Courseiva

CRISC Information Technology and Security Practice Question

An organization is deploying a large number of IoT sensors in a smart building project. The sensors are from multiple vendors and some have limited firmware update capabilities. Which of the following risks should be the PRIMARY concern for the risk manager?

⚠ Common exam trap

CRISC often tests the distinction between a security risk (unpatchable vulnerabilities) and operational/compliance concerns (interoperability, sovereignty, power) — candidates pick the most visible issue rather than the one with the greatest residual risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Inability to patch vulnerabilities in legacy IoT devices

IoT devices with limited or no firmware update capability represent an unpatched, persistent attack surface that cannot be remediated through normal vulnerability management — this is the primary risk because it is both high-likelihood and difficult to mitigate. Unlike interoperability or power issues, unpatchable firmware means known CVEs remain exploitable for the device's entire lifecycle, and IoT devices are frequently recruited into botnets (e.g., Mirai). For a risk manager, the inability to patch is the foundational risk that amplifies all others.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Data sovereignty of sensor data stored in the cloud

    Why it's wrong here

    Firmware patching limits create exploitable vulnerabilities across many unmanaged endpoints, which outweighs data-residency concerns. Sovereignty matters when sensor telemetry crosses jurisdictional borders or faces regulatory storage mandates, but here the dominant exposure is unpatched devices forming a broad attack surface.

  • ✓

    Inability to patch vulnerabilities in legacy IoT devices

    Why this is correct

    Limited firmware update capability means discovered vulnerabilities cannot be remediated, leaving flaws exploitable indefinitely across many vendor devices. This unpatched exposure is the primary risk, since other concerns such as physical tampering or data volume are secondary to permanently unpatchable attack surface.

  • ✗

    Interoperability issues between different sensor protocols

    Why it's wrong here

    Interoperability issues cause integration friction and possible data gaps, but they are addressable through gateways and protocol translation. It is tempting because multi-vendor deployments genuinely raise compatibility risk, yet the primary concern is unpatched firmware exposing exploitable vulnerabilities across the whole sensor estate.

  • ✗

    High energy consumption of sensors

    Why it's wrong here

    Energy consumption affects operating cost and battery life, not the confidentiality, integrity, or availability of building systems. It is tempting because thousands of sensors make power a visible budget line, but the primary concern remains unpatchable firmware leaving exploitable devices across the network.

About these practice questions

Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.