Courseiva
easyMultiple Choice

CRISC Practice Question: A company has implemented a new control to detect…

A company has implemented a new control to detect unauthorized access attempts. What is the PRIMARY purpose of monitoring this control?

⚠ Common exam trap

Candidates often confuse the purpose of monitoring a control (verifying its effectiveness) with the purpose of the control itself (detecting or preventing incidents), leading candidates to choose a benefit like audit evidence or risk calculation instead.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To confirm the control is working effectively.

The primary purpose of monitoring a detective control, such as one that detects unauthorized access attempts, is to confirm that the control is operating effectively as designed. Monitoring provides ongoing assurance that the control is correctly identifying and logging unauthorized access events, which is essential for maintaining the security posture and for timely incident response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To provide evidence for regulatory audits.

    Why it's wrong here

    Audit evidence is a by-product of monitoring, not its purpose; the logs exist to trigger investigation and response to detected attempts. It is tempting because monitoring output does legitimately feed compliance reporting, and in a purely assurance-driven scenario with no response capability, evidence collection would be the objective.

  • ✗

    To reduce the number of unauthorized access attempts.

    Why it's wrong here

    Monitoring observes and alerts on attempts already occurring; it cannot prevent or diminish them, which requires blocking controls such as lockouts or firewall rules. It is tempting because detection feeds remediation, and where a preventive control is already in place, monitoring validates that it is holding attempts down.

  • ✓

    To confirm the control is working effectively.

    Why this is correct

    Monitoring generates evidence about whether the detection control actually identifies unauthorised access attempts as designed, revealing gaps, misconfigurations or failures. This confirms ongoing control effectiveness, which is the primary purpose the stem asks about, rather than merely recording incidents.

  • ✗

    To calculate the residual risk level.

    Why it's wrong here

    Residual risk calculation combines inherent risk with control effectiveness, requiring likelihood and impact data that monitoring alone does not produce. It is tempting because monitoring results do inform control-effectiveness assessments, and in a risk-register review that is precisely the input being sought.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.