IsacaIsaca
CRISC · Question #362
CRISC Question #362: Real Exam Question with Answer & Explanation
Sign in or unlock CRISC to reveal the answer and full explanation for question #362. The question stem and answer options stay visible for context.
Submitted by fernanda_arg· Apr 18, 2026IT Risk Assessment
Question
Which of the following should a risk practitioner do NEXT after learning that Internet of Things (loT) devices installed in the production environment lack appropriate security controls for sensitive data?
Options
- AAssess the threat and associated impact.
- BEvaluate risk appetite and tolerance levels
- CRecommend device management controls
- DEnable role-based access control.
Unlock CRISC to see the answer
You've previewed enough free CRISC questions. Unlock CRISC for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#Risk assessment process#Threat identification#Impact analysis#IoT security