CRISC Information Technology and Security Practice Question
An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?
⚠ Common exam trap
CRISC often tests the distinction between a security risk (unpatchable vulnerabilities) and operational/compliance concerns (interoperability, sovereignty, power) — candidates pick the most visible issue rather than the one with the greatest residual risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Inability to patch vulnerabilities in legacy IoT devices
IoT devices with limited or no firmware update capability represent an unpatched, persistent attack surface that cannot be remediated through normal vulnerability management — this is the primary risk because it is both high-likelihood and difficult to mitigate. Unlike interoperability or power issues, unpatchable firmware means known CVEs remain exploitable for the device's entire lifecycle, and IoT devices are frequently recruited into botnets (e.g., Mirai). For a risk manager, the inability to patch is the foundational risk that amplifies all others.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Data sovereignty of sensor data stored in the cloud
Why it's wrong here
Firmware patching limits create exploitable vulnerabilities across many unmanaged endpoints, which outweighs data-residency concerns. Sovereignty matters when sensor telemetry crosses jurisdictional borders or faces regulatory storage mandates, but here the dominant exposure is unpatched devices forming a broad attack surface.
- ✓
Inability to patch vulnerabilities in legacy IoT devices
Why this is correct
Limited firmware update capability means discovered vulnerabilities cannot be remediated, leaving flaws exploitable indefinitely across many vendor devices. This unpatched exposure is the primary risk, since other concerns such as physical tampering or data volume are secondary to permanently unpatchable attack surface.
- ✗
Interoperability issues between different sensor protocols
Why it's wrong here
Interoperability issues cause integration friction and possible data gaps, but they are addressable through gateways and protocol translation. It is tempting because multi-vendor deployments genuinely raise compatibility risk, yet the primary concern is unpatched firmware exposing exploitable vulnerabilities across the whole sensor estate.
- ✗
High energy consumption of sensors
Why it's wrong here
Energy consumption affects operating cost and battery life, not the confidentiality, integrity, or availability of building systems. It is tempting because thousands of sensors make power a visible budget line, but the primary concern remains unpatchable firmware leaving exploitable devices across the network.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.