Courseiva

CRISC Information Technology and Security Practice Question

An organization is deploying a large number of Internet of Things (IoT) sensors for environmental monitoring in a remote facility. The sensors have limited processing power and cannot be patched easily. Which risk should the risk manager prioritize?

⚠ Common exam trap

CRISC often tests prioritization of security risk over operational or strategic risk, so candidates who pick vendor lock-in or bandwidth issues mistake business/performance concerns for the most pressing security exposure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Expanded attack surface with unpatched devices

IoT sensors with limited processing power that cannot be easily patched represent a classic expanded attack surface with unpatched devices. Each unpatched sensor is a potential entry point into the network, and the sheer number of devices multiplies the risk. Because patching is infeasible, compensating controls (network segmentation, monitoring, least privilege) become critical, making this the priority risk for the risk manager.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vendor lock-in to proprietary protocols

    Why it's wrong here

    Vendor lock-in concerns long-term protocol portability, not the immediate exposure created by unpatched, low-power devices. It is tempting because proprietary protocols do constrain future options, but the priority here is the exploitable attack surface from unpatchable sensors, which outweighs strategic lock-in.

  • ✓

    Expanded attack surface with unpatched devices

    Why this is correct

    Unpatchable, low-power IoT sensors each expose services that attackers can reach, so every added device widens the exploitable footprint. Prioritising this expanded attack surface with unpatched devices addresses the constraint that firmware cannot be remediated easily across the remote facility.

  • ✗

    Insufficient bandwidth for data transmission

    Why it's wrong here

    Bandwidth insufficiency affects data delivery performance, not the security exposure of unpatchable devices. It is tempting because remote facilities often have constrained links, but the stem emphasises limited processing power and inability to patch, pointing to vulnerability exploitation rather than throughput.

  • ✗

    Data integrity issues from sensor malfunction

    Why it's wrong here

    Sensor malfunction causing data integrity issues is an availability and accuracy concern, not the primary risk from unpatchable, resource-constrained devices. It is tempting because integrity matters for environmental data, but the stem's emphasis on patching limitations points to compromise of vulnerable sensors.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.