Courseiva

CRISC Information Technology and Security Practice Question

A power utility must comply with NERC CIP standards. Which of the following is a key requirement under these standards?

⚠ Common exam trap

The trap is selecting a well-known OT standard (IEC 62443) or a trendy technology (AI) as a NERC CIP requirement — candidates must recognize that NERC CIP is a prescriptive, region-specific regulatory framework with its own defined controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identifying and securing Critical Cyber Assets (CCAs)

NERC CIP (Critical Infrastructure Protection) standards require utilities to identify and protect Critical Cyber Assets (CCAs) — later evolved into BES Cyber Systems — that support the reliable operation of the Bulk Electric System. Identification, categorization, and implementation of security controls for these assets is a foundational requirement across the CIP standards (CIP-002 through CIP-014).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implementing IEC 62443 for all control systems

    Why it's wrong here

    IEC 62443 is an ISA/IEC industrial automation security standard, not a NERC CIP requirement; CIP mandates its own CIP-002 through CIP-014 control families. It is tempting because IEC 62443 genuinely applies to OT environments, but a power utility complying with NERC CIP must implement the CIP standards themselves.

  • ✓

    Identifying and securing Critical Cyber Assets (CCAs)

    Why this is correct

    NERC CIP requires utilities to identify and protect Critical Cyber Assets supporting the bulk electric system, forming the basis for subsequent controls. This directly satisfies the standard's core obligation to catalogue and secure assets whose compromise could disrupt reliable power delivery.

  • ✗

    Deploying AI for threat detection

    Why it's wrong here

    NERC CIP prescribes specific controls such as electronic security perimeters, patch management and personnel risk assessment for bulk electric system assets; AI threat detection is not among them. It is tempting because AI genuinely aids security monitoring, but the standards mandate defined baseline controls rather than emerging detection technologies.

  • ✗

    Using only air-gapped networks

    Why it's wrong here

    NERC CIP permits controlled, monitored connections between trusted networks; it mandates Electronic Security Perimeters with specific controls, not universal air gaps. Air-gapping is tempting because it eliminates network-borne attacks entirely, and suits isolated generation control systems where no external data exchange is required.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.