CRISC Information Technology and Security Practice Question
An energy company is integrating its IT network with OT systems for real-time monitoring. The risk manager is assessing the expanded attack surface. Which risk should be given the HIGHEST priority due to its potential for physical consequences?
⚠ Common exam trap
CRISC often tests the IT vs OT risk distinction, and candidates commonly default to familiar IT risks (malware, DoS, financial system access) — the trap is failing to recognize that OT risks are prioritized by physical safety and equipment consequences, not data confidentiality.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Manipulation of operational parameters leading to equipment damage
When IT and OT networks are integrated, the highest-priority risk is one with physical consequences. Manipulation of operational parameters (e.g., changing setpoints, valve positions, or PLC logic) can directly cause equipment damage, safety incidents, or environmental harm — consequences unique to OT environments. This makes it the top priority because the potential for physical impact elevates severity beyond typical IT risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increased number of malware infections
Why it's wrong here
Malware infections primarily degrade data confidentiality and availability across IT assets, lacking a direct pathway to manipulate physical process control. It is tempting because infections spread quickly across converged networks, but the question prioritises risks producing physical consequences, which require manipulation of OT control commands.
- ✗
Unauthorized access to corporate financial systems
Why it's wrong here
Financial system compromise causes monetary and data loss, not physical process disruption, because those systems are separated from operational control loops. It is tempting as a high-impact corporate risk, but the stem demands the risk with physical consequences, which only manipulation of OT control commands delivers.
- ✓
Manipulation of operational parameters leading to equipment damage
Why this is correct
Manipulating operational parameters can drive actuators, valves or turbines beyond safe limits, producing physical destruction or safety incidents rather than mere data loss. That direct kinetic consequence outranks confidentiality or availability risks when integrating IT with OT for real-time monitoring.
- ✗
Denial of service affecting IT services
Why it's wrong here
Denial of service affecting IT services disrupts business applications, not the physical process, since IT outages do not directly command field devices. It is tempting because availability loss feels severe, but the stem prioritises physical consequences, which arise from compromised OT control rather than IT service interruption.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.