easyMultiple Choice
CRISC Practice Question: A company implements a new automated control to…
A company implements a new automated control to monitor user access rights. The control sends a daily report of any users with excessive privileges. What is the PRIMARY benefit of this control?
⚠ Common exam trap
A common mix-up: candidates confuse 'automated reporting' with 'real-time alerting' or assume that automation completely replaces manual processes, but the question specifically describes a daily report, which is a detective control focused on timely (not immediate) remediation, not a preventive or real-time control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enables timely remediation of access violations
The primary benefit of an automated control that sends a daily report of users with excessive privileges is that it enables timely remediation of access violations. By providing a regular, scheduled summary of privilege anomalies, the control allows the IT security team to investigate and revoke unauthorized access within a defined timeframe (e.g., 24 hours), reducing the window of exposure. This aligns with the principle of continuous monitoring and rapid response, which is critical for minimizing risk from privilege creep or misconfigured roles.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enables timely remediation of access violations
Why this is correct
Daily reporting of users holding excessive privileges lets the team identify and revoke inappropriate access promptly, shrinking the exposure window. This satisfies the primary benefit sought: timely remediation of access violations before they can be exploited.
- ✗
Reduces the number of user access reviews
Why it's wrong here
The report surfaces excessive privileges daily, which typically increases the volume and frequency of reviews rather than reducing them. It changes who and what is reviewed, not how many reviews occur. Fewer reviews would follow only if the control itself remediated access, which it does not.
- ✗
Eliminates the need for manual checks
Why it's wrong here
The control still requires someone to review the daily report and remediate excessive privileges, so manual checks continue. It automates detection, not the review process itself. Elimination of manual checks would only hold if the tool auto-revoked rights, which the stem does not state.
- ✗
Provides real-time alerts for critical changes
Why it's wrong here
The control produces a daily report, so alerts arrive on a scheduled cadence rather than in real time. Real-time alerting would be correct if the requirement were immediate notification of critical privilege changes as they occur, not a periodic summary of excessive rights.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.