CRISC Information Technology and Security Practice Question
An organization is deploying IoT devices in a smart building. Which of the following are significant security risks associated with IoT? (Choose THREE.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Firmware update challenges due to device diversity
IoT risks include expanded attack surface, legacy device security gaps, and firmware update challenges.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Firmware update challenges due to device diversity
Why this is correct
Smart buildings mix devices from many vendors with differing firmware formats and update mechanisms, so no single patching process applies. This diversity makes timely firmware remediation impractical, leaving vulnerabilities unaddressed and directly constituting the update challenge the scenario identifies.
- ✓
Legacy device security gaps from unpatched vulnerabilities
Why this is correct
Many IoT devices ship with outdated firmware and lack vendor patching, leaving known vulnerabilities exploitable long after disclosure. In a smart building these unpatched devices become persistent footholds, directly creating the legacy security gap the scenario's risk assessment must capture.
- ✗
Increased power consumption
Why it's wrong here
Power draw is an operational cost and capacity concern, not a security risk; IoT threats centre on weak authentication, unpatched firmware and unencrypted traffic. It is tempting because always-on devices genuinely consume more electricity, so the option would fit a facilities or energy-management question rather than a security risk assessment.
- ✗
Higher data transmission speeds
Why it's wrong here
Throughput is a performance characteristic, not a vulnerability; faster links do not themselves expose data. It is tempting because high-bandwidth IoT telemetry strains network capacity and monitoring, so the option would be relevant to a bandwidth-planning or network-design question rather than one asking about security risks.
- ✓
Expanded attack surface due to many connected devices
Why this is correct
Each connected IoT device adds endpoints, protocols and management interfaces that attackers can probe, multiplying entry points beyond traditional IT boundaries. This proliferation across a smart building directly expands the attack surface, satisfying the scenario's requirement to identify significant IoT security risks.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.