CRISC Information Technology and Security Practice Question
Which of the following is a characteristic of IoT devices that increases cybersecurity risk?
⚠ Common exam trap
The trap here is that candidates may equate 'standardized protocols' or 'automatic updates' with risk, when in fact those are generally risk-reducing; the exam tests whether you recognize that resource constraints — not standards — are the inherent IoT weakness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Limited processing power for security features
IoT devices are frequently constrained by cost, size, and power, which limits CPU, memory, and battery. This directly restricts their ability to run strong encryption, host-based firewalls, secure boot, or frequent patching, expanding the attack surface. Limited processing power is therefore a structural characteristic that elevates cybersecurity risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Built-in hardware security modules
Why it's wrong here
Hardware security modules store and protect cryptographic keys, which reduces risk rather than increasing it. They are the correct choice when a device must perform secure key operations resistant to extraction. The stem asks for a characteristic that raises exposure, so a risk-reducing control cannot satisfy it.
- ✓
Limited processing power for security features
Why this is correct
Constrained CPUs and memory prevent IoT devices from running robust encryption, patching, or intrusion detection, so security controls are weakened or omitted. This processing limitation directly widens the attack surface, satisfying the stem's characteristic that increases cybersecurity risk.
- ✗
Standardized communication protocols
Why it's wrong here
Standardised protocols let devices interoperate and are widely reviewed, which lowers rather than raises risk. They are the correct choice when heterogeneous devices must communicate reliably. The stem asks for a characteristic that increases exposure, so an interoperability enabler does not satisfy it.
- ✗
Regular automatic firmware updates
Why it's wrong here
Automatic firmware updates patch known vulnerabilities, lowering rather than raising exposure. They are the right answer when a fleet must stay current without manual intervention. The stem seeks a characteristic that increases cybersecurity risk, so a mitigating maintenance mechanism fails the requirement.
About these practice questions
This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.