CRISC Information Technology and Security Practice Question
An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?
⚠ Common exam trap
CRISC often tests prioritization of security risk over operational or strategic risk, so candidates who pick vendor lock-in or bandwidth issues mistake business/performance concerns for the most pressing security exposure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Expanded attack surface with unpatched devices
IoT sensors with limited processing power that cannot be easily patched represent a classic expanded attack surface with unpatched devices. Each unpatched sensor is a potential entry point into the network, and the sheer number of devices multiplies the risk. Because patching is infeasible, compensating controls (network segmentation, monitoring, least privilege) become critical, making this the priority risk for the risk manager.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vendor lock-in to proprietary protocols
Why it's wrong here
Vendor lock-in concerns long-term protocol portability, not the immediate exposure created by unpatched, low-power devices. It is tempting because proprietary protocols do constrain future options, but the priority here is the exploitable attack surface from unpatchable sensors, which outweighs strategic lock-in.
- ✓
Expanded attack surface with unpatched devices
Why this is correct
Unpatchable, low-power IoT sensors each expose services that attackers can reach, so every added device widens the exploitable footprint. Prioritising this expanded attack surface with unpatched devices addresses the constraint that firmware cannot be remediated easily across the remote facility.
- ✗
Insufficient bandwidth for data transmission
Why it's wrong here
Bandwidth insufficiency affects data delivery performance, not the security exposure of unpatchable devices. It is tempting because remote facilities often have constrained links, but the stem emphasises limited processing power and inability to patch, pointing to vulnerability exploitation rather than throughput.
- ✗
Data integrity issues from sensor malfunction
Why it's wrong here
Sensor malfunction causing data integrity issues is an availability and accuracy concern, not the primary risk from unpatchable, resource-constrained devices. It is tempting because integrity matters for environmental data, but the stem's emphasis on patching limitations points to compromise of vulnerable sensors.
Go deeper
Related to this question
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.