CRISC IT Risk Identification Practice Question
A risk manager at a healthcare organization is identifying risks related to the use of Internet of Medical Things (IoMT) devices. The organization has a large number of legacy devices that cannot be patched. Which of the following is the MOST significant risk factor to consider when assessing the risk of a ransomware attack?
⚠ Common exam trap
The trap here is focusing on easily fixable vulnerabilities like default passwords while overlooking the systemic risk created by unpatched devices on a flat network.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The devices are connected to the network without segmentation.
The most significant risk factor is the lack of network segmentation, which allows ransomware to spread from vulnerable IoMT devices to critical systems. Legacy devices that cannot be patched are inherently risky, but segmentation can contain the impact. Other factors like default passwords or vendor diversity are important but can be addressed more readily than architectural segmentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The devices are connected to the network without segmentation.
Why this is correct
Unsegmented networks allow ransomware to spread laterally from IoMT devices to critical systems. Legacy devices that cannot be patched are vulnerable, and without segmentation, they become entry points for attackers. This significantly increases the likelihood and impact of a ransomware attack, making it the most significant risk factor in this scenario.
- ✗
The devices generate a large volume of data that is stored indefinitely.
Why it's wrong here
Data volume and retention affect privacy and storage costs but do not directly increase ransomware risk. Ransomware targets availability and extortion; large data volumes might increase impact if exfiltrated, but the primary risk is the unpatched, unsegmented devices enabling spread. This factor is less significant than network segmentation.
- ✗
The devices use default administrative passwords that are rarely changed.
Why it's wrong here
Default passwords are a serious vulnerability, but they can be mitigated through password changes. In contrast, unpatched legacy devices cannot be remediated, and without network segmentation, they pose a persistent risk. While default passwords increase likelihood, the inability to patch combined with lack of segmentation is more significant.
- ✗
The devices are manufactured by various vendors with different security standards.
Why it's wrong here
Vendor diversity can complicate patch management and security consistency, but it is not the most significant factor for ransomware risk. The critical issue is that legacy devices cannot be patched and are on a flat network, which directly enables ransomware propagation. Vendor diversity is a secondary concern.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.