nerdexam
Isaca

CRISC · Question #463

Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?

The correct answer is D. Visibility into all networked devices. To effectively assess IoT risk exposure, an organization must first have comprehensive visibility into all IoT devices connected to its network.

Submitted by suresh_in· Apr 18, 2026IT Risk Assessment

Question

Which of the following is MOST important when identifying an organization's risk exposure associated with Internet of Things (loT) devices?

Options

  • ADefined remediation plans
  • BManagement sign-off on the scope
  • CManual testing of device vulnerabilities
  • DVisibility into all networked devices

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    14% (3)
  • D
    76% (16)

Why each option

To effectively assess IoT risk exposure, an organization must first have comprehensive visibility into all IoT devices connected to its network.

ADefined remediation plans

Defined remediation plans are crucial for managing risks after they have been identified, but they cannot be created without first understanding the full scope of devices and their vulnerabilities.

BManagement sign-off on the scope

Management sign-off on the scope is important for governance but does not, by itself, provide the technical information needed to identify actual risk exposure of IoT devices.

CManual testing of device vulnerabilities

Manual testing of device vulnerabilities is a valuable technique but is only effective for devices that have already been identified and brought into scope, and it may not scale for a large number of IoT devices.

DVisibility into all networked devicesCorrect

Comprehensive visibility into all networked IoT devices is paramount because unknown or unmonitored devices cannot be protected or assessed for vulnerabilities. Without full visibility, an organization cannot identify its complete attack surface, making it impossible to accurately determine risk exposure or implement effective security measures.

Concept tested: IoT device inventory and visibility

Topics

#IoT Security#Asset Management#Risk Identification#Network Visibility

Community Discussion

No community discussion yet for this question.

Full CRISC Practice