mediumMultiple Choice
CRISC Practice Question: A company has implemented an automated control…
A company has implemented an automated control monitoring system that generates alerts when transactions exceed predefined thresholds. The system has been in production for six months. The risk team notices that the number of alerts has been decreasing, while actual control failures have remained constant. Which of the following is the MOST likely cause?
⚠ Common exam trap
CRISC often tests the misconception that fewer alerts automatically means better control effectiveness, when in fact a degraded data feed can mask ongoing control failures and produce a false sense of security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The data feed from transaction systems has degraded, causing missing data
A decreasing alert volume with constant control failures strongly suggests the monitoring system is no longer receiving complete transaction data, so fewer transactions are evaluated and fewer threshold breaches are detected. A degraded data feed (missing or delayed records) would suppress alerts without any real improvement in control effectiveness. This is a classic monitoring integrity issue: the control may still be failing at the same rate, but the detection mechanism is blind to it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Employees have learned to bypass the monitoring system
Why it's wrong here
Deliberate bypass would typically alter failure or alert patterns inconsistently, and the stem gives no evidence of evasion; failures remained constant while alerts fell. It is tempting because insider circumvention is a known risk, but the correct explanation is threshold or monitoring configuration drift, not employee behaviour.
- ✗
The control effectiveness has improved significantly
Why it's wrong here
Improved control effectiveness would reduce actual failures, yet the stem states failures remained constant, so the alert decline cannot reflect genuine improvement. It is tempting because fewer alerts superficially suggest stronger controls, but the correct explanation is threshold drift or monitoring coverage gaps that suppress detection without changing underlying failure rates.
- ✓
The data feed from transaction systems has degraded, causing missing data
Why this is correct
A degraded data feed means fewer transactions reach the monitoring engine, so fewer threshold breaches are detected even though genuine control failures continue unchanged. The falling alert count reflects missing input data rather than improved control effectiveness, explaining the divergence from the constant failure rate.
- ✗
The thresholds were automatically adjusted to be more restrictive
Why it's wrong here
Tightening thresholds would increase alerts, not decrease them, so this contradicts the observed decline. It is tempting because threshold changes plausibly affect alert volume, but the direction is wrong; the correct cause is thresholds loosened or widened, or monitoring scope reduced, suppressing alerts while failures stay constant.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.