Courseiva

CRISC Information Technology and Security Practice Question

A power utility subject to NERC CIP standards is planning to deploy a new SCADA system. Which of the following requirements is MOST likely mandated by NERC CIP?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Establishment of an electronic security perimeter around critical cyber assets

NERC CIP standards require identification and protection of critical cyber assets, including clear boundaries (electronic security perimeters) to control access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Establishment of an electronic security perimeter around critical cyber assets

    Why this is correct

    NERC CIP requires responsible entities to define and protect an Electronic Security Perimeter enclosing critical cyber assets, controlling all electronic access points into the bulk electric system environment. This is a mandated CIP-005 control, unlike generic measures such as encryption or patching, which are not perimeter-specific.

  • ✗

    Adoption of a cloud-based backup solution

    Why it's wrong here

    NERC CIP mandates specific controls for bulk electric system cyber assets, such as electronic security perimeters and patch management; it does not require cloud-based backup, which introduces third-party risk the standards restrict. Cloud backup is tempting because it addresses availability and disaster recovery, and would suit organisations without CIP's on-premises custody obligations.

  • ✗

    Use of quantum-resistant encryption for all communications

    Why it's wrong here

    NERC CIP prescribes current cryptographic protections for operational technology communications, not quantum-resistant algorithms, which remain largely standardised-in-progress and unimplemented in CIP requirements. Quantum-resistant encryption is tempting because it future-proofs long-lived grid infrastructure against harvest-now-decrypt-later attacks, making it a sensible strategic choice outside mandated compliance baselines.

  • ✗

    Implementation of IEC 62443 security levels

    Why it's wrong here

    NERC CIP defines its own prescriptive control families and requirement numbering; IEC 62443 is an international industrial-automation security standard, not the framework CIP audits against. IEC 62443 is tempting because it provides maturity-based security levels tailored to OT environments, and would be the right reference for a manufacturer seeking voluntary OT hardening.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.