Courseiva

CRISC Information Technology and Security Practice Question

A power utility is integrating its industrial control system (ICS) with the corporate IT network to enable real-time operational data access. The risk manager identifies that the ICS uses legacy proprietary protocols without authentication. Which risk treatment option best addresses this issue while maintaining operational availability?

⚠ Common exam trap

It's easy for candidates to choose upgrading protocols (Option C) as the 'best practice' without considering the operational availability constraints of legacy ICS environments, where a unidirectional gateway provides a non-disruptive security layer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a unidirectional gateway that enforces one-way data flow

A unidirectional gateway (data diode) enforces one-way data flow from the ICS to the corporate IT network, preventing any inbound traffic that could exploit the legacy protocols' lack of authentication. This maintains operational availability because the ICS remains isolated from direct network attacks while still providing real-time data access. It is the only option that addresses the authentication gap without disrupting legacy system operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement a unidirectional gateway that enforces one-way data flow

    Why this is correct

    A unidirectional gateway permits data to flow only from the ICS outward to corporate IT, physically preventing inbound commands or protocol exploitation. This isolates the unauthenticated legacy protocols while preserving real-time operational data access, satisfying the availability constraint without modifying the control system.

  • ✗

    Deploy a host-based intrusion detection system on each ICS device

    Why it's wrong here

    A host-based IDS only detects and alerts on malicious activity; it cannot authenticate the legacy proprietary protocol traffic, so the missing-authentication risk remains untreated. Host-based detection suits environments where endpoint compromise monitoring is the goal, not where protocol-level authentication must be added while preserving availability.

  • ✗

    Upgrade the ICS to modern protocols with built-in authentication

    Why it's wrong here

    Upgrading ICS protocols to authenticated versions requires replacing legacy field devices and controllers, causing outages incompatible with continuous power operations. Protocol modernisation is the right long-term treatment during planned plant refurbishment, but it cannot address the immediate integration risk while maintaining operational availability.

  • ✗

    Disconnect the ICS from the corporate network and use manual data transfer

    Why it's wrong here

    Disconnecting the ICS eliminates the real-time operational data access the integration exists to deliver, so it fails the availability requirement in the stem. Air-gapping with manual transfer is a valid risk treatment where no real-time connectivity is needed, such as isolated safety systems, but not here.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.