CRISC Information Technology and Security Practice Question
An organization is connecting its industrial control systems (ICS) to the corporate network for real-time data analytics. Which of the following is the PRIMARY risk introduced by this IT/OT convergence?
⚠ Common exam trap
The trap is selecting a consequence (reduced availability) or a non-risk (cost, complexity) instead of the root risk — the expansion of the attack surface to OT systems.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Expansion of the attack surface to OT systems
Connecting ICS/OT systems to the corporate IT network exposes previously isolated OT devices to the corporate attack surface, allowing threats that compromise IT to pivot into OT. This expansion of the attack surface is the primary risk of IT/OT convergence because OT systems often lack security controls and cannot be easily patched. The other options are secondary or not risks at all.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reduced availability of OT systems
Why it's wrong here
Reduced availability is a consequence of successful attacks rather than the primary risk itself; convergence exposes OT to corporate-network threats and lateral movement. It is tempting because availability is the OT priority, and it would be the correct answer if the question asked about the impact of a realised attack.
- ✗
Higher cost of network equipment
Why it's wrong here
Higher equipment cost is a financial consideration, not the primary risk; convergence exposes ICS to corporate-network threats and lateral movement. It is tempting because convergence does require additional network hardware, and it would be correct if the question asked about a budgetary impact rather than a risk.
- ✓
Expansion of the attack surface to OT systems
Why this is correct
Connecting ICS to the corporate network exposes OT devices to enterprise-originated threats, expanding the attack surface. Previously isolated industrial protocols and controllers become reachable, enabling lateral movement from compromised corporate endpoints into operational technology, which directly satisfies the stem's IT/OT convergence scenario and its primary risk.
- ✗
Increased complexity of data analytics
Why it's wrong here
Increased analytics complexity is an implementation challenge, not a risk introduced by convergence; the primary risk is expanded attack surface enabling lateral movement into OT. It is tempting because analytics drives the convergence, and it would be correct if the question asked about a project difficulty rather than a security risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.