CRISC IT Risk Assessment Practice Question
A multinational manufacturer is assessing the risk of a ransomware attack on its operational technology (OT) network. The risk team has identified that the OT network is segmented from the corporate IT network, but a shared jump server allows administrators to move between them. The team must determine the MOST significant factor that could increase the likelihood of ransomware spreading from IT to OT. Which factor should they prioritize?
⚠ Common exam trap
The trap here is focusing on endpoint weaknesses like legacy systems or missing antivirus, while overlooking the architectural connectivity that enables lateral movement across network boundaries.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The presence of the shared jump server
The shared jump server acts as a bridge between the segmented IT and OT networks. If ransomware compromises the IT environment, the jump server provides a direct path to the OT network, effectively negating the segmentation. This makes it the most significant factor increasing the likelihood of cross-network spread. Other factors like legacy systems and missing antivirus affect impact or vulnerability but do not create the initial pathway.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The lack of antivirus software on OT endpoints
Why it's wrong here
Antivirus software can help detect and block malware, but many OT environments intentionally avoid it due to performance and compatibility concerns. The absence of antivirus increases the potential impact once malware arrives, but it does not increase the likelihood of the malware reaching OT from IT. The jump server is the factor that creates the pathway, making it the most significant for likelihood.
- ✗
The frequency of security awareness training for IT staff
Why it's wrong here
Security awareness training reduces the chance of phishing and other initial compromise vectors, but it does not address the specific risk of lateral movement from IT to OT. Even well-trained staff can be compromised. The shared jump server is a structural weakness that directly facilitates the spread of ransomware, making it the priority factor to address.
- ✓
The presence of the shared jump server
Why this is correct
The shared jump server creates a bridge between the corporate IT and OT networks. If an attacker compromises the IT network, they can use the jump server to pivot into the OT environment, bypassing the segmentation. This significantly increases the likelihood of ransomware spreading to OT. The jump server is the most critical factor because it directly enables lateral movement across the security boundary.
- ✗
The OT network's use of legacy operating systems
Why it's wrong here
Legacy operating systems may lack modern security patches and increase vulnerability, but they do not by themselves enable the spread of ransomware from IT to OT. Without a path to reach the OT network, the legacy systems remain isolated. While they are a concern for exploitation, the shared jump server is the primary enabler of cross-network propagation in this scenario.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.