, not when linking plant-floor control networks to enterprise IT.

  • ✓

    Potential for physical damage and safety incidents

    Why this is correct

    OT systems drive physical processes, so a successful intrusion can manipulate actuators or halt production, causing equipment damage or injury. This safety consequence is unique to IT/OT convergence and satisfies the stem's manufacturing risk scenario.

  • ✗

    Increased data storage costs

    Why it's wrong here

    Storage cost is a capacity-planning concern, not a convergence risk; OT telemetry volumes are modest and predictable. The significant risks are safety, availability and lateral movement into control systems, where IT security weaknesses reach physical processes. Cost tracking belongs in budget reviews, not OT/IT risk assessments.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.