Courseiva
IT Risk Identification →hardMultiple Select

CRISC IT Risk Identification Practice Question

A risk practitioner is performing risk identification for a manufacturing firm that relies on industrial control systems (ICS) to operate assembly lines. The practitioner is cataloging vulnerabilities that could be exploited to disrupt production. Which TWO of the following represent vulnerabilities rather than threats? (Choose two.)

⚠ Common exam trap

The trap here is labeling threat actors or natural hazard events as vulnerabilities, which misdirects treatment toward controlling the attacker or the weather instead of fixing internal weaknesses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Flat network architecture that allows engineering workstations to reach production PLCs without segmentation.

Vulnerabilities are internal weaknesses or conditions that a threat can exploit, such as unpatched PLCs with known flaws and flat network architecture exposing production systems. Threat actors and natural events exist independently and are classified as threats. Correctly separating the two is essential because treatment differs: vulnerabilities are remediated through patching, segmentation, and configuration, while threats are addressed by reducing exposure and improving detection and response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Flat network architecture that allows engineering workstations to reach production PLCs without segmentation.

    Why this is correct

    A flat network that permits engineering workstations to directly reach production PLCs is an architectural weakness. It increases the likelihood that a compromised workstation can pivot to control systems. This is a vulnerability because it is a condition of the environment that can be remediated through segmentation, firewalls, and access controls. It is a classic ICS risk finding, and its identification supports design changes that reduce the blast radius of an incident.

  • ✗

    A severe storm causing extended power loss to the manufacturing plant.

    Why it's wrong here

    A severe storm is a natural threat or hazard event, not a vulnerability. It exists independently of the organization's controls. The firm can mitigate its effects through backup power, but it cannot remove the storm from the threat landscape. Classifying natural events as vulnerabilities distorts risk identification and can cause the practitioner to overlook the actual internal weaknesses that determine how much damage the storm would cause.

  • ✗

    A nation-state group conducting reconnaissance against critical manufacturing infrastructure.

    Why it's wrong here

    A nation-state group is a threat actor, and its reconnaissance is threat activity, not a vulnerability. Threats are external or internal actors and events with the potential to cause harm. The firm cannot patch or configure away a nation-state group; it can only reduce exposure created by its own weaknesses. Confusing threat actors with vulnerabilities leads to misdirected treatment plans that attempt to control the attacker rather than the internal condition.

  • ✗

    Ransomware operators targeting industrial organizations for extortion payments.

    Why it's wrong here

    Ransomware operators are threat actors, and their targeting is a threat, not a vulnerability. The organization cannot eliminate the existence of ransomware groups; it can only reduce the weaknesses those groups exploit. Treating this as a vulnerability would mislead the risk register and produce ineffective treatment. The correct handling is to pair this threat with the actual weaknesses, such as unpatched PLCs or flat networks, to form complete risk scenarios.

  • ✓

    Unpatched programmable logic controllers (PLCs) running firmware with known remote code execution flaws.

    Why this is correct

    Unpatched PLCs with known remote code execution flaws are a weakness in the environment that an attacker could exploit. This is a vulnerability because it is an internal condition, not an external actor or event. It directly affects the ICS attack surface and production continuity, so it belongs in the vulnerability catalog. Identifying it enables prioritization of patching or compensating controls such as network segmentation and monitoring.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.