Courseiva
mediumMultiple Choice

CRISC Practice Question: A bank's fraud detection system generates an…

A bank's fraud detection system generates an alert for a transaction, but subsequent investigation finds it false. What should be done?

⚠ Common exam trap

It's easy for candidates to assume immediate corrective action (reducing sensitivity) is best, but CRISC emphasizes data-driven decision-making and documentation before making control changes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the false positive for trend analysis.

Documenting false positives enables trend analysis to identify patterns in detection logic errors, such as rule misconfigurations or data quality issues. This aligns with the CRISC domain of risk and control monitoring, where logging and analyzing false alerts improves detection accuracy over time without prematurely adjusting thresholds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the false positive for trend analysis.

    Why this is correct

    Documenting the false positive builds a record for trend analysis, letting the bank tune detection thresholds and reduce recurring noise. This satisfies the need to improve fraud detection accuracy over time rather than treating each alert in isolation.

  • ✗

    Report to the board.

    Why it's wrong here

    Escalating one investigated false positive to the board bypasses the operational tuning and documentation process; boards govern risk appetite, not individual alert outcomes. It is tempting because board reporting is expected for significant fraud risk, and it would be correct when false positives reveal a systemic control failure or material risk exposure.

  • ✗

    Ignore future similar alerts.

    Why it's wrong here

    Ignoring similar future alerts suppresses potentially genuine fraud, removing detection coverage without analysis. It is tempting because repeated false positives cause alert fatigue, and dismissing them would be defensible only after documented tuning proves the pattern is consistently benign, not as a blanket response to one false alert.

  • ✗

    Reduce the sensitivity of the detection system.

    Why it's wrong here

    Lowering sensitivity would suppress genuine fraud alerts alongside false positives, increasing missed fraud. It is tempting because tuning thresholds is a legitimate response to alert fatigue, and it would be appropriate where analysis shows the detection rule itself is misconfigured and generating systematic false positives, not for a single investigated false alert.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.