CRISC Information Technology and Security Practice Question
A risk manager is assessing IT/OT convergence risks at a manufacturing plant. Which TWO of the following are primary risks introduced by connecting industrial control systems to the corporate network?
⚠ Common exam trap
CRISC often tests whether candidates can distinguish primary security risks (attack path expansion, legacy vulnerabilities) from operational or financial impacts (efficiency, storage costs) or benefits (simplified remote access), so the trap is selecting non-risk items as primary risks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attack path expansion from IT to OT
Option A (Attack path expansion from IT to OT) is correct because bridging the corporate network with industrial control systems creates a conduit through which IT-side threats—such as compromised business workstations, phishing footholds, or lateral-movement tools like PsExec—can pivot into OT environments that were previously air-gapped or isolated behind a DMZ, dramatically widening the adversary's reachable attack surface. Option D (Legacy system vulnerabilities exposed) is correct because many ICS/SCADA devices and protocols (e.g., Modbus, DNP3, older Siemens/Rockwell PLCs) were designed without authentication, encryption, or patchability, so once reachable from corporate subnets their unpatched CVEs become exploitable in ways that were not possible under physical segmentation. Option B is not a primary convergence risk—convergence is typically pursued to improve efficiency through better data visibility and analytics, not to reduce it. Option C is incorrect because increased data storage costs are an incidental IT budgeting concern, not a security risk introduced by IT/OT connectivity. Option E is incorrect because simplified remote access is generally a business benefit of convergence (enabling remote monitoring and diagnostics), even though it must be secured; it is not itself a primary risk introduced by the connection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Attack path expansion from IT to OT
Why this is correct
Bridging IT and OT networks creates a traversable route from the corporate estate into control systems. An attacker who compromises an office workstation can pivot laterally to operational technology, satisfying the stem's requirement to identify a primary convergence risk.
- ✗
Reduced operational efficiency
Why it's wrong here
Reduced operational efficiency is a potential consequence of poor integration or of security incidents, not a primary risk introduced by connecting ICS to corporate networks. The primary risks are expanded attack surface, lateral movement and loss of process availability. Efficiency loss would be the correct concern in a process-optimisation review.
- ✗
Increased data storage costs
Why it's wrong here
Storage cost is a financial and capacity consideration, unrelated to the security and availability threats that convergence creates for industrial control systems. The primary risks are unauthorised access, malware propagation and disruption of physical processes. Storage growth would matter in a data-retention or archiving discussion, not an OT risk assessment.
- ✓
Legacy system vulnerabilities exposed
Why this is correct
Industrial control systems often run unsupported operating systems and unpatched firmware that cannot be updated without halting production. Connecting them to the corporate network exposes those latent vulnerabilities to enterprise-wide threats, satisfying the stem's requirement to identify a primary IT/OT convergence risk.
- ✗
Simplified remote access
Why it's wrong here
Simplified remote access is a business benefit of convergence, not a risk introduced by it. The actual risks are expanded attack surface, lateral movement from corporate networks into control systems, and loss of OT availability. Remote access simplification would be cited as a justification for a convergence project, not as a threat.
Visual reference
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.