Courseiva
Information Technology and SecurityhardMultiple ChoiceObjective-mapped

CRISC Information Technology and Security Practice Question

A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?

⚠ Common exam trap

It's easy for candidates to choose upgrading protocols (Option C) as the 'best practice' without considering the operational availability constraints of legacy ICS environments, where a unidirectional gateway provides a non-disruptive security layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a unidirectional gateway that enforces one-way data flow

A unidirectional gateway (data diode) enforces one-way data flow from the ICS to the corporate IT network, preventing any inbound traffic that could exploit the legacy protocols' lack of authentication. This maintains operational availability because the ICS remains isolated from direct network attacks while still providing real-time data access. It is the only option that addresses the authentication gap without disrupting legacy system operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement a unidirectional gateway that enforces one-way data flow

    Why this is correct

    A unidirectional gateway prevents external threats from entering the ICS while allowing data export, preserving availability.

  • Deploy a host-based intrusion detection system on each ICS device

    Why it's wrong here

    Host-based IDS on legacy devices may not be compatible and could impact performance.

  • Upgrade the ICS to modern protocols with built-in authentication

    Why it's wrong here

    Upgrading legacy ICS may be costly and cause downtime, potentially affecting availability.

  • Disconnect the ICS from the corporate network and use manual data transfer

    Why it's wrong here

    Manual transfer would eliminate real-time access, reducing operational efficiency.

About these practice questions

This CRISC question is part of Courseiva's 983-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.